{
    "components": {
        "schemas": {
            "authwise.identity.v1alpha1.AssetDownloadResponse": {
                "properties": {
                    "data": {
                        "format": "byte",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.AuthenticationContextVariable": {
                "properties": {
                    "description": {
                        "type": "string"
                    },
                    "name": {
                        "description": "The CEL path, e.g. risk.level.",
                        "type": "string"
                    },
                    "type": {
                        "description": "The CEL type, e.g. string, list(string), map(string, string).",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.AuthenticationFactorType": {
                "properties": {
                    "amr": {
                        "description": "RFC 8176 values a verification asserts.",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    },
                    "classes": {
                        "description": "What verifying it proves: knowledge, possession, inherence.",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    },
                    "configMessage": {
                        "description": "The message Factor.config carries for this type, empty for none.",
                        "type": "string"
                    },
                    "enabled": {
                        "description": "Whether this build runs it; a Factor of a type it does not is refused.",
                        "type": "boolean"
                    },
                    "factorType": {
                        "description": "The slug a Factor row and a rule name.",
                        "type": "string"
                    },
                    "phishingResistant": {
                        "type": "boolean"
                    },
                    "recovery": {
                        "description": "A look-up secret; never the method a requirement is met by.",
                        "type": "boolean"
                    },
                    "restricted": {
                        "description": "NIST's restricted class (SMS): offered only beside an unrestricted method.",
                        "type": "boolean"
                    },
                    "supportsEnrollment": {
                        "description": "False where enrolment happens elsewhere (Duo).",
                        "type": "boolean"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.AuthenticationProviderType": {
                "properties": {
                    "configMessage": {
                        "description": "The message Provider.config carries for this type, empty for none.",
                        "type": "string"
                    },
                    "enabled": {
                        "description": "Whether this build runs it; a Provider of a type it does not cannot sign anyone in.",
                        "type": "boolean"
                    },
                    "kind": {
                        "description": "local, passwordless or federated.",
                        "type": "string"
                    },
                    "providerType": {
                        "description": "The slug a Provider row's provider_type takes.",
                        "type": "string"
                    },
                    "restricted": {
                        "description": "NIST's restricted class (SMS): offered only beside an unrestricted method.",
                        "type": "boolean"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.CheckEndpointResponse": {
                "properties": {
                    "authScheme": {
                        "description": "none, bearer, basic, header or kit_token.",
                        "type": "string"
                    },
                    "credentialResolved": {
                        "description": "The credential's secret opened or its token was signed; nothing about whether the far side accepted it.",
                        "type": "boolean"
                    },
                    "error": {
                        "description": "One line in the transport's words, the credential redacted; empty when nothing failed.",
                        "type": "string"
                    },
                    "httpStatus": {
                        "description": "REST: the HEAD's status; 0 when none came back.",
                        "format": "int32",
                        "type": "integer"
                    },
                    "latencyMs": {
                        "description": "The whole check, in milliseconds.",
                        "format": "int32",
                        "type": "integer"
                    },
                    "reachable": {
                        "description": "A connection was made and, for TLS, the handshake completed; a REST 401 is reachable.",
                        "type": "boolean"
                    },
                    "resolvedAddress": {
                        "description": "What the dialer connected to, after resolution.",
                        "type": "string"
                    },
                    "services": {
                        "description": "gRPC: from server reflection, or grpc.health.v1.Health when only health answered.",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    },
                    "servicesKnown": {
                        "description": "The services came from reflection, so the list is complete.",
                        "type": "boolean"
                    },
                    "tls": {
                        "$ref": "#/components/schemas/authwise.identity.v1alpha1.EndpointCheckTls"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.EndpointCheckTls": {
                "properties": {
                    "attempted": {
                        "description": "Always true when set.",
                        "type": "boolean"
                    },
                    "error": {
                        "description": "The handshake's failure, if it failed.",
                        "type": "string"
                    },
                    "issuer": {
                        "type": "string"
                    },
                    "notAfter": {
                        "format": "date-time",
                        "type": "string"
                    },
                    "subject": {
                        "description": "The endpoint certificate's subject, reported even when it was not trusted.",
                        "type": "string"
                    },
                    "verified": {
                        "description": "The chain and name verified; false under insecure_skip_verify.",
                        "type": "boolean"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.EndpointReferrer": {
                "properties": {
                    "field": {
                        "description": "Where in the referrer, in proto field names, e.g. config.flow_integration_config.endpoint_name.",
                        "type": "string"
                    },
                    "referrerName": {
                        "description": "The referrer's resource name.",
                        "type": "string"
                    },
                    "referrerType": {
                        "description": "issuer, client, audience, realm, provider, factor, accessResourceType or accessSubjectType.",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.EventSearchHistogramResponse": {
                "properties": {
                    "histogram": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.HistogramResult"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.EventSearchPredicatesResponse": {
                "properties": {
                    "predicates": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.SearchPredicateDescriptor"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.EventSearchResult": {
                "properties": {
                    "entity": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Event"
                    },
                    "score": {
                        "format": "float",
                        "type": "number"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.ExportClientSamlMetadataResponse": {
                "properties": {
                    "endpointUrl": {
                        "description": "The endpoint the partner sends to: the ACS in the SP role, the SSO service in the IdP role.",
                        "type": "string"
                    },
                    "entityId": {
                        "description": "Our entity id, as it appears in the document.",
                        "type": "string"
                    },
                    "metadataXml": {
                        "description": "The document to hand the partner.",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.ExportProviderSamlMetadataResponse": {
                "properties": {
                    "endpointUrl": {
                        "description": "The endpoint the partner sends to: the ACS in the SP role, the SSO service in the IdP role.",
                        "type": "string"
                    },
                    "entityId": {
                        "description": "Our entity id, as it appears in the document.",
                        "type": "string"
                    },
                    "metadataXml": {
                        "description": "The document to hand the partner.",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.ImportClientSamlMetadataResponse": {
                "properties": {
                    "certificates": {
                        "description": "Every certificate the document published, in document order. Existing rows are reused, not duplicated.",
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Certificate"
                        },
                        "type": "array"
                    },
                    "changes": {
                        "description": "One line per field the document changes, for an operator to read before confirming.",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    },
                    "client": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Client"
                    },
                    "warnings": {
                        "description": "Things the document says that kit cannot act on — an expired certificate, more signing certificates than kit can verify against.",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.ImportProviderSamlMetadataResponse": {
                "properties": {
                    "certificates": {
                        "description": "Every certificate the document published, in document order. Existing rows are reused, not duplicated.",
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Certificate"
                        },
                        "type": "array"
                    },
                    "changes": {
                        "description": "One line per field the document changes, for an operator to read before confirming.",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    },
                    "provider": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Provider"
                    },
                    "warnings": {
                        "description": "Things the document says that kit cannot act on — an expired certificate, more signing certificates than kit can verify against.",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.InviteUserResponse": {
                "properties": {
                    "acceptUrl": {
                        "description": "Carries the plaintext token. Returned exactly once per mint and never retrievable again.",
                        "type": "string"
                    },
                    "createdUser": {
                        "description": "False when the invitation attached to a user that already existed.",
                        "type": "boolean"
                    },
                    "deliveryMessageId": {
                        "description": "Platform's id for the message when one was enqueued. Empty when SKIPPED.",
                        "type": "string"
                    },
                    "deliveryReason": {
                        "description": "Why the message was not queued: platform's rejection reason, or kit's skip reason (delivery-unconfigured, recipient-not-email).",
                        "type": "string"
                    },
                    "deliveryStatus": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.MessageDeliveryStatus"
                    },
                    "expiresAt": {
                        "format": "date-time",
                        "type": "string"
                    },
                    "identifier": {
                        "type": "string"
                    },
                    "reissued": {
                        "type": "boolean"
                    },
                    "userId": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.ListAccessPermissionsByScopeResponse": {
                "properties": {
                    "accessPermissions": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.AccessPermission"
                        },
                        "type": "array"
                    },
                    "nextPageToken": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.ListAppearanceProfilesResponse": {
                "properties": {
                    "appearanceProfiles": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.AppearanceProfile"
                        },
                        "type": "array"
                    },
                    "nextPageToken": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.ListAssetsResponse": {
                "properties": {
                    "assets": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Asset"
                        },
                        "type": "array"
                    },
                    "nextPageToken": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.ListAudiencesResponse": {
                "properties": {
                    "audiences": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Audience"
                        },
                        "type": "array"
                    },
                    "nextPageToken": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.ListCertificatesResponse": {
                "properties": {
                    "certificates": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Certificate"
                        },
                        "type": "array"
                    },
                    "nextPageToken": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.ListClientSecretsResponse": {
                "properties": {
                    "clientSecrets": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.ClientSecret"
                        },
                        "type": "array"
                    },
                    "nextPageToken": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.ListClientsResponse": {
                "properties": {
                    "clients": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Client"
                        },
                        "type": "array"
                    },
                    "nextPageToken": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.ListDomainsResponse": {
                "properties": {
                    "domains": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Domain"
                        },
                        "type": "array"
                    },
                    "nextPageToken": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.ListEndpointReferrersResponse": {
                "properties": {
                    "referrers": {
                        "description": "Every row of the tenant naming the endpoint; empty when a delete would be allowed.",
                        "items": {
                            "$ref": "#/components/schemas/authwise.identity.v1alpha1.EndpointReferrer"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.ListEndpointsResponse": {
                "properties": {
                    "endpoints": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Endpoint"
                        },
                        "type": "array"
                    },
                    "nextPageToken": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.ListEventsResponse": {
                "properties": {
                    "events": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Event"
                        },
                        "type": "array"
                    },
                    "nextPageToken": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.ListFactorsResponse": {
                "properties": {
                    "factors": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Factor"
                        },
                        "type": "array"
                    },
                    "nextPageToken": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.ListGroupsByUserResponse": {
                "properties": {
                    "groups": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Group"
                        },
                        "type": "array"
                    },
                    "nextPageToken": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.ListGroupsResponse": {
                "properties": {
                    "groups": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Group"
                        },
                        "type": "array"
                    },
                    "nextPageToken": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.ListIssuersResponse": {
                "properties": {
                    "issuers": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Issuer"
                        },
                        "type": "array"
                    },
                    "nextPageToken": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.ListMessageKeysResponse": {
                "properties": {
                    "canSendPasswordReset": {
                        "description": "True when this install can send a password-reset e-mail: it delivers messages (messaging.delivery is not none) and no operator has disabled the password-recovery message. Exactly the check ResetUserPassword refuses on (no_delivery_channel, message_disabled) and the self-service reset is offered on — a realm's self_service_reset shows the login page's link only where this is true too. Install-wide. kit#384.",
                        "type": "boolean"
                    },
                    "messageKeys": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.identity.v1alpha1.MessageKeyMetadata"
                        },
                        "type": "array"
                    },
                    "templatesReadOnly": {
                        "description": "True when this install serves message templates from its overlay rather than a database, so every write would be refused. A console reads this to decide whether to offer an editor or a viewer — asking here beats discovering it from a failed save.",
                        "type": "boolean"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.ListMessageTemplateRevisionsResponse": {
                "properties": {
                    "revisions": {
                        "description": "Newest first. At most 50.",
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.MessageTemplateRevision"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.ListMessageTemplatesResponse": {
                "properties": {
