One declaration belonging to the tenant in the path, including its current
derivedAudience — the value that must be configured as the audience of
the machine-to-machine application in the external IdP.
🔴 An issuer id belonging to a DIFFERENT tenant answers 404, never 403,
and the two answers are identical. A 403 for a row that exists and a 404 for one
that does not is an existence oracle, and the operator holding this scope must not
be able to walk one customer's issuer ids into another customer's registry. The
lookup carries the tenant, so the service never learns the difference either.
A DEPLOYMENT-scoped issuer id is also 404 here, for the same reason read from the other side: this route reads one tenant's own declarations, and the deployment registry is a different resource with a different plane.
Not entitlement-gated. The operator is the party that sells the edition, so
refusing them on it would be the platform refusing itself. The tenant's own verdict is
readable at ../workload-identity/entitlement (SR-10.6).
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||