Skip to content
GET
/v1/organizations/{organizationId}/projects/{projectId}/environments/{environmentId}/surface-registrations/{surfaceRegistrationId}/tenants/{tenantId}/identity-bindings/{issuer}/{subject}

Read one Surface identity binding

Resolve one provider issuer and subject binding within the Tenant and Surface scope named in the path.

Authentication

Send an API key as a Bearer token in the Authorization header.

Parameters

NameLocationRequiredDescription
organizationIdpathYes
The Organization to address.
string
All of
  • maximum length 64
A Cantora Organization identifier, prefixed with `org_`.
  • pattern ^org_[\s\S]+$
projectIdpathYes
The Project to address.
string
All of
  • maximum length 64
A Cantora Project identifier, prefixed with `proj_`.
  • pattern ^proj_[\s\S]+$
environmentIdpathYes
The Environment to address.
string
All of
  • maximum length 64
A Cantora Environment identifier, prefixed with `env_`.
  • pattern ^env_[\s\S]+$
surfaceRegistrationIdpathYes
The Environment Surface registration to address.
string
All of
  • maximum length 64
A Cantora Surface registration identifier, prefixed with `surface_`.
  • pattern ^surface_[\s\S]+$
tenantIdpathYes
The Tenant to address.
string
All of
  • maximum length 64
A Cantora Tenant identifier, prefixed with `tenant_`.
  • pattern ^tenant_[\s\S]+$
issuerpathYes
The provider-defined identity namespace.
string
All of
  • minimum length 1
  • maximum length 512
  • pattern ^[!-~]+$
subjectpathYes
The provider-defined identity within the issuer.
string
All of
  • minimum length 1
  • maximum length 512
  • pattern ^[!-~]+$

Responses

200SurfaceIdentityBinding
400The request path, headers, query, or JSON body did not satisfy the published schema
401Unauthorized
application/json
403Forbidden
application/json
404NotFound
application/json

Reusable schemas

SurfaceIdentityBindingJsonEncoding

object
  • unknown properties allowed false
organizationIdrequired
stringThe Organization identifier.
All of
  • maximum length 64
A Cantora Organization identifier, prefixed with `org_`.
  • pattern ^org_[\s\S]+$
projectIdrequired
stringThe Project identifier.
All of
  • maximum length 64
A Cantora Project identifier, prefixed with `proj_`.
  • pattern ^proj_[\s\S]+$
environmentIdrequired
stringThe Environment identifier.
All of
  • maximum length 64
A Cantora Environment identifier, prefixed with `env_`.
  • pattern ^env_[\s\S]+$
tenantIdrequired
stringThe Tenant identifier.
All of
  • maximum length 64
A Cantora Tenant identifier, prefixed with `tenant_`.
  • pattern ^tenant_[\s\S]+$
surfaceRegistrationIdrequired
stringThe Environment Surface registration identifier.
All of
  • maximum length 64
A Cantora Surface registration identifier, prefixed with `surface_`.
  • pattern ^surface_[\s\S]+$
providerrequired
stringThe model or Surface provider key.
  • allowed values "slack"
issuerrequired
stringThe provider-defined identity namespace.
All of
  • minimum length 1
  • maximum length 512
  • pattern ^[!-~]+$
subjectrequired
stringThe provider-defined identity within the issuer.
All of
  • minimum length 1
  • maximum length 512
  • pattern ^[!-~]+$
targetrequired
SurfaceIdentityTargetThe User or Agent Principal this provider identity resolves to.
createdAtrequired
stringWhen the resource was created, in UTC.
  • format date-time

UnauthorizedJsonEncoding

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "Unauthorized"
reasonrequired
stringA safe explanation of why the credential was rejected.

ForbiddenJsonEncoding

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "Forbidden"
permissionrequired
stringThe permission required by the refused operation.

NotFoundJsonEncoding

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "NotFound"
resourcerequired
stringThe resource type relevant to the error.
idrequired
stringThe identifier supplied for the resource that was not found.

SurfaceIdentityTarget

Any of
object
  • unknown properties allowed false
kindrequired
stringWhether the target Principal is a User or Agent.
  • allowed values "user"
principalIdrequired
stringThe Principal identifier.
All of
  • maximum length 64
A Cantora Principal identifier, prefixed with `principal_`.
  • pattern ^principal_[\s\S]+$
object
  • unknown properties allowed false
kindrequired
stringWhether the target Principal is a User or Agent.
  • allowed values "agent"
principalIdrequired
stringThe Principal identifier.
All of
  • maximum length 64
A Cantora Principal identifier, prefixed with `principal_`.
  • pattern ^principal_[\s\S]+$