                    "messageTemplates": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.MessageTemplate"
                        },
                        "type": "array"
                    },
                    "nextPageToken": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.ListProvidersResponse": {
                "properties": {
                    "nextPageToken": {
                        "type": "string"
                    },
                    "providers": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Provider"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.ListRealmsResponse": {
                "properties": {
                    "nextPageToken": {
                        "type": "string"
                    },
                    "realms": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Realm"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.ListScopesResponse": {
                "properties": {
                    "nextPageToken": {
                        "type": "string"
                    },
                    "scopes": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Scope"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.ListSecretsResponse": {
                "properties": {
                    "nextPageToken": {
                        "type": "string"
                    },
                    "secrets": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Secret"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.ListThemesResponse": {
                "properties": {
                    "nextPageToken": {
                        "type": "string"
                    },
                    "themes": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Theme"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.ListUserAuthenticatorsResponse": {
                "properties": {
                    "authenticators": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.identity.v1alpha1.UserAuthenticatorMetadata"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.ListUserDevicesResponse": {
                "properties": {
                    "devices": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.identity.v1alpha1.UserDeviceMetadata"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.ListUserIdentifiersResponse": {
                "properties": {
                    "identifiers": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.identity.v1alpha1.UserIdentifierMetadata"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.ListUsersByGroupResponse": {
                "properties": {
                    "nextPageToken": {
                        "type": "string"
                    },
                    "users": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.User"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.ListUsersResponse": {
                "properties": {
                    "nextPageToken": {
                        "type": "string"
                    },
                    "users": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.User"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.MakeDefaultAppearanceProfileResponse": {
                "properties": {
                    "default": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.AppearanceProfile"
                    },
                    "previous": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.AppearanceProfile"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.MessageKeyMetadata": {
                "properties": {
                    "channels": {
                        "description": "The channels this key renders in. Only \"email\" today.",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    },
                    "defaults": {
                        "description": "The template sources kit ships for this key, one entry per channel and shipped locale — what a recipient gets when the tenant has no copy. Template SOURCE, not rendered output: a console prefills an editor from it, and \"Start over from kit's default\" restores it. Read only, so it needs no permission beyond listing the keys. kit#673.",
                        "items": {
                            "$ref": "#/components/schemas/authwise.identity.v1alpha1.MessageTemplateDefault"
                        },
                        "type": "array"
                    },
                    "description": {
                        "description": "What this message is and when it is sent.",
                        "type": "string"
                    },
                    "disabled": {
                        "description": "True when an operator has switched this message off in this install's configuration (messaging.keys.\u003ckey\u003e.disabled), so kit sends nothing for it and reports SKIPPED with reason key-disabled. Read it before telling an author their message is live: :sendTest deliberately still delivers on a disabled key, so that a message can be inspected before it is turned on — which means a test send that arrives is NOT evidence that real sends happen. False for a key no operator has named, which is also what an older server reports, so the safe reading is the default one. Install-wide rather than per-tenant, unlike locales.",
                        "type": "boolean"
                    },
                    "key": {
                        "description": "The key a MessageTemplate row names, e.g. \"tenant-invitation\".",
                        "type": "string"
                    },
                    "locales": {
                        "description": "The locales this key can be rendered in for this tenant: the ones the build ships plus any the tenant has added by overriding them. A tenant may write a locale kit does not ship, and that locale then appears here.",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    },
                    "sample": {
                        "description": "Realistic values for those variables. The same ones save-time validation renders against and :render previews with, so \"it validated\" and \"the preview looked right\" are one fact rather than two that can disagree.",
                        "type": "object"
                    },
                    "variables": {
                        "description": "The variables a template for this key may reference, as a JSON Schema object. Derived from the Go struct the templates render against, so what a console offers and what a template may use cannot disagree. Every leaf carries title (the human label), description, x-source (where the value comes from: appearance_profile, tenant, issuer, realm, recipient or ceremony) and x-role (how a template may use it: text, url, color, datetime, flag or list). kit#702.",
                        "type": "object"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.MessageTemplateDefault": {
                "properties": {
                    "channel": {
                        "description": "\"email\" or \"sms\".",
                        "type": "string"
                    },
                    "htmlBody": {
                        "description": "The HTML body's html/template source: what a recipient's mail client shows until the tenant publishes a copy. Email only.",
                        "type": "string"
                    },
                    "locale": {
                        "description": "A locale kit ships for this key. A locale only a tenant has written has no default and no entry.",
                        "type": "string"
                    },
                    "mjml": {
                        "description": "A starter for the layout editor: MJML saying what html_body says, built only from mj-section, mj-column, mj-text, mj-button, mj-image, mj-divider and mj-spacer, with template actions kept inline as text. Never sent: html_body stays the default until a tenant publishes. Email only.",
                        "type": "string"
                    },
                    "subject": {
                        "description": "The subject's text/template source. Email only.",
                        "type": "string"
                    },
                    "textBody": {
                        "description": "The plain body's text/template source: the text part of an e-mail, or the whole of a text message.",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.MintClientSecretResponse": {
                "properties": {
                    "clientSecret": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.ClientSecret"
                    },
                    "secret": {
                        "description": "The secret to authenticate with, as \u003cid\u003e_\u003cplaintext\u003e. Returned exactly once and never retrievable again.",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.PublishMessageTemplateResponse": {
                "properties": {
                    "messageTemplate": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.MessageTemplate"
                    },
                    "revision": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.MessageTemplateRevision"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.RealmAuthenticationContextSchema": {
                "properties": {
                    "factorTypes": {
                        "description": "Every factor type kit knows, and whether this build runs it.",
                        "items": {
                            "$ref": "#/components/schemas/authwise.identity.v1alpha1.AuthenticationFactorType"
                        },
                        "type": "array"
                    },
                    "providerTypes": {
                        "description": "Every provider type kit knows, and whether this build runs it (kit#600).",
                        "items": {
                            "$ref": "#/components/schemas/authwise.identity.v1alpha1.AuthenticationProviderType"
                        },
                        "type": "array"
                    },
                    "variables": {
                        "description": "What a rule condition may read, in the order the docs list them.",
                        "items": {
                            "$ref": "#/components/schemas/authwise.identity.v1alpha1.AuthenticationContextVariable"
                        },
                        "type": "array"
                    },
                    "warnings": {
                        "description": "The realm's stored policy judged against its enabled factors: what a write would return as Authwise-Warning.",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.RemoveUserIdentifierResponse": {
                "properties": {
                    "removed": {
                        "$ref": "#/components/schemas/authwise.identity.v1alpha1.UserIdentifierMetadata"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.RenderMessageTemplateResponse": {
                "properties": {
                    "brandAppearanceProfile": {
                        "description": "The appearance profile that was read (ap-…), whether or not it named the brand — the place to change it. Empty when the issuer has none.",
                        "type": "string"
                    },
                    "brandIssuer": {
                        "description": "The issuer the brand was resolved for (i-…); empty when brand_source is \"sample\".",
                        "type": "string"
                    },
                    "brandSource": {
                        "description": "Where Brand.DisplayName came from: \"appearance_profile\", \"tenant\" (its display name), \"issuer_host\" (neither named one), or \"sample\" (the tenant has no issuer, so the catalog's sample brand was used). kit#701.",
                        "type": "string"
                    },
                    "htmlBody": {
                        "type": "string"
                    },
                    "locale": {
                        "description": "The locale that was actually rendered, which is not always the one requested. Returned so a console can say \"showing en, you asked for fr-CA\" rather than silently showing the wrong thing.",
                        "type": "string"
                    },
                    "subject": {
                        "type": "string"
                    },
                    "textBody": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.ResetUserPasswordResponse": {
                "properties": {
                    "deliveryMessageId": {
                        "description": "Platform's id for the message when one was enqueued.",
                        "type": "string"
                    },
                    "deliveryReason": {
                        "description": "Why the message was not queued, when it was not.",
                        "type": "string"
                    },
                    "deliveryStatus": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.MessageDeliveryStatus"
                    },
                    "expiresAt": {
                        "description": "When the link stops working.",
                        "format": "date-time",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.RotateCertificateResponse": {
                "properties": {
                    "predecessor": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Certificate"
                    },
                    "successor": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Certificate"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.SearchEventsResponse": {
                "properties": {
                    "nextPageToken": {
                        "type": "string"
                    },
                    "results": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.identity.v1alpha1.EventSearchResult"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.SearchUsersResponse": {
                "properties": {
                    "nextPageToken": {
                        "type": "string"
                    },
                    "results": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.identity.v1alpha1.UserSearchResult"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.SendTestMessageResponse": {
                "properties": {
                    "brandAppearanceProfile": {
                        "description": "The appearance profile that was read (ap-…), whether or not it named the brand — the place to change it. Empty when the issuer has none.",
                        "type": "string"
                    },
                    "brandIssuer": {
                        "description": "The issuer the brand was resolved for (i-…); empty when brand_source is \"sample\".",
                        "type": "string"
                    },
                    "brandSource": {
                        "description": "Where Brand.DisplayName came from: \"appearance_profile\", \"tenant\" (its display name), \"issuer_host\" (neither named one), or \"sample\" (the tenant has no issuer, so the catalog's sample brand was used). kit#701.",
                        "type": "string"
                    },
                    "deliveryStatus": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.MessageDeliveryStatus"
                    },
                    "locale": {
                        "description": "The locale that was sent, as for :render.",
                        "type": "string"
                    },
                    "messageId": {
                        "type": "string"
                    },
                    "reason": {
                        "description": "Why delivery did not happen, when it did not. Empty on success.",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.UserAuthenticatorMetadata": {
                "properties": {
                    "createdAt": {
                        "format": "date-time",
                        "type": "string"
                    },
                    "displayName": {
                        "type": "string"
                    },
                    "factorType": {
                        "description": "totp, webauthn, otp-email, otp-sms, recovery-code, duo, external.",
                        "type": "string"
                    },
                    "id": {
                        "description": "The authenticator's id, what revokeAuthenticator takes.",
                        "type": "string"
                    },
                    "lastUsedAt": {
                        "description": "Unset when it was never used.",
                        "format": "date-time",
                        "type": "string"
                    },
                    "status": {
                        "description": "active, or disabled after repeated failures.",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.UserDeviceMetadata": {
                "properties": {
                    "displayName": {
                        "type": "string"
                    },
                    "id": {
                        "description": "The device's id, what revokeDevice takes. Never the cookie digest.",
                        "type": "string"
                    },
                    "lastIp": {
                        "type": "string"
                    },
                    "lastSeenAt": {
                        "format": "date-time",
                        "type": "string"
                    },
                    "revokedAt": {
                        "description": "Set when trust has ended.",
                        "format": "date-time",
                        "type": "string"
                    },
                    "trustedUntil": {
                        "description": "Unset once revoked.",
                        "format": "date-time",
                        "type": "string"
                    },
                    "userAgentFamily": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.UserIdentifierMetadata": {
                "properties": {
                    "createdAt": {
                        "format": "date-time",
                        "type": "string"
                    },
                    "credentialEstablished": {
                        "description": "Whether a password is set. Never the credential itself — this answers \"can they sign in yet\", which is the question the surface exists for. False is normal for a federated identifier, where the upstream provider authenticates.",
                        "type": "boolean"
                    },
                    "identifier": {
                        "description": "The login identifier itself — normally an email address or username.",
                        "type": "string"
                    },
                    "kind": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.UserIdentifierKind"
                    },
                    "lastUsedAt": {
                        "description": "The last completed sign-in through this identifier. Unset means never.",
                        "format": "date-time",
                        "type": "string"
                    },
                    "providerDisplayName": {
                        "description": "The provider's display name, for a page to print.",
                        "type": "string"
                    },
                    "providerId": {
                        "description": "The provider this identifier signs in through.",
                        "type": "string"
                    },
                    "providerType": {
                        "description": "The provider's type — google, oidc, usernamePassword, magicLink. The mark a page shows derives from it.",
                        "type": "string"
                    },
                    "updatedAt": {
                        "description": "Moves when the credential is re-established, so it doubles as \"password last changed\".",
                        "format": "date-time",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.UserSearchHistogramResponse": {
