Every issuer this tenant has declared, whether it is currently in the trust set or
not, ordered by canonical issuer URL.
Disabled declarations are included deliberately. A configuration surface that showed only the enabled rows would hide a disabled issuer from the operator who disabled it, and there would be no way back to it.
The list does not include the deployment-scoped issuers this tenant also
trusts. Those are the operator's declarations, not this tenant's, and they are
composed into the effective trust set at verification time — a tenant's own issuers
are additional to them, never a replacement for them.
Ungated. A tenant whose edition does not include workload identity can
still see, and still act on, what it already configured.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||