How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Fortanix Accounts API

The Accounts API from Fortanix — 9 operation(s) for accounts.

Fortanix Accounts API is one of 51 APIs that Fortanix publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Account. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.

This API exposes 18 operations across 9 paths, and defines 252 schemas. It is described by OpenAPI 3.2.0, at version 1.0.

Requests are made against 2 base URLs: https://ccm.fortanix.com, {dsmEndpoint}.

18 operations 9 paths 252 schemas 3 DELETE8 GET3 PATCH4 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.0
Base URL
https://amer.smartkey.io
Authentication
API Key, HTTP Basic, API Key
License
Resource Areas
1

Authentication & Security 3

Fortanix Accounts API declares 3 security schemes for authenticating requests. An API key is passed in the header as Authentication (bearerToken). It accepts HTTP basic authentication (basicAuth). An API key is passed in the header as Authorization (apiKeyAuth).

  • bearerToken — A JWT bearer token to be passed once authenticated.
  • apiKeyAuth — Please enter your token prefixed with 'Basic ' (e.g., 'Basic yourtokenhere')

Paths & Operations 18

Across 9 paths, the API surfaces 18 operations — 3 DELETE, 8 GET, 3 PATCH, 4 POST. Each is listed below with its method, path, parameters, and response codes.

Accounts 18
GET
/v1/accounts
Get all accounts.
getAccounts 4 params → 200
POST
/v1/accounts
Create a new account.
createAccount 1 param → 200
GET
/v1/accounts/{account-id}
Get a specific account.
getAccount 2 params → 200
DELETE
/v1/accounts/{account-id}
Delete an account.
deleteAccount 1 param → 204
PATCH
/v1/accounts/{account-id}
Update an account.
updateAccount 2 params → 200
GET
/sys/v1/accounts/{acct_id}/usage
Get account usage information. See input and output of this API for info on what it can return.
AccountUsage 2 params → 2XX
POST
/sys/v1/accounts
Create a new account.
CreateAccount body → 2XX
GET
/sys/v1/accounts
Get info about all accounts.
ListAccounts 1 param → 2XX
POST
/sys/v1/accounts/{acct_id}/replication/credentials
Create an admin app credential that can be used to perform account replication.
CreateReplicationCredential 1 param body → 2XX
GET
/sys/v1/accounts/{acct_id}/replication/credentials
Retrieve all stored replication credentials under the account.
ListReplicationCredentials 1 param → 2XX
DELETE
/sys/v1/accounts/{acct_id}
Delete an account.
DeleteAccount 1 param → 204
GET
/sys/v1/accounts/{acct_id}
Get info for a specific account.
GetAccount 2 params → 2XX
PATCH
/sys/v1/accounts/{acct_id}
Update account settings such as authentication, logging, etc.
UpdateAccount 1 param body → 2XX
DELETE
/sys/v1/accounts/{acct_id}/replication/credentials/{credential_id}
Delete the specified replication credential.
DeleteReplicationCredential 2 params → 204
GET
/sys/v1/accounts/{acct_id}/replication/credentials/{credential_id}
Retrieve the specified replication credential.
GetReplicationCredential 2 params → 2XX
PATCH
/sys/v1/accounts/{acct_id}/replication/credentials/{credential_id}
Update the specified replication credential.
UpdateReplicationCredential 2 params body → 2XX
GET
/sys/v1/accounts/{acct_id}/replication/recent_scan_summary
Fetch a summary of recent scans.
RecentReplicationScanSummary 1 param → 2XX
POST
/sys/v1/accounts/{acct_id}/replication/credentials/{credential_id}/self_sign
Generate a self-signed cert for the specified credential.
ReplicationCredentialSelfSignedCert 2 params body → 2XX

Schemas 252

The contract defines 252 schemas that model the data the API accepts and returns. The most detailed are Account (14 properties), AccountUpdateRequest (10 properties), AuthConfigOauth (9 properties), AccountRequest (5 properties). Each schema is shown below with its type and property counts.

