POST
/v1/organizations/{organizationId}/projects/{projectId}/environments/{environmentId}/surface-registrations/{surfaceRegistrationId}/tenants/{tenantId}/identity-bindingsBind one Surface identity to a User or Agent
Bind one exact provider issuer and subject to a Tenant-scoped User or Agent for a registered Surface.
Authentication
Send an API key as a Bearer token in the Authorization header.
Parameters
Request body
Required.
application/jsonobject- unknown properties allowed
false
issuerrequiredstringThe provider-defined identity namespace.All of- minimum length
1
- maximum length
512
- pattern
^[!-~]+$
- minimum length
subjectrequiredstringThe provider-defined identity within the issuer.All of- minimum length
1
- maximum length
512
- pattern
^[!-~]+$
- minimum length
targetrequired- SurfaceIdentityTargetThe User or Agent Principal this provider identity resolves to.
Responses
201SurfaceIdentityBindingCreatedapplication/json400The request path, headers, query, or JSON body did not satisfy the published schema401Unauthorizedapplication/json403Forbiddenapplication/json404NotFoundapplication/json409Conflictapplication/jsonReusable schemas
SurfaceIdentityBindingCreatedJsonEncoding
object- unknown properties allowed
false
organizationIdrequiredstringThe Organization identifier.All of- maximum length
64
A Cantora Organization identifier, prefixed with `org_`.- pattern
^org_[\s\S]+$
- maximum length
projectIdrequiredstringThe Project identifier.All of- maximum length
64
A Cantora Project identifier, prefixed with `proj_`.- pattern
^proj_[\s\S]+$
- maximum length
environmentIdrequiredstringThe Environment identifier.All of- maximum length
64
A Cantora Environment identifier, prefixed with `env_`.- pattern
^env_[\s\S]+$
- maximum length
tenantIdrequiredstringThe Tenant identifier.All of- maximum length
64
A Cantora Tenant identifier, prefixed with `tenant_`.- pattern
^tenant_[\s\S]+$
- maximum length
surfaceRegistrationIdrequiredstringThe Environment Surface registration identifier.All of- maximum length
64
A Cantora Surface registration identifier, prefixed with `surface_`.- pattern
^surface_[\s\S]+$
- maximum length
providerrequiredstringThe model or Surface provider key.- allowed values
"slack"
- allowed values
issuerrequiredstringThe provider-defined identity namespace.All of- minimum length
1
- maximum length
512
- pattern
^[!-~]+$
- minimum length
subjectrequiredstringThe provider-defined identity within the issuer.All of- minimum length
1
- maximum length
512
- pattern
^[!-~]+$
- minimum length
targetrequired- SurfaceIdentityTargetThe User or Agent Principal this provider identity resolves to.
createdAtrequiredstringWhen the resource was created, in UTC.- format
date-time
- format
UnauthorizedJsonEncoding
object- unknown properties allowed
false
_tagrequiredstringThe stable machine-readable error type.- allowed values
"Unauthorized"
- allowed values
reasonrequiredstringA safe explanation of why the credential was rejected.
ForbiddenJsonEncoding
object- unknown properties allowed
false
_tagrequiredstringThe stable machine-readable error type.- allowed values
"Forbidden"
- allowed values
permissionrequiredstringThe permission required by the refused operation.
NotFoundJsonEncoding
object- unknown properties allowed
false
_tagrequiredstringThe stable machine-readable error type.- allowed values
"NotFound"
- allowed values
resourcerequiredstringThe resource type relevant to the error.idrequiredstringThe identifier supplied for the resource that was not found.
ConflictJsonEncoding
object- unknown properties allowed
false
_tagrequiredstringThe stable machine-readable error type.- allowed values
"Conflict"
- allowed values
resourcerequiredstringThe resource type relevant to the error.reasonrequiredstringA safe explanation of the state conflict.
SurfaceIdentityTarget
Any of
object- unknown properties allowed
false
kindrequiredstringWhether the target Principal is a User or Agent.- allowed values
"user"
- allowed values
principalIdrequiredstringThe Principal identifier.All of- maximum length
64
A Cantora Principal identifier, prefixed with `principal_`.- pattern
^principal_[\s\S]+$
- maximum length
object- unknown properties allowed
false
kindrequiredstringWhether the target Principal is a User or Agent.- allowed values
"agent"
- allowed values
principalIdrequiredstringThe Principal identifier.All of- maximum length
64
A Cantora Principal identifier, prefixed with `principal_`.- pattern
^principal_[\s\S]+$
- maximum length