Declare a trusted issuer for this tenant

Registers an external authorization server this tenant is willing to accept
workload tokens from, and returns the derivedAudience that must be
configured in that server.

The declaration lands switched off. enabled is server-set to false and cannot be sent: a body carrying it is rejected, and admitting

the issuer into the trust set is the separate enable verb. That
separation is what makes an abandoned half-finished form harmless.

🔴 No credential is submitted here, and none exists. ANKASecure verifies

tokens from this issuer against the public key set the issuer itself publishes, so
there is no secret to store, seal, mask or rotate. Revoking the workload in your own
IdP is therefore sufficient to stop it authenticating.

The issuer is stored in canonical form — lowercase scheme and

host, the default port removed, no trailing slash — because that string is both the
uniqueness key and the value a presented token's iss claim is compared
against. The response reports the canonical form, which is frequently not the string
that was typed. The path keeps its case: Keycloak realm names and Okta authorization
server ids are case-sensitive.

derivedAudience is computed by this server from the declaration's

scope and is never stored. Configure it verbatim as the API identifier / audience of
the machine-to-machine application in the external IdP. A one-character divergence
between what is configured there and what is required here produces a 401 that
cannot be diagnosed from either side, which is why the value is projected rather
than composed by any client.

Entitlement-gated. Declaring is one of the verbs a tenant's edition

governs. Reading, disabling, withdrawing and validating are not.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Path Params
uuid
required
Body Params

The declaration. preset selects the vendor mechanism and NARROWS the platform algorithm allow-list; issuer is the identifier the provider publishes in its discovery document; maximumTokenLifetime may lower the platform ceiling and never raise it. scope, tenantId, derivedAudience, status and enabled are server-derived and are REJECTED if present.

A trusted-issuer declaration. Carries no credential of any kind: ANKASecure verifies tokens from this issuer against the PUBLIC key set the issuer publishes, so there is no secret to submit, store, seal or rotate.

string
enum
required

The vendor mechanism. It NARROWS the platform algorithm allow-list and can never widen it; choose GENERIC_OIDC for any provider not named here.

Allowed:
string
required
length between 0 and 2048

The issuer identifier, exactly as the provider publishes it in its OpenID Connect discovery document. HTTPS only, no query and no fragment (OpenID Connect Discovery 1.0 section 2). It is stored in canonical form — lowercase scheme and host, the default port removed, no trailing slash — because that string is both the uniqueness key and the value a presented token's iss claim is compared against.

string
length between 0 and 200

An operator-chosen label. Carries no meaning to any rule and is never compared against anything in a token.

permittedAlgorithms
array of strings
length between 0 and 9

The signature algorithms a token from this issuer may use. Omit it to accept the preset's own set. Every entry must be a member of that set — a narrower list is admitted, a wider one is refused by name.

permittedAlgorithms
string
required

The longest exp - iat a token from this issuer may declare, as an ISO-8601 duration. It may LOWER the platform ceiling and never raise it. The ceiling is an accept-or-refuse gate on the ISSUER rather than a bound on any one token: a declaration above it is refused outright, and every token that issuer mints is refused with it, a five-minute one included.

Headers
string
enum
Defaults to application/json

Generated from available response content types

Allowed:
Responses

Language
Credentials
Bearer
JWT
URL
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json
application/problem+json