The identity and technical contract details declared by the specification.
AccountExtensionCreateRequest
AccountPermissions
string
MANAGELOGGING: Permission to manage logging integrations, and enable/disable error logging. MANAGEAUTH: Permission to manage SSO and password policy. MANAGEWOR…
AccountPurpose
Describes the purpose of the account.
AccountPurposeVariantStandard
AccountPurposeVariantAccountReplication
AccountPurposeType
The purpose of the account (minus any configuration-related details).
AccountPurposeTypeVariantStandard
AccountPurposeTypeVariantAccountReplication
AccountReplicationConfiguration
AccountReplicationConnection
AccountReplicationScanSettings
AgreeKeyMechanism
string
Options to use for key agreement mechanism.
Algorithm
string
A cryptographic algorithm.
All
string
A helper enum with a single variant, All, which indicates that something should apply to an entire part. (This is here mainly to allow other untagged enums to…
AppAccountRoleDescriptorVariantSystemDefined
AppAccountRoleDescriptorVariantCustom
AppGroupRoleDescriptorVariantSystemDefined
AppGroupRoleDescriptorVariantCustom
AppOauthConfig
OAuth settings for an app. If enabled, an app can request to act on behalf of a user.
AppOauthConfigVariantEnabled
AppOauthConfigVariantDisabled
AppPermissions
string
Operations allowed to be performed by an app. SIGN: VERIFY: ENCRYPT: DECRYPT: WRAPKEY: UNWRAPKEY: DERIVEKEY: MACGENERATE: MACVERIFY: EXPORT: MANAGE: AGREEKEY:…
AppRole
string
App's role.
ApprovalRequestSettingsRequest
ApprovalStatus
string
Approval request status.
ApprovalSubject
Identifies an object acted upon by an approval request.
AttestationConveyancePreference
string
If you really want to understand attestation, read the following: This enum just specified how the attestation should be conveyed to the RP. You can see doc of…
AuthMethodOauthAuthCodeGrant
AuthMethodVariantPassword
AuthMethodVariantSamlPost
AuthMethodVariantOauthAuthCodeGrant
AuthMethodVariantLdapPassword
AuthRequestMethodSamlResponse
AuthRequestMethodLdapBasicAuth
AuthRequestMethodAuthByAppName
AuthRequestMethodPassword
AuthRequestMethodVariantSamlResponse
AuthRequestMethodVariantOauthAuthCode
AuthRequestMethodVariantLdapBasicAuth
AuthRequestMethodVariantAuthByAppName
AuthRequestMethodVariantAwsIam
AuthRequestMethodVariantPassword
AuthenticationExtensionsClientInputs
AuthenticationExtensionsClientOutputs
AuthenticatorAssertionResponse
AuthenticatorAttachment
string
AuthenticatorAttestationResponse
AuthenticatorSelectionCriteria
AuthenticatorTransport
Hints by relying party on how client should communicate with the authenticator. https://www.w3.org/TR/webauthn-2/enum-transport
AuthenticatorTransportInner
string
See [AuthenticatorTransport] type.
AwsKeyOrigin
string
Origin of the AWS KMS key. See the [AWS documentation](https://docs.aws.amazon.com/kms/latest/APIReference/APIKeyMetadata.htmlKMS-Type-KeyMetadata-Origin) for…
AwsKeyRotationStatusKeyRotationEnabled
AwsKeyRotationStatusVariantKeyRotationDisabled
AwsKeyRotationStatusVariantKeyRotationEnabled
AwsKmsKeyMaterialMapping
string
AwsMultiRegionKeyType
string
Specifies the type of multi-Region keys. https://docs.aws.amazon.com/kms/latest/developerguide/multi-region-keys-overview.htmlmulti-region-concepts
AwskmsService
string
Specifies the AWS service. Only kms is supported for now.
