List an actor's external identities (platform)

Every external identity currently able to authenticate as this actor. This is the
answer to "which workloads can act as this principal", which is the question an
incident asks first.

The canonical issuer URL is reported beside the issuer id, because the id alone forces the reader to resolve it against a registry that may since have changed.

An actor with no bindings answers an empty array. That is a complete answer, not a missing one: an actor may authenticate through a credential this feature knows nothing about.

The ROOT tenant is a valid target for this READ, unlike on the write. A read creates no row and emits no audit, so the ROOT-target refusal has nothing to protect.

Not entitlement-gated. The operator is the party that sells the edition, so

refusing them on it would be the platform refusing itself. The tenant's own verdict is
readable at ../workload-identity/entitlement (SR-10.6).

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Path Params
uuid
required
uuid
required
Headers
string
enum
Defaults to application/json

Generated from available response content types

Allowed:
Responses

Language
Credentials
Bearer
JWT
URL
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json
application/problem+json