Skip to main content

Api

How the API works

The pages talk to the id service through a REST API in the style of Kubernetes.

Outline
  • Sections:
    • Conventions
    • Who is asking
    • Resources

Read more

Interactions

A sign-in in progress.

Outline
  • Sections:
    • Phases
    • Signing in

Read more

Sessions and accounts

Who is signed in, and their details.

Outline
  • Sections:
    • sessions/current
    • accounts/<name>

Read more

Passkeys

The signed-in person's passkeys.

Read more

Grants

What the signed-in person has agreed to share, service by service.

Read more

Policy decisions

The decisions policy made about the signed-in person, from the same record an audit reads.

Read more

Policies

The policy in force, for anyone to read — signed in or not — and every revision id has run.

Read more

Claims reviews

Not served by the id service: sent by it, to a service that owns a scope, at <URL>/api/v1alpha1/claimsreviews or FG_ID_SERVICE_<NAME>_CLAIMS_ENDPOINT.

Read more