---
title: "Create Integration Instance Auth Credential"
url: "https://us-prod.jeffyongtaotang.com/apis/konnect-service-catalog-1/versions/cdbef9b7-686c-4189-bbc8-55c727a972e8/operations/create-integration-instance-auth-credential"
---

> Full API specification: https://us-prod.jeffyongtaotang.com/apis/konnect-service-catalog-1/versions/cdbef9b7-686c-4189-bbc8-55c727a972e8.md

# Create Integration Instance Auth Credential

`POST` `/integration-instances/{integrationInstanceId}/auth-credential`

Operation ID: `create-integration-instance-auth-credential`

Creates an auth credential scoped to the given integration instance. Auth credentials are singleton resources that have a 1-to-1 relationship with an integration instance. An attempt to create subsequent auth credentials for an instance will result in a 409 response.

## Path parameters

- `integrationInstanceId` (string, required) - The `id` of the integration instance.

## Request body (required)

Content types: `application/json`

## Responses

- `201` - A response containing an integration instance auth credential.
- `400` - Bad Request
- `401` - Unauthorized
- `403` - Forbidden
- `404` - Not Found
- `409` - Conflict

## OpenAPI definition

```yaml
openapi: 3.0.3
info:
  title: Konnect Service Catalog
  version: 1.3.0
servers:
  - url: https://us.api.konghq.com/v1
    description: United-States Production region
  - url: https://eu.api.konghq.com/v1
    description: Europe Production region
  - url: https://au.api.konghq.com/v1
    description: Australia Production region
  - url: https://me.api.konghq.com/v1
    description: Middle-East Production region
  - url: https://in.api.konghq.com/v1
    description: India Production region
  - url: https://sg.api.konghq.com/v1
    description: Singapore Production region
paths:
  /integration-instances/{integrationInstanceId}/auth-credential:
    parameters:
      - schema:
          type: string
          example: 3f51fa25-310a-421d-bd1a-007f859021a3
        name: integrationInstanceId
        in: path
        required: true
        description: The `id` of the integration instance.
    post:
      x-speakeasy-entity-operation: IntegrationInstanceAuthCredential#create
      summary: Create Integration Instance Auth Credential
      operationId: create-integration-instance-auth-credential
      description: >
        Creates an auth credential scoped to the given integration instance.

        Auth credentials are singleton resources that have a 1-to-1 relationship
        with

        an integration instance.


        An attempt to create subsequent auth credentials for an instance will
        result in a 409 response.
      requestBody:
        $ref: "#/components/requestBodies/CreateIntegrationInstanceAuthCredentialReques\
          t"
      responses:
        "201":
          $ref: "#/components/responses/IntegrationInstanceAuthCredentialResponse"
        "400":
          $ref: "#/components/responses/BadRequest"
        "401":
          $ref: "#/components/responses/Unauthorized"
        "403":
          $ref: "#/components/responses/Forbidden"
        "404":
          $ref: "#/components/responses/NotFound"
        "409":
          $ref: "#/components/responses/Conflict"
      tags:
        - Integration Instance Auth Credentials
security:
  - konnectAccessToken: []
  - personalAccessToken: []
  - systemAccountAccessToken: []
components:
  requestBodies:
    CreateIntegrationInstanceAuthCredentialRequest:
      required: true
      content:
        application/json:
          schema:
            $ref: "#/components/schemas/CreateIntegrationInstanceAuthCredential"
          examples:
            SwaggerHub:
              $ref: "#/components/examples/SampleCreateSwaggerHubMultiKeyAuthPayload"
            Datadog:
              $ref: "#/components/examples/SampleCreateDatadogMultiKeyAuthPayload"
            Traceable:
              $ref: "#/components/examples/SampleCreateTraceableMultiKeyAuthPayload"
            AwsApiGateway:
              $ref: "#/components/examples/SampleCreateAWSRoleDelegationAuthPayload"
            Dynatrace:
              $ref: "#/components/examples/SampleCreateDynatraceMultiKeyAuthPayload"
            SonarQube:
              $ref: "#/components/examples/SampleCreateSonarQubeMultiKeyAuthPayload"
            azureApiManagement:
              $ref: "#/components/examples/AzureApiManagementAuthConfigPayload"
            azureDevops:
              $ref: "#/components/examples/SampleCreateAzureDevopsMultiKeyAuthPayload"
  responses:
    IntegrationInstanceAuthCredentialResponse:
      description: A response containing an integration instance auth credential.
