diff --git a/docs/platform/reference/crds/index.mdx b/docs/platform/reference/crds/index.mdx index 310bd1bb..d39c4c3f 100644 --- a/docs/platform/reference/crds/index.mdx +++ b/docs/platform/reference/crds/index.mdx @@ -6,9 +6,10 @@ description: import DocCard from '@theme/DocCard'; -Stacklok Enterprise adds Kubernetes custom resources for role-based access -control and authorization policy enforcement. Each reference includes the -resource fields, defaults, validation rules, and an example manifest. +The Stacklok Enterprise platform extends the Kubernetes API with custom +resources for role-based access control and authorization policy enforcement. +Each page below documents one resource - its fields, defaults, validation rules, +and a minimal example manifest - and links to the other resources it references. ## Enterprise authorization diff --git a/static/api-specs/ai-gateway-management-api.yaml b/static/api-specs/ai-gateway-management-api.yaml index 79253d2d..605d3a50 100644 --- a/static/api-specs/ai-gateway-management-api.yaml +++ b/static/api-specs/ai-gateway-management-api.yaml @@ -1,134 +1,5 @@ components: schemas: - AIPolicy: - properties: - apiVersion: - type: string - kind: - type: string - metadata: - $ref: '#/components/schemas/ObjectMeta' - spec: - $ref: '#/components/schemas/AIPolicySpec' - status: - $ref: '#/components/schemas/AIPolicyStatus' - required: - - spec - type: object - AIPolicyList: - properties: - apiVersion: - type: string - items: - items: - $ref: '#/components/schemas/AIPolicy' - type: array - uniqueItems: false - kind: - type: string - nextPageToken: - type: string - remainingItemCount: - description: |- - RemainingItemCount is nullable on the wire. The apiserver omits it - on the last page, when the count was not computed, and — per the - Kubernetes API spec — whenever a label or field selector is - applied. Generated clients should treat the absence of the key as - "unknown" rather than expecting a non-null integer. swag v2 RC5 - does not emit the `nullable`/`type: [integer, "null"]` hint for - *int64. - format: int64 - type: integer - required: - - items - type: object - AIPolicyPatch: - properties: - spec: - $ref: '#/components/schemas/AIPolicySpecPatch' - type: object - AIPolicySpec: - properties: - description: - description: Description is a free-form human-readable description of this - policy. - maxLength: 2048 - type: string - gatewayRef: - $ref: '#/components/schemas/LocalObjectReference' - mcpPolicy: - $ref: '#/components/schemas/MCPPolicy' - principalMatchers: - description: |- - PrincipalMatchers identifies the principals this policy applies to. - Must contain 1..32 entries. Matchers combine as OR; claims within - a matcher combine as AND. Admission rejects violations with 422. - items: - $ref: '#/components/schemas/PrincipalMatcher' - type: array - uniqueItems: false - required: - - gatewayRef - - principalMatchers - type: object - AIPolicySpecPatch: - properties: - description: - maxLength: 2048 - type: string - mcpPolicy: - $ref: '#/components/schemas/MCPPolicy' - principalMatchers: - description: When present, replaces the stored principalMatchers entirely. - 1..32 entries. - items: - $ref: '#/components/schemas/PrincipalMatcher' - type: array - uniqueItems: false - type: object - AIPolicyStatus: - properties: - appliedToSecurityPolicy: - type: string - conditions: - items: - $ref: '#/components/schemas/Condition' - type: array - uniqueItems: false - observedGeneration: - type: integer - type: object - Condition: - properties: - lastTransitionTime: - format: date-time - type: string - message: - maxLength: 32768 - type: string - observedGeneration: - format: int64 - minimum: 0 - type: integer - reason: - maxLength: 1024 - type: string - status: - enum: - - "True" - - "False" - - Unknown - type: string - type: - maxLength: 316 - type: string - required: - - lastTransitionTime - - message - - reason - - status - - type - type: object Error: properties: error: @@ -157,43 +28,6 @@ components: - name - namespace type: object - LocalObjectReference: - description: GatewayRef names the AIGateway in the same namespace this policy - targets. - properties: - name: - example: main - maxLength: 253 - type: string - required: - - name - type: object - MCPPolicy: - description: |- - MCPPolicy binds matched principals to MCP servers. Forward-compatible; - not enforced in Phase 8. - properties: - servers: - description: Servers lists MCP server names matched principals may use. - 0..64 entries. - items: - type: string - type: array - uniqueItems: false - type: object - MatchedPolicy: - properties: - description: - maxLength: 2048 - type: string - mcpPolicy: - $ref: '#/components/schemas/PolicyMCP' - name: - maxLength: 253 - type: string - required: - - name - type: object McpServerCatalog: properties: items: @@ -227,16 +61,6 @@ components: type: string type: array uniqueItems: false - matchedPolicies: - items: - $ref: '#/components/schemas/MatchedPolicy' - type: array - uniqueItems: false - models: - items: - type: string - type: array - uniqueItems: false roles: items: type: string @@ -245,57 +69,10 @@ components: subject: example: github|42 type: string - unrestrictedModels: - description: |- - UnrestrictedModels is true when at least one matched policy grants - wildcard model access (a ModelPool with model "*"). When true, Models - is informational only — the caller may invoke any model the gateway - exposes, and explicit scoped pools in the same policy set still - surface in Models alongside the wildcard signal. When false, Models - is the authoritative allow-list: an empty array means deny-all. - example: false - type: boolean required: - groups - - matchedPolicies - - models - roles - subject - - unrestrictedModels - type: object - ObjectMeta: - properties: - annotations: - additionalProperties: - type: string - type: object - creationTimestamp: - format: date-time - type: string - deletionGracePeriodSeconds: - format: int64 - type: integer - deletionTimestamp: - format: date-time - type: string - generation: - format: int64 - type: integer - labels: - additionalProperties: - type: string - type: object - name: - example: main-budget - maxLength: 253 - type: string - namespace: - type: string - resourceVersion: - type: string - uid: - format: uuid - type: string type: object OpenAIModel: properties: @@ -336,33 +113,10 @@ components: - data - object type: object - PolicyMCP: - properties: - servers: - description: Servers lists MCP server names matched principals may use. - 0..64 entries. - items: - type: string - type: array - uniqueItems: false - type: object - PrincipalMatcher: - properties: - claims: - additionalProperties: - type: string - description: |- - Claims maps claim name to the expected value. Must contain at least - one entry; all entries must match (AND) for the matcher to admit - a principal. - type: object - required: - - claims - type: object Violation: properties: field: - example: /spec/principalMatchers/0/claims + example: /spec/auth/workloadIssuers/0/allowedSubjects type: string message: example: must contain at least one entry @@ -382,52 +136,30 @@ externalDocs: url: "" info: contact: - name: Stacklok - url: https://docs.stacklok.com/platform + name: Stacklok LLM Gateway + url: https://github.com/stacklok/stacklok-llm-gateway description: |- - Admin-scoped HTTP API backing the help-desk UI. The server is a thin - facade over the Kubernetes API: write endpoints translate to typed - `AIPolicy` CR create/update/delete calls via controller-runtime, and - introspection endpoints read from the same cache. No parallel store. + Gateway-scoped HTTP API backing caller introspection and model/MCP catalogs. + Endpoints read the owning `AIGateway` and, for `/v1/me`, the + authenticated caller's identity directly from the apiserver. + No parallel store. ## Scope Each API server instance is bound to exactly one Kubernetes namespace - (configured via operator flag) and all `AIPolicy` CRs live in that - namespace. The namespace is therefore **not** in the URL path; multi- - namespace deployments run multiple API instances. A future major version - may introduce `/v1/namespaces/{ns}/...` if multi-tenant scoping is - required; clients should treat the current paths as namespace-local. + (configured via operator flag) and the `AIGateway` it serves lives in + that namespace. The namespace is therefore **not** in the URL path; + multi-namespace deployments run multiple API instances. ## Authentication and authorization All requests require a bearer JWT validated against the OIDC provider - configured on the target `AIGateway` (`spec.auth.oidc`). Role checks are - performed per path; role names (`admin`, `policyEditor`, `authenticated`) - are conventional and are themselves resolved against - `AIGateway.spec.auth.authz.roles`, which maps each role name to a list - of principal matchers. - - ## Concurrency control - - `GET` on a single policy returns an `ETag` header whose value is the - quoted `metadata.resourceVersion`. `PATCH` and `DELETE` both - **require** the `If-Match` header. Concurrency failures use distinct - status codes so the UI can branch without parsing error strings: - - - **428 Precondition Required** (RFC 6585) — `If-Match` header is - missing. This is a client bug; UIs should surface it as a dev-tools - error rather than a user-facing "policy changed" dialog. - - **412 Precondition Failed** (RFC 7232) — `If-Match` was sent but - the value no longer matches the server's `resourceVersion` (another - admin edited concurrently). UIs should re-fetch and offer a - merge/overwrite flow. - - **409 Conflict** — reserved for `POST` with a `metadata.name` that - already exists. UIs should prompt for a different name. + configured on the target `AIGateway` (`spec.auth.oidc`). `/v1/me` also + returns roles resolved from `AIGateway.spec.auth.authz.roles`. license: name: Apache-2.0 url: https://www.apache.org/licenses/LICENSE-2.0.html - title: AI Gateway Management API + title: Stacklok LLM Gateway Management API version: 0.1.0 openapi: 3.1.0 paths: @@ -518,11 +250,7 @@ paths: - Catalog /v1/me: get: - description: |- - Returns subject, groups, resolved roles, the set of AIPolicies - whose principalMatchers the caller satisfies, and the union of - models granted by those policies' budgets. Matched-only — the - response never includes policies the caller does not match. + description: Returns subject, groups, and resolved management roles. operationId: getMe parameters: - description: Correlation ID; echoed on responses and included in audit records. @@ -548,37 +276,26 @@ paths: schema: $ref: '#/components/schemas/Error' description: Missing or invalid JWT. - "403": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: Authenticated but bound to a namespace the caller cannot query. - "429": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: Rate limit exceeded. - "503": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: Kubernetes API unavailable. x-required-role: authenticated security: - BearerAuth: [] - summary: Return the caller's identity and resolved policy bindings. + summary: Return the caller's identity and resolved management roles. tags: - Introspection /v1/models: get: description: |- - Derived from the owning AIGateway's `spec.routes[].match.model`. - Deduplicated and sorted by model id, OpenAI-shaped - (`object:"list"`, `data[]`) to match the data-plane - GET /v1/models intercept. + Derived from the owning AIGateway's `spec.routes[].match.model`, + then filtered to the caller's effective model access as the + Directory decides it — so this surface and the data-plane + GET /v1/models intercept always agree about what the caller + may call. Deduplicated and sorted by model id, OpenAI-shaped + (`object:"list"`, `data[]`) to match that intercept. + + `?scope=all` returns the complete configured catalog instead, + unfiltered, for an Admin authoring a Model Set — who must be + able to grant models their own access does not include. It + requires the deployment's admin role. operationId: listModels parameters: - description: Correlation ID; echoed on responses and included in audit records. @@ -586,6 +303,14 @@ paths: name: X-Request-Id schema: type: string + - description: Set to `all` for the complete configured catalog, unfiltered. + Requires the admin role. + in: query + name: scope + schema: + enum: + - all + type: string responses: "200": content: @@ -603,7 +328,7 @@ paths: application/json: schema: $ref: '#/components/schemas/Error' - description: Multiple AIGateways found; single-gateway assumption broken. + description: Multiple AIGateways found, or an unsupported scope value. "401": content: application/json: @@ -615,7 +340,8 @@ paths: application/json: schema: $ref: '#/components/schemas/Error' - description: Authenticated but bound to a namespace the caller cannot query. + description: Authenticated but bound to a namespace the caller cannot query, + or asked for scope=all without the admin role. "404": content: application/json: @@ -633,467 +359,13 @@ paths: application/json: schema: $ref: '#/components/schemas/Error' - description: Kubernetes API unavailable. + description: Kubernetes API unavailable, or model access could not be decided. + Never answered with an unfiltered catalog. x-required-role: authenticated security: - BearerAuth: [] - summary: List all models visible to the gateway in the current namespace. + summary: List the models the calling user may use. tags: - Catalog - /v1/policies: - get: - description: |- - Returns a page of AIPolicies. `limit` caps the underlying - apiserver page size (max 500; larger values are clamped). - `pageToken` resumes a prior list at the next page boundary. - `labelSelector` accepts the standard apimachinery selector - syntax (e.g., `team=eng,tier!=internal`). `gatewayRef` is a - post-list filter applied to the returned page; when used with - `limit`, the returned page may contain fewer matches than the - limit — callers must keep paging while `nextPageToken` is - non-empty to enumerate every match. When `labelSelector` is - set, the apiserver omits `remainingItemCount` (per the - Kubernetes API spec: the remaining count is unknown for - selector-filtered lists), so the field will be absent on the - response regardless of how many pages remain. A - present-but-empty value for `limit`, `pageToken`, or - `labelSelector` (e.g., `?limit=`) is equivalent to the - parameter being absent and uses the server default for that - parameter — empty is not "explicitly clear this filter". - operationId: listPolicies - parameters: - - description: Correlation ID; echoed on responses and included in audit records. - in: header - name: X-Request-Id - schema: - type: string - - description: Max items per page (1..500). Values above 500 are clamped to - 500; 0 or omitted uses the server default (500). - in: query - name: limit - schema: - type: integer - - description: Opaque continue token from a previous response. An expired or - malformed token returns 400; restart the list from page one. - in: query - name: pageToken - schema: - type: string - - description: Kubernetes label selector (e.g., team=eng,tier!