{
  "components": {
    "parameters": {
      "XCorrelationID": {
        "in": "header",
        "name": "X-Correlation-ID",
        "required": false,
        "schema": {
          "maxLength": 128,
          "type": "string"
        }
      }
    },
    "responses": {
      "InternalError": {
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/ErrorResponse"
            }
          }
        },
        "description": "Internal Server Error"
      },
      "ValidationError": {
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/ErrorResponse"
            }
          }
        },
        "description": "Bad Request"
      }
    },
    "schemas": {
      "DiscoveryDocument": {
        "properties": {
          "acr_values_supported": {
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "authorization_endpoint": {
            "format": "uri",
            "type": "string"
          },
          "backchannel_logout_session_supported": {
            "enum": [
              true
            ],
            "type": "boolean"
          },
          "backchannel_logout_supported": {
            "enum": [
              true
            ],
            "type": "boolean"
          },
          "claims_supported": {
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "code_challenge_methods_supported": {
            "items": {
              "enum": [
                "S256"
              ],
              "type": "string"
            },
            "type": "array"
          },
          "end_session_endpoint": {
            "format": "uri",
            "type": "string"
          },
          "grant_types_supported": {
            "items": {
              "enum": [
                "authorization_code"
              ],
              "type": "string"
            },
            "type": "array"
          },
          "id_token_signing_alg_values_supported": {
            "items": {
              "enum": [
                "RS256"
              ],
              "type": "string"
            },
            "type": "array"
          },
          "introspection_endpoint": {
            "format": "uri",
            "type": "string"
          },
          "issuer": {
            "format": "uri",
            "type": "string"
          },
          "jwks_uri": {
            "format": "uri",
            "type": "string"
          },
          "prompt_values_supported": {
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "response_types_supported": {
            "items": {
              "enum": [
                "code"
              ],
              "type": "string"
            },
            "type": "array"
          },
          "revocation_endpoint": {
            "format": "uri",
            "type": "string"
          },
          "subject_types_supported": {
            "items": {
              "enum": [
                "public"
              ],
              "type": "string"
            },
            "type": "array"
          },
          "token_endpoint": {
            "format": "uri",
            "type": "string"
          },
          "userinfo_endpoint": {
            "format": "uri",
            "type": "string"
          }
        },
        "required": [
          "issuer",
          "authorization_endpoint",
          "token_endpoint",
          "userinfo_endpoint",
          "jwks_uri",
          "revocation_endpoint",
          "introspection_endpoint",
          "backchannel_logout_supported",
          "end_session_endpoint",
          "grant_types_supported",
          "response_types_supported",
          "code_challenge_methods_supported",
          "subject_types_supported",
          "id_token_signing_alg_values_supported"
        ],
        "type": "object"
      },
      "ErrorDetail": {
        "properties": {
          "code": {
            "type": "string"
          },
          "field": {
            "type": "string"
          },
          "message": {
            "type": "string"
          }
        },
        "required": [
          "field",
          "message",
          "code"
        ],
        "type": "object"
      },
      "ErrorResponse": {
        "properties": {
          "error": {
            "properties": {
              "code": {
                "enum": [
                  "VALIDATION_ERROR",
                  "BAD_REQUEST",
                  "UNAUTHORIZED",
                  "FORBIDDEN",
                  "NOT_FOUND",
                  "CONFLICT",
                  "UNPROCESSABLE",
                  "RATE_LIMITED",
                  "INTERNAL_ERROR"
                ],
                "type": "string"
              },
              "correlation_id": {
                "type": "string"
              },
              "details": {
                "items": {
                  "$ref": "#/components/schemas/ErrorDetail"
                },
                "type": "array"
              },
              "message": {
                "type": "string"
              },
              "timestamp": {
                "format": "date-time",
                "type": "string"
              }
            },
            "required": [
              "code",
              "message",
              "correlation_id",
              "timestamp"
            ],
            "type": "object"
          }
        },
        "required": [
          "error"
        ],
        "type": "object"
      },
      "JWK": {
        "properties": {
          "alg": {
            "enum": [
              "RS256"
            ],
            "type": "string"
          },
          "e": {
            "type": "string"
          },
          "kid": {
            "type": "string"
          },
          "kty": {
            "enum": [
              "RSA"
            ],
            "type": "string"
          },
          "n": {
            "type": "string"
          },
          "use": {
            "enum": [
              "sig"
            ],
            "type": "string"
          }
        },
        "required": [
          "kty",
          "use",
          "alg",
          "kid",
          "n",
          "e"
        ],
        "type": "object"
      },
      "JWKSet": {
        "properties": {
          "keys": {
            "items": {
              "$ref": "#/components/schemas/JWK"
            },
            "type": "array"
          }
        },
        "required": [
          "keys"
        ],
        "type": "object"
      },
      "MeMembershipsList": {
        "properties": {