      content:
        application/json:
          schema:
            $ref: "#/components/schemas/IntegrationInstanceAuthCredential"
          examples:
            SwaggerHub:
              $ref: "#/components/examples/SampleCreateSwaggerHubMultiKeyAuthResponse"
            AwsApiGateway:
              $ref: "#/components/examples/SampleCreateAWSRoleDelegationAuthResponse"
            Dynatrace:
              $ref: "#/components/examples/SampleCreateDynatraceMultiKeyAuthResponse"
            SonarQube:
              $ref: "#/components/examples/SampleCreateSonarQubeMultiKeyAuthResponse"
            azureApiManagement:
              $ref: "#/components/examples/AzureApiManagementAuthConfigResponse"
            azureDevops:
              $ref: "#/components/examples/SampleCreateAzureDevopsMultiKeyAuthResponse"
    BadRequest:
      description: Bad Request
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/BadRequestError"
    Unauthorized:
      description: Unauthorized
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/UnauthorizedError"
          examples:
            UnauthorizedExample:
              $ref: "#/components/examples/UnauthorizedExample"
    Forbidden:
      description: Forbidden
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/ForbiddenError"
          examples:
            UnauthorizedExample:
              $ref: "#/components/examples/ForbiddenExample"
    NotFound:
      description: Not Found
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/NotFoundError"
          examples:
            NotFoundExample:
              $ref: "#/components/examples/NotFoundExample"
    Conflict:
      description: Conflict
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/ConflictError"
  schemas:
    CreateIntegrationInstanceAuthCredential:
      title: CreateIntegrationInstanceAuthCredential
      oneOf:
        - $ref: "#/components/schemas/CreateOAuthCredential"
        - $ref: "#/components/schemas/CreateGitHubAppInstallationCredential"
        - $ref: "#/components/schemas/CreateMultiKeyAuthCredential"
        - $ref: "#/components/schemas/CreateAWSRoleDelegationAuthCredential"
    IntegrationInstanceAuthCredential:
      title: IntegrationInstanceAuthCredential
      description: Object containing metadata for an integration instance auth credential.
      oneOf:
        - $ref: "#/components/schemas/OAuthCredential"
        - $ref: "#/components/schemas/GitHubAppInstallationCredential"
        - $ref: "#/components/schemas/MultiKeyAuthCredential"
        - $ref: "#/components/schemas/AWSRoleDelegationAuthCredential"
    BadRequestError:
      allOf:
        - $ref: "#/components/schemas/BaseError"
        - type: object
          required:
            - invalid_parameters
          properties:
            invalid_parameters:
              $ref: "#/components/schemas/InvalidParameters"
    UnauthorizedError:
      allOf:
        - $ref: "#/components/schemas/BaseError"
        - type: object
          properties:
            status:
              example: 401
            title:
              example: Unauthorized
            type:
              example: https://httpstatuses.com/401
            instance:
              example: kong:trace:1234567890
            detail:
              example: Invalid credentials
    ForbiddenError:
      allOf:
        - $ref: "#/components/schemas/BaseError"
        - type: object
          properties:
            status:
              example: 403
            title:
              example: Forbidden
            type:
              example: https://httpstatuses.com/403
            instance:
              example: kong:trace:1234567890
            detail:
              example: Forbidden
    NotFoundError:
      allOf:
        - $ref: "#/components/schemas/BaseError"
        - type: object
          properties:
            status:
              example: 404
            title:
              example: Not Found
            type:
              example: https://httpstatuses.com/404
            instance:
              example: kong:trace:1234567890
            detail:
              example: Not found
    ConflictError:
      allOf:
        - $ref: "#/components/schemas/BaseError"
        - type: object
          properties:
            status:
              example: 409
            title:
              example: Conflict
            type:
              example: https://httpstatuses.com/409
            instance:
              example: kong:trace:1234567890
            detail:
              example: Conflict
    CreateOAuthCredential:
      type: object
      description: Payload used to create an `OAuth` credential for an integration instance.
