Probe a trusted issuer on a tenant's behalf

Reaches the issuer once, through the same transport the authentication path uses, and reports a PARTITION of the runtime checks: the ones it exercised and the ones it could not. Without a sample token every runtime check is reported as not exercised and the verdict is REACHABLE_UNVERIFIED, which is deliberately not a green — reachability is not authentication. Supply a token the issuer minted to exercise the rest; it is evaluated and discarded. Nothing about the declaration's trust state changes on either outcome.

Not entitlement-gated. The operator is the party that sells the edition, so refusing them on it would be the platform refusing itself. The tenant's own verdict is readable at ../workload-identity/entitlement (SR-10.6).

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Path Params
uuid
required
uuid
required
Body Params

An optional sample token, which is what lets the probe exercise the runtime checks a login makes. Without one the response names every check it could not run.

string
length between 0 and 8192

A JWT this issuer minted for a workload of yours. Optional. It is evaluated and discarded: it is never stored, logged, audited or returned.

Headers
string
enum
Defaults to application/json

Generated from available response content types

Allowed:
Responses

Language
Credentials
Bearer
JWT
URL
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json
application/problem+json