AzureAuthConfigClientSecret
AzureAuthConfigTokenAuthConfig
AzureAuthConfigVariantClientSecret
AzureAuthConfigVariantTokenAuthConfig
AzureCredentialAuthClientSecret
AzureCredentialAuthCertificate
AzureCredentialAuth
Authentication configuration for Azure integrations that use Credential Objects.
AzureCredentialAuthVariantClientSecret
AzureCredentialAuthVariantCertificate
AzureKeyVaultType
string
Types of Azure Key Vault based on the protection level.
AzureLogAnalyticsLoggingConfig
AzureLogAnalyticsLoggingConfigRequest
AzureLogIngestionLoggingConfig
AzureLogIngestionLoggingConfigRequest
BatchExecutionType
string
BatchResponseObjectResult
BatchResponseObjectSkipped
BindToPrincipal
A security principal that a session can be bound to. Eg: When app-1 creates a session that can be validated against app-2's credentials, app-1 specifies app-2'…
Bip32Network
string
The BIP32 network The Testnet network is usually an actual network with nodes and miners, and free cryptocurrency. This provides a testing environment for deve…
BlsVariant
string
Signature/public-key size trade-off for BLS.
CaSet
string
Predefined CA sets.
CertificateReplicationCredential
CipherMode
string
Cipher mode used for symmetric key algorithms.
ClientConfigurationsRequest
ClientFileLoggingVariantEnabled
ClientFileLoggingVariantDisabled
CountAccuracy
An indicator of how accurate a count of objects is.
CountAccuracyVariantExact
CountAccuracyVariantApproximate
CreateReplicationCredentialRequest
A request to create a new admin app credential for account replication purposes. Note that the result is not immediately usable; further steps are needed in or…
CreateReplicationCredentialRequestVariantCertificate
CredentialDetails
Describes the authentication type for a given integration. This type is the "backbone" to the credential objects in DSM as it's what contains the relevant info…
CredentialDetailsVariantOci
CredentialDetailsVariantAzure
CredentialId
A wrapper type to provide better clarity that the id referenced is an integration credential object.
CryptMode
CipherMode or RsaEncryptionPadding, depending on the encryption algorithm.
CustomAttributeSearchMetadata
DeriveKeyMechanismBip32MasterKey
DeriveKeyMechanismBip32HardenedChild
DeriveKeyMechanismSlip10HardenedChild
DeriveKeyMechanism
Mechanism to be used when deriving a new key from an existing key.
DigestAlgorithm
string
A hash algorithm.
EffectiveKeyOperations
string
Operations allowed to be performed on a given key by a given User or an app SIGN: If this is set, the key can be used for signing. VERIFY: If this is set, the…
EllipticCurve
string
Identifies a standardized elliptic curve.
EsStatsCountQueryResponse
ExportPolicyVariantWrapped
ExportPolicyVariantUnrestricted
ExportSobjectComponentsRequest
ExternalEntropySourceInfo
ExternalKeyIdAzureKeyVault
ExternalKeyId
Identification information for an external key. There are multiple variants of this type to represent the different kinds of keys DSM supports (e.g., AWS, Azur…
ExternalKmsInfo
Information about a specific external KMS key object.
ExternalKmsInfoVariantAWS
ExternalKmsInfoVariantOci
ExternalRoleKind
string
Type of an external role.
Fido2MfaChallengeResponse
Fido2 options when requesting assertion or attestation to a device
FpeCharSet
The alphabet to use for an encrypted portion of a complex tokenization data type. Characters should be specified as a list of pairs, where each pair [a, b] rep…
FpeCompoundPart
Structure of a compound portion of a complex tokenization data type, itself composed of smaller parts.
FpeConstraintsApplicability
A structure indicating which subparts to which to apply a set of constraints.
FpeDataPart
Structure for specifying (part of) a complex tokenization data type.
FpeDate
A structure for specifying a token part representing a date that occurs after a specified date and/or occurs before a specified date. Depending on the subparts…
FpeDateConstraint
Possible date-related constraint types for a portion of a complex tokenization data type.
