The operations
Every operation needs a bearer token with the
partners permission. Access Manager resolves your tenant from the token. There is no tenant field in the path or in the body, and you never see the partners of another tenant.
To learn which restrictions a product accepts, read its scope catalog with GET /v1/scope-catalog/{product}.
The partner fields
The response also carries
id, applicationsCount, createdAt, and updatedAt.
Rules that apply to the fields:
productis a product slug from List Available Applications, such asmidaz.actionsare lowercase HTTP verbs:get,post,put,patch,delete.headcomes withget.- The wildcard
*is not accepted inresourcesoractions. List the values. - A product in
scopemust also be inpermissions. - Midaz requires one
organizationIdfor each partner with Midaz permissions. A dimension that the catalog does not mark as multi-valued takes one value only. - Access Manager does not check that the
valuesexist in the product. Use the IDs that the product’s own API returns. statenever readsexpired. AftervalidUntil, the partner still readsactive, with avalidUntilin the past.
The IP allowlist field
ipAllowlist has three meanings on PATCH, and they are not the same:
On
POST, omit the field or send null to use your tenant’s list. A partner’s own list replaces your tenant’s list. It does not add to it.
validFrom and validUntil work in a similar way on PATCH: omit a bound to keep it, send an instant to set it, or send null to remove it.
Examples
Replace the placeholders with your Identity API base URL, a bearer token that holds the
partners permission, and IDs from your own Midaz organization.
Issue the partner’s credentials
A partner without an application cannot call anything. After you create the partner:
- Create an application with Create an Application, and send the partner’s
idinpartnerId. Setnameto the product slug, such asmidaz. Create one application per product. - Copy
clientIdandclientSecretfrom the response. The response is the only time the secret is shown. - Send both values to the partner through a secure channel.
id in the partnerId query parameter of List Applications. If partnerId does not name a partner of your tenant, both operations return 404 with IDE-1046, and nothing is created.
Change, suspend, or delete a partner
- On
PATCH, send only the fields you change. Apermissionsor ascopelist replaces the stored list as a whole. Read the partner first, then send the complete new list. - To suspend a partner, send
"state": "suspended". To reactivate it, send"state": "active". - A change applies from the partner’s next request. A suspension also refuses tokens that the partner already holds.
- You cannot delete a partner that still has applications. The response is
409withIDE-1049, and itserrorslist names each blocking application with its client ID. Delete those applications first.
Error codes
Errors in the partner operations:
Errors a partner’s own system receives:
For every other code, see the Access Manager error list.