          "data": {
            "items": {
              "properties": {
                "membership_id": {
                  "format": "uuid",
                  "type": "string"
                },
                "org_id": {
                  "format": "uuid",
                  "type": "string"
                },
                "org_name": {
                  "type": "string"
                },
                "org_slug": {
                  "type": "string"
                },
                "org_status": {
                  "enum": [
                    "active",
                    "deleted"
                  ],
                  "type": "string"
                },
                "status": {
                  "enum": [
                    "active",
                    "suspended"
                  ],
                  "type": "string"
                }
              },
              "required": [
                "membership_id",
                "org_id",
                "org_slug",
                "org_name",
                "status",
                "org_status"
              ],
              "type": "object"
            },
            "type": "array"
          },
          "pagination": {
            "properties": {
              "has_next": {
                "type": "boolean"
              },
              "has_previous": {
                "type": "boolean"
              },
              "page": {
                "type": "integer"
              },
              "page_size": {
                "type": "integer"
              },
              "total_items": {
                "type": "integer"
              },
              "total_pages": {
                "type": "integer"
              }
            },
            "required": [
              "page",
              "page_size",
              "total_items",
              "total_pages",
              "has_next",
              "has_previous"
            ],
            "type": "object"
          }
        },
        "required": [
          "data",
          "pagination"
        ],
        "type": "object"
      }
    },
    "securitySchemes": {
      "bearerAuth": {
        "scheme": "bearer",
        "type": "http"
      },
      "clientSecretBasic": {
        "scheme": "basic",
        "type": "http"
      }
    }
  },
  "info": {
    "description": "The OpenID Connect endpoints a relying party calls to sign people in with Aldelo SSO. Guides: https://sso.aldelo.com/api",
    "title": "Aldelo SSO integration API",
    "version": "1.0.0"
  },
  "openapi": "3.1.0",
  "paths": {
    "/.well-known/jwks.json": {
      "get": {
        "operationId": "getJwks",
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/JWKSet"
                }
              }
            },
            "description": "OK"
          },
          "503": {
            "description": "Service Unavailable"
          }
        },
        "security": [],
        "summary": "JSON Web Key Set",
        "tags": [
          "OIDC"
        ]
      }
    },
    "/.well-known/openid-configuration": {
      "get": {
        "operationId": "getDiscovery",
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/DiscoveryDocument"
                }
              }
            },
            "description": "OK"
          },
          "503": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorResponse"
                }
              }
            },
            "description": "Service Unavailable"
          }
        },
        "security": [],
        "summary": "OIDC discovery document",
        "tags": [
          "OIDC"
        ]
      }
    },
    "/api/v1/me/memberships": {
      "get": {
        "operationId": "listMyMemberships",
        "parameters": [
          {
            "in": "query",
            "name": "page",
            "required": false,
            "schema": {
              "default": 1,
              "minimum": 1,
              "type": "integer"
            }
          },
          {
            "in": "query",
            "name": "page_size",
            "required": false,
            "schema": {
              "default": 20,
              "maximum": 100,
              "minimum": 1,
              "type": "integer"
            }
          },
          {
            "$ref": "#/components/parameters/XCorrelationID"
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/MeMembershipsList"
                }
              }
            },
            "description": "OK"
          },
          "400": {
            "$ref": "#/components/responses/ValidationError"
          },
          "401": {
            "content": {
              "application/json": {
                "schema": {
                  "properties": {
                    "error": {
                      "type": "string"
                    }
                  },
                  "required": [
                    "error"
                  ],
                  "type": "object"
                }
              }
            },
            "description": "Unauthorized",
            "headers": {
              "WWW-Authenticate": {
                "schema": {
                  "const": "Bearer error=\"invalid_token\"",
                  "type": "string"
                }
              }
            }
          },
          "500": {
            "$ref": "#/components/responses/InternalError"
          },
          "503": {
            "content": {
              "application/json": {
                "schema": {
                  "properties": {
                    "error": {
                      "type": "string"
                    },
                    "error_description": {
                      "type": "string"
                    }
                  },
                  "required": [
                    "error"
                  ],
                  "type": "object"
                }
              }
            },
            "description": "Service Unavailable"
          }
        },
        "security": [
          {
            "bearerAuth": []
          }
        ],
        "summary": "List the token subject memberships (RP read)",
        "tags": [
          "Memberships"
        ]
      }
    },
    "/authorize": {
      "get": {
        "operationId": "authorizeEntry",
        "parameters": [
          {
            "in": "query",
            "name": "client_id",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "redirect_uri",
            "required": true,
