Grants one external workload identity — an issuer plus the sub claim
its tokens carry — the right to authenticate as one of this tenant's Cryptographic
Actors. This is the act that completes an onboarding: until it exists, a token from
a trusted issuer authenticates nothing.
The issuerId must be one THIS TENANT trusts — either a declaration
of its own or a deployment-scoped one every tenant inherits. An id it cannot reach
answers 404, including one belonging to another tenant, answered identically.
The subject is compared verbatim and case-sensitively against the
token's sub. Take it from the machine-to-machine application in the
external IdP rather than typing it: Auth0 emits <clientId>@clients,
Keycloak the service-account user id, and a SPIFFE-shaped issuer a full
spiffe:// URI.
🔴 No actor is created. A binding naming an actor that does not exist in
this tenant is a 404 and writes nothing — on this plane most of all, since creating
it would be a platform operator provisioning a customer's principal as a side effect
of granting an external identity access to it.
Not entitlement-gated. The operator is the party that sells the edition.
The audit row is filed under the tenant in the path, with
actorPlane = PLATFORM and the operator's own username, so the customer's
own audit query returns it.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||