                "properties": {
                    "histogram": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.HistogramResult"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.UserSearchPredicatesResponse": {
                "properties": {
                    "predicates": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.SearchPredicateDescriptor"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.identity.v1alpha1.UserSearchResult": {
                "properties": {
                    "entity": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.User"
                    },
                    "score": {
                        "format": "float",
                        "type": "number"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.AccessConfig": {
                "description": "AccessConfig holds the audience-level Authwise Access settings.\nPer-resource-type and per-subject-type expansion settings live in\nruntime tables managed via the access.v1 API; the fields here are\naudience-level defaults consulted when a type does not declare its\nown override.\n\nThere is no longer a mode that gates them. Every audience's catalog is\nlive for its own tokens (kit#506), so an audience that declares no\nexpander endpoints simply has no pull-mode defaults, which is a\ndifferent statement from \"Access is off here\".",
                "properties": {
                    "decisionSampling": {
                        "description": "decision_sampling is the percentage of ALLOW decisions recorded as\n`access.decision` audit events, 0-100 (docswip/EVENTS.md §4.9).\n\nDENY is never sampled and this field cannot turn it off. A refused\nauthorization is the fact the catalog exists to record; an allow is\nevidence, and evidence at one row per check is a firehose — the runtime\nsurface answers a Check per protected action of every caller, which is\norders of magnitude more traffic than the admin API produces.\n\nThe zero value records no allows, which is the safe default and the\nhonest reading of an unset field: an install that has said nothing\nabout sampling has not asked for the volume.\n\n# Why this is on the audience and not on the realm\n\nThe design staged it as a realm setting, and the realm is the wrong\nscope for the thing being sampled. An Access decision is evaluated\nagainst a CATALOG, and a catalog is an audience (kit#506): the rows the\nevaluator reads are the audience's roles, permissions, bindings and\nconditions, and the runtime credential model resolves a tenant, an\nissuer and an audience from the bearer — never a realm. A realm-keyed\nknob would be a setting no decision could ever look up, which is worse\nthan no knob at all: it would report as configured and sample nothing.",
                        "format": "int32",
                        "type": "integer"
                    },
                    "defaultResourceExpanderEndpointName": {
                        "description": "Default Endpoint name for pull-mode resource-parent expansion when\na resource type does not declare its own endpoint. References an\nEndpoint row by name (see authwise.types.core.v1alpha1.Endpoint).",
                        "type": "string"
                    },
                    "defaultSubjectExpanderEndpointName": {
                        "description": "Default Endpoint name for pull-mode subject-group expansion.",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.AccessPermission": {
                "description": "AccessPermission is a namespaced action (e.g. \"idm.tenants.create\",\n\"invoices.read\"). resource_type is optional and constrains the\npermission to a specific resource type. Provenance is `service`, which\nalready namespaces the shared admin audience (identity.* vs\nguardcontrol.*).",
                "properties": {
                    "description": {
                        "type": "string"
                    },
                    "name": {
                        "description": "The resource name, which for this resource is also its KEY. Unlike every\nother resource in this file it is client-supplied and REQUIRED on create:\nthere is no generated id for the server to render a name from, so the\ncreate service reads this field and uses it as the row's key. It is\nignored on update — renaming is not an operation.\n\nThis comment must never contain the phrase protoc-gen-openapiv2 keys\nreadOnly off — it matches the words wherever they appear, not only at\nthe start, so even quoting them here to say \"not that\" marked all four\nof these fields read-only and would have broken every create. Making\nthe surface uniform means giving create a separate client-specified id\nfield (AIP-133); it is a change to the create surface, not a comment.",
                        "type": "string"
                    },
                    "resourceType": {
                        "title": "@gotags: yaml:\"resource_type\"",
                        "type": "string"
                    },
                    "service": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.AcrLevel": {
                "properties": {
                    "name": {
                        "type": "string"
                    },
                    "require": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Requirement"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.AppearanceProfile": {
                "properties": {
                    "content": {
                        "type": "object"
                    },
                    "displayName": {
                        "type": "string"
                    },
                    "isDefault": {
                        "description": "Whether this is the issuer's default profile: the appearance of every\npage the issuer renders without a client or audience that names one —\nincluding a mailed landing (/recovery, /magic-link) that has no authorize\ninteraction (kit#680). Once an issuer has any profile, exactly one is its\ndefault. The first profile created becomes the default whatever this\nsays; a write that would make a second default, or leave none, is refused\nwith FAILED_PRECONDITION. Move the default with MakeDefaultAppearanceProfile.\n\n@gotags: yaml:\"is_default\"",
                        "type": "boolean"
                    },
                    "labels": {
                        "additionalProperties": {
                            "type": "string"
                        },
                        "type": "object"
                    },
                    "name": {
                        "description": "Output only. The resource name, rendered from the row's id: the address\nused to GET, PATCH and DELETE this row, not a label. A value sent on\ncreate or update is ignored — the server always builds it from the id.\nFor a human-readable label, use display_name.",
                        "readOnly": true,
                        "type": "string"
                    },
                    "stylesheetAttributes": {
                        "type": "object"
                    },
                    "themeId": {
                        "title": "@gotags: yaml:\"theme_id\"",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.Asset": {
                "properties": {
                    "displayName": {
                        "type": "string"
                    },
                    "labels": {
                        "additionalProperties": {
                            "type": "string"
                        },
                        "type": "object"
                    },
                    "mimeType": {
                        "title": "@gotags: yaml:\"media_type\"",
                        "type": "string"
                    },
                    "name": {
                        "description": "Output only. The resource name, rendered from the row's id: the address\nused to GET, PATCH and DELETE this row, not a label. A value sent on\ncreate or update is ignored — the server always builds it from the id.\nFor a human-readable label, use display_name.",
                        "readOnly": true,
                        "type": "string"
                    },
                    "path": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.AssociationRequest": {
                "properties": {
                    "remove": {
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    },
                    "set": {
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.Audience": {
                "properties": {
                    "appearanceProfileId": {
                        "title": "@gotags: yaml:\"appearance_profile_id\"",
                        "type": "string"
                    },
                    "config": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.AudienceConfig"
                    },
                    "displayName": {
                        "type": "string"
                    },
                    "labels": {
                        "additionalProperties": {
                            "type": "string"
                        },
                        "type": "object"
                    },
                    "name": {
                        "description": "Output only. The resource name, rendered from the row's id: the address\nused to GET, PATCH and DELETE this row, not a label. A value sent on\ncreate or update is ignored — the server always builds it from the id.\nFor a human-readable label, use display_name.",
                        "readOnly": true,
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.AudienceAuthorizationConfig": {
                "description": "AudienceAuthorizationConfig configures the audience's Authwise Access\nsettings.\n\nField 1 was `AuthorizationMode mode`, the SIMPLE-or-ACCESS selector\nadded in kit#21 and removed in kit#506. There is one authorization\nscheme — Authwise Access — and the flat `roles` / `permissions` claims\nare a projection of root-anchored bindings rather than a second model\n(docswip/AW_AUTHZ.md Turn 8, kit#505). A field that selected between\ntwo schemes has nothing left to select between, and leaving it in\nplace would keep offering a choice the engine no longer honours.\n\nThe number and the name are reserved rather than reused: a stored\nconfig written by the console before kit#506 still carries `mode`, and\na future field at 1 would silently inherit its value.",
                "properties": {
                    "access": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.AccessConfig"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.AudienceConfig": {
                "properties": {
                    "accessTokenExpireSeconds": {
                        "format": "int32",
                        "type": "integer"
                    },
                    "authorization": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.AudienceAuthorizationConfig"
                    },
                    "cors": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.CorsConfig"
                    },
                    "flowIntegrationConfig": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.IntegrationConfig"
                    },
                    "interactionForwardUri": {
                        "type": "string"
                    },
                    "refreshTokenAbsoluteExpireSeconds": {
                        "format": "int32",
                        "type": "integer"
                    },
                    "refreshTokenExpireSeconds": {
                        "format": "int32",
                        "type": "integer"
                    },
                    "scopes": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.ScopesConfig"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.AuthenticationPolicy": {
                "description": "AuthenticationPolicy is how strongly a person must prove who they are to\nthis realm (docswip/AUTHENTICATION.md §6.1).\n\nOrdered RULES rather than an execution tree. A Keycloak-style tree of\nREQUIRED / ALTERNATIVE / CONDITIONAL nodes is what a rule set COMPILES to,\nand authoring it directly is the part every operator gets wrong and that\nterraform cannot validate. A rule is a condition and an outcome; the tree\nis the plan compiler's business.\n\nThe FLOOR is the whole reason rules are safe. Adaptive authentication\nmeans rules may RELAX a requirement — no second factor on a trusted device\nat low risk is the point of the feature — and a misjudged rule, or a\ncompromised external risk evaluator, must not be able to relax below what\nthe realm meant. Every rule's outcome is raised to the floor, so the worst\na bad rule can do is ask for more.",
                "properties": {
                    "acrLevels": {
                        "description": "The acr vocabulary this realm can emit: a name and what a session must\nsatisfy to have earned it. Evaluated in order and the LAST satisfied\nentry is the emitted acr, so they are listed weakest first.",
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.AcrLevel"
                        },
                        "type": "array"
                    },
                    "enrollment": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.EnrollmentPolicy"
                    },
                    "floor": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Requirement"
                    },
                    "rememberDevice": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.RememberDevicePolicy"
                    },
                    "risk": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.RiskPolicy"
                    },
                    "rules": {
                        "description": "Rules, evaluated in order; the first whose condition holds decides. A\nrealm with no rules behaves as one rule `true` -\u003e the floor.",
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.AuthenticationRule"
                        },
                        "type": "array"
                    },
                    "session": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.SessionPolicy"
                    },
                    "throttle": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.FactorThrottle"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.AuthenticationRule": {
                "properties": {
                    "condition": {
                        "description": "condition is CEL over the authentication context (§6.2). Empty or\n\"true\" always matches, which is what makes a default rule last.",
                        "type": "string"
                    },
                    "name": {
                        "description": "name is the `rule` attribute on the authn.login row. It is how an\noperator answers \"why was I asked for a factor\", so an unnamed rule is\nrefused by admission.",
                        "type": "string"
                    },
                    "require": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Requirement"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.AuthorizationConfig": {
                "properties": {
                    "includePermissions": {
                        "type": "boolean"
                    },
                    "includeRoles": {
                        "type": "boolean"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.BotProtection": {
                "description": "BotProtection is a realm's challenge at the anonymous request surfaces:\nmagic-link request and resend, the one-time-code resend, and userpass\nsignup (docswip/AUTHENTICATION.md §35).\n\nThe login UI renders the provider's widget with site_key and posts the\ntoken it yields as `bot_token`; kit verifies it before the surface does\nanything — before its throttles too, so a script that cannot pass the\nchallenge cannot spend a person's request budget either.",
                "properties": {
                    "endpointName": {
                        "description": "endpoint_name is the Endpoint serving AuthwiseBotCheckService, for\nENDPOINT.",
                        "type": "string"
                    },
                    "failMode": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.BotProtection.FailMode"
                    },
                    "mode": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.BotProtection.Mode"
                    },
                    "provider": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.BotProtection.Provider"
                    },
                    "refuseDisposableSignup": {
                        "description": "refuse_disposable_signup refuses account CREATION from an address on\nthe disposable-domain list (§35.6). Without it the domain is a risk\nsignal and an audit attribute only. Existing accounts still sign in.",
                        "type": "boolean"
                    },
                    "secretRef": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.SecretRef"
                    },
                    "siteKey": {
                        "description": "site_key is the provider's PUBLIC key, exported to the login UI so it\ncan render the widget. Never a secret.",
                        "type": "string"
                    },
                    "timeout": {
                        "description": "timeout bounds one verification. Default 3s.",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.BotProtection.FailMode": {
                "default": "CLOSED",
                "description": " - CLOSED: CLOSED — a verifier that cannot be reached has not said the request\nis a person's, so it is treated as failed. The default.",
                "enum": [
                    "CLOSED",
                    "OPEN"
                ],
                "type": "string"
            },
            "authwise.types.core.v1alpha1.BotProtection.Mode": {
                "default": "OFF",
                "description": " - OFF: OFF — no challenge. The default.\n - ALWAYS: ALWAYS — every request on the guarded surfaces carries a token.\n - ADAPTIVE: ADAPTIVE — reserved, and refused at admission: a challenge only when\nthe request looks automated needs a pre-authentication signal kit\ndoes not compute yet (§35.1 B2).",
                "enum": [
                    "OFF",
                    "ALWAYS",
                    "ADAPTIVE"
                ],
                "type": "string"
            },
            "authwise.types.core.v1alpha1.BotProtection.Provider": {
                "default": "PROVIDER_UNSPECIFIED",
                "description": " - TURNSTILE: Cloudflare Turnstile, verified at its siteverify URL.\n - HCAPTCHA: hCaptcha, verified at its siteverify URL.\n - ENDPOINT: ENDPOINT — any other verifier, behind an Endpoint row that serves\nAuthwiseBotCheckService.",
                "enum": [
                    "PROVIDER_UNSPECIFIED",
                    "TURNSTILE",
                    "HCAPTCHA",
                    "ENDPOINT"
                ],
                "type": "string"
            },
            "authwise.types.core.v1alpha1.Certificate": {
                "description": "Certificate is metadata over a row in the keys table: everything an\noperator or an API client needs to reason about a certificate, and nothing\nthat would let them extract the private half.\n\ncertificate_pem is the public certificate only. There is no RPC that\nreturns private material and there is not going to be one; has_private_key\nis a boolean because that is the entire answer a caller is owed.",
                "properties": {
                    "certificatePem": {
                        "description": "Output only. The public certificate, PEM encoded.",
                        "readOnly": true,
                        "type": "string"
                    },
                    "displayName": {
                        "type": "string"
                    },
                    "fingerprintSha256": {