            "schema": {
              "format": "uri",
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "response_type",
            "required": true,
            "schema": {
              "enum": [
                "code"
              ],
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "scope",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "state",
            "required": true,
            "schema": {
              "minLength": 8,
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "code_challenge",
            "required": true,
            "schema": {
              "minLength": 1,
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "code_challenge_method",
            "required": true,
            "schema": {
              "enum": [
                "S256"
              ],
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "prompt",
            "required": false,
            "schema": {
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "max_age",
            "required": false,
            "schema": {
              "format": "int64",
              "minimum": 0,
              "type": "integer"
            }
          },
          {
            "in": "query",
            "name": "acr_values",
            "required": false,
            "schema": {
              "maxLength": 512,
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "nonce",
            "required": false,
            "schema": {
              "maxLength": 512,
              "minLength": 8,
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "organization_hint",
            "required": false,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "text/html": {
                "schema": {
                  "type": "string"
                }
              }
            },
            "description": "OK"
          },
          "302": {
            "description": "Found"
          },
          "303": {
            "description": "See Other"
          },
          "400": {
            "content": {
              "text/html": {
                "schema": {
                  "type": "string"
                }
              }
            },
            "description": "Bad Request"
          },
          "404": {
            "content": {
              "text/html": {
                "schema": {
                  "type": "string"
                }
              }
            },
            "description": "Not Found"
          },
          "503": {
            "content": {
              "text/html": {
                "schema": {
                  "type": "string"
                }
              }
            },
            "description": "Service Unavailable"
          }
        },
        "security": [],
        "summary": "OIDC authorize entry (HTML surface)",
        "tags": [
          "OIDC"
        ]
      }
    },
    "/authorize/organization": {
      "get": {
        "operationId": "authorizeOrganizationPicker",
        "parameters": [
          {
            "in": "query",
            "name": "q",
            "required": false,
            "schema": {
              "maxLength": 64,
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "after",
            "required": false,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "before",
            "required": false,
            "schema": {
              "format": "uuid",
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "text/html": {
                "schema": {
                  "type": "string"
                }
              }
            },
            "description": "OK"
          },
          "302": {
            "description": "Found"
          },
          "400": {
            "content": {
              "text/html": {
                "schema": {
                  "type": "string"
                }
              }
            },
            "description": "Bad Request"
          },
          "404": {
            "content": {
              "text/html": {
                "schema": {
                  "type": "string"
                }
              }
            },
            "description": "Not Found"
          },
          "503": {
            "content": {
              "text/html": {
                "schema": {
                  "type": "string"
                }
              }
            },
            "description": "Service Unavailable"
          }
        },
        "security": [],
        "summary": "Organization picker (HTML surface)",
        "tags": [
          "OIDC"
        ]
      }
    },
    "/logout": {
      "get": {
        "operationId": "oidcEndSession",
        "parameters": [
          {
            "in": "query",
            "name": "id_token_hint",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "post_logout_redirect_uri",
            "required": false,
            "schema": {
              "format": "uri",
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "client_id",
            "required": false,
            "schema": {
              "type": "string"
            }
          },
          {
            "in": "query",
            "name": "state",
            "required": false,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "text/html": {
                "schema": {
                  "type": "string"
                }
              }
            },
            "description": "OK"
          },
          "302": {
            "description": "Found",
            "headers": {
              "Location": {
                "schema": {
                  "type": "string"
                }
              }
            }
          },
          "400": {
            "content": {
              "text/html": {
                "schema": {
                  "type": "string"
                }
              }
            },
            "description": "Bad Request"
          },
          "500": {
            "content": {
              "text/html": {
                "schema": {
                  "type": "string"
                }
              }
            },
            "description": "Internal Server Error"
          },
          "503": {
            "content": {
              "text/html": {
                "schema": {
                  "type": "string"
                }
              }
            },
            "description": "Service Unavailable"
          }
        },
        "security": [],
        "summary": "RP-initiated logout (end_session_endpoint, HTML surface)",
        "tags": [