CaConfig
object
2 properties
AccessRoles
string
Roles of a user.
AuthConfigPassword
object
Configuration for password-based authentication.
2 properties 2 required
TlsConfigRequired
object
4 properties 2 required
AccountRequest
object
5 properties 1 required
AccountUpdateRequest
object
10 properties
AzureCvmPcrPriority
array
Ordered list of exactly the integer elements 0 through 22
AuthConfigRef
object
1 property 1 required
AuthConfigOauth
object
9 properties 8 required
AuthenticationConfig
object
3 properties
CaSet
string
NodeEnrollment
object
1 property 1 required
Account
object
14 properties 3 required
UserAccountStatus
string
Status of an Account for a user.
TlsConfig
object
3 properties
AccountListResponse
object
1 property
ObjectCounts
object
3 properties 3 required
AccountStatus
string
AccountComponent
string
Get the account type.
ClientFileLogging
SigningKeysVariantStored
FpeDate
A structure for specifying a token part representing a date that occurs after a specified date and/or occurs before a specified date. Depending on the subparts…
ApiPath
FpeDataPart
Structure for specifying (part of) a complex tokenization data type.
AccountPurpose
Describes the purpose of the account.
NotificationPref
string
Notification preferences.
CipherMode
string
Cipher mode used for symmetric key algorithms.
CountAccuracy
An indicator of how accurate a count of objects is.
AccountPurposeTypeVariantAccountReplication
TlsConfigVariantOpportunistic
AccountReplicationScanSettings
FpeDayMonthDate
FpeInputProcessing
Options to apply some pre- and post-processing to the input.
CommonClientConfig
RemovableKmipClientConfig
SplunkLoggingConfigRequest
KeyExpiryAlertTrigger
ReplicationCredentialVariantCertificate
SigningKeysStored
CertificateOptionsPolicy
AccountPurposeVariantAccountReplication
Des3OptionsPolicy
ApprovalRequestSettingsRequest
FpeInputProcessingPassthroughSpecific
UpdateReplicationCredentialRequestVariantCertificate
AccountPurposeTypeVariantStandard
AuthConfig
ReplicationScan
CertificateReplicationCredential
KeyExpiryAlertConfig
AuthConfigLdap
ApprovalAuthConfig
TepKeyMapList
LmsOptionsPolicy
AutoScanSettings
LdapRoleConflictResolution
string
Controls how we resolve conflicting role assignments with LDAP authorization. When users are authorized through LDAP, their DSM group memberships are determine…
FpeConstraints
WorkspaceCseIdentityProvider
FpeCompoundPartOr
EcKcdsaOptionsPolicy
OnPremSubscriptionType
SyslogFacility
string
GetAccountParams
LdapUserSelfProvisioningConfig
LegacyKeyPolicy
string
MetadataStringConstraintRequired
TepKeyMap
FpeDayMonthYearDate
MlDsaOptionsPolicy
AccountSort
FpeOptions
FPE-specific options (for specifying the format of the data to be encrypted)
LoggingConfig
CountParams
SubscriptionTypeTrial
DsaOptionsPolicy
KeyHistoryPolicy
SyslogLoggingConfig
AzureLogIngestionLoggingConfigRequest
LegacyUserAccountRole
string
Legacy user account role
UserAccountFlag
string
User account flag
LdapUserSelfProvisioningRole
A structure indicating how self-provisioned LDAP users will be assigned account roles.
FpeSection
CaConfig_2
CA settings.
CryptographicPolicy
FpeMonthYearDate
ClientConfigurationsRequest
FpeVariant
AccountReplicationConfiguration
Bip32OptionsPolicy
FpeDateDayMonthYear
AzureLogIngestionLoggingConfig
ReplicationCredential
Details about the admin app credential used to replicate objects from the source account.
SubscriptionType
