Skip to main content
PUT
Register an AWS delegated grant

Autorizaciones

Authorization
string
header
requerido

A bearer JWT issued by plugin-auth (lib-auth). The tenant identity is resolved from the validated token claims; the /v1 surface never reads a tenant from the body, path, or query. Machine callers obtain a token via the plugin-auth client-credentials flow. The /admin surface authorizes against an operator scope and carries no tenant context.

Encabezados

X-Idempotency
string
requerido

A client-chosen unique key that makes this mutation at-most-once. A mutation sent without it is rejected before any write with 400 missing_idempotency_key. Reusing the same key with an identical request replays the original response byte-for-byte (with X-Idempotency-Replayed: true); reusing it with a different request body returns 409 idempotency_conflict. To re-drive a corrected request, mint a new key.

Parámetros de ruta

id
string<uuid>
requerido

The unique identifier of the subscription (UUIDv7).

Cuerpo

application/json

The non-secret AWS delegated-grant coordinates. No AWS credential crosses this body — the role is assumed per delivery, guarded by the separately minted ExternalId.

roleArn
string
requerido

The cross-account delivery role ARN Streaming Hub assumes at delivery time.

Ejemplo:

"arn:aws:iam::444455556666:role/streaming-hub-delegated-delivery"

region
string
requerido

The AWS region of the destination.

Ejemplo:

"us-east-1"

destination
string
requerido

The resolved destination (queue URL or event-bus ARN). SSRF-validated before the write.

Ejemplo:

"https://sqs.us-east-1.amazonaws.com/444455556666/orders"

Respuesta

The grant was persisted (no body; the verification state is unchanged).