FpeDatePart
string
Possible date-related constraint types that do not form a complete date (by themselves) for a complex tokenization data type.
FpeInputDefaultProcessing
string
FpeInputProcessingPassthroughSpecific
FpeInputProcessing
Options to apply some pre- and post-processing to the input.
FpeOptions
FPE-specific options (for specifying the format of the data to be encrypted)
FpePreserveMask
A structure indicating which indices in an encrypted part to mask or preserve.
FpeTokenizeMode
string
How to tokenize a given input. The most secure option is "PreserveFormat".
FpeWords
A set of fixed-length strings.
GcpAppPermissions
string
CRYPTOSPACEGETINFO: CRYPTOSPACEGETPUBLICKEY:
GetUserPermissionsResponse
GoogleAccessReason
string
An access reason provided by Google when making EKMS API calls.
GoogleServiceAccountCredential
GroupPermissions
string
CREATEGROUPAPPROVALPOLICY: Permission to create group-level approval policy. Note that updating/deleting the approval policy is protected by the approval polic…
HmgConfigFortanixFipsCluster
HmgConfigVariantAwsCloudHsm
HmgConfigVariantFortanixFipsCluster
HmgConfigVariantAzureKeyVault
HmgConfigVariantGcpKeyRing
HmgListKeyCollectionsRequest
HmgListKeyCollectionsRequestVariantOciVault
HmgListKeyCollectionsResponseOciKeyVault
HmgListKeyCollectionsResponse
HmgListKeyCollectionsResponseVariantOciKeyVault
HmgRedundancyScheme
string
The scheme for determining how multiple HmgConfigs on a group should behave. If not specified, the backend will go through the list in random order, and use th…
ImportSobjectComponentsRequest
IntegrationCredentialCreateRequest
IntegrationCredentialRotationRequest
IntegrationCredentialUpdateRequest
IpAddressPolicy
The IPs that are allowed for an application. ipv4 or ipv6 both are acceptable types.
KcvMethod
string
Methods for calculating a Key Checksum Value.
KeyAttestationStatementFormat
string
KeyCreationMethod
Information about the method by which a key was created
KeyCreationMethodVariantGenerate
KeyCreationMethodVariantAgree
KeyCreationMethodVariantTransform
KeyCreationMethodVariantDerive
KeyCreationMethodVariantUnwrap
KeyCreationMethodVariantImport
KeyCreationMethodVariantEncapsulate
KeyCreationMethodVariantDecapsulate
KeyExpiryAlertConfigRequest
KeyExpiryAlertSiemToolConfig
KeyExpiryAlertTriggerVariantDaysAhead
KeyFormat
string
Key Format
KeyOperations
string
Operations allowed to be performed on a given key. SIGN: If this is set, the key can be used to for signing. VERIFY: If this is set, the key can used for verif…
Language
string
Language of plugin code.
LastAppOperationTimestamp
LdapAccountRole
Role of a user or app in an account for the purpose of LDAP configurations.
LdapDnResolutionConstruct
LdapDnResolution
Distinguished Name (DN) resolution method. Given a user's email address, a DN resolution method is used to find the user's DN in an LDAP directory.
LdapDnResolutionVariantConstruct
LdapDnResolutionVariantSearchByMail
LdapDnResolutionVariantUserPrincipalName
LdapRoleConflictResolution
string
Controls how we resolve conflicting role assignments with LDAP authorization. When users are authorized through LDAP, their DSM group memberships are determine…
LdapUserSelfProvisioningConfig
LdapUserSelfProvisioningRoleFixed
LdapUserSelfProvisioningRole
A structure indicating how self-provisioned LDAP users will be assigned account roles.
LdapUserSelfProvisioningRoleVariantFixed
LegacyLdapAccountRole
string
Role of a user or app in an account for the purpose of LDAP configurations.
