Registers an external authorization server THIS TENANT is willing to accept workload
tokens from, written by a platform operator, and returns the
derivedAudience that must be configured in that server.
The row is TENANT-scoped and owned by the tenant in the path. It is not a
deployment-wide declaration and never becomes one: no other tenant's trust set
moves. The deployment registry has its own plane at
/api/v3/admin/platform/workload-identity/issuers, and choosing between
them is choosing whether one customer or all of them will trust this issuer.
The declaration lands switched off, exactly as on the tenant plane.
enabled is server-set to false and cannot be sent;
admitting the issuer into the trust set is the separate enable verb.
🔴 No credential is submitted here, and none exists. Verification uses the
public key set the issuer itself publishes, so there is no secret to store, seal,
mask or rotate — which is why an operator can complete this configuration without
ever holding customer key material.
Not entitlement-gated. A tenant whose edition does not include workload
identity is still provisioned here. The operator is the party that sells the
edition. The verdict is readable at ../workload-identity/entitlement
on this same plane, as information.
The audit row is filed under the tenant in the path, with
actorPlane = PLATFORM and the operator's own username — so a
tenant-scoped audit query run by that customer returns it.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||