{
  "openapi": "3.1.0",
  "info": {
    "title": "Identity & Access API",
    "version": "1.0.0",
    "description": "OAuth 2.0 endpoints for the Iron Brick sandbox. Exchange application credentials for a short-lived bearer token and validate tokens. Live on dev.ironbrick.us. Agency deployments use the agency identity provider (for example Login.gov, Okta, or Entra ID with PIV/CAC) with the same token semantics.",
    "contact": {
      "name": "Iron Brick LLC",
      "email": "info@ironbrick.us",
      "url": "https://dev.ironbrick.us"
    }
  },
  "servers": [
    {
      "url": "https://dev.ironbrick.us",
      "description": "Iron Brick sandbox (live)"
    }
  ],
  "paths": {
    "/oauth/token": {
      "post": {
        "operationId": "issueToken",
        "summary": "Get an access token",
        "tags": [
          "OAuth"
        ],
        "description": "Client credentials grant (RFC 6749 section 4.4). Authenticate with HTTP Basic (preferred) or form fields. Tokens are JWTs valid for 3600 seconds. Request a subset of your application's scopes with `scope`.",
        "security": [
          {
            "basicClient": []
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/x-www-form-urlencoded": {
              "schema": {
                "type": "object",
                "required": [
                  "grant_type"
                ],
                "properties": {
                  "grant_type": {
                    "type": "string",
                    "enum": [
                      "client_credentials"
                    ]
                  },
                  "scope": {
                    "type": "string",
                    "description": "Space-separated scopes (optional)."
                  },
                  "client_id": {
                    "type": "string",
                    "description": "Only if not using HTTP Basic."
                  },
                  "client_secret": {
                    "type": "string",
                    "description": "Only if not using HTTP Basic."
                  }
                }
              },
              "example": {
                "grant_type": "client_credentials",
                "scope": "cases:read"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Token issued",
            "content": {
              "application/json": {
                "example": {
                  "access_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6ImF0K2p3dCJ9.eyJpc3MiOi...",
                  "token_type": "Bearer",
                  "expires_in": 3600,
                  "scope": "cases:read"
                }
              }
            }
          },
          "400": {
            "description": "invalid_request, unsupported_grant_type, or invalid_scope",
            "content": {
              "application/json": {
                "example": {
                  "error": "invalid_scope",
                  "error_description": "Not granted to this application: audit:read"
                }
              }
            }
          },
          "401": {
            "description": "invalid_client",
            "content": {
              "application/json": {
                "example": {
                  "error": "invalid_client",
                  "error_description": "Client authentication failed."
                }
              }
            }
          },
          "429": {
            "description": "slow_down"
          }
        }
      }
    },
    "/oauth/introspect": {
      "post": {
        "operationId": "introspectToken",
        "summary": "Validate a token",
        "tags": [
          "OAuth"
        ],
        "description": "Token introspection (RFC 7662). Authenticate with any application on the same account. Returns `active: false` for tokens that are expired, revoked, rotated, malformed, or owned by another account.",
        "security": [
          {
            "basicClient": []
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/x-www-form-urlencoded": {
              "schema": {
                "type": "object",
                "required": [
                  "token"
                ],
                "properties": {
                  "token": {
                    "type": "string"
                  }
                }
              },
              "example": {
                "token": "eyJhbGciOiJIUzI1NiIs..."
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Introspection result",
            "content": {
              "application/json": {
                "example": {
                  "active": true,
                  "scope": "cases:read",
                  "client_id": "ib_4f0c2a9d8e1b7c3a5f6d2e10",
                  "token_type": "Bearer",
                  "exp": 1791043200,
                  "iat": 1791039600,
                  "nbf": 1791039600,
                  "sub": "ib_4f0c2a9d8e1b7c3a5f6d2e10",
                  "aud": "ironbrick-sandbox",
                  "iss": "https://dev.ironbrick.us",
                  "jti": "9b1e6f0a4c2d8e7f1a3b5c6d",
                  "plan": "sandbox"
                }
              }
            }
          },
          "401": {
            "description": "invalid_client"
          }
        }
      }
    }
  },
  "components": {
    "securitySchemes": {
      "basicClient": {
        "type": "http",
        "scheme": "basic",
        "description": "client_id as username, client_secret as password."
      }
    }
  }
}