                        "description": "Output only. Lower-case hex SHA-256 over the DER. Unique per tenant: it\nis what makes importing the same partner certificate twice idempotent.",
                        "readOnly": true,
                        "type": "string"
                    },
                    "hasPrivateKey": {
                        "description": "Output only. False for an imported partner certificate.",
                        "readOnly": true,
                        "type": "boolean"
                    },
                    "importCertificatePem": {
                        "description": "Input only, and only on import: the partner's certificate, PEM encoded.\nOn a read, certificate_pem carries the public certificate of any row,\nimported or minted.",
                        "type": "string"
                    },
                    "keyId": {
                        "description": "Output only. The keys row holding the material. This is the id the saml\nlibrary addresses when it signs or verifies.",
                        "readOnly": true,
                        "type": "string"
                    },
                    "keySize": {
                        "format": "int32",
                        "type": "integer"
                    },
                    "labels": {
                        "additionalProperties": {
                            "type": "string"
                        },
                        "type": "object"
                    },
                    "name": {
                        "description": "Output only. The resource name, rendered from the row's id: the address\nused to GET, PATCH and DELETE this row, not a label. A value sent on\ncreate or update is ignored — the server always builds it from the id.\nFor a human-readable label, use display_name.",
                        "readOnly": true,
                        "type": "string"
                    },
                    "notAfter": {
                        "description": "Output only. Read from the certificate.",
                        "format": "date-time",
                        "readOnly": true,
                        "type": "string"
                    },
                    "notBefore": {
                        "description": "Output only. Read from the certificate.",
                        "format": "date-time",
                        "readOnly": true,
                        "type": "string"
                    },
                    "origin": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.CertificateOrigin"
                    },
                    "status": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.CertificateStatus"
                    },
                    "subject": {
                        "description": "Output only. RFC 4514 distinguished name, read from the certificate.",
                        "readOnly": true,
                        "type": "string"
                    },
                    "subjectCommonName": {
                        "description": "Input only, and only on create: the parameters the key pair is minted\nwith. They describe how to make the material, not the material, so they\nare never echoed back on a read — subject, not_before and not_after are\nthe answers, read from what was actually produced.\n\nDefaults are applied when unset: the common name falls back to\ndisplay_name, validity to 825 days (the CA/Browser Forum's maximum for a\nserver certificate, and a reasonable SAML rollover period), and the key\nto RSA-2048.",
                        "type": "string"
                    },
                    "use": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.CertificateUse"
                    },
                    "validityDays": {
                        "format": "int32",
                        "type": "integer"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.CertificateOrigin": {
                "default": "CERTIFICATE_ORIGIN_UNSPECIFIED",
                "description": "Where a Certificate's material came from. GENERATED means kit minted the\nkey pair and holds the private half, wrapped by Platform. IMPORTED means a\npartner sent a public certificate and there is no private half at all —\nwhich is why keys.key is nullable.",
                "enum": [
                    "CERTIFICATE_ORIGIN_UNSPECIFIED",
                    "CERTIFICATE_ORIGIN_GENERATED",
                    "CERTIFICATE_ORIGIN_IMPORTED"
                ],
                "type": "string"
            },
            "authwise.types.core.v1alpha1.CertificateStatus": {
                "default": "CERTIFICATE_STATUS_UNSPECIFIED",
                "description": "Where a Certificate sits in a rollover. Signing uses ACTIVE; verification\naccepts RETIRING as well, so a partner that has not yet picked up the new\ncertificate still validates. RETIRED is neither.",
                "enum": [
                    "CERTIFICATE_STATUS_UNSPECIFIED",
                    "CERTIFICATE_STATUS_ACTIVE",
                    "CERTIFICATE_STATUS_RETIRING",
                    "CERTIFICATE_STATUS_RETIRED"
                ],
                "type": "string"
            },
            "authwise.types.core.v1alpha1.CertificateUse": {
                "default": "CERTIFICATE_USE_UNSPECIFIED",
                "description": "What a Certificate may be used for. A partner's metadata declares this per\nKeyDescriptor, and an empty `use` there means both — hence the combined\nvalue rather than a repeated field.",
                "enum": [
                    "CERTIFICATE_USE_UNSPECIFIED",
                    "CERTIFICATE_USE_SIGNING",
                    "CERTIFICATE_USE_ENCRYPTION",
                    "CERTIFICATE_USE_SIGNING_AND_ENCRYPTION"
                ],
                "type": "string"
            },
            "authwise.types.core.v1alpha1.ClaimMap": {
                "description": "ClaimMap maps target names to source paths. It is declared here, rather than\ninside a SAML message, because the same shaping is wanted for OIDC\nfederation and for custom claims on a token; those adopt it without a\nsecond vocabulary to learn.\n\nEvery field is map\u003cstring, string\u003e or repeated string on purpose: tfinfra\ncannot model `repeated \u003cmessage\u003e`, so anything richer would be unreachable\nfrom Terraform, and Terraform is how most of this gets configured.\n\nSource paths are a closed vocabulary, validated at admission — an unknown\npath is InvalidArgument rather than a claim that silently never populates.\nThe list is in docswip/SAML.md §5.1, with the OAuth-family prefixes in\ndocswip/SOCIAL_PROVIDERS.md §4.6, and enforced by pkg/lib/claimmap.\n\nConditions and transforms are deliberately absent. They want an expression\nlanguage, kit already has CEL for Access conditions, and bolting a second\nhalf-language onto a string map would be the wrong shape to live with. That\nis kit#492.",
                "properties": {
                    "map": {
                        "additionalProperties": {
                            "type": "string"
                        },
                        "description": "target name → source path.",
                        "type": "object"
                    },
                    "passthrough": {
                        "description": "Source names copied through unchanged when present. Applied after `map`\nand `static`, and never overwrites either.",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    },
                    "static": {
                        "additionalProperties": {
                            "type": "string"
                        },
                        "description": "target name → literal value, for claims that do not come from anywhere.",
                        "type": "object"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.Client": {
                "properties": {
                    "appearanceProfileId": {
                        "title": "@gotags: yaml:\"appearance_profile_id\"",
                        "type": "string"
                    },
                    "applicationUrl": {
                        "title": "@gotags: yaml:\"login_url\"",
                        "type": "string"
                    },
                    "audienceId": {
                        "type": "string"
                    },
                    "config": {
                        "$ref": "#/components/schemas/google.protobuf.Any"
                    },
                    "displayName": {
                        "type": "string"
                    },
                    "expiresAt": {
                        "description": "When set, the token endpoint refuses the client after it.\n\n@gotags: yaml:\"expires_at\"",
                        "format": "date-time",
                        "type": "string"
                    },
                    "grantTypes": {
                        "description": "The grants the client may use at the token endpoint, RFC 7591 §2\nvalues: authorization_code, refresh_token, client_credentials, and\nsaml_idp for a SAML relying party. A grant not listed is refused\nunauthorized_client, and a refresh token is issued only to a client\nthat lists refresh_token. Required.\n\n@gotags: yaml:\"grant_types\"",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    },
                    "kind": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.ClientKind"
                    },
                    "labels": {
                        "additionalProperties": {
                            "type": "string"
                        },
                        "type": "object"
                    },
                    "loginUrl": {
                        "title": "@gotags: yaml:\"login_url\"",
                        "type": "string"
                    },
                    "name": {
                        "description": "Output only. The resource name, rendered from the row's id: the address\nused to GET, PATCH and DELETE this row, not a label. A value sent on\ncreate or update is ignored — the server always builds it from the id.\nFor a human-readable label, use display_name.",
                        "readOnly": true,
                        "type": "string"
                    },
                    "postLogoutRedirectUris": {
                        "items": {
                            "type": "string"
                        },
                        "title": "@gotags: yaml:\"post_logout_redirect_uris\"",
                        "type": "array"
                    },
                    "status": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.ClientStatus"
                    },
                    "tokenEndpointAuthMethod": {
                        "description": "How the client authenticates at the token endpoint, RFC 7591 §2:\nclient_secret_basic, client_secret_post or none. `none` is a public\nclient — it may hold no secret and must use PKCE — and only an\nAPPLICATION may be one. private_key_jwt is refused until kit#411.\nDefaults to none for an APPLICATION, client_secret_basic otherwise.\n\n@gotags: yaml:\"token_endpoint_auth_method\"",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.ClientKind": {
                "default": "CLIENT_KIND_UNSPECIFIED",
                "description": "ClientKind is what a client is (kit#404, AGENT_SECURITY.md §3.2).\nAPPLICATION signs people in; SERVICE is a machine principal; AGENT is a\nservice that may also act for users. It sets the defaults a client gets\nand what it may be registered with — `none` authentication is\nAPPLICATION's alone.",
                "enum": [
                    "CLIENT_KIND_UNSPECIFIED",
                    "CLIENT_KIND_APPLICATION",
                    "CLIENT_KIND_SERVICE",
                    "CLIENT_KIND_AGENT"
                ],
                "type": "string"
            },
            "authwise.types.core.v1alpha1.ClientSecret": {
                "description": "ClientSecret is a single client credential row. Multiple secrets may exist per\nclient to support rotation. The generated resource name is\n`tenants/\u003ct\u003e/issuers/\u003ci\u003e/clients/\u003cc\u003e/secrets/\u003ccs\u003e`. Note: the `hash`/`salt`\nfields are write-once at create time and are not returned on list/get; the\nservice masks them in protobuf responses.",
                "properties": {
                    "expiresAt": {
                        "description": "expires_at is optional; nil means the secret never expires.\n\n@gotags: yaml:\"expires_at,omitempty\"",
                        "format": "date-time",
                        "type": "string"
                    },
                    "hashEnabled": {
                        "title": "@gotags: yaml:\"hash_enabled\"",
                        "type": "boolean"
                    },
                    "name": {
                        "description": "Output only. The resource name, rendered from the row's id: the address\nused to GET, PATCH and DELETE this row, not a label. A value sent on\ncreate or update is ignored — the server always builds it from the id.",
                        "readOnly": true,
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.ClientStatus": {
                "default": "CLIENT_STATUS_UNSPECIFIED",
                "description": "ClientStatus is the client's standing (kit#404). DISABLED and QUARANTINED\nboth refuse the token endpoint with invalid_client, and introspection\nanswers their tokens inactive. QUARANTINED is the kill switch: kit#428\nadds revoking every live token of the client.",
                "enum": [
                    "CLIENT_STATUS_UNSPECIFIED",
                    "CLIENT_STATUS_ACTIVE",
                    "CLIENT_STATUS_DISABLED",
                    "CLIENT_STATUS_QUARANTINED"
                ],
                "type": "string"
            },
            "authwise.types.core.v1alpha1.CorsConfig": {
                "properties": {
                    "allowedOrigins": {
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    },
                    "allowedOriginsRegexp": {
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.Domain": {
                "properties": {
                    "config": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.DomainConfig"
                    },
                    "labels": {
                        "additionalProperties": {
                            "type": "string"
                        },
                        "type": "object"
                    },
                    "name": {
                        "description": "The resource name, which for this resource is also its KEY. Unlike every\nother resource in this file it is client-supplied and REQUIRED on create:\nthere is no generated id for the server to render a name from, so the\ncreate service reads this field and uses it as the row's key. It is\nignored on update — renaming is not an operation.\n\nThis comment must never contain the phrase protoc-gen-openapiv2 keys\nreadOnly off — it matches the words wherever they appear, not only at\nthe start, so even quoting them here to say \"not that\" marked all four\nof these fields read-only and would have broken every create. Making\nthe surface uniform means giving create a separate client-specified id\nfield (AIP-133); it is a change to the create surface, not a comment.",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.DomainConfig": {
                "description": "DomainConfig is empty. cookie_domain was its only field (see the note\nabove TenantConfig). The message and Domain.config stay so the domain\nresource keeps its shape and a later domain-scoped setting has somewhere to\nland without a second wire break.",
                "type": "object"
            },
            "authwise.types.core.v1alpha1.ENDPOINT_TYPE": {
                "default": "REST",
                "enum": [
                    "REST",
                    "GRPC"
                ],
                "type": "string"
            },
            "authwise.types.core.v1alpha1.Endpoint": {
                "properties": {
                    "address": {
                        "description": "GRPC: host:port, or a dns:///host:port target. REST: an absolute\nhttp(s):// URL, the base a consumer appends its path to. A loopback,\nlink-local, private or unique-local destination is refused unless the\ninstall's integration.allowPrivateAddresses is on.",
                        "type": "string"
                    },
                    "auth": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.EndpointAuth"
                    },
                    "displayName": {
                        "type": "string"
                    },
                    "endpointType": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.ENDPOINT_TYPE"
                    },
                    "insecure": {
                        "description": "Plaintext: no TLS at all. GRPC only — a REST address says it in its\nscheme, so insecure on a REST row is refused. Not \"skip verification\":\nthat is tls.insecure_skip_verify.",
                        "type": "boolean"
                    },
                    "labels": {
                        "additionalProperties": {
                            "type": "string"
                        },
                        "type": "object"
                    },
                    "name": {
                        "description": "Output only. The resource name, rendered from the row's id: the address\nused to GET, PATCH and DELETE this row, not a label. A value sent on\ncreate or update is ignored — the server always builds it from the id.\nFor a human-readable label, use display_name.",
                        "readOnly": true,
                        "type": "string"
                    },
                    "timeout": {
                        "description": "The per-call deadline when the caller sets none; unset means the\ninstall's integration.defaultTimeoutMs (5 s). A consumer with a bound of\nits own keeps it — the risk policy's timeout, for one. 100 ms to 60 s.",
                        "type": "string"
                    },
                    "tls": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.EndpointTls"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.EndpointAuth": {
                "description": "EndpointAuth is the credential kit presents on every call to an Endpoint.\nIt is resolved at call time, so rotating the secret (AddSecretVersion)\ntakes effect without touching the endpoint.",
                "properties": {
                    "basic": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.EndpointAuthBasic"
                    },
                    "bearer": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.EndpointAuthBearer"
                    },
                    "header": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.EndpointAuthHeader"
                    },
                    "kitToken": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.EndpointAuthKitToken"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.EndpointAuthBasic": {
                "description": "EndpointAuthBasic sends `authorization: Basic base64(username:password)`.",
                "properties": {
                    "password": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.SecretRef"
                    },
                    "username": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.EndpointAuthBearer": {
                "description": "EndpointAuthBearer sends `authorization: Bearer \u003ctoken\u003e`.",
                "properties": {
                    "token": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.SecretRef"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.EndpointAuthHeader": {
                "description": "EndpointAuthHeader sends `\u003cname\u003e: \u003cvalue\u003e` — an API-key header.",
                "properties": {
                    "name": {
                        "description": "The header name, lower-cased on the wire (gRPC metadata keys are).",