      additionalProperties: false
      required:
        - type
        - config
      properties:
        type:
          type: string
          enum:
            - oauth
          x-terraform-transform-const: true
        config:
          type: object
          title: CreateOAuthCredentialConfig
          additionalProperties: false
          required:
            - grant_type
            - code
            - redirect_uri
          properties:
            grant_type:
              type: string
              description: The OAuth 2.0 grant type used for authorization (e.g.,
                `authorization_code`).
              enum:
                - authorization_code
            code:
              type: string
              description: The authorization code used to exchange for an access token with
                the identity server.
              example: Yzk5ZDczMzRlNDEwY
            redirect_uri:
              type: string
              format: uri
              description: >
                The redirect URI submitted to the authorization server during
                the authentication request

                to retrieve the authorization code.
              example: https://cloud.konghq.com/us/service-catalog/integrations/pagerduty/oauth
    CreateGitHubAppInstallationCredential:
      type: object
      description: Payload used to create an `GitHub App Installation` credential for
        an integration instance.
      additionalProperties: false
      required:
        - type
        - config
      properties:
        type:
          type: string
          enum:
            - github_app_installation
          x-terraform-transform-const: true
        config:
          type: object
          title: CreateGitHubAppInstallationCredentialConfig
          additionalProperties: false
          required:
            - installation_id
            - code
          properties:
            installation_id:
              type: string
              description: The GitHub App installation ID.
              example: "46952218"
            code:
              type: string
              description: The authorization code used to exchange for a GitHub user-scoped
                access token.
              example: Yzk5ZDczMzRlNDEwY
            app_installed_by:
              type: string
              description: The GitHub user who installed the app
    CreateMultiKeyAuthCredential:
      writeOnly: true
      x-speakeasy-name-override: multi_key_auth
      type: object
      description: Payload used to create an `Multi Key` credential for an integration
        instance.
      additionalProperties: false
      required:
        - type
        - config
      properties:
        type:
          type: string
          enum:
            - multi_key_auth
          x-terraform-transform-const: true
        config:
          x-speakeasy-param-suppress-computed-diff: true
          x-speakeasy-param-force-new: true
          type: object
          title: CreateMultiKeyAuthCredentialConfig
          additionalProperties: false
          required:
            - headers
          properties:
            headers:
              type: array
              description: >
                A list of header key/value pairs used to transmit API
                credentials to the integration's external API.

                Header names are defined by the integration within its `Multi
                Key` authorization strategy definition.
              items:
                type: object
                required:
                  - name
                  - key
                properties:
                  name:
                    description: Name of the request header
                    type: string
                  key:
                    description: The key used to populate the request header
                    type: string
              example:
                - name: x-api-key
                  key: 9f2a3b4c8d6e7f00112233445566778899aabbccddeeff001122334455667788
    CreateAWSRoleDelegationAuthCredential:
      type: object
      description: Payload used to create an `AWS Role Delegation` credential for an
        integration instance.
      additionalProperties: false
      required:
        - type
        - config
      properties:
        type:
          type: string
          enum:
            - aws_role_delegation
        config:
          type: object
          title: CreateAWSRoleDelegationAuthCredentialConfig
          additionalProperties: false
          required:
            - role_arn
          properties:
            role_arn:
              type: string
              description: |
                The AWS Role ARN string
              example: arn:aws:iam::084735895545:role/KonnectServiceCatalogRole
    OAuthCredential:
      x-speakeasy-param-suppress-computed-diff: true
      type: object
      required:
        - id
        - integration_instance
        - missing_permissions
        - tainted
        - expires_at
        - created_at
        - type
      properties:
        id:
          type: string
          format: uuid
          example: 4f535923-ec24-456c-b4e5-e67f65c8c208
        integration_instance:
          $ref: "#/components/schemas/IntegrationInstanceRef"
        missing_permissions:
          type: array
          description: List of detected missing permissions required to enable the full
            functionality of the given integration instance.
          items:
            $ref: "#/components/schemas/MissingPermission"
        tainted:
          type: boolean
          description: Indicates that the credential is no longer valid and must be
            replaced with a new valid credential.
          example: false
        expires_at:
          type: string
          format: date-time
          nullable: true
          example: 2025-04-01T07:20:50Z
          description: >
            Timestamp denoting when the when the credential will expire in
            RFC-3339 format with a "T" character separating date from time
            within the field value.