=internal). Malformed - selectors return 400. - in: query - name: labelSelector - schema: - type: string - - description: Restrict to policies targeting this AIGateway name. Applied as - a post-list filter; may reduce the returned page size below limit. - in: query - name: gatewayRef - schema: - type: string - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/AIPolicyList' - description: OK - headers: - X-Request-Id: - description: Echoed correlation ID. - schema: - type: string - "400": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: Malformed query parameter. - "401": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: Missing or invalid JWT. - "403": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: Caller lacks required role. - "429": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: Rate limit exceeded. - "503": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: Kubernetes API unavailable. - x-required-role: policyEditor - security: - - BearerAuth: [] - summary: List AIPolicies in the configured namespace. - tags: - - Policies - post: - description: |- - Use `metadata.name` as the idempotency key. Retrying a POST - with the same name returns 409 Conflict; clients should treat - this as either a duplicate submission (succeeded previously) or - a deliberate collision (surface to the user). - operationId: createPolicy - parameters: - - description: Correlation ID; echoed on responses and included in audit records. - in: header - name: X-Request-Id - schema: - type: string - requestBody: - content: - application/json: - schema: - oneOf: - - type: object - - $ref: '#/components/schemas/AIPolicy' - description: Full AIPolicy object. metadata.namespace is ignored; - the server's configured namespace wins. - summary: body - description: Full AIPolicy object. metadata.namespace is ignored; the server's - configured namespace wins. - required: true - responses: - "201": - content: - application/json: - schema: - $ref: '#/components/schemas/AIPolicy' - description: Policy created. - headers: - ETag: - description: Quoted resourceVersion. - schema: - type: string - Location: - description: Absolute path of the created policy. - schema: - type: string - X-Request-Id: - description: Echoed correlation ID. - schema: - type: string - "400": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: Malformed body or missing required field. - "401": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: Missing or invalid JWT. - "403": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: Caller lacks required role. - "409": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: metadata.name already exists. - "422": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: CRD/CEL admission rejection. - "429": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: Rate limit exceeded. - "503": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: Kubernetes API unavailable. - x-required-role: admin - security: - - BearerAuth: [] - summary: Create a new AIPolicy. - tags: - - Policies - /v1/policies/{name}: - delete: - description: |- - If-Match is required; missing returns 428 and stale returns - 412, so accidental wipes during a concurrent edit never - silently succeed. - operationId: deletePolicy - parameters: - - description: Policy name. - in: path - name: name - required: true - schema: - type: string - - description: Quoted resourceVersion from a preceding GET. Required. - in: header - name: If-Match - required: true - schema: - type: string - - description: Correlation ID; echoed on responses and included in audit records. - in: header - name: X-Request-Id - schema: - type: string - responses: - "204": - description: Policy deleted; no content. - headers: - X-Request-Id: - description: Echoed correlation ID. - schema: - type: string - "401": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: Missing or invalid JWT. - "403": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: Caller lacks required role. - "404": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: Policy not found. - "412": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: If-Match does not match the stored resourceVersion. - "428": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: If-Match header is required. - "429": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: Rate limit exceeded. - "503": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: Kubernetes API unavailable. - x-required-role: admin - security: - - BearerAuth: [] - summary: Delete an AIPolicy. - tags: - - Policies - get: - operationId: getPolicy - parameters: - - description: Policy name (DNS-1123 subdomain, max 253 chars). - in: path - name: name - required: true - schema: - type: string - - description: Correlation ID; echoed on responses and included in audit records. - in: header - name: X-Request-Id - schema: - type: string - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/AIPolicy' - description: Policy found. - headers: - ETag: - description: Quoted resourceVersion; pass back via If-Match on PATCH - or DELETE. - schema: - type: string - X-Request-Id: - description: Echoed correlation ID. - schema: - type: string - "401": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: Missing or invalid JWT. - "403": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: Caller lacks required role. - "404": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: Policy not found. - "429": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: Rate limit exceeded. - "503": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: Kubernetes API unavailable. - x-required-role: policyEditor - security: - - BearerAuth: [] - summary: Get a single AIPolicy by name. - tags: - - Policies - patch: - description: |- - Patches are applied against `spec` only; any `status` or - `metadata.resourceVersion` sent in the body is ignored (use - `If-Match` for optimistic concurrency). `spec.gatewayRef` is - immutable after creation; attempting to modify it returns 422. - operationId: patchPolicy - parameters: - - description: Policy name. - in: path - name: name - required: true - schema: - type: string - - description: 'Quoted resourceVersion from a preceding GET. Required: missing - returns 428 Precondition Required; stale returns 412 Precondition Failed.' - in: header - name: If-Match - required: true - schema: - type: string - - description: Correlation ID; echoed on responses and included in audit records. - in: header - name: X-Request-Id - schema: - type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/AIPolicyPatch' - description: RFC 7396 JSON merge patch; only /spec may be patched. - summary: body - application/merge-patch+json: - schema: - type: string - description: RFC 7396 JSON merge patch; only /spec may be patched. - required: true - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/AIPolicy' - description: Policy updated. - headers: - ETag: - description: Updated quoted resourceVersion. - schema: - type: string - X-Request-Id: - description: Echoed correlation ID. - schema: - type: string - "400": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: Malformed merge-patch body or unsupported top-level key. - "401": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: Missing or invalid JWT. - "403": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: Caller lacks required role. - "404": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: Policy not found. - "412": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: If-Match does not match the stored resourceVersion. - "422": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: CRD/CEL admission rejection or attempt to modify gatewayRef. - "428": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: If-Match header is required. - "429": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: Rate limit exceeded. - "503": - content: - application/json: - schema: - $ref: '#/components/schemas/Error' - description: Kubernetes API unavailable. - x-required-role: admin - security: - - BearerAuth: [] - summary: Update an AIPolicy using JSON merge patch. - tags: - - Policies servers: - url: management.invalid/ diff --git a/static/api-specs/enterprise-crds/clusterplatformrolebindings.schema.json b/static/api-specs/enterprise-crds/clusterplatformrolebindings.schema.json index bdaeaab9..0d1aae92 100644 --- a/static/api-specs/enterprise-crds/clusterplatformrolebindings.schema.json +++ b/static/api-specs/enterprise-crds/clusterplatformrolebindings.schema.json @@ -23,8 +23,62 @@ "from": { "description": "From is the list of principal conditions that receive the role.", "items": { - "description": "PrincipalCondition identifies principals by group membership or role assignment.", + "description": "PrincipalCondition identifies principals by group membership or role assignment.\n\nDo NOT add a claimConditions disjunct to the rule below: claims narrow an\nidentity-anchored permit, they never anchor one. A condition with only\nClaimConditions and empty Groups/Roles must stay rejected.", "properties": { + "claimConditions": { + "description": "ClaimConditions optionally narrow the permit on JWT/OIDC claim predicates.\nAdditive: a condition must still anchor on groups or roles (see the\nXValidation rule above). They cannot independently grant a role.", + "items": { + "description": "ClaimCondition narrows an identity-anchored permit on a single JWT/OIDC claim.\nSome claims (azp, scp, aud) are request attributes rather than principal\nidentity; hosting them here is a compromise for shared plumbing.\n\nOnly simple, string-valued claims are supported. The Claim pattern\n(^[a-zA-Z0-9_]+$) covers azp, scp, idtyp, aud, and tid but deliberately\nexcludes URI-, dot-, slash-, and hyphen-namespaced claim names, because the\nname becomes a Cedar attribute identifier (claim_). This is a\ndocumented boundary — the Pattern also blocks a claim-name injection\nvector (distinct from claim-value escaping, which is handled elsewhere in\nthe compiler).\n\nThe three XValidation rules below are phrased as per-operator exclusions\n(self.operator != 'X' || ...), so each passes vacuously for any Operator\nvalue outside the Equals;Absent;Contains enum. That gap is closed by the\nrules — so any Go-level compiler validation of ClaimCondition MUST\nindependently reject an unrecognized Operator (fail-closed default case),\nnot just reimplement these checks.", + "properties": { + "claim": { + "description": "Claim is the JWT/OIDC claim name (without the claim_ prefix), e.g. \"azp\".", + "maxLength": 253, + "minLength": 1, + "pattern": "^[a-zA-Z0-9_]+$", + "type": "string" + }, + "operator": { + "description": "Operator selects the predicate: Equals (whole-string match), Contains\n(space-delimited element membership), or Absent.", + "enum": [ + "Equals", + "Absent", + "Contains" + ], + "type": "string" + }, + "values": { + "description": "Values are the accepted claim values for Equals/Contains (ORed).\nForbidden for Absent.", + "items": { + "maxLength": 253, + "type": "string" + }, + "maxItems": 32, + "type": "array" + } + }, + "required": [ + "claim", + "operator" + ], + "type": "object", + "x-kubernetes-validations": [ + { + "message": "values is required and must be non-empty when operator is Equals", + "rule": "self.operator != 'Equals' || (has(self.values) && size(self.values) > 0)" + }, + { + "message": "values is required and must be non-empty when operator is Contains", + "rule": "self.operator != 'Contains' || (has(self.values) && size(self.values) > 0)" + }, + { + "message": "values must be empty when operator is Absent", + "rule": "self.operator != 'Absent' || !has(self.values) || size(self.values) == 0" + } + ] + }, + "maxItems": 32, + "type": "array" + }, "groups": { "description": "Groups is the list of OIDC groups a principal must belong to.", "items": { diff --git a/static/api-specs/enterprise-crds/platformrolebindings.schema.json b/static/api-specs/enterprise-crds/platformrolebindings.schema.json index 253cf372..6f3b8237 100644 --- a/static/api-specs/enterprise-crds/platformrolebindings.schema.json +++ b/static/api-specs/enterprise-crds/platformrolebindings.schema.json @@ -23,8 +23,62 @@ "from": { "description": "From is the list of principal conditions that receive the role.", "items": { - "description": "PrincipalCondition identifies principals by group membership or role assignment.", + "description": "PrincipalCondition identifies principals by group membership or role assignment.\n\nDo NOT add a claimConditions disjunct to the rule below: claims narrow an\nidentity-anchored permit, they never anchor one. A condition with only\nClaimConditions and empty Groups/Roles must stay rejected.", "properties": { + "claimConditions": { + "description": "ClaimConditions optionally narrow the permit on JWT/OIDC claim predicates.\nAdditive: a condition must still anchor on groups or roles (see the\nXValidation rule above). They cannot independently grant a role.", + "items": { + "description": "ClaimCondition narrows an identity-anchored permit on a single JWT/OIDC claim.\nSome claims (azp, scp, aud) are request attributes rather than principal\nidentity; hosting them here is a compromise for shared plumbing.\n\nOnly simple, string-valued claims are supported. The Claim pattern\n(^[a-zA-Z0-9_]+$) covers azp, scp, idtyp, aud, and tid but deliberately\nexcludes URI-, dot-, slash-, and hyphen-namespaced claim names, because the\nname becomes a Cedar attribute identifier (claim_). This is a\ndocumented boundary — the Pattern also blocks a claim-name injection\nvector (distinct from claim-value escaping, which is handled elsewhere in\nthe compiler).\n\nThe three XValidation rules below are phrased as per-operator exclusions\n(self.operator != 'X' || ...), so each passes vacuously for any Operator\nvalue outside the Equals;Absent;Contains enum. That gap is closed by the\nrules — so any Go-level compiler validation of ClaimCondition MUST\nindependently reject an unrecognized Operator (fail-closed default case),\nnot just reimplement these checks.", + "properties": { + "claim": { + "description": "Claim is the JWT/OIDC claim name (without the claim_ prefix), e.g. \"azp\".", + "maxLength": 253, + "minLength": 1, + "pattern": "^[a-zA-Z0-9_]+$", + "type": "string" + }, + "operator": { + "description": "Operator selects the predicate: Equals (whole-string match), Contains\n(space-delimited element membership), or Absent.", + "enum": [ + "Equals", + "Absent", + "Contains" + ], + "type": "string" + }, + "values": { + "description": "Values are the accepted claim values for Equals/Contains (ORed).\nForbidden for Absent.", + "items": { + "maxLength": 253, + "type": "string" + }, + "maxItems": 32, + "type": "array" + } + }, + "required": [ + "claim", + "operator" + ], + "type": "object", + "x-kubernetes-validations": [ + { + "message": "values is required and must be non-empty when operator is Equals", + "rule": "self.operator != 'Equals' || (has(self.values) && size(self.values) > 0)" + }, + { + "message": "values is required and must be non-empty when operator is Contains", + "rule": "self.operator != 'Contains' || (has(self.values) && size(self.values) > 0)" + }, + { + "message": "values must be empty when operator is Absent", + "rule": "self.operator != 'Absent' || !has(self.values) || size(self.values) == 0" + } + ] + }, + "maxItems": 32, + "type": "array" + }, "groups": { "description": "Groups is the list of OIDC groups a principal must belong to.", "items": { diff --git a/static/api-specs/enterprise-crds/toolhiveauthorizationpolicies.schema.json b/static/api-specs/enterprise-crds/toolhiveauthorizationpolicies.schema.json index f323c417..fabed058 100644 --- a/static/api-specs/enterprise-crds/toolhiveauthorizationpolicies.schema.json +++ b/static/api-specs/enterprise-crds/toolhiveauthorizationpolicies.schema.json @@ -23,8 +23,62 @@ "from": { "description": "From optionally narrows this binding to a subset of principals.\nWhen omitted, the binding applies to every principal granted this role\nvia the cluster-scoped binding CRD.", "items": { - "description": "PrincipalCondition identifies principals by group membership or role assignment.", + "description": "PrincipalCondition identifies principals by group membership or role assignment.\n\nDo NOT add a claimConditions disjunct to the rule below: claims narrow an\nidentity-anchored permit, they never anchor one. A condition with only\nClaimConditions and empty Groups/Roles must stay rejected.", "properties": { + "claimConditions": { + "description": "ClaimConditions optionally narrow the permit on JWT/OIDC claim predicates.