                        "type": "string"
                    },
                    "value": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.SecretRef"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.EndpointAuthKitToken": {
                "description": "EndpointAuthKitToken sends `authorization: Bearer \u003ctoken\u003e`, where the\ntoken is an access token kit signs from the named issuer for each call\n(cached until 30 s before it expires): `iss` the issuer, `aud` the\naudience below, `sub: authwise-internal`, five minutes. The endpoint\nverifies it against the issuer's JWKS. No secret is stored anywhere\n(kit#603).",
                "properties": {
                    "audience": {
                        "description": "The `aud` claim. Required.",
                        "type": "string"
                    },
                    "issuer": {
                        "description": "tenants/{tenant}/issuers/{issuer}, of this tenant.",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.EndpointTls": {
                "description": "EndpointTls is the TLS side of an Endpoint (kit#603).",
                "properties": {
                    "caPem": {
                        "description": "Extra trust anchors, a PEM bundle of one or more certificates, added to\nthe system roots. Public material, so it is stored and returned as is.",
                        "type": "string"
                    },
                    "clientCertificate": {
                        "description": "tenants/{tenant}/certificates/{certificate}: a Certificate of this\ntenant holding a private key, presented as kit's client certificate\n(mTLS).",
                        "type": "string"
                    },
                    "insecureSkipVerify": {
                        "description": "Development only: accept any certificate the endpoint presents. The\nconnection is still encrypted and still authenticated to nobody.",
                        "type": "boolean"
                    },
                    "serverName": {
                        "description": "The name verified, and sent as SNI, when it is not the address's host:\nan IP address, or an internal alias the certificate does not carry.",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.EnrollmentPolicy": {
                "properties": {
                    "grace": {
                        "description": "A bounded \"skip for now\" window. 0 means no skip, which is the default.",
                        "type": "string"
                    },
                    "inFlow": {
                        "description": "Whether a person may enrol a factor inside the login flow when a rule\ndemands one they lack. Default TRUE — refusing instead strands every\nuser the day a realm turns MFA on.\n\nA bool with a true default cannot express \"explicitly off\" in proto3, so\nthe resolver reads the absence of the whole EnrollmentPolicy message as\nthe default and a present message at face value.",
                        "type": "boolean"
                    },
                    "offerRecoveryCodes": {
                        "description": "Whether recovery codes are offered after the first factor is enrolled.",
                        "type": "boolean"
                    },
                    "selfServiceTypes": {
                        "description": "Types a person may add from the account page. Empty means every factor\nenabled on the realm.",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.Event": {
                "description": "Event is one audit row (docswip/EVENTS.md §3, kit#524).\n\nREMOVED in kit#525: start_state (11), end_state (12), start_time (13) and\nend_time (14). They were span bookkeeping: end_state carried\nSuccess|Error|Redirect for the one span event and Recorded|Error for\neverything else, which meant a policy refusal and a crashed request both\nread as \"Error\" and no consumer could tell them apart. outcome and\nseverity replace them as their own dimensions, and occurred_at replaces\nthe timestamp pair (duration_ms carries the span where there is one).\n\nThe numbers and the JSON names are both reserved. A stored row that still\ncarries \"startState\" is read back through protojson with DiscardUnknown,\nso the key is dropped rather than failing the parse — reserving the NAME\nas well is what stops a future field from silently inheriting the old\nkey's meaning.",
                "properties": {
                    "actorId": {
                        "title": "@gotags: yaml:\"actor_id\"",
                        "type": "string"
                    },
                    "actorType": {
                        "description": "Who performed the action, as distinct from who the row is about: on a\nlogin they are the same person, on \"admin A disabled user U\" they are\nnot. One of user, client, operator, system, anonymous.\n\n@gotags: yaml:\"actor_type\"",
                        "type": "string"
                    },
                    "attributes": {
                        "type": "object"
                    },
                    "audienceId": {
                        "title": "@gotags: yaml:\"audience_id\"",
                        "type": "string"
                    },
                    "category": {
                        "description": "The catalog heading: authn, session, authz, token, consent, account,\nchange, tenancy, access, security, messaging, system.",
                        "type": "string"
                    },
                    "clientId": {
                        "title": "@gotags: yaml:\"client_id\"",
                        "type": "string"
                    },
                    "createdAt": {
                        "format": "date-time",
                        "title": "@gotags: yaml:\"created_at\"",
                        "type": "string"
                    },
                    "durationMs": {
                        "description": "Set only on the few spans — an authorize transaction, a token grant.\n\n@gotags: yaml:\"duration_ms\"",
                        "format": "int32",
                        "type": "integer"
                    },
                    "eventMessage": {
                        "title": "@gotags: yaml:\"event_message\"",
                        "type": "string"
                    },
                    "eventType": {
                        "title": "@gotags: yaml:\"event_type\"",
                        "type": "string"
                    },
                    "interactionId": {
                        "title": "@gotags: yaml:\"interaction_id\"",
                        "type": "string"
                    },
                    "issuerId": {
                        "title": "@gotags: yaml:\"issuer_id\"",
                        "type": "string"
                    },
                    "name": {
                        "description": "Output only. The resource name, rendered from the row's id: the address\nused to GET, PATCH and DELETE this row, not a label. A value sent on\ncreate or update is ignored — the server always builds it from the id.",
                        "readOnly": true,
                        "type": "string"
                    },
                    "occurredAt": {
                        "description": "When the fact happened. created_at is when the row was written.\n\n@gotags: yaml:\"occurred_at\"",
                        "format": "date-time",
                        "type": "string"
                    },
                    "outcome": {
                        "description": "One of success, failure, denied, error. failure is bad input, denied is\na policy decision, error is ours.",
                        "type": "string"
                    },
                    "realmId": {
                        "title": "@gotags: yaml:\"realm_id\"",
                        "type": "string"
                    },
                    "reason": {
                        "description": "A code from the closed list, empty on success. Never an error string.",
                        "type": "string"
                    },
                    "requestId": {
                        "title": "@gotags: yaml:\"request_id\"",
                        "type": "string"
                    },
                    "schemaVersion": {
                        "description": "The stream consumer's contract (kit#122).\n\n@gotags: yaml:\"schema_version\"",
                        "format": "int32",
                        "type": "integer"
                    },
                    "sessionId": {
                        "description": "The sha256 hash of the session id, not the identifier itself.\n\n@gotags: yaml:\"session_id\"",
                        "type": "string"
                    },
                    "severity": {
                        "description": "One of info, notice, warning, critical.",
                        "type": "string"
                    },
                    "sourceIp": {
                        "title": "@gotags: yaml:\"source_ip\"",
                        "type": "string"
                    },
                    "targetId": {
                        "title": "@gotags: yaml:\"target_id\"",
                        "type": "string"
                    },
                    "targetType": {
                        "description": "What was written, on a change event. target_id is a plain string\nbecause not every entity is id-keyed — a Scope and an AccessRole are\naddressed by name.\n\n@gotags: yaml:\"target_type\"",
                        "type": "string"
                    },
                    "userId": {
                        "title": "@gotags: yaml:\"user_id\"",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.ExternalProviderSelector": {
                "properties": {
                    "endpointName": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.Factor": {
                "description": "Factor is a second-step method this realm OFFERS\n(docswip/AUTHENTICATION.md D2). A sibling of Provider, with the same\nadmin CRUD and the same static YAML shape, because it answers the sibling\nquestion: a Provider is how a person establishes who they are, a Factor is\nhow they confirm it.",
                "properties": {
                    "config": {
                        "$ref": "#/components/schemas/google.protobuf.Any"
                    },
                    "displayName": {
                        "type": "string"
                    },
                    "factorType": {
                        "description": "The type slug: totp, webauthn, otp-email, otp-sms, recovery-code, duo,\nexternal. Rules reference types and never ids — a rule naming a row\nwould break the moment an operator recreated it.\n\n@gotags: yaml:\"factor_type\"",
                        "type": "string"
                    },
                    "labels": {
                        "additionalProperties": {
                            "type": "string"
                        },
                        "type": "object"
                    },
                    "name": {
                        "description": "Output only. The resource name, rendered from the row's id: the address\nused to GET, PATCH and DELETE this row, not a label. A value sent on\ncreate or update is ignored — the server always builds it from the id.\nFor a human-readable label, use display_name.",
                        "readOnly": true,
                        "type": "string"
                    },
                    "status": {
                        "description": "active or disabled. Disabling is not deleting: the authenticators people\nenrolled against this row survive, so turning a method back on does not\nmake everyone re-enrol.",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.FactorDuo": {
                "description": "FactorWebAuthn configures the WebAuthn factor, `webauthn` (kit#195,\ndocswip/AUTHENTICATION.md §5.4) — and, because the credentials are the same\nrows, the passkey primary provider too: ProviderPasskey reads its relying\nparty from the realm's webauthn Factor.\nFactorDuo is Duo Universal Prompt as a second step (kit#542,\ndocswip/AUTHENTICATION.md §5.6). Duo owns enrolment: a person with no Duo\nenrolment is handled by Duo's own prompt.",
                "properties": {
                    "apiHost": {
                        "description": "The API hostname Duo assigned, e.g. api-XXXXXXXX.duosecurity.com.",
                        "type": "string"
                    },
                    "clientId": {
                        "description": "The Duo application's client id.",
                        "type": "string"
                    },
                    "clientSecretRef": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.SecretRef"
                    },
                    "failmode": {
                        "description": "What an unreachable Duo does to the step: closed (the default) fails it;\nopen lets the person through with no factor asserted, recorded as\nauthn.factor success reason=upstream_bypass at warning.",
                        "type": "string"
                    },
                    "usernameAttribute": {
                        "description": "Which of the person's attributes is their Duo username:\npreferred_username (the default) or email.",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.FactorExternal": {
                "description": "FactorExternal is an operator's own factor behind an Endpoint that serves\nAuthwiseFactorService (kit#542, docswip/AUTHENTICATION.md §5.7).",
                "properties": {
                    "config": {
                        "description": "Handed to the endpoint verbatim on every call.",
                        "type": "object"
                    },
                    "endpointName": {
                        "description": "tenants/{t}/endpoints/{e}. The endpoint's own auth (kit#373) is what the\nfactor service knows kit by.",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.FactorTOTP": {
                "description": "FactorTOTP configures RFC 6238 authenticator apps (kit#193,\ndocswip/AUTHENTICATION.md §5.2).\n\nEvery field is optional and zero means \"the interoperable default\", not\n\"strict\". proto3 cannot tell an unset int32 from a zero one, so a realm\nthat wrote nothing would otherwise get six-digit codes over a zero-second\nperiod in a zero-step window — a factor that can never verify. The\ndefaults live in pkg/lib/otp.",
                "properties": {
                    "algorithm": {
                        "description": "SHA1, SHA256 or SHA512. Default SHA1, deliberately: Google Authenticator\nand Authy IGNORE the algorithm parameter in an otpauth:// URI, so a realm\nthat configured SHA-256 would hand those apps a secret they derive codes\nfrom differently, and every code would be wrong with nothing to say why.",
                        "type": "string"
                    },
                    "digits": {
                        "description": "Code length. Default 6, which is what every authenticator app shows.",
                        "format": "int32",
                        "type": "integer"
                    },
                    "issuerLabel": {
                        "description": "What the authenticator app shows above the account. Default the issuer's\ndisplay name — it is how somebody with three Authwise-hosted logins tells\nthem apart.",
                        "type": "string"
                    },
                    "period": {
                        "description": "Step length in seconds. Default 30.",
                        "format": "int32",
                        "type": "integer"
                    },
                    "skew": {
                        "description": "How many steps either side of the current one are accepted. Default 1,\nRFC 6238's own suggestion, which covers a phone whose clock has drifted\nand a person who typed slowly.",
                        "format": "int32",
                        "type": "integer"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.FactorThrottle": {
                "properties": {
                    "otpAttempts": {
                        "format": "int32",
                        "type": "integer"
                    },
                    "pushesPerInteraction": {
                        "format": "int32",
                        "type": "integer"
                    },
                    "recoveryAttemptsPerHour": {
                        "format": "int32",
                        "type": "integer"
                    },
                    "sendsPerHour": {
                        "format": "int32",
                        "type": "integer"
                    },
                    "totpAttemptsPerWindow": {
                        "format": "int32",
                        "type": "integer"
                    },
                    "totpWindow": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.FactorWebAuthn": {
                "properties": {
                    "allowedOrigins": {
                        "description": "The origins a ceremony may come from, beyond the issuer's own (which is\nalways allowed): the external_ui_url when the login UI is served from\nelsewhere. Each must be the rp_id or a subdomain of it unless the rp_id\nhost serves WebAuthn L3 related origins (/.well-known/webauthn).",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    },
                    "attestation": {
                        "description": "none | indirect | direct | enterprise. Default none: consumer passkeys\ncarry no attestation, so a public surface cannot demand it.",
                        "type": "string"
                    },
                    "authenticatorAttachment": {
                        "description": "platform | cross-platform, or empty for either.",
                        "type": "string"
                    },
                    "hints": {
                        "description": "L3 hints, passed through: security-key | client-device | hybrid.",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    },
                    "residentKey": {
                        "description": "required | preferred | discouraged. Default preferred, so a credential\nenrolled as a factor can later sign in as a passkey.",
                        "type": "string"
                    },
                    "rpDisplayName": {
                        "description": "What the browser's passkey sheet names. Default the issuer's host.",
                        "type": "string"
                    },
                    "rpId": {
                        "description": "The relying party id every credential is scoped to. Default the issuer's\nhost. CHANGING IT ORPHANS EVERY CREDENTIAL enrolled under the old one —\nthe browser will not offer them to a different rp_id — which is why a\nrealm sets it once, before anybody enrols.",
                        "type": "string"
                    },
                    "userVerification": {
                        "description": "required | preferred | discouraged. Default preferred. A realm that\nwants a passkey to count as two kinds of proof alone sets required.",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.Group": {
                "description": "Group is a named set of users inside a realm, and a principal both\nauthorization schemes can target (kit#351). Membership is a sub-resource of\nthe group: AssociateUsersToGroup is the only write, and ListUsersByGroup /\nListGroupsByUser are the two reads. There are no nested groups.\n\ndisplay_name carries no uniqueness constraint — two teams may both call a\ngroup \"Contractors\" and the resource name is the identity. That matches\nSCIM's Group, which this shape is meant to map onto (kit#192).",
                "properties": {
                    "createdAt": {
