Read one of a tenant's trusted issuers (platform)

One declaration belonging to the tenant in the path, including its current
derivedAudience — the value that must be configured as the audience of

the machine-to-machine application in the external IdP.

🔴 An issuer id belonging to a DIFFERENT tenant answers 404, never 403,

and the two answers are identical. A 403 for a row that exists and a 404 for one
that does not is an existence oracle, and the operator holding this scope must not
be able to walk one customer's issuer ids into another customer's registry. The
lookup carries the tenant, so the service never learns the difference either.

A DEPLOYMENT-scoped issuer id is also 404 here, for the same reason read from the other side: this route reads one tenant's own declarations, and the deployment registry is a different resource with a different plane.

Not entitlement-gated. The operator is the party that sells the edition, so

refusing them on it would be the platform refusing itself. The tenant's own verdict is
readable at ../workload-identity/entitlement (SR-10.6).

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Path Params
uuid
required
uuid
required
Headers
string
enum
Defaults to application/json

Generated from available response content types

Allowed:
Responses

Language
Credentials
Bearer
JWT
URL
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json
application/problem+json