          "OIDC"
        ]
      },
      "post": {
        "operationId": "oidcEndSessionPost",
        "requestBody": {
          "content": {
            "application/x-www-form-urlencoded": {
              "schema": {
                "properties": {
                  "client_id": {
                    "type": "string"
                  },
                  "id_token_hint": {
                    "type": "string"
                  },
                  "post_logout_redirect_uri": {
                    "format": "uri",
                    "type": "string"
                  },
                  "state": {
                    "type": "string"
                  }
                },
                "required": [
                  "id_token_hint"
                ],
                "type": "object"
              }
            }
          },
          "required": true
        },
        "responses": {
          "200": {
            "description": "OK"
          },
          "302": {
            "description": "Found"
          },
          "400": {
            "description": "Bad Request"
          },
          "500": {
            "description": "Internal Server Error"
          },
          "503": {
            "description": "Service Unavailable"
          }
        },
        "security": [],
        "summary": "RP-initiated logout (POST flavor)",
        "tags": [
          "OIDC"
        ]
      }
    },
    "/oauth2/introspect": {
      "post": {
        "operationId": "oauth2Introspect",
        "requestBody": {
          "content": {
            "application/x-www-form-urlencoded": {
              "schema": {
                "properties": {
                  "client_id": {
                    "type": "string"
                  },
                  "client_secret": {
                    "type": "string"
                  },
                  "token": {
                    "type": "string"
                  },
                  "token_type_hint": {
                    "enum": [
                      "access_token"
                    ],
                    "type": "string"
                  }
                },
                "required": [
                  "token"
                ],
                "type": "object"
              }
            }
          },
          "required": true
        },
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "properties": {
                    "active": {
                      "type": "boolean"
                    },
                    "client_id": {
                      "type": "string"
                    },
                    "exp": {
                      "format": "int64",
                      "type": "integer"
                    },
                    "organization_id": {
                      "type": "string"
                    },
                    "scope": {
                      "type": "string"
                    },
                    "sid": {
                      "type": "string"
                    },
                    "sub": {
                      "type": "string"
                    }
                  },
                  "required": [
                    "active"
                  ],
                  "type": "object"
                }
              }
            },
            "description": "OK"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "properties": {
                    "error": {
                      "type": "string"
                    },
                    "error_description": {
                      "type": "string"
                    }
                  },
                  "required": [
                    "error"
                  ],
                  "type": "object"
                }
              }
            },
            "description": "Bad Request"
          },
          "401": {
            "content": {
              "application/json": {
                "schema": {
                  "properties": {
                    "error": {
                      "type": "string"
                    },
                    "error_description": {
                      "type": "string"
                    }
                  },
                  "required": [
                    "error"
                  ],
                  "type": "object"
                }
              }
            },
            "description": "Unauthorized"
          },
          "429": {
            "content": {
              "application/json": {
                "schema": {
                  "properties": {
                    "error": {
                      "properties": {
                        "code": {
                          "type": "string"
                        },
                        "correlation_id": {
                          "type": "string"
                        },
                        "message": {
                          "type": "string"
                        }
                      },
                      "type": "object"
                    }
                  },
                  "type": "object"
                }
              }
            },
            "description": "Too Many Requests"
          },
          "503": {
            "content": {
              "application/json": {
                "schema": {
                  "properties": {
                    "error": {
                      "type": "string"
                    },
                    "error_description": {
                      "type": "string"
                    }
                  },
                  "required": [
                    "error"
                  ],
                  "type": "object"
                }
              }
            },
            "description": "Service Unavailable"
          }
        },
        "security": [
          {
            "clientSecretBasic": []
          }
        ],
        "summary": "Token introspection (RFC 7662)",
        "tags": [
          "OIDC"
        ]
      }
    },
    "/oauth2/revoke": {
      "post": {
        "operationId": "oauth2Revoke",
        "requestBody": {
          "content": {
            "application/x-www-form-urlencoded": {
              "schema": {
                "properties": {
                  "client_id": {
                    "type": "string"
                  },
                  "client_secret": {
                    "type": "string"
                  },
                  "token": {
