Information
- License: Apache-2.0
- OpenAPI version:
3.1.0
The control plane of a participant: the management API (/api/v1) used by the management UI and by bl, and the protocol endpoints that other participants and data planes call. Operations carry x-cli: the bl command that offers them, or none with a reason (decisions #63). x-role is the role a caller needs.
The session of the management UI (backend for frontend, decisions #11 and #62). GET /auth/login starts an OpenID Connect login at the participant’s own identity provider; /auth/callback sets this HttpOnly cookie (SameSite=Lax, and Secure when the service’s public URL is https). The session lives on the server and checks back with the identity provider every 10 minutes, so a disabled account or a changed role counts within minutes. A change (POST, PUT, PATCH, DELETE) with this cookie must come from a page of the service itself: Sec-Fetch-Site: same-origin, or without that header an Origin (or else a Referer) on the service’s public URL; otherwise 403 cross_site_request (decisions #83).
Security scheme type: apiKey
Cookie parameter name: bl_<slug>_session
A session of the bl CLI (decisions #62): bl login runs the Device Authorization Grant (RFC 8628) at POST /api/v1/cli/device and POST /api/v1/cli/token. The opaque access token (10 minutes) and the rotating refresh token are bound to the CLI’s P-256 key with DPoP (RFC 9449): every request sends Authorization: DPoP <token> and a DPoP header with a fresh proof (htm, htu, iat within 60 s, a single-use jti, and ath, the hash of the token).
Security scheme type: http
An API key (Instellingen → API-sleutels, /api/v1/api-keys) as Authorization: Bearer <key>. In development also the break-glass token BL_ADMIN_TOKEN.
Security scheme type: http
A Self-Issued ID token of the calling participant (Decentralized Claims Protocol 1.0), with an access token that lets this connector query the caller’s membership credential.
Security scheme type: http
Bearer format: JWT
A signaling token (Data Plane Signaling): a JWT that a data plane signs for this control plane, used once.
Security scheme type: http
Bearer format: JWT