                        "description": "Output only. Set by the server; a value sent on create or update is\nignored rather than refused, because the row's own timestamps are not a\nthing a client can assert.\n\n@gotags: yaml:\"created_at\"",
                        "format": "date-time",
                        "readOnly": true,
                        "type": "string"
                    },
                    "description": {
                        "type": "string"
                    },
                    "displayName": {
                        "title": "@gotags: yaml:\"display_name\"",
                        "type": "string"
                    },
                    "labels": {
                        "additionalProperties": {
                            "type": "string"
                        },
                        "type": "object"
                    },
                    "name": {
                        "description": "Output only. The resource name, rendered from the row's id: the address\nused to GET, PATCH and DELETE this row, not a label. A value sent on\ncreate or update is ignored — the server always builds it from the id.\nFor a human-readable label, use display_name.",
                        "readOnly": true,
                        "type": "string"
                    },
                    "updatedAt": {
                        "description": "Output only. The phrase is repeated verbatim rather than shared with\ncreated_at above, because the marker is per-field: a note one field up,\nor the same words with a comma after \"only\", produces a schema where\nhalf the pair is read-only and the console's form generator believes it.\n\nCorrected after measuring it: the generator matches the phrase ANYWHERE\nin the field's comment, not only at the start, so a comment MENTIONING\nit marks the field. See guide/GENERATED_CODE.md — that is a live trap,\nnot trivia.\n\n@gotags: yaml:\"updated_at\"",
                        "format": "date-time",
                        "readOnly": true,
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.HISTOGRAM_INTERVAL_UNIT": {
                "default": "HIU_AUTO",
                "description": "HISTOGRAM_INTERVAL_UNIT names the calendar/duration unit for a\nSearchHistogram bucketing. HIU_AUTO defers the choice to the server,\nwhich picks the smallest unit that yields ~30-100 buckets across the\nrequested [min, max] window.",
                "enum": [
                    "HIU_AUTO",
                    "HIU_MINUTE",
                    "HIU_HOUR",
                    "HIU_DAY",
                    "HIU_WEEK",
                    "HIU_MONTH"
                ],
                "type": "string"
            },
            "authwise.types.core.v1alpha1.HistogramBucket": {
                "description": "HistogramBucket is a single time-slice count.",
                "properties": {
                    "count": {
                        "format": "int64",
                        "type": "string"
                    },
                    "key": {
                        "format": "date-time",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.HistogramInterval": {
                "description": "HistogramInterval is the bucket-width spec. step is meaningful for\nHIU_MINUTE and HIU_HOUR (e.g. step=5 with HIU_MINUTE = 5-minute\nfixed-width buckets); it is ignored for HIU_DAY, HIU_WEEK, HIU_MONTH,\nand HIU_AUTO. A step of 0 is treated as 1.",
                "properties": {
                    "step": {
                        "format": "int32",
                        "type": "integer"
                    },
                    "unit": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.HISTOGRAM_INTERVAL_UNIT"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.HistogramResult": {
                "description": "HistogramResult is the response payload for a SearchHistogram query.\nresolved_interval echoes the unit/step the server actually used; when\nthe caller asked for HIU_AUTO this is the unit the server picked, so\nthe client can label buckets without re-running the resolver.",
                "properties": {
                    "buckets": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.HistogramBucket"
                        },
                        "type": "array"
                    },
                    "resolvedInterval": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.HistogramInterval"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.HistogramSpec": {
                "description": "HistogramSpec is the request payload for a date-histogram aggregation\non a SearchHistogram endpoint. min and max bound the window inclusively;\nthe response includes one bucket per interval slice across [min, max],\nincluding empty buckets at the edges.",
                "properties": {
                    "interval": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.HistogramInterval"
                    },
                    "max": {
                        "format": "date-time",
                        "type": "string"
                    },
                    "min": {
                        "format": "date-time",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.IdentifierField": {
                "description": "IdentifierField is the one field the identifier screen asks for.",
                "properties": {
                    "kind": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.IdentifierField.Kind"
                    },
                    "label": {
                        "description": "The field's label. Empty: \"E-mail address\" or \"Username\" by kind.",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.IdentifierField.Kind": {
                "default": "KIND_UNSPECIFIED",
                "description": " - KIND_UNSPECIFIED: Read as EMAIL.\n - EMAIL: autocomplete=email; the value must hold an '@'.\n - USERNAME: autocomplete=username. A username has no domain, so a selector of\nthis kind may not carry a domain rule.\n - ANY: Either.",
                "enum": [
                    "KIND_UNSPECIFIED",
                    "EMAIL",
                    "USERNAME",
                    "ANY"
                ],
                "type": "string"
            },
            "authwise.types.core.v1alpha1.IntegrationConfig": {
                "properties": {
                    "endpointName": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.InteractiveClientConfig": {
                "properties": {
                    "accessTokenExpireSeconds": {
                        "format": "int32",
                        "type": "integer"
                    },
                    "allowedRedirectUris": {
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    },
                    "cors": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.CorsConfig"
                    },
                    "flowIntegrationConfig": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.IntegrationConfig"
                    },
                    "interactionForwardUri": {
                        "type": "string"
                    },
                    "refreshTokenAbsoluteExpireSeconds": {
                        "format": "int32",
                        "type": "integer"
                    },
                    "refreshTokenExpireSeconds": {
                        "description": "refresh_token_expire_seconds is the IDLE lifetime of a refresh token: it\nslides forward on every rotation, so a client that keeps refreshing keeps\nits family alive. refresh_token_absolute_expire_seconds is the hard cap on\nthe family, set once when it is created and never extended — it is what\nbounds a stolen-and-silently-rotated token.\n\nZero means \"not set here\"; the value is resolved through\nGetCombinedConfig in the same tenant -\u003e issuer -\u003e audience -\u003e client order\nas access_token_expire_seconds, and falls back to\nkeys.DefaultRefreshTokenExpireSeconds / ...AbsoluteExpireSeconds when no\nlayer sets it (kit#476).",
                        "format": "int32",
                        "type": "integer"
                    },
                    "requireConsent": {
                        "description": "require_consent makes /authorize ask the end user to approve this\nclient for the scopes it requests, before a grant is built (kit#478).\n\nDefault false, and deliberately client-level only: consent is about\none relying party asking one person for access, so there is no\ntenant or issuer layer to inherit it from. A first-party console is\nthe client the person is already signing in to, and prompting there\nasks them to approve the thing they just opened.\n\n`prompt=consent` prompts regardless of this flag — that is what the\nvalue means — so this is the floor, not the switch.",
                        "type": "boolean"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.Issuer": {
                "properties": {
                    "config": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.IssuerConfig"
                    },
                    "domainName": {
                        "type": "string"
                    },
                    "labels": {
                        "additionalProperties": {
                            "type": "string"
                        },
                        "type": "object"
                    },
                    "name": {
                        "description": "Output only. The resource name, rendered from the row's id: the address\nused to GET, PATCH and DELETE this row, not a label. A value sent on\ncreate or update is ignored — the server always builds it from the id.",
                        "readOnly": true,
                        "type": "string"
                    },
                    "path": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.IssuerConfig": {
                "properties": {
                    "accessTokenExpireSeconds": {
                        "format": "int32",
                        "type": "integer"
                    },
                    "accountClientId": {
                        "description": "account_client_id names this issuer's account-page client (kit#543,\ndocswip/AUTHENTICATION.md §10.2): the public PKCE client the\naccount page ({issuer_ui}account/) signs in with. The account API accepts only\ntokens minted for it — a token another relying party holds for the\nsame person must not manage their authenticators — and\n`GET /api/v1/account/client` hands it to the page. Empty: this issuer\nhas no account page, and the account API refuses every token.",
                        "type": "string"
                    },
                    "cors": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.CorsConfig"
                    },
                    "externalProviderSelector": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.ExternalProviderSelector"
                    },
                    "externalUiUrl": {
                        "type": "string"
                    },
                    "flowIntegrationConfig": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.IntegrationConfig"
                    },
                    "multiRealmProviderSelector": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.MultiRealmProviderSelector"
                    },
                    "refreshTokenAbsoluteExpireSeconds": {
                        "format": "int32",
                        "type": "integer"
                    },
                    "refreshTokenExpireSeconds": {
                        "format": "int32",
                        "type": "integer"
                    },
                    "singleRealmProviderSelector": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.SingleRealmProviderSelector"
                    }
                },
                "title": "TODO - config split between this and issuer",
                "type": "object"
            },
            "authwise.types.core.v1alpha1.MessageDeliveryStatus": {
                "default": "MESSAGE_DELIVERY_STATUS_UNSPECIFIED",
                "description": "MessageDeliveryStatus reports what happened when kit asked the platform\nmessaging service to deliver a message it rendered (kit#344). Values 1-5\nmirror platform's MessagingStatus one for one; SKIPPED is kit's own and\nmeans no request was made at all — delivery is unconfigured\n(messaging.delivery: none) or the recipient is not addressable on the\nchannel.\n\nQUEUED is the most a synchronous send can promise: platform's Send returns\nafter one durable write, and the provider call happens later in its own\ndispatch loop, so a send that a provider ultimately refuses still reports\nQUEUED here with an empty reason and a populated message id. Never render\nQUEUED as delivered.\n\nOn the invitation path, a caller that receives anything but QUEUED or SENT\nstill holds the accept URL and passes it on itself, exactly as before\ndelivery existed. That sentence is scoped to invitations on purpose: this\nenum is also returned by SendTestMessage, where there is no accept URL and\nnothing for the caller to fall back to.\n\n - MESSAGE_DELIVERY_STATUS_QUEUED: Durably enqueued by platform, not yet handed to a provider.\n - MESSAGE_DELIVERY_STATUS_SENT: Accepted by the provider. Not a delivery receipt.\n - MESSAGE_DELIVERY_STATUS_FAILED: Platform could not be reached, or exhausted its retries.\n - MESSAGE_DELIVERY_STATUS_REJECTED: Refused before enqueue: no provider for the channel, malformed address.\n - MESSAGE_DELIVERY_STATUS_SUPPRESSED: Refused because the recipient is on platform's suppression list.\n - MESSAGE_DELIVERY_STATUS_SKIPPED: kit made no request: delivery is unconfigured or the recipient is not\nan e-mail address. The reason field on whichever response carried this\nstatus says which — spelled delivery_reason on InviteUserResponse and\nreason on SendTestMessageResponse. Both are named because this enum is\nshared by both paths and naming only the first sent a reader looking\nfor a delivery_reason that a test send does not have.",
                "enum": [
                    "MESSAGE_DELIVERY_STATUS_UNSPECIFIED",
                    "MESSAGE_DELIVERY_STATUS_QUEUED",
                    "MESSAGE_DELIVERY_STATUS_SENT",
                    "MESSAGE_DELIVERY_STATUS_FAILED",
                    "MESSAGE_DELIVERY_STATUS_REJECTED",
                    "MESSAGE_DELIVERY_STATUS_SUPPRESSED",
                    "MESSAGE_DELIVERY_STATUS_SKIPPED"
                ],
                "type": "string"
            },
            "authwise.types.core.v1alpha1.MessageTemplate": {
                "description": "MessageTemplate is a tenant's own copy of one transactional message, in\none channel and one locale. The catalog ships a default for every key;\na row here replaces it for this tenant only (MESSAGING.md Stage 1).\n\nThe three body fields are Go templates over the key's variable schema,\nwhich GET :messageKeys publishes — subject and text_body through\ntext/template, html_body through html/template with an allowlist over\nthe markup. An empty part falls back to the shipped default for that\npart, so a tenant may override only the subject.",
                "properties": {
                    "blocks": {
                        "description": "The layout editor's block document (MESSAGING.md Stage 2, kit#153),\nwhich for a block-authored copy is the source of truth: the console\ncompiles it to mjml and html_body in the browser and saves all three.\nAbsent for a copy written as text — the Stage 1 editor, or code mode —\nwhich a console keeps editing as text.",
                        "type": "object"
                    },
                    "channel": {
                        "description": "channel is \"email\" today. The only channel that renders.",
                        "type": "string"
                    },
                    "draft": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.MessageTemplateDraft"
                    },
                    "htmlBody": {
                        "title": "@gotags: yaml:\"html_body\"",
                        "type": "string"
                    },
                    "key": {
                        "description": "key names the message, e.g. \"tenant-invitation\". One of the keys\nListMessageKeys returns; anything else is refused at save.",
                        "type": "string"
                    },
                    "labels": {
                        "additionalProperties": {
                            "type": "string"
                        },
                        "type": "object"
                    },
                    "locale": {
                        "description": "locale is the BCP 47 tag this copy is written in. A tenant may write\na locale kit does not ship — that is reachable, and deliberate.",
                        "type": "string"
                    },
                    "mjml": {
                        "description": "The MJML html_body was compiled from. kit stores it and never compiles\nit; what reaches a recipient is html_body. Writing MJML with no blocks\nbeside it is code mode, which needs identity.messageTemplates.writeAdvanced.",
                        "type": "string"
                    },
                    "name": {
                        "description": "Output only. The resource name, rendered from the row's id: the address\nused to GET, PATCH and DELETE this row, not a label. A value sent on\ncreate or update is ignored — the server always builds it from the id.\nThis resource carries no label field: its identity is (key, channel, locale).\n\nIgnored here means discarded rather than refused, and that holds on the\nmasked PATCH path as well as the unmasked PUT one: merge does write a\ncaller's name onto the proto, but toModel drops it and the response\nre-derives it from the id. So a console that read this as a label and\nbound it to a \"name for your own reference\" input lost every edit\nsilently — which is what happened on this field while it was the one\nresource name in this file with no comment (kit-admin, 2026-09-07).\nData loss in the caller's form, not a rename anyone could perform. It is\nalso why there is no display_name here to bind instead, as Theme and\nAppearanceProfile have: a copy has nothing a label would distinguish.",
                        "readOnly": true,
                        "type": "string"
                    },
                    "publishedAt": {
                        "description": "Output only. When this copy was last published with :publish. Absent\nfor a copy written as text, whose parts are live on save.\n\n@gotags: yaml:\"published_at\"",
                        "format": "date-time",
                        "readOnly": true,
                        "type": "string"
                    },
                    "publishedBy": {
                        "description": "Output only. Who published it.\n\n@gotags: yaml:\"published_by\"",
                        "readOnly": true,
                        "type": "string"
                    },
                    "subject": {
                        "type": "string"
                    },
                    "textBody": {
                        "title": "@gotags: yaml:\"text_body\"",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.MessageTemplateDraft": {
                "description": "MessageTemplateDraft is a message template's unpublished content: the same\nparts the template carries live (kit#153). A draft may be incomplete; every\npart it does carry is validated as a published part is.",
                "properties": {
                    "blocks": {
                        "type": "object"
                    },
                    "htmlBody": {
                        "title": "@gotags: yaml:\"html_body\"",
                        "type": "string"
                    },
                    "mjml": {
                        "type": "string"
                    },
                    "subject": {
                        "type": "string"