\nAdditive: a condition must still anchor on groups or roles (see the\nXValidation rule above). They cannot independently grant a role.", + "items": { + "description": "ClaimCondition narrows an identity-anchored permit on a single JWT/OIDC claim.\nSome claims (azp, scp, aud) are request attributes rather than principal\nidentity; hosting them here is a compromise for shared plumbing.\n\nOnly simple, string-valued claims are supported. The Claim pattern\n(^[a-zA-Z0-9_]+$) covers azp, scp, idtyp, aud, and tid but deliberately\nexcludes URI-, dot-, slash-, and hyphen-namespaced claim names, because the\nname becomes a Cedar attribute identifier (claim_). This is a\ndocumented boundary — the Pattern also blocks a claim-name injection\nvector (distinct from claim-value escaping, which is handled elsewhere in\nthe compiler).\n\nThe three XValidation rules below are phrased as per-operator exclusions\n(self.operator != 'X' || ...), so each passes vacuously for any Operator\nvalue outside the Equals;Absent;Contains enum. That gap is closed by the\nrules — so any Go-level compiler validation of ClaimCondition MUST\nindependently reject an unrecognized Operator (fail-closed default case),\nnot just reimplement these checks.", + "properties": { + "claim": { + "description": "Claim is the JWT/OIDC claim name (without the claim_ prefix), e.g. \"azp\".", + "maxLength": 253, + "minLength": 1, + "pattern": "^[a-zA-Z0-9_]+$", + "type": "string" + }, + "operator": { + "description": "Operator selects the predicate: Equals (whole-string match), Contains\n(space-delimited element membership), or Absent.", + "enum": [ + "Equals", + "Absent", + "Contains" + ], + "type": "string" + }, + "values": { + "description": "Values are the accepted claim values for Equals/Contains (ORed).\nForbidden for Absent.", + "items": { + "maxLength": 253, + "type": "string" + }, + "maxItems": 32, + "type": "array" + } + }, + "required": [ + "claim", + "operator" + ], + "type": "object", + "x-kubernetes-validations": [ + { + "message": "values is required and must be non-empty when operator is Equals", + "rule": "self.operator != 'Equals' || (has(self.values) && size(self.values) > 0)" + }, + { + "message": "values is required and must be non-empty when operator is Contains", + "rule": "self.operator != 'Contains' || (has(self.values) && size(self.values) > 0)" + }, + { + "message": "values must be empty when operator is Absent", + "rule": "self.operator != 'Absent' || !has(self.values) || size(self.values) == 0" + } + ] + }, + "maxItems": 32, + "type": "array" + }, "groups": { "description": "Groups is the list of OIDC groups a principal must belong to.", "items": { @@ -203,7 +257,8 @@ "description": "Kind is the kind of the target resource. Defaults to MCPServer.", "enum": [ "MCPServer", - "MCPRemoteProxy" + "MCPRemoteProxy", + "VirtualMCPServer" ], "type": "string" }, diff --git a/static/api-specs/enterprise-manager-api.json b/static/api-specs/enterprise-manager-api.json index 073c1233..7565517d 100644 --- a/static/api-specs/enterprise-manager-api.json +++ b/static/api-specs/enterprise-manager-api.json @@ -71,7 +71,7 @@ "type": "string" }, "subject_id": { - "description": "SubjectID is the opaque principal identifier: the OIDC subject for a user\nbudget, the directory group UUID for a group budget.", + "description": "SubjectID is the opaque principal identifier: the directory platform user\nUUID for a user budget, the directory group UUID for a group budget.", "type": "string" } }, @@ -195,14 +195,6 @@ }, "type": "object" }, - "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse": { - "properties": { - "error": { - "type": "string" - } - }, - "type": "object" - }, "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.EventRecord": { "properties": { "auth_issuer": { @@ -301,6 +293,10 @@ "google": { "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.PricingGoogleRates" }, + "managedBy": { + "description": "ManagedBy and Unpriced mirror PricingCatalogEntry. A tombstoned pair\nanswers 200 with Unpriced true rather than 404, so a caller can tell a\ndeliberate block from a model nothing has ever priced. Field order and\ntypes must stay identical to PricingCatalogEntry: pricingEntryToResponse\nconverts between the two structurally.", + "type": "string" + }, "model": { "type": "string" }, @@ -309,6 +305,9 @@ }, "provider": { "type": "string" + }, + "unpriced": { + "type": "boolean" } }, "type": "object" @@ -323,7 +322,7 @@ "additionalProperties": { "type": "string" }, - "description": "ProviderAliases folds a data-plane provider spelling onto the provider a\nPricingCatalogEntry is keyed under, for the spellings where the two\ndiffer. A client joining a model list against Spec.Entries MUST apply it\nto BOTH sides — the model's provider AND the entry's own Provider —\nafter lowercasing and trimming each, falling back to that normalized\nspelling when it is absent from the map.\n\nBoth halves are load-bearing. Spec is returned verbatim as stored, so an\nentry carries the spelling whoever authored it typed, while the server\nkeyed its own row on the folded spelling; folding only the model's side\nleaves an entry authored as \"vertex\" unreachable from a data plane\nreporting \"vertex\". And the server's fold lowercases and trims first, so\na client matching raw prices nothing for a spelling the charge path\nbills without complaint.\n\nIt exists because the two names come from different vocabularies and are\nnot reconcilable by the client: a data plane reports the provider it was\nconfigured with (sprout's provider kind, or the legacy gateway's provider\nCR Name) while an entry is keyed on the rate sheet it bills off. Two\ndistinct providers can share one sheet — AI Studio and Vertex both price\nas \"google\" — so the fold is deliberately many-to-one and cannot be\nundone by renaming either side.\n\nOnly non-identity folds are present, so an absent key means \"already the\ncatalog spelling\", not \"unknown provider\". Omitted when empty.", + "description": "ProviderAliases folds a data-plane provider spelling onto the provider a\nPricingCatalogEntry is keyed under, for the spellings where the two\ndiffer. A client joining a model list against Spec.Entries MUST apply it\nto BOTH sides — the model's provider AND the entry's own Provider —\nafter lowercasing and trimming each, falling back to that normalized\nspelling when it is absent from the map.\n\nBoth halves are load-bearing. Spec is returned verbatim as stored, so an\nentry carries the spelling whoever authored it typed, while the server\nkeyed its own row on the folded spelling; folding only the model's side\nleaves an entry authored as \"vertex\" unreachable from a data plane\nreporting \"vertex\". And the server's fold lowercases and trims first, so\na client matching raw prices nothing for a spelling the charge path\nbills without complaint.\n\nIt exists because the two names come from different vocabularies and are\nnot reconcilable by the client: a data plane reports the provider it was\nconfigured with (AI Gateway v2's provider kind, or the legacy gateway's provider\nCR Name) while an entry is keyed on the rate sheet it bills off. Two\ndistinct providers can share one sheet — AI Studio and Vertex both price\nas \"google\" — so the fold is deliberately many-to-one and cannot be\nundone by renaming either side.\n\nOnly non-identity folds are present, so an absent key means \"already the\ncatalog spelling\", not \"unknown provider\". Omitted when empty.", "type": "object" }, "spec": { @@ -364,6 +363,19 @@ }, "type": "object" }, + "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ListPricingVersionsResponse": { + "properties": { + "versions": { + "description": "Versions are ordered by EffectiveFrom descending. Empty when no version\nhas been published, which is a 200 rather than a 404: unlike a point read\nof a named version, a listing of nothing is an answer.", + "items": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.PricingVersionSummary" + }, + "type": "array", + "uniqueItems": false + } + }, + "type": "object" + }, "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.MeCellItem": { "properties": { "limit_usd": { @@ -486,6 +498,10 @@ "google": { "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.PricingGoogleRates" }, + "managedBy": { + "description": "ManagedBy records who owns this rate: ManagedByBaseline for one tracking\nthe shipped baseline, ManagedByOperator for one an admin set. It is\nserver-owned: PutPricingEntryRequest declares no ManagedBy field, so a\nclient that sends one has it silently ignored rather than rejected,\nbecause a client that could claim ManagedByBaseline for its own rate\nwould have that rate overwritten by the next refresh without asking\nfor it.", + "type": "string" + }, "model": { "type": "string" }, @@ -494,6 +510,10 @@ }, "provider": { "type": "string" + }, + "unpriced": { + "description": "Unpriced marks a tombstone: a rate an admin deliberately removed,\nrecorded rather than left as an absence, so no refresh resurrects it. A\ntombstone carries no rate block, and the entry is skipped when the\nCostCatalog is built, so the model is unpriceable and denied at admission\n(toolhive-enterprise ADR-0021) unless another spelling folds onto the\nsame canonical key and prices it.", + "type": "boolean" } }, "type": "object" @@ -508,6 +528,10 @@ "type": "array", "uniqueItems": false }, + "snapshotDate": { + "description": "SnapshotDate names the shipped-baseline snapshot this spec's\nbaseline-managed entries track. The generator stamps it on the baseline;\na per-entry write inherits it unchanged; only the boot reconciler\nadvances it, and only forward. Absent on any version written before\nownership existed, which is every version the backfill runs against.", + "type": "string" + }, "tools": { "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.PricingToolRates" } @@ -627,6 +651,23 @@ }, "type": "object" }, + "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.PricingVersionSummary": { + "properties": { + "created_at": { + "description": "CreatedAt is when the row was written, which differs from EffectiveFrom\nfor a staged version and for the shipped baseline (dated in a 1970 epoch\nband so it never outranks an operator's own rates).", + "type": "string" + }, + "effective_from": { + "description": "EffectiveFrom is when this version takes, or took, effect — and the key\nthat addresses it on GET /v1/budgets/pricing/versions/{effectiveFrom}. A\nvalue in the future is a staged version, which every pricing write\nrefuses until it becomes active or is deleted.", + "type": "string" + }, + "snapshotDate": { + "description": "SnapshotDate names the shipped-baseline snapshot THIS version's\nbaseline-managed entries track — not the one the running binary ships.\nEmpty for any version published before the pointer survived a per-entry\nwrite, which is every version currently in the field.", + "type": "string" + } + }, + "type": "object" + }, "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.PutDefaultUserBudgetRequest": { "properties": { "limit_usd": { @@ -667,6 +708,10 @@ }, "openai": { "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.PricingOpenAIRates" + }, + "unpriced": { + "description": "Unpriced is accepted only so the contradiction below can be reported.\nA PUT prices a model; removing one is DELETE. It is declared rather than\nignored because GetPricingEntryResponse carries the field, so a caller\ndoing the documented read-modify-write round trip can send it back, and\nsilently dropping it would store rates under an entry the caller believed\nwas tombstoned.", + "type": "boolean" } }, "type": "object" @@ -745,6 +790,14 @@ }, "type": "object" }, + "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse": { + "properties": { + "error": { + "type": "string" + } + }, + "type": "object" + }, "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AWSStsAuthDTO": { "properties": { "fallback_role_arn": { @@ -815,14 +868,6 @@ ], "type": "object" }, - "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse": { - "properties": { - "error": { - "type": "string" - } - }, - "type": "object" - }, "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.BearerTokenAuthRequest": { "properties": { "token": { @@ -1082,6 +1127,9 @@ }, "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.ConnectorPolicyGroupRefDTO": { "properties": { + "display_name": { + "type": "string" + }, "id": { "type": "string" }, @@ -1137,6 +1185,11 @@ "type": "string" }, "transport": { + "description": "Transport is the MCP transport the connector's server speaks: one of\n\"streamable-http\" or \"sse\". An out-of-set value is rejected with a 400.", + "enum": [ + "streamable-http", + "sse" + ], "type": "string" }, "version": { @@ -1262,6 +1315,28 @@ ], "type": "object" }, + "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.CreateModelSetRequest": { + "properties": { + "description": { + "type": "string" + }, + "model_ids": { + "description": "No dive tag: swag reads a trailing `required` inside one as the FIELD\nbeing required, which would make an empty set uncreatable. Each id is\nvalidated by the aggregate, which rejects blanks and over-long ones.", + "items": { + "type": "string" + }, + "type": "array", + "uniqueItems": false + }, + "name": { + "type": "string" + } + }, + "required": [ + "name" + ], + "type": "object" + }, "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.DCRConfigDTO": { "properties": { "discovery_url": { @@ -1282,6 +1357,70 @@ }, "type": "object" }, + "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.DiscoverConnectorIdentityProviderRequest": { + "properties": { + "mcp_url": { + "type": "string" + } + }, + "required": [ + "mcp_url" + ], + "type": "object" + }, + "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.DiscoveredConnectorIdentityProviderDTO": { + "properties": { + "authorization_endpoint": { + "type": "string" + }, + "authorization_server": { + "type": "string" + }, + "discovery_url": { + "type": "string" + }, + "mcp_url": { + "type": "string" + }, + "registration_endpoint": { + "type": "string" + }, + "resource": { + "type": "string" + }, + "resource_metadata_url": { + "type": "string" + }, + "scopes_supported": { + "items": { + "type": "string" + }, + "type": "array", + "uniqueItems": false + }, + "token_endpoint": { + "type": "string" + }, + "token_endpoint_auth_methods_supported": { + "items": { + "type": "string" + }, + "type": "array", + "uniqueItems": false + } + }, + "required": [ + "authorization_endpoint", + "authorization_server", + "discovery_url", + "mcp_url", + "registration_endpoint", + "resource", + "resource_metadata_url", + "token_endpoint" + ], + "type": "object" + }, "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.DiscoveredServerDTO": { "properties": { "allow_private_ips": { @@ -1362,6 +1501,62 @@ ], "type": "object" }, + "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.GrantSourceDTO": { + "properties": { + "group_id": { + "description": "GroupID and GroupName are ABSENT for \"default\" and \"user\" sources, which\ncarry no group. They are an omitempty pointer rather than an empty string\nso a client cannot render the zero UUID as if it named a group, and so the\nwire matches the generated `group_id?: string` instead of sending null.", + "type": "string" + }, + "group_name": { + "type": "string" + }, + "kind": { + "description": "Kind is \"default\", \"user\", or \"group\" — the same spelling GrantSubjectDTO\nuses, so a client reads one vocabulary across both endpoints.", + "enum": [ + "default", + "user", + "group" + ], + "type": "string" + } + }, + "type": "object" + }, + "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.GrantSubjectDTO": { + "properties": { + "display_name": { + "type": "string" + }, + "email": { + "description": "Email is a user's primary email; absent for a group or a user without one.", + "type": "string" + }, + "granted_at": { + "type": "string" + }, + "id": { + "type": "string" + }, + "kind": { + "description": "Kind