                    "type": "string"
                  },
                  "token_type_hint": {
                    "enum": [
                      "access_token"
                    ],
                    "type": "string"
                  }
                },
                "required": [
                  "token"
                ],
                "type": "object"
              }
            }
          },
          "required": true
        },
        "responses": {
          "200": {
            "description": "OK"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "properties": {
                    "error": {
                      "type": "string"
                    },
                    "error_description": {
                      "type": "string"
                    }
                  },
                  "required": [
                    "error"
                  ],
                  "type": "object"
                }
              }
            },
            "description": "Bad Request"
          },
          "401": {
            "content": {
              "application/json": {
                "schema": {
                  "properties": {
                    "error": {
                      "type": "string"
                    },
                    "error_description": {
                      "type": "string"
                    }
                  },
                  "required": [
                    "error"
                  ],
                  "type": "object"
                }
              }
            },
            "description": "Unauthorized"
          },
          "429": {
            "content": {
              "application/json": {
                "schema": {
                  "properties": {
                    "error": {
                      "properties": {
                        "code": {
                          "type": "string"
                        },
                        "correlation_id": {
                          "type": "string"
                        },
                        "message": {
                          "type": "string"
                        }
                      },
                      "type": "object"
                    }
                  },
                  "type": "object"
                }
              }
            },
            "description": "Too Many Requests"
          },
          "503": {
            "content": {
              "application/json": {
                "schema": {
                  "properties": {
                    "error": {
                      "type": "string"
                    },
                    "error_description": {
                      "type": "string"
                    }
                  },
                  "required": [
                    "error"
                  ],
                  "type": "object"
                }
              }
            },
            "description": "Service Unavailable"
          }
        },
        "security": [
          {
            "clientSecretBasic": []
          }
        ],
        "summary": "Token revocation (RFC 7009)",
        "tags": [
          "OIDC"
        ]
      }
    },
    "/oauth2/token": {
      "post": {
        "operationId": "oauth2Token",
        "requestBody": {
          "content": {
            "application/x-www-form-urlencoded": {
              "schema": {
                "properties": {
                  "client_id": {
                    "type": "string"
                  },
                  "client_secret": {
                    "type": "string"
                  },
                  "code": {
                    "type": "string"
                  },
                  "code_verifier": {
                    "type": "string"
                  },
                  "grant_type": {
                    "enum": [
                      "authorization_code"
                    ],
                    "type": "string"
                  },
                  "redirect_uri": {
                    "type": "string"
                  },
                  "scope": {
                    "type": "string"
                  }
                },
                "required": [
                  "grant_type",
                  "code",
                  "redirect_uri",
                  "code_verifier"
                ],
                "type": "object"
              }
            }
          },
          "required": true
        },
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "properties": {
                    "access_token": {
                      "type": "string"
                    },
                    "expires_in": {
                      "format": "int64",
                      "type": "integer"
                    },
                    "id_token": {
                      "type": "string"
                    },
                    "scope": {
                      "type": "string"
                    },
                    "token_type": {
                      "enum": [
                        "bearer"
                      ],
                      "type": "string"
                    }
                  },
                  "required": [
                    "access_token",
                    "token_type",
                    "expires_in",
                    "scope"
                  ],
                  "type": "object"
                }
              }
            },
            "description": "OK"
          },
          "400": {
            "content": {
              "application/json": {
                "schema": {
                  "properties": {
                    "error": {
                      "type": "string"
                    },
                    "error_description": {
                      "type": "string"
                    }
                  },
                  "required": [
                    "error"
                  ],
                  "type": "object"
                }
              }
            },
            "description": "Bad Request"
          },
          "401": {
            "content": {
              "application/json": {
                "schema": {
                  "properties": {
                    "error": {
                      "type": "string"
                    },
                    "error_description": {
                      "type": "string"
                    }
                  },
                  "required": [
                    "error"
