v1

latestOpenAPI 3.0.02026-07-246171,3332.1 MB
v2

post/create-auth-method-oauth2

Request body

access-expiresinteger

Access expiration date in Unix timestamp (select 0 for access without expiry date)

allowed-client-typestring[]

limit the auth method usage for specific client types [cli,ui,gateway-admin,sdk,mobile,extension]

audiencestring

The audience in the JWT

audit-logs-claimsstring[]

Subclaims to include in audit logs, e.g "--audit-logs-claims email --audit-logs-claims username"

bound-client-idsstring[]

The clients ids that the access is restricted to

bound-ipsstring[]

A CIDR whitelist with the IPs that the access is restricted to

certstring

CertificateFile Path to a file that contain the certificate in a PEM format.

cert-file-datastring

CertificateFileData PEM Certificate in a Base64 format.

delete_protectionstring

Protection from accidental deletion of this object [true/false]

descriptionstring

Auth Method description

expiration-event-instring[]

How many days before the expiration of the auth method would you like to be notified.

force-sub-claimsboolean

if true: enforce role-association must include sub claims

gateway-urlstring

Akeyless Gateway URL (Configuration Management port). Relevant only when the jwks-uri is accessible only from the gateway.

gw-bound-ipsstring[]

A CIDR whitelist with the GW IPs that the access is restricted to

issuerstring

Issuer URL

jsonboolean

Set output format to JSON

jwks-json-datastring

The JSON Web Key Set (JWKS) that containing the public keys that should be used to verify any JSON Web Token (JWT) issued by the authorization server. base64 encoded string

jwks-uristring

The URL to the JSON Web Key Set (JWKS) that containing the public keys that should be used to verify any JSON Web Token (JWT) issued by the authorization server.

jwt-ttlinteger

Jwt TTL

namestring required

Auth Method name

product-typestring[]

Choose the relevant product type for the auth method [sm, sra, pm, dp, ca]

subclaims-delimitersstring[]

A list of additional sub claims delimiters (relevant only for SAML, OIDC, OAuth2/JWT)

tokenstring

Authentication token (see /auth and /configure)

uid-tokenstring

The universal identity token, Required only for universal_identity authentication

unique-identifierstring required

A unique identifier (ID) value should be configured for OAuth2, LDAP and SAML authentication method types and is usually a value such as the email, username, or upn for example. Whenever a user logs in with a token, these authentication types issue a "sub claim" that contains details uniquely identifying that user. This sub claim includes a key containing the ID value that you configured, and is used to distinguish between different users from within the same organization.

Response

createAuthMethodOAuth2Response wraps response body.

access_idstring