API HTTPidentity-svc

POST /auth/keys

Crear una API key personal (login reciente; el secreto se muestra una vez)

ImplementadoSin versión del tren todavía· generada desde apps/docs/generated/openapi/identity-svc.json

Página generada desde apps/identity-svc/src/app.aot.ts. No se edita a mano: bun run docs:gen la regenera y bun run docs:check falla si difiere.

POST /auth/keys

Scopes obligatorios y ⊆ permisos actuales del creador; caducidad obligatoria con tope. Una credencial pat no puede crear keys. Sólo se guarda el SHA-256.

Acceso: Bearer de identity con policy resource:api-key:create, con login reciente.

CampoValor
Servicioidentity-svc
operationIdpostAuthKeys
Policy (dec-0118 §3)resource:api-key:create
Tagsidentity

Cuerpo

Requerido: sí.

application/json

{
  "type": "object",
  "required": [
    "name",
    "scopes"
  ],
  "properties": {
    "name": {
      "type": "string",
      "minLength": 1,
      "maxLength": 64
    },
    "scopes": {
      "type": "array",
      "items": {
        "type": "string",
        "minLength": 3,
        "maxLength": 64
      },
      "minItems": 1,
      "maxItems": 64
    },
    "expiresInSeconds": {
      "type": "integer",
      "minimum": 60
    }
  }
}

application/x-www-form-urlencoded

{
  "type": "object",
  "required": [
    "name",
    "scopes"
  ],
  "properties": {
    "name": {
      "type": "string",
      "minLength": 1,
      "maxLength": 64
    },
    "scopes": {
      "type": "array",
      "items": {
        "type": "string",
        "minLength": 3,
        "maxLength": 64
      },
      "minItems": 1,
      "maxItems": 64
    },
    "expiresInSeconds": {
      "type": "integer",
      "minimum": 60
    }
  }
}

multipart/form-data

{
  "type": "object",
  "required": [
    "name",
    "scopes"
  ],
  "properties": {
    "name": {
      "type": "string",
      "minLength": 1,
      "maxLength": 64
    },
    "scopes": {
      "type": "array",
      "items": {
        "type": "string",
        "minLength": 3,
        "maxLength": 64
      },
      "minItems": 1,
      "maxItems": 64
    },
    "expiresInSeconds": {
      "type": "integer",
      "minimum": 60
    }
  }
}

Respuestas

201

Response for status 201

application/json

{
  "type": "object",
  "required": [
    "key",
    "token"
  ],
  "properties": {
    "key": {
      "type": "object",
      "required": [
        "id",
        "name",
        "displayPrefix",
        "scopes",
        "createdAt",
        "expiresAt"
      ],
      "properties": {
        "id": {
          "type": "string",
          "format": "uuid"
        },
        "name": {
          "type": "string"
        },
        "displayPrefix": {
          "type": "string"
        },
        "scopes": {
          "type": "array",
          "items": {
            "type": "string",
            "minLength": 3,
            "maxLength": 64
          },
          "maxItems": 64
        },
        "createdAt": {
          "type": "integer"
        },
        "expiresAt": {
          "type": "integer"
        },
        "lastUsedAt": {
          "type": "integer"
        },
        "revokedAt": {
          "type": "integer"
        }
      }
    },
    "token": {
      "type": "string"
    }
  }
}

400

Problem Details (RFC 9457), status 400. Códigos: IDENTITY_INVALID_INPUT, IDENTITY_RETURN_TO_NOT_ALLOWED, IDENTITY_OIDC_STATE_MISMATCH, IDENTITY_SCOPE_INVALID, IDENTITY_DEVICE_AUTHORIZATION_PENDING, IDENTITY_DEVICE_SLOW_DOWN, IDENTITY_DEVICE_ACCESS_DENIED, IDENTITY_DEVICE_CODE_EXPIRED, IDENTITY_DEVICE_CLIENT_UNKNOWN, IDENTITY_INVITE_INVALID.