            When expired, the credential must be replaced with a new valid
            credential to re-enable full functionality for the given integration
            instance.


            A `null` value indicates no known expiration time.
        created_at:
          $ref: "#/components/schemas/CreatedAt"
        type:
          type: string
          enum:
            - oauth
          x-terraform-transform-const: true
      title: OAuthCredential
      x-speakeasy-name-override: Oauth
      description: Represents a credential scoped to an integration instance that
        supports the `OAuth` authorization strategy.
    GitHubAppInstallationCredential:
      x-speakeasy-param-suppress-computed-diff: true
      type: object
      required:
        - id
        - integration_instance
        - missing_permissions
        - tainted
        - expires_at
        - created_at
        - type
        - config
      properties:
        id:
          type: string
          format: uuid
          example: 4f535923-ec24-456c-b4e5-e67f65c8c208
        integration_instance:
          $ref: "#/components/schemas/IntegrationInstanceRef"
        missing_permissions:
          type: array
          description: List of detected missing permissions required to enable the full
            functionality of the given integration instance.
          items:
            $ref: "#/components/schemas/MissingPermission"
        tainted:
          type: boolean
          description: Indicates that the credential is no longer valid and must be
            replaced with a new valid credential.
          example: false
        expires_at:
          type: string
          format: date-time
          nullable: true
          example: 2025-04-01T07:20:50Z
          description: >
            Timestamp denoting when the when the credential will expire in
            RFC-3339 format with a "T" character separating date from time
            within the field value.

            When expired, the credential must be replaced with a new valid
            credential to re-enable full functionality for the given integration
            instance.


            A `null` value indicates no known expiration time.
        created_at:
          $ref: "#/components/schemas/CreatedAt"
        type:
          type: string
          enum:
            - github_app_installation
          x-terraform-transform-const: true
        config:
          title: GitHubAppInstallationCredentialConfig
          type: object
          required:
            - installation_id
            - app_installed_by
          properties:
            installation_id:
              type: string
              description: The GitHub App installation ID
            app_installed_by:
              type: string
              description: The GitHub user who installed the app.
              nullable: true
      title: GitHubAppInstallationCredential
      x-speakeasy-name-override: GithubAppInstallation
      description: Represents a credential scoped to an integration instance that
        supports the `GitHub App Installation` authorization strategy.
    MultiKeyAuthCredential:
      x-speakeasy-param-suppress-computed-diff: true
      type: object
      required:
        - id
        - integration_instance
        - missing_permissions
        - tainted
        - expires_at
        - created_at
        - type
      properties:
        id:
          type: string
          format: uuid
          example: 4f535923-ec24-456c-b4e5-e67f65c8c208
        integration_instance:
          $ref: "#/components/schemas/IntegrationInstanceRef"
        missing_permissions:
          type: array
          description: List of detected missing permissions required to enable the full
            functionality of the given integration instance.
          items:
            $ref: "#/components/schemas/MissingPermission"
        tainted:
          type: boolean
          description: Indicates that the credential is no longer valid and must be
            replaced with a new valid credential.
          example: false
        expires_at:
          type: string
          format: date-time
          nullable: true
          example: 2025-04-01T07:20:50Z
          description: >
            Timestamp denoting when the when the credential will expire in
            RFC-3339 format with a "T" character separating date from time
            within the field value.

            When expired, the credential must be replaced with a new valid
            credential to re-enable full functionality for the given integration
            instance.


            A `null` value indicates no known expiration time.
        created_at:
          $ref: "#/components/schemas/CreatedAt"
        type:
          type: string
          enum:
            - multi_key_auth
          x-terraform-transform-const: true
      title: MultiKeyAuthCredential
      description: Represents a credential scoped to an integration instance that
        supports the `Multi Key` authorization strategy.
    AWSRoleDelegationAuthCredential:
      x-speakeasy-param-suppress-computed-diff: true
      type: object
      required:
        - id
        - integration_instance
        - missing_permissions
        - tainted
        - expires_at
        - created_at
        - type
        - config
      properties:
        id:
          type: string
          format: uuid
          example: 4f535923-ec24-456c-b4e5-e67f65c8c208
        integration_instance:
          $ref: "#/components/schemas/IntegrationInstanceRef"
        missing_permissions:
          type: array
          description: List of detected missing permissions required to enable the full
            functionality of the given integration instance.
          items:
            $ref: "#/components/schemas/MissingPermission"
        tainted:
          type: boolean
          description: Indicates that the credential is no longer valid and must be
            replaced with a new valid credential.
          example: false
        expires_at:
          type: string
          format: date-time
          nullable: true
          example: 2025-04-01T07:20:50Z
          description: >
            Timestamp denoting when the when the credential will expire in
            RFC-3339 format with a "T" character separating date from time
            within the field value.

