Admit a deployment-wide trusted issuer into every tenant's trust set

Admits the issuer into the effective trust set of every tenant on the
deployment
, effective on the very next request.

This is the verb that actually widens what the deployment will accept a token from, which is why declaring and enabling are separate acts. Nothing here is written per tenant: a tenant's trust set is composed at read time as the deployment-scoped issuers union its own, so one row becoming enabled is the whole change.

Enable it after the bindings that make it useful exist. A binding may name a disabled issuer deliberately, so the natural order is declare, bind the workloads, then enable.

Never entitlement-gated. No Edition widens or narrows this plane. These are

the deployment operator's own declarations rather than a tenant's, so there is no
Edition to consult (FR-181.16).

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Path Params
uuid
required
Headers
string
enum
Defaults to application/json

Generated from available response content types

Allowed:
Responses

Language
Credentials
Bearer
JWT
URL
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json
application/problem+json