Api
- How the API works - (Outline, Contents)
- Interactions - (Outline, Contents)
- Sessions and accounts - (Outline, Contents)
- Passkeys - (Outline, Contents)
- Grants - (Outline, Contents)
- Policy decisions - (Outline, Contents)
- Policies - (Outline, Contents)
- Claims reviews - (Outline, Contents)
How the API works
The pages talk to the id service through a REST API in the style of Kubernetes.
Outline
- Sections:
- Conventions
- Who is asking
- Resources
Interactions
A sign-in in progress.
Outline
- Sections:
- Phases
- Signing in
Sessions and accounts
Who is signed in, and their details.
Outline
- Sections:
sessions/currentaccounts/<name>
Passkeys
The signed-in person's passkeys.
Grants
What the signed-in person has agreed to share, service by service.
Policy decisions
The decisions policy made about the signed-in person, from the same record an audit reads.
Policies
The policy in force, for anyone to read — signed in or not — and every revision id has run.
Claims reviews
Not served by the id service: sent by it, to a service that
owns a scope, at <URL>/api/v1alpha1/claimsreviews or
FG_ID_SERVICE_<NAME>_CLAIMS_ENDPOINT.