            When expired, the credential must be replaced with a new valid
            credential to re-enable full functionality for the given integration
            instance.


            A `null` value indicates no known expiration time.
        created_at:
          $ref: "#/components/schemas/CreatedAt"
        type:
          type: string
          enum:
            - aws_role_delegation
        config:
          title: AWSRoleDelegationAuthCredentialConfig
          type: object
          required:
            - role_arn
          properties:
            role_arn:
              type: string
              description: The Role ARN use for AWS Assume Role.
      title: AWSRoleDelegationAuthCredential
      description: Represents a credential scoped to an integration instance that
        supports the `AWS Role Delegation` authorization strategy.
    BaseError:
      type: object
      title: Error
      description: standard error
      required:
        - status
        - title
        - instance
        - detail
      properties:
        status:
          type: integer
          description: >
            The HTTP status code of the error. Useful when passing the response

            body to child properties in a frontend UI. Must be returned as an
            integer.
          readOnly: true
        title:
          type: string
          description: |
            A short, human-readable summary of the problem. It should not
            change between occurences of a problem, except for localization.
            Should be provided as "Sentence case" for direct use in the UI.
          readOnly: true
        type:
          type: string
          description: The error type.
          readOnly: true
        instance:
          type: string
          description: |
            Used to return the correlation ID back to the user, in the format
            kong:trace:<correlation_id>. This helps us find the relevant logs
            when a customer reports an issue.
          readOnly: true
        detail:
          type: string
          description: >
            A human readable explanation specific to this occurence of the
            problem.

            This field may contain request/entity data to help the user
            understand

            what went wrong. Enclose variable values in square brackets. Should
            be

            provided as "Sentence case" for direct use in the UI.
          readOnly: true
    InvalidParameters:
      type: array
      nullable: false
      uniqueItems: true
      minItems: 1
      description: invalid parameters
      items:
        oneOf:
          - $ref: "#/components/schemas/InvalidParameterStandard"
          - $ref: "#/components/schemas/InvalidParameterMinimumLength"
          - $ref: "#/components/schemas/InvalidParameterMaximumLength"
          - $ref: "#/components/schemas/InvalidParameterChoiceItem"
          - $ref: "#/components/schemas/InvalidParameterDependentItem"
    IntegrationInstanceRef:
      type: object
      description: Short-hand descriptor of an integration instance.
      required:
        - id
        - name
        - display_name
      properties:
        id:
          type: string
          format: uuid
          example: 772b9caf-ddbc-4f4f-8aa4-8dfbbe420351
          description: The integration instance ID.
        name:
          type: string
          description: >
            The machine name of the integration instance that uniquely
            identifies it within the catalog.
          pattern: ^[0-9a-z.-]+$
          example: aws-lambda-prod
        display_name:
          type: string
          description: The display name of the integration instance.
          example: AWS (prod)
    MissingPermission:
      type: object
      required:
        - scopes
        - message
      properties:
        scopes:
          type: array
          items:
            type: string
            nullable: true
          example:
            - incident:read
        message:
          type: string
          description: >
            Describes the degraded experience of the integration instance due to
            the missing permission.

            May also include a message on how to resolve the missing permission.
