Skip to content
Developer docs
Menu

Reference

API reference

Every endpoint a relying party calls, generated from the service's OpenAPI contract.

These are the endpoints a relying party calls, generated from the service's OpenAPI contract. The same contract is available as OpenAPI (JSON). Every endpoint is on https://sso.aldelo.com. For how and when to call them, read the guides.

GET /.well-known/openid-configuration

OIDC discovery document

Responses

StatusContent
200application/json (DiscoveryDocument)
503application/json (ErrorResponse)

GET /.well-known/jwks.json

JSON Web Key Set

Responses

StatusContent
200application/json (JWKSet)
503No body

GET /authorize

OIDC authorize entry (HTML surface)

Parameters

NameInTypeRequired
client_idquerystringYes
redirect_uriquerystring (uri)Yes
response_typequerystring: one of codeYes
scopequerystringYes
statequerystringYes
code_challengequerystringYes
code_challenge_methodquerystring: one of S256Yes
promptquerystringNo
max_agequeryinteger (int64)No
acr_valuesquerystringNo
noncequerystringNo
organization_hintquerystring (uuid)No

Responses

StatusContent
200text/html
302No body
303No body
400text/html
404text/html
503text/html

GET /authorize/organization

Organization picker (HTML surface)

Parameters

NameInTypeRequired
qquerystringNo
afterquerystring (uuid)No
beforequerystring (uuid)No

Responses

StatusContent
200text/html
302No body
400text/html
404text/html
503text/html

POST /oauth2/token

Token endpoint — authorization code exchange

Authentication: client secret (HTTP Basic) or none (public client with PKCE)

Request body: application/x-www-form-urlencoded (required)

FieldTypeRequired
client_idstringNo
client_secretstringNo
codestringYes
code_verifierstringYes
grant_typestring: one of authorization_codeYes
redirect_uristringYes
scopestringNo

Responses

StatusContent
200application/json
400application/json
401application/json
429application/json
503application/json

Response 200 body

FieldTypeRequired
access_tokenstringYes
expires_ininteger (int64)Yes
id_tokenstringNo
scopestringYes
token_typestring: one of bearerYes

Response 400 body

FieldTypeRequired
errorstringYes
error_descriptionstringNo

Response 401 body

FieldTypeRequired
errorstringYes
error_descriptionstringNo

Response 429 body

FieldTypeRequired
errorobjectNo
error.codestringNo
error.correlation_idstringNo
error.messagestringNo

Response 503 body

FieldTypeRequired
errorstringYes
error_descriptionstringNo

POST /oauth2/introspect

Token introspection (RFC 7662)

Authentication: client secret (HTTP Basic)

Request body: application/x-www-form-urlencoded (required)

FieldTypeRequired
client_idstringNo
client_secretstringNo
tokenstringYes
token_type_hintstring: one of access_tokenNo

Responses

StatusContent
200application/json
400application/json
401application/json
429application/json
503application/json

Response 200 body

FieldTypeRequired
activebooleanYes
client_idstringNo
expinteger (int64)No
organization_idstringNo
scopestringNo
sidstringNo
substringNo

Response 400 body

FieldTypeRequired
errorstringYes
error_descriptionstringNo

Response 401 body

FieldTypeRequired
errorstringYes
error_descriptionstringNo

Response 429 body

FieldTypeRequired
errorobjectNo
error.codestringNo
error.correlation_idstringNo
error.messagestringNo

Response 503 body

FieldTypeRequired
errorstringYes
error_descriptionstringNo

POST /oauth2/revoke

Token revocation (RFC 7009)

Authentication: client secret (HTTP Basic)

Request body: application/x-www-form-urlencoded (required)

FieldTypeRequired
client_idstringNo
client_secretstringNo
tokenstringYes
token_type_hintstring: one of access_tokenNo

Responses

StatusContent
200No body
400application/json
401application/json
429application/json
503application/json

Response 400 body

FieldTypeRequired
errorstringYes
error_descriptionstringNo

Response 401 body

FieldTypeRequired
errorstringYes
error_descriptionstringNo

Response 429 body

FieldTypeRequired
errorobjectNo
error.codestringNo
error.correlation_idstringNo
error.messagestringNo

Response 503 body

FieldTypeRequired
errorstringYes
error_descriptionstringNo

GET /userinfo

End-user claims for a validated access token

Authentication: Bearer access token (Authorization: Bearer <token>)

