Skip to main content
POST
Create a partner

Autorizações

Authorization
string
header
obrigatório

JWT bearer token issued by the identity provider.

Corpo

application/json

The partner to create.

displayName
string
obrigatório

Human-readable name for the partner, unique within the organization (a duplicate is refused with IDE-1040). 1-128 characters after trimming. This is NOT the id: the id is a server-generated UUID returned in the response.

Required string length: 1 - 128
Exemplo:

"Loja do Zé"

permissions
object[] | null
obrigatório

What the partner may do, per product. A product with no entry here is unreachable by the partner, whatever its scope says.

ipAllowlist
object[] | null

The partner's own IP allowlist. Omit it or send null to inherit the organization's list — for a partner "no list" means INHERIT, never "allow everything". An empty array is refused (IDE-1048).

scope
object[] | null

Where the partner may do it, per product and dimension. Optional as a whole; when a product's published scope catalog marks a dimension required and that product is scoped, the entry for that dimension is mandatory.

validFrom
string<date-time>

RFC 3339 instant before which the partner's credentials are not honoured. Absent means "valid immediately".

Exemplo:

"2026-01-01T00:00:00Z"

validUntil
string<date-time>

RFC 3339 instant after which the partner's credentials stop being honoured (the authorize call answers authorized=false with reason "expired", which the calling product turns into 401). Absent means "no end date". Must be later than validFrom, else IDE-1045.

Exemplo:

"2027-01-01T00:00:00Z"

Resposta

Created

applicationsCount
integer<int64>
obrigatório

How many M2M applications are currently attached to this partner. A non-zero value is what makes DELETE answer 409 (IDE-1049).

Exemplo:

2

createdAt
string
obrigatório

When the partner was created (RFC 3339).

Exemplo:

"2026-01-15T09:30:00Z"

displayName
string
obrigatório

Human-readable name, unique within the organization.

Exemplo:

"Loja do Zé"

id
string
obrigatório

Server-generated identifier of the partner (UUID). This is the value to pass as partnerId when creating an application, and the value that travels in the credential's partner claim.

Exemplo:

"00000000-0000-0000-0000-000000000000"

ipAllowlist
object[] | null
obrigatório

The partner's own IP allowlist, or null when it inherits the organization's list. Null and an empty list are NOT the same thing here: null is inheritance, and an empty own list cannot be stored.

permissions
object[] | null
obrigatório

What the partner may do, per product.

scope
object[] | null
obrigatório

Where the partner may do it, per product and dimension. An empty list means the partner is not restricted by instance in any product.

state
enum<string>
obrigatório

Whether the partner's credentials are honoured. Note this never reads "expired": expiry is derived from validUntil at decision time, so a closed window shows here as "active" with a past validUntil.

Opções disponíveis:
active,
suspended
Exemplo:

"active"

updatedAt
string
obrigatório

When it was last modified (RFC 3339).

Exemplo:

"2026-01-15T09:30:00Z"

validFrom
string<date-time> | null
obrigatório

Start of the validity window (RFC 3339), or null when it is open-ended.

Exemplo:

"2026-01-01T00:00:00Z"

validUntil
string<date-time> | null
obrigatório

End of the validity window (RFC 3339), or null when it is open-ended. A past value means every credential of this partner is already refused.

Exemplo:

"2027-01-01T00:00:00Z"