    CreatedAt:
      type: string
      format: date-time
      example: 2022-11-04T20:10:06.927Z
      description: An ISO-8601 timestamp representation of entity creation date.
      readOnly: true
      x-speakeasy-param-suppress-computed-diff: true
    InvalidParameterStandard:
      type: object
      additionalProperties: false
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          $ref: "#/components/schemas/InvalidRules"
        source:
          type: string
          example: body
        reason:
          type: string
          example: is a required field
          readOnly: true
      required:
        - field
        - reason
    InvalidParameterMinimumLength:
      type: object
      additionalProperties: false
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          description: invalid parameters rules
          type: string
          readOnly: true
          nullable: false
          enum:
            - min_length
            - min_digits
            - min_lowercase
            - min_uppercase
            - min_symbols
            - min_items
            - min
        minimum:
          type: integer
          example: 8
        source:
          type: string
          example: body
        reason:
          type: string
          example: must have at least 8 characters
          readOnly: true
      required:
        - field
        - reason
        - rule
        - minimum
    InvalidParameterMaximumLength:
      type: object
      additionalProperties: false
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          description: invalid parameters rules
          type: string
          readOnly: true
          nullable: false
          enum:
            - max_length
            - max_items
            - max
        maximum:
          type: integer
          example: 8
        source:
          type: string
          example: body
        reason:
          type: string
          example: must not have more than 8 characters
          readOnly: true
      required:
        - field
        - reason
        - rule
        - maximum
    InvalidParameterChoiceItem:
      type: object
      additionalProperties: false
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          description: invalid parameters rules
          type: string
          readOnly: true
          nullable: false
          enum:
            - enum
        reason:
          type: string
          example: is a required field
          readOnly: true
        choices:
          type: array
          uniqueItems: true
          readOnly: true
          nullable: false
          minItems: 1
          items: {}
        source:
          type: string
          example: body
      required:
        - field
        - reason
        - rule
        - choices
    InvalidParameterDependentItem:
      type: object
      additionalProperties: false
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          description: invalid parameters rules
          type: string
          readOnly: true
          nullable: true
          enum:
            - dependent_fields
        reason:
          type: string
          example: is a required field
          readOnly: true
        dependents:
          type: array
          uniqueItems: true
          nullable: true
          items: {}
          readOnly: true
        source:
          type: string
          example: body
      required:
        - field
        - rule
        - reason
        - dependents
    InvalidRules:
      description: invalid parameters rules
      type: string
      readOnly: true
      nullable: true
      enum:
        - required
        - is_array
        - is_base64
        - is_boolean
        - is_date_time
        - is_integer
        - is_null
        - is_number
        - is_object
        - is_string
        - is_uuid
        - is_fqdn
        - is_arn
        - unknown_property
        - missing_reference
        - is_label
        - matches_regex
        - invalid
        - is_supported_network_availability_zone_list
        - is_supported_network_cidr_block
        - is_supported_provider_region
        - type
  examples:
    SampleCreateSwaggerHubMultiKeyAuthPayload:
      value:
        type: multi_key_auth
        config:
          headers:
            - name: authorization
              key: swaggerhub-api-key
    SampleCreateDatadogMultiKeyAuthPayload:
      value:
        type: multi_key_auth
        config:
          headers:
            - name: DD-API-KEY
              key: datadaog-api-key
            - name: DD-APPLICATION-KEY
              key: datadaog-application-key
    SampleCreateTraceableMultiKeyAuthPayload:
      value:
        type: multi_key_auth
        config:
          headers:
            - name: authorization
              key: platform-api-token
    SampleCreateAWSRoleDelegationAuthPayload:
      value:
        type: aws_role_delegation
        config:
          role_arn: arn:aws:iam::084735895545:role/KonnectServiceCatalogRole
    SampleCreateDynatraceMultiKeyAuthPayload:
      value:
        type: multi_key_auth
        config:
          headers:
            - name: authorization
              key: dynatrace-api-key