                    },
                    "textBody": {
                        "title": "@gotags: yaml:\"text_body\"",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.MessageTemplateRevision": {
                "description": "MessageTemplateRevision is one :publish of a message template, as it was\npublished (kit#153). Revisions are kept newest first, the newest 50 per\ntemplate; :publish with a revision_id puts one back.",
                "properties": {
                    "blocks": {
                        "type": "object"
                    },
                    "htmlBody": {
                        "title": "@gotags: yaml:\"html_body\"",
                        "type": "string"
                    },
                    "mjml": {
                        "type": "string"
                    },
                    "name": {
                        "description": "Output only. tenants/{tenant}/message-templates/{template}/revisions/{revision}.\nThe last segment is the revision_id :publish takes.",
                        "readOnly": true,
                        "type": "string"
                    },
                    "publishedAt": {
                        "format": "date-time",
                        "title": "@gotags: yaml:\"published_at\"",
                        "type": "string"
                    },
                    "publishedBy": {
                        "title": "@gotags: yaml:\"published_by\"",
                        "type": "string"
                    },
                    "subject": {
                        "type": "string"
                    },
                    "textBody": {
                        "title": "@gotags: yaml:\"text_body\"",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.MultiRealmProviderSelector": {
                "description": "MultiRealmProviderSelector is identifier-first login with realm routing\n(kit#609, docswip/IDENTIFIER_FIRST.md §4.1): the login page asks for an\nidentifier, the rules pick a realm (and optionally one provider in it) from\nthe identifier's shape, and an identifier no rule matches goes to the\ndefault. Nothing is looked up to route; whether the account exists is\nlearned at the credential step.",
                "properties": {
                    "defaultTarget": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.RoutingTarget"
                    },
                    "identifier": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.IdentifierField"
                    },
                    "realmNames": {
                        "description": "The realms this issuer serves, as realm names\n(tenants/{t}/realms/{r}). Every rule target and the default must name\none of these. Invitations and SCIM admission read this list and\nnothing else.",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    },
                    "rules": {
                        "description": "Ordered; the first match wins. Admission refuses a rule no identifier\ncan reach.",
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.RoutingRule"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.OidcEndpoints": {
                "description": "OidcEndpoints overrides discovery, entry by entry.",
                "properties": {
                    "authorizationUrl": {
                        "type": "string"
                    },
                    "jwksUrl": {
                        "type": "string"
                    },
                    "tokenUrl": {
                        "type": "string"
                    },
                    "userinfoUrl": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.PasswordValidatorConfig": {
                "properties": {
                    "config": {
                        "type": "object"
                    },
                    "name": {
                        "type": "string"
                    },
                    "type": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.Provider": {
                "properties": {
                    "config": {
                        "$ref": "#/components/schemas/google.protobuf.Any"
                    },
                    "displayName": {
                        "type": "string"
                    },
                    "labels": {
                        "additionalProperties": {
                            "type": "string"
                        },
                        "type": "object"
                    },
                    "linkByVerifiedEmail": {
                        "description": "Offer to connect this provider to an existing account at login, when\nthe upstream states a verified e-mail that exactly one active account\nin the realm holds verified — confirmed by the person signing in to that\naccount with its password first, never silently\n(docswip/USER_IDENTIFIERS.md §5, kit#633). Default false: it is a trust\nin this upstream's email_verified, per relationship, as\ntrust_upstream_amr is. Only a federated type may carry it.\n\n@gotags: yaml:\"link_by_verified_email\"",
                        "type": "boolean"
                    },
                    "name": {
                        "description": "Output only. The resource name, rendered from the row's id: the address\nused to GET, PATCH and DELETE this row, not a label. A value sent on\ncreate or update is ignored — the server always builds it from the id.\nFor a human-readable label, use display_name.",
                        "readOnly": true,
                        "type": "string"
                    },
                    "providerType": {
                        "title": "@gotags: yaml:\"provider_type\"",
                        "type": "string"
                    },
                    "trustUpstreamAmr": {
                        "description": "Whether the `amr` this provider RELAYS from its upstream may be counted\nas evidence (kit#540, D19).\n\nDefault false, and the default is the security position. A federated\nprimary proves ONE class whatever its assertion said, because kit\nverified a signature and not a factor — and a partner IdP that claims\n`mfa` is claiming something kit has no way to check. With the flag the\nrelayed RFC 8176 values are mapped through the §5.1 class table (`mfa`\ncounts as two classes, `hwk`/`swk` as phishing-resistant), so a B2B\nrealm whose partner already did MFA is not asked for a second factor\nagain.\n\nPer provider rather than per realm, which is what Okta's \"federated IdP\nsatisfies MFA\" and Entra's cross-tenant MFA trust both are: trust is in\nthe relationship with one identity provider, and a realm that federates\nto two has no reason to extend it to both.\n\n@gotags: yaml:\"trust_upstream_amr\"",
                        "type": "boolean"
                    },
                    "trustUpstreamEmailVerified": {
                        "description": "Count this upstream's email_verified as kit's own proof of the address\n(kit#663, docswip/USER_IDENTIFIERS.md §22). Default false: an upstream's\nemail_verified is an assertion about its own records, kept on the link\nand read only by the login-time link offer; it never makes the address\na password-recovery route. Set it for an identity provider that IS the\ndirectory of record (a Workplace IdP): each login that states the\naddress verified then records it as a proven channel address, which is\na recovery route. Per relationship, as trust_upstream_amr is; only a\nfederated type may carry it.\n\n@gotags: yaml:\"trust_upstream_email_verified\"",
                        "type": "boolean"
                    },
                    "upstreamAcrMap": {
                        "additionalProperties": {
                            "type": "string"
                        },
                        "description": "Maps an upstream `acr` value to one of this realm's acr level names,\nfor identity providers that assert a context class rather than methods.\nConsulted only when trust_upstream_amr is set, for the same reason.\n\n@gotags: yaml:\"upstream_acr_map\"",
                        "type": "object"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.ProviderApple": {
                "properties": {
                    "authorizationParams": {
                        "additionalProperties": {
                            "type": "string"
                        },
                        "type": "object"
                    },
                    "claimMap": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.ClaimMap"
                    },
                    "clientId": {
                        "description": "The Services ID.",
                        "type": "string"
                    },
                    "identifierClaim": {
                        "description": "Default: sub.",
                        "type": "string"
                    },
                    "keyId": {
                        "type": "string"
                    },
                    "privateKeyRef": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.SecretRef"
                    },
                    "scopes": {
                        "description": "Default: name email.",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    },
                    "teamId": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.ProviderAuth0": {
                "properties": {
                    "authorizationParams": {
                        "additionalProperties": {
                            "type": "string"
                        },
                        "type": "object"
                    },
                    "claimMap": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.ClaimMap"
                    },
                    "clientId": {
                        "type": "string"
                    },
                    "clientSecretRef": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.SecretRef"
                    },
                    "identifierClaim": {
                        "description": "Default: sub.",
                        "type": "string"
                    },
                    "issuer": {
                        "title": "e.g. https://{tenant}.auth0.com/",
                        "type": "string"
                    },
                    "scopes": {
                        "description": "Default: openid profile email.",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.ProviderAuthwise": {
                "properties": {
                    "clientId": {
                        "type": "string"
                    },
                    "internalIssuer": {
                        "title": "In case you need to get the token from a different server side address",
                        "type": "string"
                    },
                    "issuer": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.ProviderFacebook": {
                "properties": {
                    "authorizationParams": {
                        "additionalProperties": {
                            "type": "string"
                        },
                        "title": "display, auth_type…",
                        "type": "object"
                    },
                    "claimMap": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.ClaimMap"
                    },
                    "clientId": {
                        "description": "The App ID.",
                        "type": "string"
                    },
                    "clientSecretRef": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.SecretRef"
                    },
                    "fields": {
                        "description": "Graph `fields` for /me: what claim_map can see. Default:\nid,name,first_name,last_name,email,picture.",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    },
                    "graphVersion": {
                        "description": "Default: the Graph API version the flavor pins.",
                        "type": "string"
                    },
                    "identifierClaim": {
                        "description": "Default: id, which Facebook scopes to the app.",
                        "type": "string"
                    },
                    "scopes": {
                        "description": "Default: email public_profile.",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.ProviderGitHub": {
                "properties": {
                    "authorizationParams": {
                        "additionalProperties": {
                            "type": "string"
                        },
                        "type": "object"
                    },
                    "baseUrl": {
                        "description": "GitHub Enterprise Server, e.g. https://ghes.example.com. Empty: github.com.\nGoverns the authorization, token and API hosts together.",
                        "type": "string"
                    },
                    "claimMap": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.ClaimMap"
                    },
                    "clientId": {
                        "type": "string"
                    },
                    "clientSecretRef": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.SecretRef"
                    },
                    "identifierClaim": {
                        "description": "Default: id, which is numeric and permanent; login can change.",
                        "type": "string"
                    },
                    "scopes": {
                        "description": "Default: read:user user:email.",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.ProviderGoogle": {
                "properties": {
                    "authorizationParams": {
                        "additionalProperties": {
                            "type": "string"
                        },
                        "type": "object"
                    },
                    "claimMap": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.ClaimMap"
                    },
                    "clientId": {
                        "type": "string"
                    },
                    "clientSecretRef": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.SecretRef"
                    },
                    "hostedDomains": {
                        "description": "Google Workspace domains whose accounts may sign in. Sent as the `hd`\nhint AND verified against the id_token's `hd` claim; a token without the\nclaim, or with another domain, is refused. Empty: any account.",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    },
                    "identifierClaim": {
                        "description": "Default: sub.",
                        "type": "string"
                    },
                    "scopes": {
                        "description": "Default: openid email profile.",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.ProviderLinkedIn": {
                "description": "LinkedIn's issuer (https://www.linkedin.com/oauth), client auth and PKCE\nsetting are fixed by the flavor, so a row is a client id and a secret.",
                "properties": {
                    "authorizationParams": {
                        "additionalProperties": {
                            "type": "string"
                        },
                        "type": "object"
                    },
                    "claimMap": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.ClaimMap"
                    },
                    "clientId": {
                        "type": "string"
                    },
                    "clientSecretRef": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.SecretRef"
                    },
                    "identifierClaim": {
                        "description": "Default: sub.",
                        "type": "string"
                    },
                    "scopes": {
                        "description": "Default: openid profile email.",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.ProviderMagicLink": {
                "description": "ProviderMagicLink configures the magic-link primary provider, `magicLink`\n(kit#194, docswip/AUTHENTICATION.md §8, D7): one mail carrying a link and a\nshort code, the link redeemable ONLY in the browser that asked for it, the\ncode typed into that same tab. Signup follows the realm's self_signup\nchannel, as the username/password provider's does; there is no per-provider\nflag for it.",
                "properties": {
                    "codeLength": {
                        "description": "Digits in the code, 6 to 8. Default 6: the attempt cap, not the length,\nis what makes a short code safe, and six is what a phone keyboard types.",
                        "format": "int32",
                        "type": "integer"
                    },
                    "identifierAttribute": {
                        "description": "The user attribute the identifier is matched against. Only \"email\" is\nsupported, and it is the default.",
                        "type": "string"
                    },
                    "mode": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.ProviderMagicLink.Mode"
                    },
                    "ttl": {
                        "description": "How long the link and the code live. Default 10 minutes, NIST's ceiling\nfor an out-of-band secret.",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.ProviderMagicLink.Mode": {
                "default": "MODE_UNSPECIFIED",
                "description": " - MODE_UNSPECIFIED: A link and a code in one mail. The default.\n - CODE_ONLY: The code alone — for a realm whose people read mail on one device and\nsign in on another, where a link could only ever say \"go back\".",
                "enum": [
                    "MODE_UNSPECIFIED",
                    "LINK_AND_CODE",
                    "CODE_ONLY"
                ],
                "type": "string"
            },
            "authwise.types.core.v1alpha1.ProviderMicrosoft": {
                "properties": {
                    "allowedTenants": {
                        "description": "With a multi-tenant `tenant`, the tenant ids (`tid`) that may sign in.\nVerified on the id_token. Empty: any tenant the authority admits.",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    },
                    "authorizationParams": {
                        "additionalProperties": {
                            "type": "string"
                        },
                        "title": "prompt, domain_hint, login_hint…",
                        "type": "object"
                    },
                    "claimMap": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.ClaimMap"
                    },
                    "clientId": {
                        "type": "string"
                    },
                    "clientSecretRef": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.SecretRef"
                    },
                    "identifierClaim": {
                        "description": "Default: sub, which Microsoft makes pairwise per application; oid is the\ndirectory-wide alternative.",
                        "type": "string"
                    },
                    "scopes": {
                        "description": "Default: openid email profile.",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    },
                    "tenant": {
                        "description": "common | organizations | consumers | a tenant id or verified domain.\nSelects the authority, and therefore who can sign in at all.",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.ProviderOAuth": {
                "description": "ProviderOAuth is OAuth 2.0 with no id_token: explicit endpoints, a userinfo\ndocument, and a claim map over it. X, Discord, Amazon, Twitch, Spotify and\nBitbucket are recipes on it rather than types.",
                "properties": {
                    "authorizationParams": {
                        "additionalProperties": {