Type of subscription.
FpeCompoundPartMultiple
All
string
A helper enum with a single variant, All, which indicates that something should apply to an entire part. (This is here mainly to allow other untagged enums to…
HmacOptionsPolicy
WorkspaceCseAuthorizationProvider
RecentScanSummary
FpeWords
A set of fixed-length strings.
CountAccuracyVariantExact
TepSchemaVariantOpenAPI
GetUsageResponse
KeyOpsOverride
Secs
MetadataDurationConstraint
RestrictedDuration
SeedOptionsPolicy
RsaEncryptionPaddingPolicy
RSA encryption padding policy.
LdapServiceAccount
MgfPolicy
MGF policy.
SigningKeys
Signing keys used to validate JSON Web Signature objects including signed JSON Web Tokens.
RsaSignaturePaddingPolicyPss
ReplicationCredentialSelfSignedCertRequest
TepSchema
FpePreserveMask
A structure indicating which indices in an encrypted part to mask or preserve.
RsaEncryptionPaddingPolicyOaep
RemovableWorkspaceCseConfig
TepKeyContext
string
MlKemOptionsPolicy
AccountReplicationConnection
OpaqueOptionsPolicy
ObjectTypeFilterSelection
MgfPolicyMgf1
LdapDnResolutionVariantUserPrincipalName
CreateReplicationCredentialRequestVariantCertificate
Account_2
AuthConfigVcd
RemovablePkcs11ClientConfig
ObjectCounts_2
MetadataPolicyItem
SyslogLoggingConfigRequest
RemovableCommonClientConfig
AccountPurposeVariantStandard
FpeChecksum
string
FpeGroup
ClientLogConfig
TepClientConfig
LdapAuthorizationConfig
FpeCharSet
The alphabet to use for an encrypted portion of a complex tokenization data type. Characters should be specified as a list of pairs, where each pair [a, b] rep…
EllipticCurve
string
Identifies a standardized elliptic curve.
SubscriptionChangeRequest
FpeFormatV2
OauthAuthenticationParameters
CustomSubscriptionType
DesOptionsPolicy
RemovableTepClientConfig
ObjectTypeFilter
KeyExpiryAlertTriggerVariantDaysAhead
AuthConfigPassword_2
AccountRequest_2
TlsConfigRequired_2
FpeWordsIntegerRanges
AzureLogAnalyticsLoggingConfigRequest
ClientFileLoggingVariantDisabled
QuorumPolicy
RsaSignaturePaddingPolicy
RSA signature padding policy.
LdapDnResolutionConstruct
FpeOptionsV2
ClientConfigurations
FpeDatePart
string
Possible date-related constraint types that do not form a complete date (by themselves) for a complex tokenization data type.
CustomAttributeSearchMetadata
LdapDnResolutionVariantSearchByMail
FpeCompoundPartConcat
GoogleServiceAccountKey
FpeOptionsBasic
ResellerSubscriptionType
SubscriptionFeatures
string
Features in subscription TOKENIZATION: HMG: AWSBYOK: AZUREBYOK: GCPBYOK: GCPEKMCONTROLPLANE: OCIBYOK:
SigningKeysVariantFetched
KeyOperations
string
Operations allowed to be performed on a given key. SIGN: If this is set, the key can be used to for signing. VERIFY: If this is set, the key can used for verif…
SecretOptionsPolicy
RemovablePluginCodeSigningPolicy
StackdriverLoggingConfigRequest
LdapDnResolution
Distinguished Name (DN) resolution method. Given a user's email address, a DN resolution method is used to find the user's DN in an LDAP directory.
AuthConfigOauth_2
SplunkLoggingConfig
ApprovalRequestSettings
KeyMetadataPolicy
ReplicationCredentialSelfSignedCertResponse
FpeCode
AccountApprovalPolicy
ApprovalWaitConfig
CaSet_2
string
Predefined CA sets.
KmipClientConfig
ObjectTypeFilterVariantAll
KeyExpiryAlertConfigRequest
ListReplicationCredentialsResponse
LoggingConfigRequest
LdapUserSelfProvisioningRoleVariantFixed
FreemiumSubscriptionType
WorkspaceCseAuthMethod
string
