Upsert a plugin declaration
Creates or replaces the access-manager declaration for the given plugin slug. Called by the product itself, at start-up, with its own M2M token: the token must be issued to the target application (app.ClientId == token azp) and that application must declare for the slug, else 403.
The body has two sections and each is replaced ONLY when present, so a product can publish one without touching the other:
- the ACCESS section —
permissions,rolesandm2mtogether (a permission names the roles it grants to, so they are applied as one full sync: what the section no longer declares is removed). Served in single-tenant deployments only; in multi-tenant it answers501, because the tenant manager materializes permissions there. - the SCOPE section —
scope.dimensions, the dimensions the product’s routes address instances by, andpartners, the product’s opt-in to partner credentials (either alone is the section), pluslevelsin the scope-only form. It replaces the product’s scope catalog wholesale and is served in single- AND multi-tenant deployments: the catalog is global per product. Every partner write is validated against it, andGET /v1/scope-catalog/{product}reads it back.
A body carrying both sections in multi-tenant applies the scope section and then answers 501 for the access section.
Failures: 422 — the manifest is malformed (the message lists every violation), declares neither section, its service is not the slug, no application is registered for the calling client, or the identity provider refused the scope catalog (the message repeats its code, e.g. CRDH-3120); 403 — the token does not speak for the slug; 409 — the access section could not be persisted; 501 — the access section in a multi-tenant deployment; 503 IDE-0060 — the identity provider is unavailable, retry later; 500 — another dependency failed, retry.
Autorizações
JWT bearer token issued by the identity provider.
Parâmetros de caminho
Plugin slug that owns the declaration being upserted.
"plugin-fees"
Corpo
Declaration manifest to upsert for the slug.
Scope-only form of the permissions' levels: one entry per permission that declares a level, sent when the permission section is not. Forwarded with the scope catalog. Not accepted next to permissions, which carry their level themselves; alone it is not a section, since it would replace the catalog's dimensions and opt-in with nothing.
Bilateral machine-to-machine contract: which targets this plugin calls and whether it is callable.
Opts the product in to partner credentials: a partner can be granted this product only when it is true. Forwarded with the scope catalog; a body carrying only this member is a scope-only body. Replaces the opt-in whenever the catalog is replaced.
true
Permissions declared by the plugin; one entry per (resource, action).
Roles declared by the plugin. Names may use '/' for hierarchy but must not repeat the service prefix (it is added automatically).
Dimensions the product's routes address instances by — the WHERE a partner's scope lines name. Replaces the product's catalog when present; leaves it untouched when absent. Accepted in single- and multi-tenant deployments.
Service that owns this declaration; matches the caller token (the plugin- prefix is kept).
"plugin-fees"
Advisory manifest version. Must be a positive integer. Excluded from the canonical content hash.
3