                  ],
                  "type": "object"
                }
              }
            },
            "description": "Unauthorized"
          },
          "429": {
            "content": {
              "application/json": {
                "schema": {
                  "properties": {
                    "error": {
                      "properties": {
                        "code": {
                          "type": "string"
                        },
                        "correlation_id": {
                          "type": "string"
                        },
                        "message": {
                          "type": "string"
                        }
                      },
                      "type": "object"
                    }
                  },
                  "type": "object"
                }
              }
            },
            "description": "Too Many Requests"
          },
          "503": {
            "content": {
              "application/json": {
                "schema": {
                  "properties": {
                    "error": {
                      "type": "string"
                    },
                    "error_description": {
                      "type": "string"
                    }
                  },
                  "required": [
                    "error"
                  ],
                  "type": "object"
                }
              }
            },
            "description": "Service Unavailable"
          }
        },
        "security": [
          {
            "clientSecretBasic": []
          },
          {}
        ],
        "summary": "Token endpoint — authorization code exchange",
        "tags": [
          "OIDC"
        ]
      }
    },
    "/userinfo": {
      "get": {
        "operationId": "oidcUserinfo",
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "properties": {
                    "email": {
                      "type": "string"
                    },
                    "email_verified": {
                      "type": "boolean"
                    },
                    "organization_id": {
                      "type": "string"
                    },
                    "sub": {
                      "type": "string"
                    }
                  },
                  "required": [
                    "sub",
                    "organization_id"
                  ],
                  "type": "object"
                }
              }
            },
            "description": "OK"
          },
          "401": {
            "content": {
              "application/json": {
                "schema": {
                  "properties": {
                    "error": {
                      "type": "string"
                    }
                  },
                  "required": [
                    "error"
                  ],
                  "type": "object"
                }
              }
            },
            "description": "Unauthorized",
            "headers": {
              "WWW-Authenticate": {
                "schema": {
                  "const": "Bearer error=\"invalid_token\"",
                  "type": "string"
                }
              }
            }
          },
          "500": {
            "content": {
              "application/json": {
                "schema": {
                  "properties": {
                    "error": {
                      "type": "string"
                    },
                    "error_description": {
                      "type": "string"
                    }
                  },
                  "required": [
                    "error"
                  ],
                  "type": "object"
                }
              }
            },
            "description": "Internal Server Error"
          },
          "503": {
            "content": {
              "application/json": {
                "schema": {
                  "properties": {
                    "error": {
                      "type": "string"
                    },
                    "error_description": {
                      "type": "string"
                    }
                  },
                  "required": [
                    "error"
                  ],
                  "type": "object"
                }
              }
            },
            "description": "Service Unavailable"
          }
        },
        "security": [
          {
            "bearerAuth": []
          }
        ],
        "summary": "End-user claims for a validated access token",
        "tags": [
          "OIDC"
        ]
      },
      "post": {
        "operationId": "oidcUserinfoPost",
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "properties": {
                    "email": {
                      "type": "string"
                    },
                    "email_verified": {
                      "type": "boolean"
                    },
                    "organization_id": {
                      "type": "string"
                    },
                    "sub": {
                      "type": "string"
                    }
                  },
                  "required": [
                    "sub",
                    "organization_id"
                  ],
                  "type": "object"
                }
              }
            },
            "description": "OK"
          },
          "401": {
            "description": "Unauthorized",
            "headers": {
              "WWW-Authenticate": {
                "schema": {
                  "type": "string"
                }
              }
            }
          },
          "500": {
            "description": "Internal Server Error"
          },
          "503": {
            "description": "Service Unavailable"
          }
        },
        "security": [
          {
            "bearerAuth": []
          }
        ],
        "summary": "End-user claims for a validated access token (POST flavor)",
        "tags": [
          "OIDC"
        ]
      }
    }
  },
  "security": [],
  "servers": [
    {
      "url": "https://sso.aldelo.com"
    }
  ],
  "tags": [
    {
      "description": "The organizations the signed-in user belongs to.",
      "name": "Memberships"
    },
    {
      "description": "The OpenID Connect provider endpoints a relying party calls.",
      "name": "OIDC"
    }
  ]
}