Roles
The roles of the management API and the endpoints that accept them, generated
from the backend's role enum and the @Secured decorators of its controllers.
How to assign roles to clients and users is described in
Tenants and access.
A token passes the role check if it carries any of an endpoint's roles.
Most endpoints also act on the tenant in the token and refuse a token without
one, such as the root client's. Without a tenant, tenants:manage works for the
/api/tenant endpoints and for rotating client secrets.
Roles
| Role | Description | Endpoints |
|---|---|---|
presentation:manage | To manage presentation resources | 40 |
presentation:request | To create offers | 12 |
issuance:manage | To manage issuance resources | 54 |
issuance:offer | To create offers | 10 |
clients:manage | To manage client resources | 7 |
users:manage | To manage human users | 5 |
tenants:manage | To manage tenant resources | 21 |
tenant:admin | To manage the current tenant's full configuration | 15 |
registrar:manage | To manage registrar configuration and operations | 16 |
Endpoints
| Method | Path | Accepted roles |
|---|---|---|
| GET | /api/admin/audit-logs | clients:manage |
| DELETE | /api/cache | issuance:manage or presentation:manage |
| GET | /api/cache/stats | issuance:manage or presentation:manage |
| DELETE | /api/cache/status-list | issuance:manage or presentation:manage |
| DELETE | /api/cache/trust-list | issuance:manage or presentation:manage |
| GET, POST | /api/client | clients:manage |
| DELETE, GET, PATCH | /api/client/:id | clients:manage |
| POST | /api/client/:id/rotate-secret | clients:manage or tenants:manage |
| POST | /api/config-bundles/documents/upgrade | tenants:manage or tenant:admin |
| GET | /api/config-bundles/export | tenants:manage or tenant:admin |
| POST | /api/config-bundles/import | tenants:manage or tenant:admin |
| POST | /api/config-bundles/import/archive | tenants:manage or tenant:admin |
| GET | /api/config-bundles/operations | tenants:manage or tenant:admin |
| GET | /api/config-bundles/operations/:id | tenants:manage or tenant:admin |
| POST | /api/config-bundles/operations/:id/acknowledge-interruption | tenants:manage or tenant:admin |
| POST | /api/config-bundles/plan | tenants:manage or tenant:admin |
| POST | /api/config-bundles/plan/archive | tenants:manage or tenant:admin |
| GET | /api/config-bundles/resources | tenants:manage or tenant:admin |
| POST | /api/config-bundles/resources/:kind/:id/detach | tenants:manage or tenant:admin |
| GET | /api/frontend-config | any valid access token |
| GET, POST | /api/issuer/attribute-providers | issuance:manage |
| DELETE, GET, PATCH | /api/issuer/attribute-providers/:id | issuance:manage |
| GET, POST | /api/issuer/config | issuance:manage |
| POST | /api/issuer/config/registration-cert/reissue | issuance:manage |
| GET, POST | /api/issuer/credentials | issuance:manage |
| DELETE, GET, PATCH | /api/issuer/credentials/:id | issuance:manage |
| POST | /api/issuer/deferred/:transactionId/complete | issuance:offer |
| POST | /api/issuer/deferred/:transactionId/fail | issuance:offer |
| POST | /api/issuer/offer | issuance:offer |
| GET, POST | /api/issuer/webhook-endpoints | issuance:manage or presentation:manage |
| DELETE, GET, PATCH | /api/issuer/webhook-endpoints/:id | issuance:manage or presentation:manage |
| GET, POST | /api/key-chain | issuance:manage or presentation:manage |
| DELETE, GET, PUT | /api/key-chain/:id | issuance:manage or presentation:manage |
| GET | /api/key-chain/:id/export | tenants:manage or tenant:admin |
| POST | /api/key-chain/:id/rotate | issuance:manage or presentation:manage |
| POST | /api/key-chain/import | issuance:manage or presentation:manage |
| GET | /api/key-chain/providers | issuance:manage or presentation:manage |
| DELETE, GET, PUT | /api/key-chain/providers/config | tenants:manage or tenant:admin |
| GET | /api/key-chain/providers/health | issuance:manage or presentation:manage |
| POST | /api/registrar/access-certificate | registrar:manage |
| DELETE, GET, PATCH, POST | /api/registrar/config | registrar:manage |
| GET | /api/schema-metadata | registrar:manage |
| GET | /api/schema-metadata/:id | registrar:manage |
| GET | /api/schema-metadata/:id/latest | registrar:manage |
| GET | /api/schema-metadata/:id/versions | registrar:manage |
| DELETE, PATCH | /api/schema-metadata/:id/versions/:version | registrar:manage |
| PATCH | /api/schema-metadata/:id/versions/:version/deprecation | registrar:manage |
| GET | /api/schema-metadata/:id/versions/:version/jwt | registrar:manage |
| GET | /api/schema-metadata/:id/versions/:version/schemas/:format | registrar:manage |
| GET | /api/schema-metadata/mine | registrar:manage |
| POST | /api/schema-metadata/publish | issuance:manage |
| POST | /api/schema-metadata/publish-version | issuance:manage |
| GET | /api/schema-metadata/vocabularies | registrar:manage |
| GET | /api/session | issuance:offer or presentation:request |
| DELETE, GET, PUT | /api/session-config | issuance:manage or presentation:manage |
| DELETE, GET | /api/session/:id | issuance:offer or presentation:request |
| GET | /api/session/:id/events | issuance:offer or presentation:request |
| GET | /api/session/:id/logs | issuance:offer or presentation:request |
| POST | /api/session/revoke | issuance:offer or issuance:manage |
| DELETE, GET, PUT | /api/status-list-config | issuance:manage |
| GET, POST | /api/status-lists | issuance:manage |
| DELETE, GET, PATCH | /api/status-lists/:listId | issuance:manage |
| POST | /api/storage | issuance:manage |
| GET, POST | /api/tenant | tenants:manage |
| DELETE, GET, PATCH | /api/tenant/:id | tenants:manage |
| GET, POST | /api/trust-list | issuance:manage or presentation:manage |
| DELETE, GET, PUT | /api/trust-list/:id | issuance:manage or presentation:manage |
| GET | /api/trust-list/:id/export | issuance:manage or presentation:manage |
| GET | /api/trust-list/:id/versions | issuance:manage or presentation:manage |
| GET | /api/trust-list/:id/versions/:versionId | issuance:manage or presentation:manage |
| GET, POST | /api/user | users:manage |
| DELETE, GET, PATCH | /api/user/:id | users:manage |
| GET | /api/verifier/config | presentation:manage or presentation:request |
| POST | /api/verifier/config | presentation:manage |
| DELETE, PATCH | /api/verifier/config/:id | presentation:manage |
| GET | /api/verifier/config/:id | presentation:manage or presentation:request |
| POST | /api/verifier/config/:id/registration-cert/reissue | presentation:manage |
| POST | /api/verifier/config/issuer-metadata/resolve | presentation:manage or presentation:request |
| GET | /api/verifier/config/schema-metadata/catalog | presentation:manage or presentation:request |
| POST | /api/verifier/config/schema-metadata/resolve | presentation:manage or presentation:request |
| POST | /api/verifier/config/schema-metadata/resolve-jwt | presentation:manage or presentation:request |
| POST | /api/verifier/offer | presentation:request or presentation:manage |
| GET | /api/version | any valid access token |
| POST | /issuers/:tenantId/authorize/interactive/complete-web-auth/:authSession | issuance:offer |