    SampleCreateSonarQubeMultiKeyAuthPayload:
      value:
        type: multi_key_auth
        config:
          headers:
            - name: authorization
              key: sonarqube-api-key
    AzureApiManagementAuthConfigPayload:
      value:
        type: oauth
        config:
          grant_type: authorization_code
          code: Yzk5ZDczMzRlNDEwY
          redirect_uri: https://cloud.konghq.com/us/servicehub/integrations/azure-api-management/oauth
    SampleCreateAzureDevopsMultiKeyAuthPayload:
      value:
        type: multi_key_auth
        config:
          headers:
            - name: authorization
              key: azure-devops-personal-access-token
    SampleCreateSwaggerHubMultiKeyAuthResponse:
      value:
        id: 4f535923-ec24-456c-b4e5-e67f65c8c208
        type: multi_key_auth
        missing_permissions: []
        tainted: false
        expires_at: null
        created_at: 2022-11-04T20:10:06.927Z
        integration_instance:
          id: e0f2388b-2efe-42a3-a9e4-86f12d3e8c77
          name: swaggerhub-internal
          display_name: SwaggerHub (Internal)
    SampleCreateAWSRoleDelegationAuthResponse:
      value:
        id: 4f535923-ec24-456c-b4e5-e67f65c8c208
        type: aws_role_delegation
        missing_permissions: []
        tainted: false
        expires_at: null
        created_at: 2022-11-04T20:10:06.927Z
        integration_instance:
          id: e0f2388b-2efe-42a3-a9e4-86f12d3e8c77
          name: swaggerhub-internal
          display_name: SwaggerHub (Internal)
        config:
          role_arn: arn:aws:iam::084735895545:role/KonnectServiceCatalogRole
    SampleCreateDynatraceMultiKeyAuthResponse:
      value:
        id: 88c58c29-ff7d-4913-b3d7-8affc279dd56
        type: multi_key_auth
        missing_permissions: []
        tainted: false
        expires_at: null
        created_at: 2022-11-04T20:10:06.927Z
        integration_instance:
          id: 70ecc595-4280-4872-8b80-87b2e57dba3f
          name: dynatrace
          display_name: Dynatrace
    SampleCreateSonarQubeMultiKeyAuthResponse:
      value:
        id: 1a048e2f-bb24-49b9-bcb3-8a4855cb4d44
        type: multi_key_auth
        missing_permissions: []
        tainted: false
        expires_at: null
        created_at: 2022-11-04T20:10:06.927Z
        integration_instance:
          id: f0f2725e-051d-48fd-a63f-e1e76d5fec34
          name: sonarqube
          display_name: SonarQube
    AzureApiManagementAuthConfigResponse:
      value:
        id: 2b7e1516-28ae-4d6c-8c2f-1e2b3c4d5e6f
        type: oauth
        missing_permissions: []
        tainted: false
        expires_at: null
        created_at: 2022-11-04T20:10:06.927Z
        integration_instance:
          id: 3c9e2f1a-4b5d-6e7f-8a9b-0c1d2e3f4a5b
          name: azure-api-management
          display_name: Azure API Management
    SampleCreateAzureDevopsMultiKeyAuthResponse:
      value:
        id: 7c91b6d3-8e2f-4e2a-9a53-f3b47eac912b
        type: multi_key_auth
        missing_permissions: []
        tainted: false
        expires_at: null
        created_at: 2024-07-18T15:42:29.314Z
        integration_instance:
          id: b4f3d2c9-7a25-43bb-8c47-d7bfa2f91a8e
          name: azure-devops
          display_name: Azure DevOps
    UnauthorizedExample:
      value:
        status: 401
        title: Unauthorized
        instance: kong:trace:8347343766220159418
        detail: Unauthorized
    ForbiddenExample:
      value:
        status: 403
        title: Forbidden
        instance: kong:trace:2723154947768991354
        detail: You do not have permission to perform this action
    NotFoundExample:
      value:
        status: 404
        title: Not Found
        instance: kong:trace:6816496025408232265
        detail: Not Found
  securitySchemes:
    konnectAccessToken:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >
        The Konnect access token is meant to be used by the Konnect dashboard
        and the decK CLI authenticate with.
    personalAccessToken:
      type: http
      scheme: bearer
      bearerFormat: Token
      description: >
        The personal access token is meant to be used as an alternative to
        basic-auth when accessing Konnect via APIs.

        You can generate a Personal Access Token (PAT) from the [personal access
        token page](https://cloud.konghq.com/global/account/tokens/) in the
        Konnect dashboard.

        The PAT token must be passed in the header of a request, for example:

        `curl -X GET 'https://global.api.konghq.com/v2/users/' --header
        'Authorization: Bearer kpat_xgfT...'`
    systemAccountAccessToken:
      type: http
      scheme: bearer
      bearerFormat: Token
      description: >
        The system account access token is meant for automations and
        integrations that are not directly associated with a human identity.

        You can generate a system account Access Token by creating a system
        account and then obtaining a system account access token for that
        account.

        The access token must be passed in the header of a request, for example:

        `curl -X GET 'https://global.api.konghq.com/v2/users/' --header
        'Authorization: Bearer spat_i2Ej...'`
```
