Saltar al contenido

Overview

The endpoints a customer organisation can call directly, plus the public signing and verification endpoints a signer’s browser uses.

Organisation-scoped operations authenticate with an OAuth2 client-credentials token carrying the org_api role. Credentials are issued self-service from the settings panel; the token’s bb_sign_org_id claim scopes every request, and there is no request shape that names a different organisation.

The signing ceremony and verification endpoints are deliberately unauthenticated — a signer is a member of the public holding a link — and are marked with an empty security array.

Information

  • OpenAPI version: 3.0.1

Client-credentials grant. The bb_sign_org_id claim is projected onto the token by an oidc-usermodel-attribute-mapper on the service-account user, so a machine identity is scoped exactly as a human one is.

Security scheme type: oauth2

Flow type: clientCredentials

Token URL: http://localhost:8180/realms/bbsign/protocol/openid-connect/token