Authentication method for Google Workspace CSE, User (default choice) requires each CSE user to be registered as a DSM user, while App requires each CSE user t…
TlsConfigVariantDisabled
SigningKeysFetched
FpeConstraintsApplicability
A structure indicating which subparts to which to apply a set of constraints.
AuthConfigSignedJwt
FpeEncryptedPart
ClientFileLoggingConfig
TimeSpan
DaysAhead
StackdriverLoggingConfig
FpeDateConstraint
Possible date-related constraint types for a portion of a complex tokenization data type.
ReplicationCredentialId
The ID of a replication credential.
RemovableCryptographicPolicy
AriaOptionsPolicy
FpeDataPartLiteral
Quorum
PluginCodeSigningPolicy
UserAccountFlags
User's role(s) and state in an account.
Subscription
SubscriptionExperimentalFeatures
Pkcs11ClientConfig
QuorumApprovalConfig
UpdateCertificateReplicationCredentialRequest
OauthAuthParamDisplay
string
Corresponds to the display parameter in https://openid.net/specs/openid-connect-core-10.htmlAuthRequest
FpeDateMonthDay
FpeWordsCustom
ClientFileLoggingVariantEnabled
KcdsaOptionsPolicy
RsaEncryptionPolicy
OauthAuthParamPrompt
string
Corresponds to the prompt parameter in https://openid.net/specs/openid-connect-core-10.htmlAuthRequest
CreateReplicationCredentialRequest
A request to create a new admin app credential for account replication purposes. Note that the result is not immediately usable; further steps are needed in or…
CountAccuracyVariantApproximate
FpeCompoundPart
Structure of a compound portion of a complex tokenization data type, itself composed of smaller parts.
BlsOptionsPolicy
AzureLogAnalyticsLoggingConfig
FpeDateMonthYear
FpeOptionsAdvanced
UserAccountFlagOrRole
User account flag or legacy user account role name or custom role id
AppCreditsUsage
RsaOptionsPolicy
CredentialId
A wrapper type to provide better clarity that the id referenced is an integration credential object.
MetadataStringConstraint
RsaSignaturePolicy
TlsConfigVariantRequired
DigestAlgorithm
string
A hash algorithm.
ObjectType
string
Type of security object.
UpdateReplicationCredentialRequest
A request to update a replication credential (e.g., associating it with an app ID). Note that changing the credential from one type to another is disallowed; u…
ObjectTypeFilterVariantSelection
EcOptionsPolicy
FpeTokenizeMode
string
How to tokenize a given input. The most secure option is "PreserveFormat".
FpeInputDefaultProcessing
string
WorkspaceCseConfig
LdapUserSelfProvisioningRoleFixed
TlsConfig_2
TLS client settings.
RemovableKeyHistoryPolicy
AesOptionsPolicy
MetadataDurationConstraintRequired
Slip10OptionsPolicy
XmssOptionsPolicy
KeyExpiryAlertSiemToolConfig
RemovableKeyMetadataPolicy
LdapDnResolutionVariantConstruct
AccountPurposeType
The purpose of the account (minus any configuration-related details).

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

fortanix-accounts-api-openapi.yml Raw ↑

Other APIs Fortanix publishes across the network.

Fortanix Confidential Computing Manager REST API
Fortanix Account Extensions API
Fortanix Admin API
Fortanix App API
Fortanix Application Config API
Fortanix Approval Requests API
Fortanix Approval Requests API
Fortanix Apps API
Fortanix Auth API
Fortanix Authentication API
Fortanix Batch API
Fortanix Build API
Where this information came from

This is an independent, third-party profile of Fortanix Accounts API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.