LegacyUserAccountRole
string
Legacy user account role
LegacyUserGroupRole
string
Legacy user group role
LegacyUserGroupRoleOrRoleId
Legacy user group role name or custom role id
ListApprovalRequestsParams
ListAppsResponseWithMetadata
ListAppsResponse
The response of the get all apps API
ListGroupsResponseWithMetadata
ListGroupsResponse
The response of the get all groups API
ListReplicationCredentialsResponse
MetadataDurationConstraintRequired
MetadataDurationConstraint
MetadataStringConstraintRequired
MfaDeviceType
string
Type of MFA device
MfaProtocol
string
Protocols for MFA.
Mgf
Specifies the Mask Generating Function (MGF) to use.
MlDsaModeVariantExternalMu
MlDsaParamSet
string
ML-DSA parameter sets
MlKemParamSet
string
ML-KEM parameter sets
NotificationPref
string
Notification preferences.
OauthAuthParamDisplay
string
Corresponds to the display parameter in https://openid.net/specs/openid-connect-core-10.htmlAuthRequest
OauthAuthParamPrompt
string
Corresponds to the prompt parameter in https://openid.net/specs/openid-connect-core-10.htmlAuthRequest
OauthAuthenticationParameters
OauthScope
string
OAuth scope.
ObjectOrigin
string
The origin of a security object - where it was created / generated.
ObjectType
string
Type of security object.
ObjectTypeFilterSelection
ObjectTypeFilterVariantAll
ObjectTypeFilterVariantSelection
OciCredentialAuthVariantApiKey
OneAppAuthType
string
Authentication method of an app.
OneAppCredential
App authentication mechanisms.
PersistTransientKeyRequest
PluginSource
Plugin code that will be executed inside SGX enclave.
PluginSourceRequestFromRepo
PluginSourceRequestInline
PluginType
string
Type of a plugin.
PolicyDefinitionVariantRego
Principal
A security principal.
PublicKeyCredentialCreationOptions
PublicKeyCredentialDescriptor
PublicKeyCredentialParameters
PublicKeyCredentialRequestOptions
PublicKeyCredentialRpEntity
PublicKeyCredentialType
string
https://www.w3.org/TR/webauthn-2/enum-credentialType This enum defines valid cred types.
PublicKeyCredentialUserEntity
PublishPublicKeyConfigEnabled
PublishPublicKeyConfig
If enabled, the public key will be available publicly (without authentication) through the GetPublicKey API.
PublishPublicKeyConfigVariantEnabled
PublishPublicKeyConfigVariantDisabled
QuorumGroupPermissions
string
Subset of GroupPermissions to represent GroupPermissions flags in use GETSOBJECTS: ROTATESOBJECTS: REVOKESOBJECTS: REVERTSOBJECTS: DELETEKEYMATERIAL: DELETESOB…
ReplicationCredential
Details about the admin app credential used to replicate objects from the source account.
ReplicationCredentialVariantCertificate
ReplicationCredentialId
The ID of a replication credential.
ReplicationCredentialSelfSignedCertRequest
ReplicationCredentialSelfSignedCertResponse
ResidentKeyRequirement
string
Tells Relying Party's requirement about client side discoverable creds (formely known as resident keys). If client side discoverable creds are there, it means…
ReviewerPrincipal
A Principal who can approve or deny an approval request.
RevocationReasonCode
string
Reasons to revoke a security object.
RoleDetailsVariantAccount
RotationMethod
Describes the how to rotate the credential and any additional information that is required for that to happen successfully.
RotationMethodVariantGenerate
RsaEncryptionPadding
Type of padding to use for RSA encryption. The use of PKCS1 v1.5 padding is strongly discouraged, because of its susceptibility to Bleichenbacher's attack. The…
RsaEncryptionPaddingPolicyOaep
RsaEncryptionPaddingPolicy
RSA encryption padding policy.
RsaSignaturePadding
Type of padding to use for RSA signatures. The padding specified must adhere to the key's signature policy. If not specified, the default based on the key's po…
RsaSignaturePaddingPolicyPss
RsaSignaturePaddingPolicy
RSA signature padding policy.
