Every external identity that can authenticate as this actor, ordered by subject.
This is the answer to "who can act as this workload", and it is the whole answer for the federated path: a token matches one of these bindings or it authenticates nothing. Credentials the actor holds directly are a separate surface.
The canonical issuer URL is projected beside each issuer id, because an operator
matching a binding to a configuration in an external IdP needs the URL a token's
iss claim carries rather than a UUID. It is null only when this tenant
cannot reach the referenced declaration at all — a binding that can never resolve,
and one to remove.
An actor id that does not exist in this tenant answers 404 rather
than an empty array. An actor with no bindings and an actor that is not there are
different facts, and answering the second with the first would tell an operator
their workload has no bindings when what is true is that they are reading the wrong
actor.
Ungated. A tenant whose edition does not include workload identity can
still see, and still act on, what it already configured.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||