List the issuers a binding here may name

Every trusted-issuer declaration a binding for this tenant may name: the ones the
DEPLOYMENT declares, which every tenant inherits, concatenated with the ones this
tenant declared for itself. Each row carries scope, so a caller can
tell an inherited declaration from the tenant's own without a second call.

🔴 This is the set the bind call accepts, not the tenant's own registry.

The registry read at ../workload-identity/issuers answers a different
question — what this tenant may edit and withdraw — and a form that offered its
answer would omit every deployment-scoped issuer, which on a deployment that
declares its issuers centrally is the whole list.

There is no enabled filter, and that is deliberate. Enabling is a

separate verb and the supported order of work is declare, bind the workloads, then
enable; withholding a declared-but-not-yet-enabled issuer here would hide exactly
the rows an operator is in the middle of setting up. A withdrawn (soft-deleted)
declaration is not returned, which is the one filter this read and the runtime
verification path share.

displayName is null on an inherited row. It is a label

a platform operator wrote for their own purposes; the row's identifying fact here
is its canonical issuer URL.

Ungated. A tenant whose edition does not include workload identity may

still read this list — reading which issuers exist is not the act that grants a
workload access, and the refusal it will meet at submit is the one that states the
real reason.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Path Params
uuid
required
Headers
string
enum
Defaults to application/json

Generated from available response content types

Allowed:
Responses

Language
Credentials
Bearer
JWT
URL
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json
application/problem+json