ScanResult
The result of a scan.
SecretCredentialRequestGenerate
ServerMode
string
Server execution mode.
SignatureMode
Signature mechanism
SigningKeys
Signing keys used to validate JSON Web Signature objects including signed JSON Web Tokens.
SigningKeysVariantFetched
SobjectDescriptor
Uniquely identifies a persisted or transient sobject.
SobjectDescriptorPersisted
Uniquely identifies a persisted sobject.
SobjectEncoding
string
Response data encoding.
SobjectId
A wrapper type to provide better clarity that the id referenced is a security object.
SobjectState
string
Security object operational state.
SplittingMethod
string
Method used to split the key into multiple components.
SplunkLoggingConfigRequest
StackdriverLoggingConfigRequest
SubjectGeneral
A GeneralName that can be used as a [subject alternative name][SAN] in a certificate. Today, the directoryName, dNSName, and iPAddress choices are supported. N…
SubscriptionChangeRequest
SubscriptionExperimentalFeatures
SubscriptionFeatures
string
Features in subscription TOKENIZATION: HMG: AWSBYOK: AZUREBYOK: GCPBYOK: GCPEKMCONTROLPLANE: OCIBYOK:
SubscriptionType
Type of subscription.
SyslogLoggingConfigRequest
TlsConfig
TLS client settings.
TlsConfigVariantOpportunistic
TokenType
string
The type of a session token. (The default session token type is Bearer.)
TransformKeyMechanismBip32WeakChild
TransformKeyMechanismSlip10WeakChild
TransformKeyMechanism
Options for mechanism to be used when transforming a key
TrustAnchor
Trust anchors (i.e., root CA certificates) for a [TrustedCaCredential].
TrustAnchorSubject
Subjects or subject alternative names (SANs) for trusted CA auth. DSM will check the subject field and any SANs inside incoming client certificates and compare…
UpdateCertificateReplicationCredentialRequest
UpdateReplicationCredentialRequest
A request to update a replication credential (e.g., associating it with an app ID). Note that changing the credential from one type to another is disallowed; u…
UpdateReplicationCredentialRequestVariantCertificate
UserAccountFlag
string
User account flag
UserAccountFlagOrRole
User account flag or legacy user account role name or custom role id
UserAccountFlags
User's role(s) and state in an account.
UserGroupRole
User's role(s) in a group.
UserVerificationRequirement
string
https://www.w3.org/TR/webauthn-2/enum-userVerificationRequirement https://www.w3.org/TR/webauthn-2/user-verification
WorkspaceCseAuthMethod
string
Authentication method for Google Workspace CSE, User (default choice) requires each CSE user to be registered as a DSM user, while App requires each CSE user t…
WorkspaceCseAuthorizationProvider
WorkspaceCseIdentityProvider
ApprovableResult
object
2 properties
2 required
COSEAlgorithmIdentifier
string
https://www.w3.org/TR/webauthn-2/typedefdef-cosealgorithmidentifier Signing algorithms from [IANA COSE Algorithms registry] that are supported on DSM side for…
PublicKeyCredentialAuthenticatorAssertionResponse
PublicKeyCredentialAuthenticatorAttestationResponse
PublicKeyCredentialEntityForRp
PublicKeyCredentialEntityForUser
RemovableCommonClientConfig
RemovableCryptographicPolicy
RemovableGoogleAccessReasonPolicy
RemovableAutoScanSettings
RemovableKeyHistoryPolicy
RemovableKeyMetadataPolicy
RemovableKmipClientConfig
RemovablePkcs11ClientConfig
RemovablePluginCodeSigningPolicy
RemovableWorkspaceCseConfig
RemovableHmgRedundancyScheme
The HmgRedundancyScheme to set for the group. If unset, the backend will assign no particular meaning to the hsmorder fields of the group's HmgConfigs, and may…
The full machine-readable OpenAPI contract behind this narrative.
Other APIs Fortanix publishes across the network.