v32

latestOpenAPI 3.1.0raw.githubusercontent.com2026-05-224341,4072.0 MB
Workload Federation

Create Provider

CreateProvider registers a new external OIDC issuer for the tenant. Validates the issuer URL via OIDC discovery synchronously.

post/api/v1/workload_federation/providers

Request body

descriptionstring

A description of what this provider is for.

displayNamestring

The display name for the new provider.

issuerUrlstring

The issuer URL. For OIDC providers, this is an HTTPS URL validated via OIDC discovery. For SPIFFE providers, this is the SPIFFE trust-domain URI (e.g., spiffe://prod.example.com). Normalized on write: lowercase scheme/host, no trailing slash. Unique within tenant.

oidcC1ApiWorkloadFederationV1OIDCSettings nullable

OIDCSettings is the kind-specific configuration block for classic OIDC providers (GitHub Actions, GitLab CI, HCP Terraform, AWS IAM Outbound, any CUSTOM provider). Empty for now; future fields like custom_jwks_url, audience overrides, and required_claims land here.

wellKnownProvider'WELL_KNOWN_WORKLOAD_PROVIDER_UNSPECIFIED' | 'WELL_KNOWN_WORKLOAD_PROVIDER_CUSTOM' | 'WELL_KNOWN_WORKLOAD_PROVIDER_GITHUB_ACTIONS' | 'WELL_KNOWN_WORKLOAD_PROVIDER_GITLAB_CI' | 'WELL_KNOWN_WORKLOAD_PROVIDER_HCP_TERRAFORM' | 'WELL_KNOWN_WORKLOAD_PROVIDER_AWS_IAM_OUTBOUND' | 'WELL_KNOWN_WORKLOAD_PROVIDER_SPIFFE'

Well-known provider type. Required -- UNSPECIFIED is rejected. When set to a named source, the backend validates issuer_url consistency. SPIFFE wkp requires settings.spiffe; all other wkp values require settings.oidc.

Response

Successful response