Skip to main content
This feature is available only in Staging for testing and is not yet available in Production.
The Identity API manages partners and their credentials. Use it when you manage partners from your own tooling instead of the Console.

The operations


Every operation needs a bearer token with the partners permission. Access Manager resolves your tenant from the token. There is no tenant field in the path or in the body, and you never see the partners of another tenant. To learn which restrictions a product accepts, read its scope catalog with GET /v1/scope-catalog/{product}.

The partner fields


The response also carries id, applicationsCount, createdAt, and updatedAt. Rules that apply to the fields:
  • product is a product slug from List Available Applications, such as midaz.
  • actions are lowercase HTTP verbs: get, post, put, patch, delete. head comes with get.
  • The wildcard * is not accepted in resources or actions. List the values.
  • A product in scope must also be in permissions.
  • Midaz requires one organizationId for each partner with Midaz permissions. A dimension that the catalog does not mark as multi-valued takes one value only.
  • Access Manager does not check that the values exist in the product. Use the IDs that the product’s own API returns.
  • state never reads expired. After validUntil, the partner still reads active, with a validUntil in the past.

The IP allowlist field


ipAllowlist has three meanings on PATCH, and they are not the same: On POST, omit the field or send null to use your tenant’s list. A partner’s own list replaces your tenant’s list. It does not add to it. validFrom and validUntil work in a similar way on PATCH: omit a bound to keep it, send an instant to set it, or send null to remove it.

Examples


Replace the placeholders with your Identity API base URL, a bearer token that holds the partners permission, and IDs from your own Midaz organization.

Issue the partner’s credentials


A partner without an application cannot call anything. After you create the partner:
  1. Create an application with Create an Application, and send the partner’s id in partnerId. Set name to the product slug, such as midaz. Create one application per product.
  2. Copy clientId and clientSecret from the response. The response is the only time the secret is shown.
  3. Send both values to the partner through a secure channel.
To list the applications of one partner, send its id in the partnerId query parameter of List Applications. If partnerId does not name a partner of your tenant, both operations return 404 with IDE-1046, and nothing is created.

Change, suspend, or delete a partner


  • On PATCH, send only the fields you change. A permissions or a scope list replaces the stored list as a whole. Read the partner first, then send the complete new list.
  • To suspend a partner, send "state": "suspended". To reactivate it, send "state": "active".
  • A change applies from the partner’s next request. A suspension also refuses tokens that the partner already holds.
  • You cannot delete a partner that still has applications. The response is 409 with IDE-1049, and its errors list names each blocking application with its client ID. Delete those applications first.

Error codes


Errors in the partner operations: Errors a partner’s own system receives: For every other code, see the Access Manager error list.