application/problem+json

{
  "type": "object",
  "required": [
    "type",
    "title",
    "status",
    "code",
    "retryable",
    "category"
  ],
  "properties": {
    "type": {
      "type": "string"
    },
    "title": {
      "type": "string"
    },
    "status": {
      "type": "number",
      "const": 400
    },
    "code": {
      "type": "string",
      "enum": [
        "IDENTITY_INVALID_INPUT",
        "IDENTITY_RETURN_TO_NOT_ALLOWED",
        "IDENTITY_OIDC_STATE_MISMATCH",
        "IDENTITY_SCOPE_INVALID",
        "IDENTITY_DEVICE_AUTHORIZATION_PENDING",
        "IDENTITY_DEVICE_SLOW_DOWN",
        "IDENTITY_DEVICE_ACCESS_DENIED",
        "IDENTITY_DEVICE_CODE_EXPIRED",
        "IDENTITY_DEVICE_CLIENT_UNKNOWN",
        "IDENTITY_INVITE_INVALID"
      ]
    },
    "detail": {
      "type": "string"
    },
    "instance": {
      "type": "string"
    },
    "retryable": {
      "type": "boolean"
    },
    "category": {
      "type": "string",
      "enum": [
        "transient",
        "permanent",
        "recoverable"
      ]
    }
  },
  "x-styx-media-type": "application/problem+json"
}

401

Problem Details (RFC 9457), status 401. Códigos: unauthenticated, reauth-required, IDENTITY_OIDC_CALLBACK_REJECTED, IDENTITY_TOKEN_EXPIRED, IDENTITY_TOKEN_INVALID, IDENTITY_SESSION_REVOKED, IDENTITY_REFRESH_TOKEN_REUSED, IDENTITY_KEY_INVALID.

application/problem+json

{
  "anyOf": [
    {
      "type": "object",
      "required": [
        "type",
        "title",
        "status",
        "code"
      ],
      "properties": {
        "type": {
          "type": "string"
        },
        "title": {
          "type": "string"
        },
        "status": {
          "type": "number",
          "const": 401
        },
        "code": {
          "type": "string",
          "enum": [
            "unauthenticated",
            "reauth-required"
          ]
        },
        "detail": {
          "type": "string"
        }
      },
      "x-styx-media-type": "application/problem+json"
    },
    {
      "type": "object",
      "required": [
        "type",
        "title",
        "status",
        "code",
        "retryable",
        "category"
      ],
      "properties": {
        "type": {
          "type": "string"
        },
        "title": {
          "type": "string"
        },
        "status": {
          "type": "number",
          "const": 401
        },
        "code": {
          "type": "string",
          "enum": [
            "IDENTITY_OIDC_CALLBACK_REJECTED",
            "IDENTITY_TOKEN_EXPIRED",
            "IDENTITY_TOKEN_INVALID",
            "IDENTITY_SESSION_REVOKED",
            "IDENTITY_REFRESH_TOKEN_REUSED",
            "IDENTITY_KEY_INVALID"
          ]
        },
        "detail": {
          "type": "string"
        },
        "instance": {
          "type": "string"
        },
        "retryable": {
          "type": "boolean"
        },
        "category": {
          "type": "string",
          "enum": [
            "transient",
            "permanent",
            "recoverable"
          ]
        }
      },
      "x-styx-media-type": "application/problem+json"
    }
  ]
}

403

Problem Details (RFC 9457), status 403. Códigos: forbidden, IDENTITY_CSRF_REJECTED, IDENTITY_FORBIDDEN, IDENTITY_SCOPE_EXCEEDS_GRANTS, IDENTITY_KEY_IN_BROWSER_CONTEXT.