is \"user\" or \"group\".", + "enum": [ + "user", + "group" + ], + "type": "string" + }, + "source": { + "description": "Source is a group's provenance, as stored; absent for a user. Clients own\nany display mapping of the raw value.", + "enum": [ + "scim", + "api", + "derived" + ], + "type": "string" + } + }, + "type": "object" + }, "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.GroupDTO": { "properties": { "created_at": { @@ -1373,6 +1568,10 @@ "display_name": { "type": "string" }, + "drained": { + "description": "Drained reports that a derived group currently has no members, which is\nwhat starts its expiry clock. Absent when the read path did not resolve\nmembership, so a client can tell \"populated\" from \"not resolved\".", + "type": "boolean" + }, "id": { "type": "string" }, @@ -1386,9 +1585,19 @@ "name": { "type": "string" }, + "projected_deletion_at": { + "description": "ProjectedDeletionAt is when reconciliation will delete a drained derived\ngroup. It is accurate only while the reconciler is actually running: a\npaused or unelected leader freezes the clock, and this field cannot say so.", + "type": "string" + }, "source": { "type": "string" }, + "source_value": { + "type": "string" + }, + "source_variable": { + "type": "string" + }, "transitive_member_count": { "type": "integer" }, @@ -1413,6 +1622,30 @@ }, "type": "object" }, + "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.GroupToolAllowlistDTO": { + "properties": { + "connector_id": { + "type": "string" + }, + "group_id": { + "type": "string" + }, + "restriction_mode": { + "type": "string" + }, + "tool_ids": { + "items": { + "type": "string" + }, + "type": "array", + "uniqueItems": false + }, + "version": { + "type": "integer" + } + }, + "type": "object" + }, "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.HeaderInjectionAuthDTO": { "properties": { "header_name": { @@ -1608,97 +1841,259 @@ }, "type": "object" }, - "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.OAuth2ConfigDTO": { + "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.ModelAccessExplanationDTO": { "properties": { - "authorization_endpoint": { - "type": "string" - }, - "client_id": { - "type": "string" - }, - "client_secret": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.ClientSecretRefDTO" - }, - "dcr": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.DCRConfigDTO" - }, - "redirect_uri": { - "type": "string" - }, - "scopes": { + "sets": { "items": { - "type": "string" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.ModelSetAccessEntryDTO" }, "type": "array", "uniqueItems": false }, - "token_endpoint": { - "type": "string" - }, - "token_endpoint_auth_method": { - "description": "TokenEndpointAuthMethod carries the same meaning and the same refusal as\nOIDCConfigDTO's. It is on both arms because neither can derive it:\nOIDC discovery advertises what a provider SUPPORTS, not which form this\nclient is registered for.", - "type": "string" + "unrestricted": { + "type": "boolean" } }, - "required": [ - "authorization_endpoint", - "token_endpoint" - ], "type": "object" }, - "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.OBOAuthDTO": { + "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.ModelSetAccessEntryDTO": { "properties": { - "audience": { - "type": "string" - }, - "authority": { + "kind": { "type": "string" }, - "cache_skew": { - "description": "CacheSkew renders the domain's *time.Duration as its Go duration string\n(e.g. \"5m\"), or is absent when unset — the OBO cache applies its own skew\nat dial time, so absence is meaningful (ADR-0024).", - "type": "string" + "member_count": { + "type": "integer" }, - "client_id": { + "name": { "type": "string" }, - "provider_id": { + "set_id": { "type": "string" }, - "scopes": { + "sources": { "items": { - "type": "string" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.GrantSourceDTO" }, "type": "array", "uniqueItems": false - }, - "tenant_id": { - "type": "string" } }, "type": "object" }, - "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.OBOAuthRequest": { + "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.ModelSetDTO": { "properties": { - "audience": { - "type": "string" - }, - "authority": { + "description": { "type": "string" }, - "cache_skew": { - "description": "CacheSkew is an optional Go duration string (e.g. \"5m\"); the mapper parses\nit into the domain's *time.Duration. Absent means \"no override\".", + "id": { "type": "string" }, - "client_id": { + "kind": { + "description": "Kind is \"authored\" or \"baseline\". It reports PERMANENCE, not scope: the\nbaseline is the one set every User holds and the one that cannot be\nrenamed or deleted. Its membership is editable like any other set's.", + "enum": [ + "authored", + "baseline" + ], "type": "string" }, - "client_secret": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.ClientSecretRefDTO" - }, - "provider_id": { - "type": "string" + "member_count": { + "description": "MemberCount is len(ModelIDs). It is NOT a count of models the caller may\nuse — see Unrestricted.", + "type": "integer" }, - "scopes": { + "model_ids": { + "description": "ModelIDs are the models an admin chose, as opaque strings.", + "items": { + "type": "string" + }, + "type": "array", + "uniqueItems": false + }, + "name": { + "type": "string" + }, + "unrestricted": { + "description": "Unrestricted means \"every model the gateway serves, including ones\nconfigured later\", whatever ModelIDs says. ANY set may have this scope,\nnot only the baseline: an authored set granted to one group widens that\ngroup while everyone else stays on the baseline.\n\nA client MUST branch on it before rendering. ModelIDs is EMPTY in this\nstate, so ignoring the flag renders \"no models\" for a set that grants all\nof them.", + "type": "boolean" + }, + "version": { + "type": "integer" + } + }, + "type": "object" + }, + "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.ModelSetImpactDTO": { + "properties": { + "group_grants": { + "type": "integer" + }, + "next_cursor": { + "description": "NextCursor is present only when a later page exists; pass it as cursor.", + "type": "string" + }, + "prev_cursor": { + "description": "PrevCursor is present only when an earlier page exists; pass it as before.", + "type": "string" + }, + "subjects": { + "description": "Subjects is one page of the grant holders, ordered by kind then\ncase-insensitive name. The counts above are totals on every page,\nwhatever the kind filter or cursor.", + "items": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.GrantSubjectDTO" + }, + "type": "array", + "uniqueItems": false + }, + "user_grants": { + "type": "integer" + } + }, + "type": "object" + }, + "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.ModelSetRefDTO": { + "properties": { + "id": { + "type": "string" + }, + "kind": { + "enum": [ + "authored", + "baseline" + ], + "type": "string" + }, + "name": { + "type": "string" + } + }, + "type": "object" + }, + "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.ModelSetSummaryDTO": { + "properties": { + "description": { + "type": "string" + }, + "id": { + "type": "string" + }, + "kind": { + "enum": [ + "authored", + "baseline" + ], + "type": "string" + }, + "member_count": { + "description": "MemberCount is the number of models an admin chose — see Unrestricted.", + "type": "integer" + }, + "name": { + "type": "string" + }, + "unrestricted": { + "description": "Unrestricted carries the same meaning and the same obligation as\nModelSetDTO.Unrestricted: branch on it before rendering MemberCount.", + "type": "boolean" + }, + "version": { + "type": "integer" + } + }, + "type": "object" + }, + "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.OAuth2ConfigDTO": { + "properties": { + "allow_private_ips": { + "description": "AllowPrivateIPs carries the same meaning as OIDCConfigDTO's, and on this\narm additionally gates a DCR provider's RFC 7591 registration POST — the\nconsumer makes that call through its own private-address guard, so\nwithout this a dynamic client cannot register against an in-cluster\nauthorization server.\n\nChanging it on a LIVE provider forces every user of that provider to\nre-authenticate: the consumer folds this field into the refresh binding\nit fingerprints an upstream by, so a toggle invalidates the stored\nrefresh bindings rather than silently reusing them against a differently\nguarded dialer. Set it when the provider is created, not as a later fix.", + "type": "boolean" + }, + "authorization_endpoint": { + "type": "string" + }, + "client_id": { + "type": "string" + }, + "client_secret": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.ClientSecretRefDTO" + }, + "dcr": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.DCRConfigDTO" + }, + "redirect_uri": { + "description": "Deprecated: inert, for the same reason and with the same effect as\nOIDCConfigDTO.RedirectURI.", + "type": "string" + }, + "scopes": { + "items": { + "type": "string" + }, + "type": "array", + "uniqueItems": false + }, + "token_endpoint": { + "type": "string" + }, + "token_endpoint_auth_method": { + "description": "TokenEndpointAuthMethod carries the same meaning and the same refusal as\nOIDCConfigDTO's. It is on both arms because neither can derive it:\nOIDC discovery advertises what a provider SUPPORTS, not which form this\nclient is registered for.", + "type": "string" + } + }, + "required": [ + "authorization_endpoint", + "token_endpoint" + ], + "type": "object" + }, + "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.OBOAuthDTO": { + "properties": { + "audience": { + "type": "string" + }, + "authority": { + "type": "string" + }, + "cache_skew": { + "description": "CacheSkew renders the domain's *time.Duration as its Go duration string\n(e.g. \"5m\"), or is absent when unset — the OBO cache applies its own skew\nat dial time, so absence is meaningful (ADR-0024).", + "type": "string" + }, + "client_id": { + "type": "string" + }, + "provider_id": { + "type": "string" + }, + "scopes": { + "items": { + "type": "string" + }, + "type": "array", + "uniqueItems": false + }, + "tenant_id": { + "type": "string" + } + }, + "type": "object" + }, + "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.OBOAuthRequest": { + "properties": { + "audience": { + "type": "string" + }, + "authority": { + "type": "string" + }, + "cache_skew": { + "description": "CacheSkew is an optional Go duration string (e.g. \"5m\"); the mapper parses\nit into the domain's *time.Duration. Absent means \"no override\".", + "type": "string" + }, + "client_id": { + "type": "string" + }, + "client_secret": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.ClientSecretRefDTO" + }, + "provider_id": { + "type": "string" + }, + "scopes": { "items": { "type": "string" }, @@ -1742,6 +2137,7 @@ "type": "string" }, "redirect_uri": { + "description": "Deprecated: inert. connector-gateway derives every Provider's upstream\ncallback as {authServerIssuer}/oauth/callback and ignores this field\n(RFC 6749 §3.1.2 — only the deployment knows the URI registered at the\nupstream). Sending it is accepted and has no effect; the value is not\nmigrated and clears on the Provider's next save, because the update\nendpoint is a full replace.", "type": "string" }, "scopes": { @@ -1776,6 +2172,42 @@ }, "type": "object" }, + "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.ReplaceModelSetGrantsRequest": { + "properties": { + "set_ids": { + "description": "Each entry is a Model Set id. Validated as `uuid`, NOT `uuid4`: the\nreserved All Models set is 00000000-0000-0000-0000-000000000001, which\ncarries no version nibble, so a version-4 check refuses the one set every\ninstall ships granted. An id that is not a UUID at all is a 400 from the\nshared validator, like every neighbouring route.", + "items": { + "type": "string" + }, + "type": "array", + "uniqueItems": false + } + }, + "required": [ + "set_ids" + ], + "type": "object" + }, + "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.ReplaceModelSetModelsRequest": { + "properties": { + "model_ids": { + "description": "required without a minimum length: the field must be PRESENT, and an\nempty array is the meaningful \"empty the set\" request.", + "items": { + "type": "string" + }, + "type": "array", + "uniqueItems": false + }, + "unrestricted": { + "description": "Unrestricted sets the set to every model the gateway serves, including\nmodels configured later. Mutually exclusive with a non-empty model_ids:\nsending both is a 400 rather than a guess, because \"unrestricted, and also\nthese three\" has two defensible readings and the wider one is a silent\nprivilege grant.\n\nIt is a FLAG, not a reserved model id. The storage encoding is the\ndirectory's own and never appears on the wire in either direction — a\nmagic value in an id field is the wildcard-injection shape that turns an\nidentifier parameter into an authorization widening.\n\nAny set may be set unrestricted, not only the baseline, and the write is\nreversible in both directions.", + "type": "boolean" + } + }, + "required": [ + "model_ids" + ], + "type": "object" + }, "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.RoleMappingDTO": { "properties": { "claim": { @@ -1850,6 +2282,28 @@ ], "type": "object" }, + "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.SetGroupToolAllowlistRequest": { + "properties": { + "restriction_mode": { + "enum": [ + "unrestricted", + "restricted" + ], + "type": "string" + }, + "tool_ids": { + "items": { + "type": "string" + }, + "type": "array", + "uniqueItems": false + } + }, + "required": [ + "restriction_mode" + ], + "type": "object" + }, "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.TokenExchangeAuthDTO": { "properties": { "audience": { @@ -1916,6 +2370,17 @@ }, "type": "object" }, + "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.UpdateModelSetRequest": { + "properties": { + "description": { + "type": "string" + }, + "name": { + "type": "string" + } + }, + "type": "object" + }, "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.UpstreamInjectAuthDTO": { "properties": { "provider_id": { @@ -2276,6 +2741,10 @@ "occurred_at": { "type": "string" }, + "original_tool_name": { + "description": "OriginalToolName is the tool's raw backend-local name, empty when no\nreversal was available (no reverser wired at capture time, a reverser\nmiss, or a record predating this field) — the client falls back to\nToolName in that case.", + "type": "string" + }, "outcome": { "description": "Outcome is \"ok\" or \"error\", or \"unspecified\" for a record whose\nCategory has no outcome (same set as Decision above; also the fallback\nfor the proto's OUTCOME_UNSPECIFIED). Not omitempty, for the same\nreason as Decision.", "type": "string" @@ -2328,6 +2797,10 @@ "connector_name": { "type": "string" }, + "original_tool_name": { + "description": "OriginalToolName is the tool's raw backend-local name, empty when no\nreversal was available (no reverser wired at capture time, a reverser\nmiss, or a row predating this field) — the client falls back to\nToolName in that case.", + "type": "string" + }, "tool_call_count": { "type": "integer" }, @@ -2468,6 +2941,29 @@ }, "type": "object" }, + "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_platformsettings_v1.ConnectivityDTO": { + "description": "Gateway connectivity state (Connected or Disconnected).", + "properties": { + "state": { + "description": "State is \"connected\" or \"disconnected\".", + "type": "string" + } + }, + "type": "object" + }, + "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_platformsettings_v1.PlatformSettingsDTO": { + "description": "The whole Platform settings picture: every known gateway's current connectivity state.", + "properties": { + "gateways": { + "additionalProperties": { + "type": "string" + }, + "description": "Gateways maps each known gateway key (\"ai-gateway\", \"connector-gateway\")\nto its current connectivity state (\"connected\"/\"disconnected\").", + "type": "object" + } + }, + "type": "object" + }, "github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_internal_config-server_config.CACertConfig": { "description": "Custom CA certificate configuration (PEM inline or by URL).", "properties": { @@ -2861,11 +3357,11 @@ }, "type": "object" }, - "internal_directory_app.ListResponse-github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1_UserDTO": { + "internal_directory_app.ListResponse-github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1_ModelSetRefDTO": { "properties": { "items": { "items": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.UserDTO" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.ModelSetRefDTO" }, "type": "array", "uniqueItems": false @@ -2878,21 +3374,57 @@ } }, "type": "object" - } - }, - "securitySchemes": { - "BearerAuth": { - "description": "Bearer token from OIDC provider", - "in": "header", - "name": "Authorization", - "type": "apiKey" - } - } - }, - "info": { - "description": "Stacklok Enterprise Manager — unified admin API for configuration delivery, directory, and budget management.", - "title": "Enterprise Manager API", - "version": "0.1.0" + }, + "internal_directory_app.ListResponse-github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1_ModelSetSummaryDTO": { + "properties": { + "items": { + "items": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.ModelSetSummaryDTO" + }, + "type": "array", + "uniqueItems": false + }, + "next_cursor": { + "type": "string" + }, + "prev_cursor": { + "type": "string" + } + }, + "type": "object" + }, + "internal_directory_app.ListResponse-github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1_UserDTO": { + "properties": { + "items": { + "items": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.UserDTO" + }, + "type": "array", + "uniqueItems": false + }, + "next_cursor": { + "type": "string" + }, + "prev_cursor": { + "type": "string" + } + }, + "type": "object" + } + }, + "securitySchemes": { + "BearerAuth": { + "description": "Bearer token from OIDC provider", + "in": "header", + "name": "Authorization", + "type": "apiKey" + } + } + }, + "info": { + "description": "Stacklok Enterprise Manager — unified admin API for configuration delivery, directory, and budget management.", + "title": "Enterprise Manager API", + "version": "0.1.0" }, "externalDocs": { "description": "", @@ -2978,6 +3510,189 @@ ] } }, + "/api/v1/platform-settings": { + "get": { + "responses": { + "200": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_platformsettings_v1.PlatformSettingsDTO" + } + } + }, + "description": "OK" + }, + "500": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Internal Server Error" + } + }, + "security": [ + { + "BearerAuth": [] + } + ], + "summary": "Get the whole Platform settings", + "tags": [ + "platform-settings" + ] + } + }, + "/api/v1/platform-settings/gateways/{gateway}/connectivity": { + "get": { + "parameters": [ + { + "description": "Gateway key", + "in": "path", + "name": "gateway", + "required": true, + "schema": { + "enum": [ + "ai-gateway", + "connector-gateway" + ], + "type": "string" + } + } + ], + "responses": { + "200": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_platformsettings_v1.ConnectivityDTO" + } + } + }, + "description": "OK" + }, + "400": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Bad Request" + }, + "500": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Internal Server Error" + } + }, + "security": [ + { + "BearerAuth": [] + } + ], + "summary": "Get gateway connectivity state", + "tags": [ + "platform-settings" + ] + }, + "put": { + "parameters": [ + { + "description": "Gateway key", + "in": "path", + "name": "gateway", + "required": true, + "schema": { + "enum": [ + "ai-gateway", + "connector-gateway" + ], + "type": "string" + } + } + ], + "requestBody": { + "content": { + "application/json": { + "schema": { + "oneOf": [ + { + "type": "object" + }, + { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_platformsettings_v1.ConnectivityDTO", + "summary": "body", + "description": "Desired state" + } + ] + } + } + }, + "description": "Desired state", + "required": true + }, + "responses": { + "200": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_platformsettings_v1.ConnectivityDTO" + } + } + }, + "description": "OK" + }, + "400": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Bad Request" + }, + "403": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Forbidden" + }, + "500": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Internal Server Error" + } + }, + "security": [ + { + "BearerAuth": [] + } + ], + "summary": "Set gateway connectivity state", + "tags": [ + "platform-settings" + ] + } + }, "/api/v1beta/config": { "get": { "description": "Returns the signed enterprise configuration envelope for the calling client.", @@ -3150,7 +3865,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -3206,7 +3921,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -3216,7 +3931,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -3226,7 +3941,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -3262,7 +3977,7 @@ } }, { - "description": "Budget subject id (OIDC sub for user budgets, group UUID for group budgets)", + "description": "Budget subject id (directory platform user UUID for user budgets, directory group UUID for group budgets)", "in": "query", "name": "subject_id", "required": true, @@ -3286,7 +4001,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -3296,7 +4011,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -3306,7 +4021,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -3403,7 +4118,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -3413,7 +4128,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -3441,7 +4156,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -3474,7 +4189,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -3484,7 +4199,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -3530,7 +4245,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -3540,7 +4255,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -3639,7 +4354,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -3649,7 +4364,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -3696,7 +4411,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -3706,7 +4421,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -3716,7 +4431,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -3774,7 +4489,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -3784,7 +4499,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -3794,7 +4509,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -3859,7 +4574,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -3869,7 +4584,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -3879,7 +4594,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -3922,7 +4637,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -3932,7 +4647,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -3952,7 +4667,7 @@ }, "/v1/budgets/pricing/entries/{provider}/{model}": { "delete": { - "description": "Remove one (provider, model) rate row outright. There is no revert-to-baseline: the next request for\nthat model is denied at admission as unpriceable. This republishes the ENTIRE remaining catalog as a\nnew operator-dated version, permanently opting this deployment out of baseline updates shipped later.", + "description": "Withdraw one (provider, model) rate. The entry is kept as an unpriced tombstone rather than removed, so\na later baseline refresh cannot resurrect the rate; the next request for that model is denied at\nadmission as unpriceable. Use POST .../revert to hand the rate back to the shipped baseline. This\nrepublishes the ENTIRE merged catalog as a new operator-dated version, but every other rate keeps its\nownership and a later release's baseline refresh still reaches the ones nobody pinned.", "parameters": [ { "description": "ETag from GET /v1/budgets/pricing or the per-entry GET", @@ -3990,7 +4705,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -4000,7 +4715,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -4010,7 +4725,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -4020,7 +4735,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -4030,7 +4745,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -4091,7 +4806,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -4101,7 +4816,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -4119,7 +4834,7 @@ ] }, "put": { - "description": "Upsert one (provider, model) rate row. The body must carry exactly one of anthropic / openai / google.\nThis republishes the ENTIRE merged catalog as a new operator-dated version: the first per-entry edit\npermanently opts this deployment out of built-in pricing baseline updates shipped in later releases,\nand a model only a newer baseline prices is then denied at admission as unpriceable.", + "description": "Upsert one (provider, model) rate row. The body must carry exactly one of anthropic / openai / google.\nThis republishes the ENTIRE merged catalog as a new operator-dated version, but only the entry it\nwrites becomes operator-managed: every other rate keeps its ownership and a later release's baseline\nrefresh still reaches the ones nobody pinned. Use POST .../revert to hand this rate back.", "parameters": [ { "description": "ETag from GET /v1/budgets/pricing or the per-entry GET", @@ -4177,7 +4892,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -4187,7 +4902,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -4197,7 +4912,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -4207,7 +4922,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -4217,7 +4932,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -4227,7 +4942,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -4245,14 +4960,32 @@ ] } }, - "/v1/budgets/pricing/versions/{effectiveFrom}": { - "delete": { - "description": "Remove a pricing catalog version staged to take effect later, addressed by its exact effective_from.\nClears the 409 a staged version causes on every pricing write. A version that has already taken\neffect cannot be removed and returns 409.", + "/v1/budgets/pricing/entries/{provider}/{model}/revert": { + "post": { + "description": "Hand one (provider, model) rate back to the built-in pricing baseline: the baseline's current rates are\nwritten into the entry, ownership is recorded as the baseline's, and any tombstone is cleared. This is\nthe remedy for a rate pinned by mistake — a pinned rate is otherwise immune to baseline refreshes.\nRefused 409 when the shipped baseline does not price the pair, since there is no rate to restore.", "parameters": [ { - "description": "Staged version's effective_from, RFC 3339", + "description": "ETag from GET /v1/budgets/pricing or the per-entry GET", + "in": "header", + "name": "If-Match", + "required": true, + "schema": { + "type": "string" + } + }, + { + "description": "Literal provider as stored", "in": "path", - "name": "effectiveFrom", + "name": "provider", + "required": true, + "schema": { + "type": "string" + } + }, + { + "description": "Model name (may contain '/')", + "in": "path", + "name": "model", "required": true, "schema": { "type": "string" @@ -4261,43 +4994,53 @@ ], "responses": { "204": { - "description": "Staged pricing catalog version removed" + "description": "Pricing catalog entry reverted to the shipped baseline" }, - "400": { + "404": { "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, - "description": "Bad Request" + "description": "Not Found" }, - "404": { + "409": { "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, - "description": "Not Found" + "description": "Conflict" }, - "409": { + "412": { "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, - "description": "Conflict" + "description": "Precondition Failed" + }, + "428": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Precondition Required" }, "500": { "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -4309,16 +5052,187 @@ "BearerAuth": [] } ], - "summary": "Delete staged pricing catalog version", + "summary": "Revert pricing catalog entry to the shipped baseline", "tags": [ "budgets" ] } }, - "/v1/budgets/spend": { + "/v1/budgets/pricing/versions": { "get": { - "description": "Zero-filled daily USD totals over the served window, including the current (in-progress) UTC day. from/to echo the bounds actually served after clamping (to at the end of the current UTC day, from at the retention horizon).", - "parameters": [ + "description": "List the published pricing catalog versions, newest first, with provenance only (no rate tables).\nAddress one of them by its effective_from on GET /v1/budgets/pricing/versions/{effectiveFrom}.", + "responses": { + "200": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ListPricingVersionsResponse" + } + } + }, + "description": "OK" + }, + "500": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Internal Server Error" + } + }, + "security": [ + { + "BearerAuth": [] + } + ], + "summary": "List pricing catalog versions", + "tags": [ + "budgets" + ] + } + }, + "/v1/budgets/pricing/versions/{effectiveFrom}": { + "delete": { + "description": "Remove a pricing catalog version staged to take effect later, addressed by its exact effective_from.\nClears the 409 a staged version causes on every pricing write. A version that has already taken\neffect cannot be removed and returns 409.", + "parameters": [ + { + "description": "Staged version's effective_from, RFC 3339", + "in": "path", + "name": "effectiveFrom", + "required": true, + "schema": { + "type": "string" + } + } + ], + "responses": { + "204": { + "description": "Staged pricing catalog version removed" + }, + "400": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Bad Request" + }, + "404": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Not Found" + }, + "409": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Conflict" + }, + "500": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Internal Server Error" + } + }, + "security": [ + { + "BearerAuth": [] + } + ], + "summary": "Delete staged pricing catalog version", + "tags": [ + "budgets" + ] + }, + "get": { + "description": "Return the pricing catalog version occupying exactly the given effective_from — active, historical, or\nstaged. Same body shape as GET /v1/budgets/pricing so two versions can be diffed through one decoder.", + "parameters": [ + { + "description": "Version's effective_from, RFC 3339", + "in": "path", + "name": "effectiveFrom", + "required": true, + "schema": { + "type": "string" + } + } + ], + "responses": { + "200": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.GetPricingResponse" + } + } + }, + "description": "OK" + }, + "400": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Bad Request" + }, + "404": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Not Found" + }, + "500": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Internal Server Error" + } + }, + "security": [ + { + "BearerAuth": [] + } + ], + "summary": "Get one pricing catalog version", + "tags": [ + "budgets" + ] + } + }, + "/v1/budgets/spend": { + "get": { + "description": "Zero-filled daily USD totals over the served window, including the current (in-progress) UTC day. from/to echo the bounds actually served after clamping (to at the end of the current UTC day, from at the retention horizon).", + "parameters": [ { "description": "Bucket granularity", "in": "query", @@ -4390,7 +5304,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -4400,7 +5314,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -4497,13 +5411,13 @@ } } }, - "description": "CSV: bucket,group_key,charge_count,charged_usd for one group_by dimension; bucket,\u003cdim1\u003e,\u003cdim2\u003e,...,charge_count,charged_usd for two or more" + "description": "CSV: bucket,group_key,charge_count,charged_usd for one group_by dimension; bucket,`\u003cdim1\u003e`,`\u003cdim2\u003e`,...,charge_count,charged_usd