Skip to content
POST
/v1/organizations/{organizationId}/projects/{projectId}/environments/{environmentId}/surface-registrations/{surfaceRegistrationId}/tenants/{tenantId}/web-surface-accesses

Admit one browser client to an exact Web Surface route

Create an authority-free ServicePrincipal, its expiring API key, and one revocable transport admission; return the key exactly once.

Authentication

Send an API key as a Bearer token in the Authorization header.

Parameters

NameLocationRequiredDescription
organizationIdpathYes
The Organization to address.
stringA Cantora Organization identifier, prefixed with `org_`.
  • maximum length 64
  • pattern ^org_[\s\S]+$
projectIdpathYes
The Project to address.
stringA Cantora Project identifier, prefixed with `proj_`.
  • maximum length 64
  • pattern ^proj_[\s\S]+$
environmentIdpathYes
The Environment to address.
stringA Cantora Environment identifier, prefixed with `env_`.
  • maximum length 64
  • pattern ^env_[\s\S]+$
surfaceRegistrationIdpathYes
The Environment Surface registration to address.
stringA Cantora Surface registration identifier, prefixed with `surface_`.
  • maximum length 64
  • pattern ^surface_[\s\S]+$
tenantIdpathYes
The Tenant to address.
stringA Cantora Tenant identifier, prefixed with `tenant_`.
  • maximum length 64
  • pattern ^tenant_[\s\S]+$

Request body

Required.

application/json
object
  • unknown properties allowed false
agentPrincipalIdrequired
stringThe Environment Agent this browser client may address.
  • maximum length 64
  • pattern ^principal_[\s\S]+$
creationRequestIdrequired
WebSurfaceAccessCreationRequestIdThe caller-chosen identifier for this exact admission attempt.
  • maximum length 36
  • minimum length 36
  • pattern ^[0-9a-f]{8}-[0-9a-f]{4}-4[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
displayNamerequired
stringThe human-readable name of the browser client ServicePrincipal.
  • maximum length 200
  • minimum length 1

Responses

201WebSurfaceAccessCreated
400The request path, headers, query, or JSON body did not satisfy the published schema
401Unauthorized
application/json
403Forbidden
application/json
404NotFound
application/json
409Conflict
application/json

Reusable schemas

WebSurfaceAccessCreatedEncoded

object
  • unknown properties allowed false
principalIdrequired
stringThe Principal identifier.
  • maximum length 64
  • pattern ^principal_[\s\S]+$
creationRequestIdrequired
WebSurfaceAccessCreationRequestIdThe caller-chosen identifier used to reconcile this creation attempt.
organizationIdrequired
stringThe Organization identifier.
  • maximum length 64
  • pattern ^org_[\s\S]+$
projectIdrequired
stringThe Project identifier.
  • maximum length 64
  • pattern ^proj_[\s\S]+$
environmentIdrequired
stringThe Environment identifier.
  • maximum length 64
  • pattern ^env_[\s\S]+$
tenantIdrequired
stringThe Tenant identifier.
  • maximum length 64
  • pattern ^tenant_[\s\S]+$
surfaceRegistrationIdrequired
stringThe Environment Surface registration identifier.
  • maximum length 64
  • pattern ^surface_[\s\S]+$
agentPrincipalIdrequired
stringThe Environment Agent Principal identifier.
  • maximum length 64
  • pattern ^principal_[\s\S]+$
createdAtrequired
stringWhen the resource was created, in UTC.
  • format date-time
revokedAtrequired
When the resource was revoked, in UTC, or null while it remains active.
  • format date-time
Any of
string
null
apiKeyIdrequired
stringThe identifier of the issued API key.
  • maximum length 64
  • pattern ^apikey_[\s\S]+$
apiKeyrequired
stringThe browser client's credential, returned exactly once and never recoverable from Cantora
expiresAtrequired
stringWhen the resource expires, in UTC, or null when it does not expire.
  • format date-time

UnauthorizedEncoded

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "Unauthorized"
reasonrequired
stringA safe explanation of why the credential was rejected.

ForbiddenEncoded

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "Forbidden"
permissionrequired
stringThe permission required by the refused operation.

NotFoundEncoded

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "NotFound"
resourcerequired
stringThe resource type relevant to the error.
idrequired
stringThe identifier supplied for the resource that was not found.

ConflictEncoded

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "Conflict"
resourcerequired
stringThe resource type relevant to the error.
reasonrequired
stringA safe explanation of the state conflict.

WebSurfaceAccessCreationRequestId

string
  • maximum length 36
  • minimum length 36
  • pattern ^[0-9a-f]{8}-[0-9a-f]{4}-4[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$