application/problem+json

{
  "anyOf": [
    {
      "type": "object",
      "required": [
        "type",
        "title",
        "status",
        "code"
      ],
      "properties": {
        "type": {
          "type": "string"
        },
        "title": {
          "type": "string"
        },
        "status": {
          "type": "number",
          "const": 403
        },
        "code": {
          "type": "string",
          "const": "forbidden"
        },
        "detail": {
          "type": "string"
        }
      },
      "x-styx-media-type": "application/problem+json"
    },
    {
      "type": "object",
      "required": [
        "type",
        "title",
        "status",
        "code",
        "retryable",
        "category"
      ],
      "properties": {
        "type": {
          "type": "string"
        },
        "title": {
          "type": "string"
        },
        "status": {
          "type": "number",
          "const": 403
        },
        "code": {
          "type": "string",
          "enum": [
            "IDENTITY_CSRF_REJECTED",
            "IDENTITY_FORBIDDEN",
            "IDENTITY_SCOPE_EXCEEDS_GRANTS",
            "IDENTITY_KEY_IN_BROWSER_CONTEXT"
          ]
        },
        "detail": {
          "type": "string"
        },
        "instance": {
          "type": "string"
        },
        "retryable": {
          "type": "boolean"
        },
        "category": {
          "type": "string",
          "enum": [
            "transient",
            "permanent",
            "recoverable"
          ]
        }
      },
      "x-styx-media-type": "application/problem+json"
    }
  ]
}

404

Problem Details (RFC 9457), status 404. Códigos: IDENTITY_SESSION_NOT_FOUND, IDENTITY_DEVICE_CODE_UNKNOWN, IDENTITY_KEY_NOT_FOUND, IDENTITY_INVITE_NOT_FOUND.

application/problem+json

{
  "type": "object",
  "required": [
    "type",
    "title",
    "status",
    "code",
    "retryable",
    "category"
  ],
  "properties": {
    "type": {
      "type": "string"
    },
    "title": {
      "type": "string"
    },
    "status": {
      "type": "number",
      "const": 404
    },
    "code": {
      "type": "string",
      "enum": [
        "IDENTITY_SESSION_NOT_FOUND",
        "IDENTITY_DEVICE_CODE_UNKNOWN",
        "IDENTITY_KEY_NOT_FOUND",
        "IDENTITY_INVITE_NOT_FOUND"
      ]
    },
    "detail": {
      "type": "string"
    },
    "instance": {
      "type": "string"
    },
    "retryable": {
      "type": "boolean"
    },
    "category": {
      "type": "string",
      "enum": [
        "transient",
        "permanent",
        "recoverable"
      ]
    }
  },
  "x-styx-media-type": "application/problem+json"
}

409

Problem Details (RFC 9457), status 409. Códigos: IDENTITY_KEY_LIMIT, IDENTITY_INVITE_EXHAUSTED, IDENTITY_ACCOUNT_EXISTS.

application/problem+json

{
  "type": "object",
  "required": [
    "type",
    "title",
    "status",
    "code",
    "retryable",
    "category"
  ],
  "properties": {
    "type": {
      "type": "string"
    },
    "title": {
      "type": "string"
    },
    "status": {
      "type": "number",
      "const": 409
    },
    "code": {
      "type": "string",
      "enum": [
        "IDENTITY_KEY_LIMIT",
        "IDENTITY_INVITE_EXHAUSTED",
        "IDENTITY_ACCOUNT_EXISTS"
      ]
    },
    "detail": {
      "type": "string"
    },
    "instance": {
      "type": "string"
    },
    "retryable": {
      "type": "boolean"
    },
    "category": {
      "type": "string",
      "enum": [
        "transient",
        "permanent",
        "recoverable"
      ]
    }
  },
  "x-styx-media-type": "application/problem+json"
}

410

Problem Details (RFC 9457), status 410. Códigos: IDENTITY_INVITE_EXPIRED.

application/problem+json

{
  "type": "object",
  "required": [
    "type",
    "title",
    "status",
    "code",
    "retryable",
    "category"
  ],
  "properties": {
    "type": {
      "type": "string"
    },
    "title": {
      "type": "string"
    },
    "status": {
      "type": "number",
      "const": 410
    },
    "code": {
      "type": "string",
      "const": "IDENTITY_INVITE_EXPIRED"
    },
    "detail": {
      "type": "string"
    },
    "instance": {
      "type": "string"
    },
    "retryable": {
      "type": "boolean"
    },
    "category": {
      "type": "string",
      "enum": [
        "transient",
        "permanent",
        "recoverable"
      ]
    }
  },
  "x-styx-media-type": "application/problem+json"
}

422

Problem Details (RFC 9457), status 422. Códigos: validation.