Responses

StatusContent
200application/json
401application/json
500application/json
503application/json

Response 200 body

FieldTypeRequired
emailstringNo
email_verifiedbooleanNo
organization_idstringYes
substringYes

Response 401 body

FieldTypeRequired
errorstringYes

Response 500 body

FieldTypeRequired
errorstringYes
error_descriptionstringNo

Response 503 body

FieldTypeRequired
errorstringYes
error_descriptionstringNo

POST /userinfo

End-user claims for a validated access token (POST flavor)

Authentication: Bearer access token (Authorization: Bearer <token>)

Responses

StatusContent
200application/json
401No body
500No body
503No body

Response 200 body

FieldTypeRequired
emailstringNo
email_verifiedbooleanNo
organization_idstringYes
substringYes

GET /api/v1/me/memberships

List the token subject memberships (RP read)

Authentication: Bearer access token (Authorization: Bearer <token>)

Parameters

NameInTypeRequired
pagequeryintegerNo
page_sizequeryintegerNo
X-Correlation-IDheaderstringNo

Responses

StatusContent
200application/json (MeMembershipsList)
400application/json (ErrorResponse)
401application/json
500application/json (ErrorResponse)
503application/json

Response 401 body

FieldTypeRequired
errorstringYes

Response 503 body

FieldTypeRequired
errorstringYes
error_descriptionstringNo

GET /logout

RP-initiated logout (end_session_endpoint, HTML surface)

Parameters

NameInTypeRequired
id_token_hintquerystringYes
post_logout_redirect_uriquerystring (uri)No
client_idquerystringNo
statequerystringNo

Responses

StatusContent
200text/html
302No body
400text/html
500text/html
503text/html

POST /logout

RP-initiated logout (POST flavor)

Request body: application/x-www-form-urlencoded (required)

FieldTypeRequired
client_idstringNo
id_token_hintstringYes
post_logout_redirect_uristring (uri)No
statestringNo

Responses

StatusContent
200No body
302No body
400No body
500No body
503No body

Schemas

DiscoveryDocument

FieldTypeRequired
acr_values_supportedarray of stringNo
authorization_endpointstring (uri)Yes
backchannel_logout_session_supportedboolean: one of trueNo
backchannel_logout_supportedboolean: one of trueYes
claims_supportedarray of stringNo
code_challenge_methods_supportedarray of string: one of S256Yes
end_session_endpointstring (uri)Yes
grant_types_supportedarray of string: one of authorization_codeYes
id_token_signing_alg_values_supportedarray of string: one of RS256Yes
introspection_endpointstring (uri)Yes
issuerstring (uri)Yes
jwks_uristring (uri)Yes
prompt_values_supportedarray of stringNo
response_types_supportedarray of string: one of codeYes
revocation_endpointstring (uri)Yes
subject_types_supportedarray of string: one of publicYes
token_endpointstring (uri)Yes
userinfo_endpointstring (uri)Yes

ErrorDetail

FieldTypeRequired
codestringYes
fieldstringYes
messagestringYes

ErrorResponse

FieldTypeRequired
errorobjectYes
error.codestring: one of VALIDATION_ERROR, BAD_REQUEST, UNAUTHORIZED, FORBIDDEN, NOT_FOUND, CONFLICT, UNPROCESSABLE, RATE_LIMITED, INTERNAL_ERRORYes
error.correlation_idstringYes
error.detailsarray of ErrorDetailNo
error.messagestringYes
error.timestampstring (date-time)Yes

JWK

FieldTypeRequired
algstring: one of RS256Yes
estringYes
kidstringYes
ktystring: one of RSAYes
nstringYes
usestring: one of sigYes

JWKSet

FieldTypeRequired
keysarray of JWKYes

MeMembershipsList

FieldTypeRequired
dataarray of objectYes
data[].membership_idstring (uuid)Yes
data[].org_idstring (uuid)Yes
data[].org_namestringYes
data[].org_slugstringYes
data[].org_statusstring: one of active, deletedYes
data[].statusstring: one of active, suspendedYes
paginationobjectYes
pagination.has_nextbooleanYes
pagination.has_previousbooleanYes
pagination.pageintegerYes
pagination.page_sizeintegerYes
pagination.total_itemsintegerYes
pagination.total_pagesintegerYes