for two or more" }, "400": { "content": { "text/csv": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -4513,7 +5427,7 @@ "content": { "text/csv": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -4531,70 +5445,100 @@ ] } }, - "/v1/budgets/summary": { + "/v1/budgets/spend/export/by-label": { "get": { + "description": "The spend export broken down by conversation label, as CSV, sorted bucket ascending then charged_usd descending then group key(s) ascending. Columns are bucket, one per group_by dimension in the order given, then facet and label, then charge_count and charged_usd. Rows do NOT partition total spend: a session carries one label per facet, so summing either measure across more than one facet multiplies it by the facet count, charge_count exactly as much as charged_usd — pass facet to narrow the export to one. Under a facet filter every row carries that facet, coverage rows included, so pivoting on it is safe. Charges with no label are still counted, under a label naming why: (no-session), (uncaptured), (unclassified) or (unset). The served window (after default/retention clamping) is echoed in the X-Spend-Export-From/To response headers. Experiment-gated; 404s when the operator has not enabled it.", "parameters": [ { - "description": "Principal tier filter", + "description": "Comma-separated grouping dimensions, e.g. user,model. Each must be one of user, model, provider, with no repeats. Defaults to user. The facet and label columns are always present in addition to these", "in": "query", - "name": "scope", + "name": "group_by", + "schema": { + "type": "string" + } + }, + { + "description": "Bucket width", + "in": "query", + "name": "granularity", "schema": { "enum": [ - "user", - "group" + "day", + "week", + "month" ], "type": "string" } }, { - "description": "Subject id prefix match", + "description": "Window start, RFC 3339 or YYYY-MM-DD (default 30 days back, including today)", "in": "query", - "name": "subject", + "name": "from", "schema": { "type": "string" } }, { - "description": "Instant the period windows are computed against, RFC 3339 (default now)", + "description": "Window end (exclusive), RFC 3339 or YYYY-MM-DD", "in": "query", - "name": "at", + "name": "to", "schema": { "type": "string" } }, { - "description": "Opaque keyset cursor from a previous page", + "description": "Filter: restrict the label column to this facet's labels, exact match. The facet vocabulary is operator configuration, so an unknown value yields an empty result rather than an error. Sessions classified without a label for this facet are still counted, under (unset)", "in": "query", - "name": "cursor", + "name": "facet", "schema": { "type": "string" } }, { - "description": "Page size (default 50, max 200, clamped)", + "description": "Filter: served model of the underlying event, exact match", "in": "query", - "name": "limit", + "name": "model", "schema": { - "type": "integer" + "type": "string" + } + }, + { + "description": "Filter: payer tier charged", + "in": "query", + "name": "scope", + "schema": { + "enum": [ + "user", + "group" + ], + "type": "string" + } + }, + { + "description": "Filter: payer charged, exact match", + "in": "query", + "name": "subject_id", + "schema": { + "type": "string" } } ], "responses": { "200": { "content": { - "application/json": { + "text/csv": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.SummaryResponse" + "type": "string" } } }, - "description": "OK" + "description": "CSV: bucket,`\u003cdim1\u003e`,...,facet,label,charge_count,charged_usd" }, "400": { "content": { - "application/json": { + "text/csv": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -4602,9 +5546,9 @@ }, "500": { "content": { - "application/json": { + "text/csv": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -4616,52 +5560,143 @@ "BearerAuth": [] } ], - "summary": "Budget cells summary", + "summary": "Spend export by conversation label (CSV)", "tags": [ "budgets" ] } }, - "/v1/budgets/users/{id}": { - "delete": { + "/v1/budgets/summary": { + "get": { "parameters": [ { - "description": "ETag from GET /v1/budgets", - "in": "header", - "name": "If-Match", + "description": "Principal tier filter", + "in": "query", + "name": "scope", "schema": { + "enum": [ + "user", + "group" + ], "type": "string" } }, { - "description": "User subject_id", - "in": "path", - "name": "id", - "required": true, + "description": "Subject id prefix match", + "in": "query", + "name": "subject", "schema": { "type": "string" } - } - ], - "responses": { - "204": { - "description": "User budget removed" - }, - "404": { - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" - } - } - }, - "description": "Not Found" + }, + { + "description": "Instant the period windows are computed against, RFC 3339 (default now)", + "in": "query", + "name": "at", + "schema": { + "type": "string" + } + }, + { + "description": "Opaque keyset cursor from a previous page", + "in": "query", + "name": "cursor", + "schema": { + "type": "string" + } + }, + { + "description": "Page size (default 50, max 200, clamped)", + "in": "query", + "name": "limit", + "schema": { + "type": "integer" + } + } + ], + "responses": { + "200": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.SummaryResponse" + } + } + }, + "description": "OK" + }, + "400": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Bad Request" + }, + "500": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Internal Server Error" + } + }, + "security": [ + { + "BearerAuth": [] + } + ], + "summary": "Budget cells summary", + "tags": [ + "budgets" + ] + } + }, + "/v1/budgets/users/{id}": { + "delete": { + "parameters": [ + { + "description": "ETag from GET /v1/budgets", + "in": "header", + "name": "If-Match", + "schema": { + "type": "string" + } + }, + { + "description": "User subject_id", + "in": "path", + "name": "id", + "required": true, + "schema": { + "type": "string" + } + } + ], + "responses": { + "204": { + "description": "User budget removed" + }, + "404": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Not Found" }, "412": { "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -4671,7 +5706,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -4729,7 +5764,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -4739,7 +5774,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -4749,7 +5784,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -4814,7 +5849,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -4824,7 +5859,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -4834,7 +5869,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -4880,7 +5915,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -4890,7 +5925,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -4900,7 +5935,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -4935,7 +5970,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -4988,7 +6023,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -4998,7 +6033,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5008,7 +6043,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5026,6 +6061,82 @@ ] } }, + "/v1/connector-identity-providers/discover": { + "post": { + "description": "Probes an MCP server and returns its RFC 9728 protected-resource and RFC 8414 authorization-server metadata.", + "requestBody": { + "content": { + "application/json": { + "schema": { + "oneOf": [ + { + "type": "object" + }, + { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.DiscoverConnectorIdentityProviderRequest", + "summary": "body", + "description": "MCP server to inspect" + } + ] + } + } + }, + "description": "MCP server to inspect", + "required": true + }, + "responses": { + "200": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.DiscoveredConnectorIdentityProviderDTO" + } + } + }, + "description": "OK" + }, + "400": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Bad Request" + }, + "422": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Unprocessable Entity" + }, + "502": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Bad Gateway" + } + }, + "security": [ + { + "BearerAuth": [] + } + ], + "summary": "Discover connector identity provider OAuth metadata", + "tags": [ + "directory" + ] + } + }, "/v1/connector-identity-providers/{id}": { "delete": { "parameters": [ @@ -5047,7 +6158,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5057,7 +6168,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5067,7 +6178,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5077,7 +6188,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5121,7 +6232,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5131,7 +6242,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5141,7 +6252,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5205,7 +6316,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5215,7 +6326,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5225,7 +6336,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5235,7 +6346,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5253,13 +6364,31 @@ ] } }, - "/v1/connectors/{id}/policy": { - "get": { + "/v1/connectors/{connector_id}/groups/{group_id}/tool-restriction": { + "delete": { "parameters": [ { "description": "Connector UUID", "in": "path", - "name": "id", + "name": "connector_id", + "required": true, + "schema": { + "type": "string" + } + }, + { + "description": "UserGroup UUID", + "in": "path", + "name": "group_id", + "required": true, + "schema": { + "type": "string" + } + }, + { + "description": "ETag from GET .../tool-restriction", + "in": "header", + "name": "If-Match", "required": true, "schema": { "type": "string" @@ -5271,7 +6400,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.ConnectorPolicyDTO" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.GroupToolAllowlistDTO" } } }, @@ -5281,7 +6410,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5291,17 +6420,37 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, "description": "Not Found" }, + "412": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Precondition Failed" + }, + "428": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Precondition Required" + }, "500": { "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5313,19 +6462,26 @@ "BearerAuth": [] } ], - "summary": "Get connector policy", + "summary": "Clear a group's tool restriction on a connector", "tags": [ "directory" ] - } - }, - "/v1/connectors/{id}/policy/cedar-mode": { - "delete": { + }, + "get": { "parameters": [ { "description": "Connector UUID", "in": "path", - "name": "id", + "name": "connector_id", + "required": true, + "schema": { + "type": "string" + } + }, + { + "description": "UserGroup UUID", + "in": "path", + "name": "group_id", "required": true, "schema": { "type": "string" @@ -5337,7 +6493,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.ConnectorPolicyDTO" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.GroupToolAllowlistDTO" } } }, @@ -5347,7 +6503,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5357,27 +6513,17 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, "description": "Not Found" }, - "412": { - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" - } - } - }, - "description": "Precondition Failed" - }, "500": { "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5389,7 +6535,7 @@ "BearerAuth": [] } ], - "summary": "Switch a connector policy back to structured authoring mode", + "summary": "Get a group's tool restriction on a connector", "tags": [ "directory" ] @@ -5399,19 +6545,293 @@ { "description": "Connector UUID", "in": "path", - "name": "id", + "name": "connector_id", + "required": true, + "schema": { + "type": "string" + } + }, + { + "description": "UserGroup UUID", + "in": "path", + "name": "group_id", + "required": true, + "schema": { + "type": "string" + } + }, + { + "description": "ETag from GET .../tool-restriction", + "in": "header", + "name": "If-Match", "required": true, "schema": { "type": "string" } } ], - "responses": { - "200": { - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.ConnectorPolicyDTO" + "requestBody": { + "content": { + "application/json": { + "schema": { + "oneOf": [ + { + "type": "object" + }, + { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.SetGroupToolAllowlistRequest", + "summary": "body", + "description": "Restriction mode and tool ids" + } + ] + } + } + }, + "description": "Restriction mode and tool ids", + "required": true + }, + "responses": { + "200": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.GroupToolAllowlistDTO" + } + } + }, + "description": "OK" + }, + "400": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Bad Request" + }, + "404": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Not Found" + }, + "412": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Precondition Failed" + }, + "422": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Unprocessable Entity" + }, + "428": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Precondition Required" + }, + "500": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Internal Server Error" + } + }, + "security": [ + { + "BearerAuth": [] + } + ], + "summary": "Set a group's tool restriction on a connector", + "tags": [ + "directory" + ] + } + }, + "/v1/connectors/{id}/policy": { + "get": { + "parameters": [ + { + "description": "Connector UUID", + "in": "path", + "name": "id", + "required": true, + "schema": { + "type": "string" + } + } + ], + "responses": { + "200": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.ConnectorPolicyDTO" + } + } + }, + "description": "OK" + }, + "400": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Bad Request" + }, + "404": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Not Found" + }, + "500": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Internal Server Error" + } + }, + "security": [ + { + "BearerAuth": [] + } + ], + "summary": "Get connector policy", + "tags": [ + "directory" + ] + } + }, + "/v1/connectors/{id}/policy/cedar-mode": { + "delete": { + "parameters": [ + { + "description": "Connector UUID", + "in": "path", + "name": "id", + "required": true, + "schema": { + "type": "string" + } + } + ], + "responses": { + "200": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.ConnectorPolicyDTO" + } + } + }, + "description": "OK" + }, + "400": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Bad Request" + }, + "404": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Not Found" + }, + "412": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Precondition Failed" + }, + "500": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Internal Server Error" + } + }, + "security": [ + { + "BearerAuth": [] + } + ], + "summary": "Switch a connector policy back to structured authoring mode", + "tags": [ + "directory" + ] + }, + "put": { + "parameters": [ + { + "description": "Connector UUID", + "in": "path", + "name": "id", + "required": true, + "schema": { + "type": "string" + } + } + ], + "responses": { + "200": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.ConnectorPolicyDTO" } } }, @@ -5421,7 +6841,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5431,7 +6851,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5441,7 +6861,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5451,7 +6871,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5517,7 +6937,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5527,7 +6947,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5537,7 +6957,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5547,7 +6967,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5557,7 +6977,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5567,7 +6987,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5577,7 +6997,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5652,7 +7072,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5662,7 +7082,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5672,7 +7092,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5682,7 +7102,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5692,7 +7112,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5702,7 +7122,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5712,7 +7132,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5722,7 +7142,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5777,7 +7197,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5787,7 +7207,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5797,7 +7217,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5807,7 +7227,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5817,7 +7237,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5863,7 +7283,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5927,7 +7347,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5937,7 +7357,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5947,7 +7367,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -5995,7 +7415,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6005,7 +7425,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6015,7 +7435,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6068,7 +7488,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6078,7 +7498,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6088,7 +7508,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6161,7 +7581,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6171,7 +7591,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6181,7 +7601,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6191,7 +7611,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6246,7 +7666,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6256,7 +7676,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6266,7 +7686,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6313,7 +7733,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6323,7 +7743,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6333,7 +7753,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6426,7 +7846,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6436,7 +7856,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6489,7 +7909,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6499,7 +7919,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6554,7 +7974,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6564,7 +7984,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6574,7 +7994,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6584,7 +8004,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6637,7 +8057,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6647,7 +8067,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6657,7 +8077,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6667,7 +8087,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6722,7 +8142,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6732,7 +8152,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6742,7 +8162,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6752,7 +8172,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6805,7 +8225,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6815,7 +8235,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6825,7 +8245,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6835,7 +8255,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6874,7 +8294,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6884,7 +8304,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6894,7 +8314,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6938,7 +8358,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6948,7 +8368,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -6958,7 +8378,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7022,7 +8442,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7032,7 +8452,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7042,7 +8462,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7052,7 +8472,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7154,7 +8574,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7164,7 +8584,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7174,7 +8594,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7213,7 +8633,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7223,7 +8643,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7267,7 +8687,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7277,7 +8697,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7287,7 +8707,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7341,7 +8761,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7351,7 +8771,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7369,9 +8789,198 @@ ] } }, - "/v1/keys": { + "/v1/groups/{id}/model-sets": { "get": { - "description": "Returns every key owned by the authenticated caller. Never\nincludes key secrets or hashes.", + "parameters": [ + { + "description": "UserGroup UUID", + "in": "path", + "name": "id", + "required": true, + "schema": { + "type": "string" + } + } + ], + "responses": { + "200": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/internal_directory_app.ListResponse-github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1_ModelSetRefDTO" + } + } + }, + "description": "OK" + }, + "400": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Bad Request" + }, + "404": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Not Found" + }, + "500": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Internal Server Error" + } + }, + "security": [ + { + "BearerAuth": [] + } + ], + "summary": "List the Model Sets granted to a UserGroup", + "tags": [ + "directory" + ] + }, + "put": { + "parameters": [ + { + "description": "UserGroup UUID", + "in": "path", + "name": "id", + "required": true, + "schema": { + "type": "string" + } + }, + { + "description": "ETag from GET /v1/groups/{id}/model-sets", + "in": "header", + "name": "If-Match", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "content": { + "application/json": { + "schema": { + "oneOf": [ + { + "type": "object" + }, + { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.ReplaceModelSetGrantsRequest", + "summary": "body", + "description": "Model Set ids" + } + ] + } + } + }, + "description": "Model Set ids", + "required": true + }, + "responses": { + "200": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/internal_directory_app.ListResponse-github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1_ModelSetRefDTO" + } + } + }, + "description": "OK" + }, + "400": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Bad Request" + }, + "404": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Not Found" + }, + "412": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Precondition Failed" + }, + "422": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Unprocessable Entity" + }, + "428": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Precondition Required" + }, + "500": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Internal Server Error" + } + }, + "security": [ + { + "BearerAuth": [] + } + ], + "summary": "Replace the Model Sets granted to a UserGroup", + "tags": [ + "directory" + ] + } + }, + "/v1/keys": { + "get": { + "description": "Returns every key owned by the authenticated caller. Never\nincludes key secrets or hashes.", "responses": { "200": { "content": { @@ -7387,7 +8996,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7397,7 +9006,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7412,7 +9021,7 @@ ], "summary": "List the caller's virtual API keys", "tags": [ - "Keys" + "keys" ] }, "post": { @@ -7452,7 +9061,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7462,7 +9071,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7472,7 +9081,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7487,7 +9096,7 @@ ], "summary": "Create a virtual API key", "tags": [ - "Keys" + "keys" ] } }, @@ -7513,7 +9122,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7523,7 +9132,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7533,7 +9142,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7548,7 +9157,7 @@ ], "summary": "Revoke one of the caller's virtual API keys", "tags": [ - "Keys" + "keys" ] }, "get": { @@ -7579,7 +9188,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7589,7 +9198,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7599,7 +9208,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7614,7 +9223,7 @@ ], "summary": "Get one of the caller's virtual API keys", "tags": [ - "Keys" + "keys" ] } }, @@ -7640,7 +9249,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7650,7 +9259,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7660,7 +9269,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7675,7 +9284,7 @@ ], "summary": "Disable one of the caller's virtual API keys", "tags": [ - "Keys" + "keys" ] } }, @@ -7701,7 +9310,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7711,7 +9320,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7721,7 +9330,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7731,7 +9340,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7746,7 +9355,7 @@ ], "summary": "Re-enable one of the caller's disabled virtual API keys", "tags": [ - "Keys" + "keys" ] } }, @@ -7779,7 +9388,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7789,7 +9398,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7799,7 +9408,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7814,7 +9423,7 @@ ], "summary": "Rotate one of the caller's virtual API keys", "tags": [ - "Keys" + "keys" ] } }, @@ -7835,7 +9444,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7888,7 +9497,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7898,7 +9507,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7908,7 +9517,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7918,7 +9527,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7957,7 +9566,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7967,7 +9576,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7977,7 +9586,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -7987,7 +9596,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8031,7 +9640,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8041,7 +9650,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8051,7 +9660,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8090,7 +9699,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8100,7 +9709,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8115,7 +9724,7 @@ ], "summary": "Get the caller's own directory profile", "tags": [ - "Me" + "me" ] } }, @@ -8179,7 +9788,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8189,7 +9798,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8199,7 +9808,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8291,7 +9900,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8301,7 +9910,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8311,7 +9920,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8383,7 +9992,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8393,7 +10002,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8403,7 +10012,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8423,7 +10032,7 @@ }, "/v1/me/budgets/summary": { "get": { - "description": "The caller's personal day/month cards (absent when no personal budget exists at that period) and every budget cell applicable to them. Group rows expose team aggregates, never teammate records; my_contribution_usd is the caller's own share, folded from their charge records (retention-bounded).", + "description": "The caller's personal day/month cards (absent when no personal budget exists at that period) and every budget cell applicable to them. Group rows expose team aggregates, never teammate records; my_contribution_usd is the caller's own period-to-date share of that cell, exact for the whole of the cell's period.", "responses": { "200": { "content": { @@ -8439,7 +10048,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8449,7 +10058,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_budgets_v1.ErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8518,7 +10127,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8528,7 +10137,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8538,7 +10147,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8552,7 +10161,7 @@ ], "summary": "List my connections", "tags": [ - "Me" + "me" ] }, "post": { @@ -8591,7 +10200,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8601,7 +10210,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8611,7 +10220,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8621,7 +10230,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8631,7 +10240,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8641,7 +10250,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8655,7 +10264,7 @@ ], "summary": "Create my connection", "tags": [ - "Me" + "me" ] } }, @@ -8680,7 +10289,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8690,7 +10299,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8700,7 +10309,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8710,7 +10319,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8720,7 +10329,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8734,7 +10343,7 @@ ], "summary": "Delete my connection", "tags": [ - "Me" + "me" ] }, "get": { @@ -8764,7 +10373,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8774,7 +10383,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8784,7 +10393,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8794,7 +10403,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8804,7 +10413,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8818,7 +10427,7 @@ ], "summary": "Get my connection", "tags": [ - "Me" + "me" ] } }, @@ -8870,7 +10479,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8880,7 +10489,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8890,7 +10499,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8900,7 +10509,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8910,7 +10519,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8924,7 +10533,7 @@ ], "summary": "Enable or disable my connection", "tags": [ - "Me" + "me" ] } }, @@ -8976,7 +10585,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8986,7 +10595,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -8996,7 +10605,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -9006,7 +10615,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -9016,7 +10625,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -9026,7 +10635,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -9040,7 +10649,7 @@ ], "summary": "Set my connection's tool narrowing", "tags": [ - "Me" + "me" ] } }, @@ -9096,7 +10705,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -9106,7 +10715,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -9116,7 +10725,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -9130,7 +10739,7 @@ ], "summary": "List Connectors visible to me", "tags": [ - "Me" + "me" ] } }, @@ -9171,7 +10780,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -9181,7 +10790,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -9191,7 +10800,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -9201,7 +10810,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -9211,7 +10820,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -9225,7 +10834,7 @@ ], "summary": "Get a Connector visible to me", "tags": [ - "Me" + "me" ] } }, @@ -9438,10 +11047,7 @@ "content": { "application/json": { "schema": { - "additionalProperties": { - "type": "string" - }, - "type": "object" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -9451,10 +11057,7 @@ "content": { "application/json": { "schema": { - "additionalProperties": { - "type": "string" - }, - "type": "object" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -9581,10 +11184,7 @@ "content": { "application/json": { "schema": { - "additionalProperties": { - "type": "string" - }, - "type": "object" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -9594,10 +11194,7 @@ "content": { "application/json": { "schema": { - "additionalProperties": { - "type": "string" - }, - "type": "object" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -9683,10 +11280,7 @@ "content": { "application/json": { "schema": { - "additionalProperties": { - "type": "string" - }, - "type": "object" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -9696,10 +11290,7 @@ "content": { "application/json": { "schema": { - "additionalProperties": { - "type": "string" - }, - "type": "object" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -9769,10 +11360,7 @@ "content": { "application/json": { "schema": { - "additionalProperties": { - "type": "string" - }, - "type": "object" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -9782,10 +11370,7 @@ "content": { "application/json": { "schema": { - "additionalProperties": { - "type": "string" - }, - "type": "object" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -9869,10 +11454,7 @@ "content": { "application/json": { "schema": { - "additionalProperties": { - "type": "string" - }, - "type": "object" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -9882,10 +11464,7 @@ "content": { "application/json": { "schema": { - "additionalProperties": { - "type": "string" - }, - "type": "object" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -9963,10 +11542,7 @@ "content": { "application/json": { "schema": { - "additionalProperties": { - "type": "string" - }, - "type": "object" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -9976,10 +11552,7 @@ "content": { "application/json": { "schema": { - "additionalProperties": { - "type": "string" - }, - "type": "object" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -10057,10 +11630,7 @@ "content": { "application/json": { "schema": { - "additionalProperties": { - "type": "string" - }, - "type": "object" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -10070,10 +11640,7 @@ "content": { "application/json": { "schema": { - "additionalProperties": { - "type": "string" - }, - "type": "object" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -10129,48 +11696,738 @@ "type": "string" } }, - { - "description": "Window end, RFC 3339, exclusive", - "in": "query", - "name": "end", - "required": true, - "schema": { - "type": "string" - } - } - ], - "responses": { - "200": { + { + "description": "Window end, RFC 3339, exclusive", + "in": "query", + "name": "end", + "required": true, + "schema": { + "type": "string" + } + } + ], + "responses": { + "200": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_metering_v1.UserUsageResponse" + } + } + }, + "description": "OK" + }, + "400": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Bad Request" + }, + "500": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Internal Server Error" + } + }, + "security": [ + { + "BearerAuth": [] + } + ], + "summary": "User usage", + "tags": [ + "metering" + ] + } + }, + "/v1/model-sets": { + "get": { + "parameters": [ + { + "description": "Case-insensitive substring match on name", + "in": "query", + "name": "search", + "schema": { + "type": "string" + } + }, + { + "description": "Opaque pagination cursor", + "in": "query", + "name": "cursor", + "schema": { + "type": "string" + } + }, + { + "description": "Maximum items to return (default 50, max 200)", + "in": "query", + "name": "limit", + "schema": { + "type": "integer" + } + } + ], + "responses": { + "200": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/internal_directory_app.ListResponse-github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1_ModelSetSummaryDTO" + } + } + }, + "description": "OK" + }, + "400": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Bad Request" + }, + "500": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Internal Server Error" + } + }, + "security": [ + { + "BearerAuth": [] + } + ], + "summary": "List Model Sets", + "tags": [ + "directory" + ] + }, + "post": { + "requestBody": { + "content": { + "application/json": { + "schema": { + "oneOf": [ + { + "type": "object" + }, + { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.CreateModelSetRequest", + "summary": "body", + "description": "Model Set" + } + ] + } + } + }, + "description": "Model Set", + "required": true + }, + "responses": { + "201": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.ModelSetDTO" + } + } + }, + "description": "Created" + }, + "400": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Bad Request" + }, + "409": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Conflict" + }, + "413": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Request Entity Too Large" + }, + "422": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Unprocessable Entity" + }, + "500": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Internal Server Error" + } + }, + "security": [ + { + "BearerAuth": [] + } + ], + "summary": "Create a Model Set", + "tags": [ + "directory" + ] + } + }, + "/v1/model-sets/{id}": { + "delete": { + "parameters": [ + { + "description": "Model Set UUID", + "in": "path", + "name": "id", + "required": true, + "schema": { + "type": "string" + } + }, + { + "description": "ETag from GET /v1/model-sets/{id}", + "in": "header", + "name": "If-Match", + "required": true, + "schema": { + "type": "string" + } + } + ], + "responses": { + "204": { + "description": "Deleted" + }, + "400": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Bad Request" + }, + "404": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Not Found" + }, + "409": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Conflict" + }, + "412": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Precondition Failed" + }, + "428": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Precondition Required" + }, + "500": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Internal Server Error" + } + }, + "security": [ + { + "BearerAuth": [] + } + ], + "summary": "Delete a Model Set", + "tags": [ + "directory" + ] + }, + "get": { + "parameters": [ + { + "description": "Model Set UUID", + "in": "path", + "name": "id", + "required": true, + "schema": { + "type": "string" + } + } + ], + "responses": { + "200": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.ModelSetDTO" + } + } + }, + "description": "OK" + }, + "400": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Bad Request" + }, + "404": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Not Found" + }, + "500": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Internal Server Error" + } + }, + "security": [ + { + "BearerAuth": [] + } + ], + "summary": "Get a Model Set", + "tags": [ + "directory" + ] + }, + "patch": { + "parameters": [ + { + "description": "Model Set UUID", + "in": "path", + "name": "id", + "required": true, + "schema": { + "type": "string" + } + }, + { + "description": "ETag from GET /v1/model-sets/{id}", + "in": "header", + "name": "If-Match", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "content": { + "application/json": { + "schema": { + "oneOf": [ + { + "type": "object" + }, + { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.UpdateModelSetRequest", + "summary": "body", + "description": "New name" + } + ] + } + } + }, + "description": "New name", + "required": true + }, + "responses": { + "200": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.ModelSetDTO" + } + } + }, + "description": "OK" + }, + "400": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Bad Request" + }, + "404": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Not Found" + }, + "409": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Conflict" + }, + "412": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Precondition Failed" + }, + "422": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Unprocessable Entity" + }, + "428": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Precondition Required" + }, + "500": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Internal Server Error" + } + }, + "security": [ + { + "BearerAuth": [] + } + ], + "summary": "Rename a Model Set", + "tags": [ + "directory" + ] + } + }, + "/v1/model-sets/{id}/impact": { + "get": { + "parameters": [ + { + "description": "Model Set UUID", + "in": "path", + "name": "id", + "required": true, + "schema": { + "type": "string" + } + }, + { + "description": "Restrict subjects to one kind", + "in": "query", + "name": "kind", + "schema": { + "enum": [ + "user", + "group" + ], + "type": "string" + } + }, + { + "description": "Opaque cursor from next_cursor; returns the page after it", + "in": "query", + "name": "cursor", + "schema": { + "type": "string" + } + }, + { + "description": "Opaque cursor from prev_cursor; returns the page before it (exclusive with cursor)", + "in": "query", + "name": "before", + "schema": { + "type": "string" + } + }, + { + "description": "Maximum subjects to return (default 50, max 200)", + "in": "query", + "name": "limit", + "schema": { + "type": "integer" + } + } + ], + "responses": { + "200": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.ModelSetImpactDTO" + } + } + }, + "description": "OK" + }, + "400": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Bad Request" + }, + "404": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Not Found" + }, + "500": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Internal Server Error" + } + }, + "security": [ + { + "BearerAuth": [] + } + ], + "summary": "Preview what deleting a Model Set would remove", + "tags": [ + "directory" + ] + } + }, + "/v1/model-sets/{id}/models": { + "put": { + "parameters": [ + { + "description": "Model Set UUID", + "in": "path", + "name": "id", + "required": true, + "schema": { + "type": "string" + } + }, + { + "description": "ETag from GET /v1/model-sets/{id}", + "in": "header", + "name": "If-Match", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "content": { + "application/json": { + "schema": { + "oneOf": [ + { + "type": "object" + }, + { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.ReplaceModelSetModelsRequest", + "summary": "body", + "description": "Model ids, or unrestricted" + } + ] + } + } + }, + "description": "Model ids, or unrestricted", + "required": true + }, + "responses": { + "200": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.ModelSetDTO" + } + } + }, + "description": "OK" + }, + "400": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Bad Request" + }, + "404": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Not Found" + }, + "412": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Precondition Failed" + }, + "413": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Request Entity Too Large" + }, + "422": { "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_metering_v1.UserUsageResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, - "description": "OK" + "description": "Unprocessable Entity" }, - "400": { + "428": { "content": { "application/json": { "schema": { - "additionalProperties": { - "type": "string" - }, - "type": "object" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, - "description": "Bad Request" + "description": "Precondition Required" }, "500": { "content": { "application/json": { "schema": { - "additionalProperties": { - "type": "string" - }, - "type": "object" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -10182,9 +12439,9 @@ "BearerAuth": [] } ], - "summary": "User usage", + "summary": "Replace a Model Set's membership", "tags": [ - "metering" + "directory" ] } }, @@ -10271,7 +12528,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -10281,7 +12538,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -10327,7 +12584,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -10337,7 +12594,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -10347,7 +12604,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -10393,7 +12650,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -10403,7 +12660,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -10413,7 +12670,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -10452,7 +12709,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -10462,7 +12719,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -10506,7 +12763,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -10516,7 +12773,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -10526,7 +12783,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -10580,7 +12837,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -10590,7 +12847,7 @@ "content": { "application/json": { "schema": { - "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.AdminErrorResponse" + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" } } }, @@ -10607,6 +12864,251 @@ "directory" ] } + }, + "/v1/users/{id}/model-access": { + "get": { + "parameters": [ + { + "description": "User UUID", + "in": "path", + "name": "id", + "required": true, + "schema": { + "type": "string" + } + } + ], + "responses": { + "200": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.ModelAccessExplanationDTO" + } + } + }, + "description": "OK" + }, + "400": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Bad Request" + }, + "500": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Internal Server Error" + } + }, + "security": [ + { + "BearerAuth": [] + } + ], + "summary": "Explain a User's effective model access", + "tags": [ + "directory" + ] + } + }, + "/v1/users/{id}/model-sets": { + "get": { + "parameters": [ + { + "description": "User UUID", + "in": "path", + "name": "id", + "required": true, + "schema": { + "type": "string" + } + } + ], + "responses": { + "200": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/internal_directory_app.ListResponse-github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1_ModelSetRefDTO" + } + } + }, + "description": "OK" + }, + "400": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Bad Request" + }, + "404": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Not Found" + }, + "500": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Internal Server Error" + } + }, + "security": [ + { + "BearerAuth": [] + } + ], + "summary": "List the Model Sets granted directly to a User", + "tags": [ + "directory" + ] + }, + "put": { + "parameters": [ + { + "description": "User UUID", + "in": "path", + "name": "id", + "required": true, + "schema": { + "type": "string" + } + }, + { + "description": "ETag from GET /v1/users/{id}/model-sets", + "in": "header", + "name": "If-Match", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "content": { + "application/json": { + "schema": { + "oneOf": [ + { + "type": "object" + }, + { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1.ReplaceModelSetGrantsRequest", + "summary": "body", + "description": "Model Set ids" + } + ] + } + } + }, + "description": "Model Set ids", + "required": true + }, + "responses": { + "200": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/internal_directory_app.ListResponse-github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_directory_v1_ModelSetRefDTO" + } + } + }, + "description": "OK" + }, + "400": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Bad Request" + }, + "404": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Not Found" + }, + "412": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Precondition Failed" + }, + "422": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Unprocessable Entity" + }, + "428": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Precondition Required" + }, + "500": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/github_com_stacklok_stacklok-enterprise-platform_enterprise_toolhive-enterprise_contracts_common_v1.ErrorResponse" + } + } + }, + "description": "Internal Server Error" + } + }, + "security": [ + { + "BearerAuth": [] + } + ], + "summary": "Replace the Model Sets granted directly to a User", + "tags": [ + "directory" + ] + } } }, "openapi": "3.1.0",