application/problem+json

{
  "type": "object",
  "required": [
    "type",
    "title",
    "status",
    "code"
  ],
  "properties": {
    "type": {
      "type": "string"
    },
    "title": {
      "type": "string"
    },
    "status": {
      "type": "number",
      "const": 422
    },
    "code": {
      "type": "string",
      "const": "validation"
    },
    "on": {
      "type": "string"
    },
    "property": {
      "type": "string"
    },
    "detail": {
      "type": "string"
    }
  },
  "x-styx-media-type": "application/problem+json"
}

429

Problem Details (RFC 9457), status 429. Códigos: rate-limited, IDENTITY_RATE_LIMITED.

application/problem+json

{
  "anyOf": [
    {
      "type": "object",
      "required": [
        "type",
        "title",
        "status",
        "code"
      ],
      "properties": {
        "type": {
          "type": "string"
        },
        "title": {
          "type": "string"
        },
        "status": {
          "type": "number",
          "const": 429
        },
        "code": {
          "type": "string",
          "const": "rate-limited"
        },
        "detail": {
          "type": "string"
        }
      },
      "x-styx-media-type": "application/problem+json"
    },
    {
      "type": "object",
      "required": [
        "type",
        "title",
        "status",
        "code",
        "retryable",
        "category"
      ],
      "properties": {
        "type": {
          "type": "string"
        },
        "title": {
          "type": "string"
        },
        "status": {
          "type": "number",
          "const": 429
        },
        "code": {
          "type": "string",
          "const": "IDENTITY_RATE_LIMITED"
        },
        "detail": {
          "type": "string"
        },
        "instance": {
          "type": "string"
        },
        "retryable": {
          "type": "boolean"
        },
        "category": {
          "type": "string",
          "enum": [
            "transient",
            "permanent",
            "recoverable"
          ]
        }
      },
      "x-styx-media-type": "application/problem+json"
    }
  ]
}

500

Problem Details (RFC 9457), status 500. Códigos: IDENTITY_INTERNAL.

application/problem+json

{
  "type": "object",
  "required": [
    "type",
    "title",
    "status",
    "code",
    "retryable",
    "category"
  ],
  "properties": {
    "type": {
      "type": "string"
    },
    "title": {
      "type": "string"
    },
    "status": {
      "type": "number",
      "const": 500
    },
    "code": {
      "type": "string",
      "const": "IDENTITY_INTERNAL"
    },
    "detail": {
      "type": "string"
    },
    "instance": {
      "type": "string"
    },
    "retryable": {
      "type": "boolean"
    },
    "category": {
      "type": "string",
      "enum": [
        "transient",
        "permanent",
        "recoverable"
      ]
    }
  },
  "x-styx-media-type": "application/problem+json"
}

503

Problem Details (RFC 9457), status 503. Códigos: IDENTITY_OIDC_PROVIDER_UNAVAILABLE, IDENTITY_CLIENT_ADDRESS_UNKNOWN, IDENTITY_DEVICE_CAPACITY, IDENTITY_STORE_UNAVAILABLE, IDENTITY_DB_READ_FAILED, IDENTITY_DB_WRITE_FAILED.

application/problem+json

{
  "type": "object",
  "required": [
    "type",
    "title",
    "status",
    "code",
    "retryable",
    "category"
  ],
  "properties": {
    "type": {
      "type": "string"
    },
    "title": {
      "type": "string"
    },
    "status": {
      "type": "number",
      "const": 503
    },
    "code": {
      "type": "string",
      "enum": [
        "IDENTITY_OIDC_PROVIDER_UNAVAILABLE",
        "IDENTITY_CLIENT_ADDRESS_UNKNOWN",
        "IDENTITY_DEVICE_CAPACITY",
        "IDENTITY_STORE_UNAVAILABLE",
        "IDENTITY_DB_READ_FAILED",
        "IDENTITY_DB_WRITE_FAILED"
      ]
    },
    "detail": {
      "type": "string"
    },
    "instance": {
      "type": "string"
    },
    "retryable": {
      "type": "boolean"
    },
    "category": {
      "type": "string",
      "enum": [
        "transient",
        "permanent",
        "recoverable"
      ]
    }
  },
  "x-styx-media-type": "application/problem+json"
}