                            "type": "string"
                        },
                        "type": "object"
                    },
                    "authorizationUrl": {
                        "type": "string"
                    },
                    "claimMap": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.ClaimMap"
                    },
                    "clientAuthMethod": {
                        "description": "client_secret_basic (default) | client_secret_post.",
                        "type": "string"
                    },
                    "clientId": {
                        "type": "string"
                    },
                    "clientSecretRef": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.SecretRef"
                    },
                    "identifierSource": {
                        "description": "Required: the userinfo path that is the stable subject, e.g. userinfo.id.",
                        "type": "string"
                    },
                    "pkce": {
                        "description": "auto | required | off; auto = S256.",
                        "type": "string"
                    },
                    "scopes": {
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    },
                    "tokenUrl": {
                        "type": "string"
                    },
                    "userinfoUrl": {
                        "description": "Fetched with the access token as a Bearer; the document claim_map reads.",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.ProviderOidc": {
                "description": "ProviderOidc is discovery-driven OpenID Connect: Okta, Auth0, Entra single\ntenant, Keycloak, Ping, OneLogin, Slack, GitLab, Salesforce, another kit.",
                "properties": {
                    "authorizationParams": {
                        "additionalProperties": {
                            "type": "string"
                        },
                        "type": "object"
                    },
                    "claimMap": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.ClaimMap"
                    },
                    "clientAuthMethod": {
                        "description": "client_secret_basic (default) | client_secret_post | none.\nprivate_key_jwt is a later addition; the field is a string so it can be.",
                        "type": "string"
                    },
                    "clientId": {
                        "type": "string"
                    },
                    "clientSecretRef": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.SecretRef"
                    },
                    "endpoints": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.OidcEndpoints"
                    },
                    "identifierClaim": {
                        "description": "Default: sub.",
                        "type": "string"
                    },
                    "internalBaseUrl": {
                        "description": "Server-to-server calls (discovery, token, JWKS, userinfo) are rewritten\nonto this base while `iss` is still checked against `issuer`: the\nin-cluster case ProviderAuthwise.internal_issuer solves.",
                        "type": "string"
                    },
                    "issuer": {
                        "description": "Discovery at {issuer}/.well-known/openid-configuration, and the exact\nvalue every id_token's `iss` must carry.",
                        "type": "string"
                    },
                    "pkce": {
                        "description": "auto (default: S256 when discovery advertises it) | required | off.",
                        "type": "string"
                    },
                    "scopes": {
                        "description": "Default: openid profile email.",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    },
                    "useUserinfo": {
                        "description": "Also call the userinfo endpoint and merge its claims under `claims.*`,\nthe id_token winning a conflict. Default false: most issuers put the\nprofile in the id_token.",
                        "type": "boolean"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.ProviderOkta": {
                "properties": {
                    "authorizationParams": {
                        "additionalProperties": {
                            "type": "string"
                        },
                        "type": "object"
                    },
                    "claimMap": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.ClaimMap"
                    },
                    "clientId": {
                        "type": "string"
                    },
                    "clientSecretRef": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.SecretRef"
                    },
                    "identifierClaim": {
                        "description": "Default: sub.",
                        "type": "string"
                    },
                    "issuer": {
                        "description": "The authorization server's issuer, e.g.\nhttps://{org}.okta.com/oauth2/default, or the org server.",
                        "type": "string"
                    },
                    "scopes": {
                        "description": "Default: openid profile email.",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.ProviderPasskey": {
                "description": "ProviderPasskey configures the passkey primary provider, `passkey`\n(kit#195, §5.4a). The relying party is the realm's webauthn Factor's — one\nset of credentials, one rp_id — so there is nothing here yet but room for\nthe provider's own settings. Its published schema is therefore an empty\nobject — deliberately, not a payload that failed to generate.",
                "type": "object"
            },
            "authwise.types.core.v1alpha1.ProviderSaml": {
                "description": "ProviderSaml configures the SP role: kit consuming assertions from an\nupstream SAML identity provider (kit#489).\n\nThe partner half (fields 1-6) is normally filled by importing their\nmetadata; the individual fields are the escape hatch for a partner who will\nnot publish one. The rest is what kit does with what arrives.\n\n--- The partner (the upstream IdP) ---",
                "properties": {
                    "acceptSha1": {
                        "description": "Accept SHA-1 signatures from this partner. Defaults false. Inbound only,\nper connection, and logged on every use.",
                        "type": "boolean"
                    },
                    "allowCreate": {
                        "type": "boolean"
                    },
                    "allowIdpInitiated": {
                        "description": "Accept an unsolicited Response — one with no InResponseTo, which\ntherefore correlates to no request we made. Defaults false: it removes\nthe replay and CSRF protection that correlation provides, and is only\nworth enabling for a partner whose portal is the intended entry point.",
                        "type": "boolean"
                    },
                    "claimMap": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.ClaimMap"
                    },
                    "clockSkewSeconds": {
                        "description": "Tolerance applied to NotBefore and NotOnOrAfter. Defaults to 120.",
                        "format": "int32",
                        "type": "integer"
                    },
                    "identifierSource": {
                        "description": "Which part of the assertion becomes the user's identifier. Defaults to\nassertion.name_id; a partner whose NameID is a transient opaque string\nwill want assertion.attributes.\u003csomething\u003e instead.",
                        "type": "string"
                    },
                    "idpEntityId": {
                        "description": "Expected Issuer on every assertion. An assertion from anyone else is\nrefused even if it is correctly signed by a certificate we trust.",
                        "type": "string"
                    },
                    "idpMetadataImportedAt": {
                        "description": "Output only.",
                        "format": "date-time",
                        "readOnly": true,
                        "type": "string"
                    },
                    "idpMetadataXml": {
                        "description": "The last metadata document imported, kept so a re-import can be diffed\nagainst it rather than applied blind.",
                        "type": "string"
                    },
                    "idpSigningCertificateId": {
                        "description": "Certificate resource name holding their signing certificate. Every\ninbound signature is checked against this one and nothing else: KeyInfo\nis never a source of trust.",
                        "type": "string"
                    },
                    "idpSsoBinding": {
                        "description": "The binding on their SingleSignOnService, which is how kit sends them an\nAuthnRequest. HTTP-Redirect (the default) or HTTP-POST. Read straight off\ntheir metadata; it describes their endpoint, not a choice we make.",
                        "type": "string"
                    },
                    "idpSsoUrl": {
                        "description": "Their SingleSignOnService location.",
                        "type": "string"
                    },
                    "nameIdFormat": {
                        "description": "Requested NameIDPolicy/@Format.",
                        "type": "string"
                    },
                    "signAuthnRequests": {
                        "type": "boolean"
                    },
                    "signingCertificateId": {
                        "description": "Certificate resource name kit signs AuthnRequests with, and decrypts\nencrypted assertions with. One field because the saml library addresses\na single key id for both; splitting it is authwise/saml#18.",
                        "type": "string"
                    },
                    "wantAssertionsSigned": {
                        "description": "Defaults true. Together with want_response_signed, at least one must be\nset: an SP that verifies nothing accepts assertions from anyone.",
                        "type": "boolean"
                    },
                    "wantResponseSigned": {
                        "type": "boolean"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.ProviderUsernamePassword": {
                "properties": {
                    "externalEndpointName": {
                        "type": "string"
                    },
                    "passwordValidators": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.PasswordValidatorConfig"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.ProvisioningPolicy": {
                "description": "ProvisioningPolicy governs which channels may create users in a realm.\n\nEvery channel defaults to false, so a realm carrying no policy accepts\nno new users through any channel while its existing users continue to\nauthenticate normally. The fail-closed default is the point: a realm has\nto say what it allows.\n\nChannels are composable, not exclusive — a realm may open self-signup and\ninvitations at the same time. Exclusivity, where an external system owns\nthe population, is expressed by the user's origin marker instead of by\ncollapsing these into an enum.\n\nFields are marked \"Reserved\" below when the surface they would gate does\nnot exist yet. A reserved field is NOT consulted at runtime: setting it\nchanges nothing. They are declared here so the message does not have to\nbe reshaped as those surfaces land.",
                "properties": {
                    "adminDirect": {
                        "description": "admin_direct allows an admin to establish a credential directly.\nReserved: no admin-direct credential surface exists yet.",
                        "type": "boolean"
                    },
                    "adminSetPermanentPassword": {
                        "description": "admin_set_permanent_password is a break-glass bit: without it, a\npassword an admin sets directly is temporary and must be changed at\nfirst login. Reserved: rides admin_direct.",
                        "type": "boolean"
                    },
                    "allowedProviderTypes": {
                        "description": "allowed_provider_types restricts which provider types may be used in\nthis realm. Reserved: awaits the per-realm provider policy surface.",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    },
                    "invitationTtl": {
                        "description": "invitation_ttl bounds how long an invitation token stays redeemable.\nEmpty means the invitation surface's own default applies.",
                        "type": "string"
                    },
                    "invitations": {
                        "description": "invitations allows an admin-created user to complete enrollment by\nredeeming a one-time token.",
                        "type": "boolean"
                    },
                    "jitFederated": {
                        "description": "jit_federated allows a user to be auto-provisioned on their first\nsuccessful federated login.",
                        "type": "boolean"
                    },
                    "passwordHashSpec": {
                        "type": "string"
                    },
                    "passwordValidators": {
                        "description": "password_validators and password_hash_spec move password policy from\nthe provider to the realm. Reserved: the provider-level fields remain\nauthoritative until that migration lands.",
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.PasswordValidatorConfig"
                        },
                        "type": "array"
                    },
                    "provisioningIntegrationConfig": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.IntegrationConfig"
                    },
                    "requireEmailVerification": {
                        "description": "require_email_verification withholds an active account until the\naddress is proven. Reserved: no verification surface exists yet.",
                        "type": "boolean"
                    },
                    "scim": {
                        "description": "scim allows an inbound SCIM client to create users.\nReserved: no SCIM channel exists yet.",
                        "type": "boolean"
                    },
                    "selfSignup": {
                        "description": "self_signup allows interactive signup on a local provider. It is the\nonly decision: the provider-level allow_signup flag it was ANDed with\nduring the kit#303 transition was retired by kit#332.",
                        "type": "boolean"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.Realm": {
                "properties": {
                    "config": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.RealmConfig"
                    },
                    "displayName": {
                        "type": "string"
                    },
                    "labels": {
                        "additionalProperties": {
                            "type": "string"
                        },
                        "type": "object"
                    },
                    "name": {
                        "description": "Output only. The resource name, rendered from the row's id: the address\nused to GET, PATCH and DELETE this row, not a label. A value sent on\ncreate or update is ignored — the server always builds it from the id.\nFor a human-readable label, use display_name.",
                        "readOnly": true,
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.RealmConfig": {
                "description": "RealmConfig is the realm's configuration blob, following the same\nentity-config convention as TenantConfig / IssuerConfig / AudienceConfig.",
                "properties": {
                    "authentication": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.AuthenticationPolicy"
                    },
                    "botProtection": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.BotProtection"
                    },
                    "defaultLocale": {
                        "description": "default_locale is the BCP 47 tag this realm writes to its people in\nwhen nothing better is known — the last signal pkg/lib/locale.Negotiate\nconsults before falling back to English (MESSAGING.md Stage 1, kit#165).\n\nIt sits on the realm rather than the tenant because a realm is the\npopulation being written to: one tenant can serve a French workforce\nrealm and an English customer realm, and a tenant-level default could\nonly be wrong for one of them.\n\nEmpty means \"no realm default\", which is not the same as \"English\" —\nnegotiation simply skips the signal, so a recipient's own stored locale\nstill wins over the fallback. Setting it to \"en\" is therefore a\ndifferent statement from leaving it blank, and only the first survives\na future change to the fallback.",
                        "type": "string"
                    },
                    "provisioning": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.ProvisioningPolicy"
                    },
                    "recovery": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.RecoveryPolicy"
                    },
                    "sms": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.SmsPolicy"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.RecoveryPolicy": {
                "description": "RecoveryPolicy is the realm's self-service password reset (kit#382).\n\nFail-closed like every provisioning bit: a realm with no recovery block,\nor one with self_service_reset false, offers no \"Forgot password?\" link\nand answers the public request with 403. An administrator's reset\n(ResetUserPassword, kit#388) does not read it: that is the\nadministrator's instrument, gated by permission instead.",
                "properties": {
                    "resetTtl": {
                        "description": "reset_ttl is how long a self-service reset link lives. Empty is one\nhour; admitted between five minutes and twenty-four hours. The request\ncannot choose it: an anonymous caller has no business picking a\nlifetime.",
                        "type": "string"
                    },
                    "selfServiceReset": {
                        "description": "self_service_reset allows POST /api/v1/recovery/request on the issuers\nserving this realm, and the redemption of the links it mints. Turning\nit off refuses a link already sent, which stays unconsumed.",
                        "type": "boolean"
                    },
                    "supportContact": {
                        "description": "support_contact is plain text the password-changed notice names as\nwhere to turn if the change was not the account holder's — an address,\na phone number, a URL written out. Never a link the mail renders as\none: the notice carries no link into any flow (§4.5).",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.RememberDevicePolicy": {
                "properties": {
                    "enabled": {
                        "type": "boolean"
                    },
                    "maxDevices": {
                        "format": "int32",
                        "type": "integer"
                    },
                    "ttl": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.Requirement": {
                "description": "Requirement is what must hold BEYOND the primary. The primary is what\nmakes an identity known at all, and `user-core` already decides its own\nfreshness from prompt and max_age; everything here is about the steps\nafter that.",
                "properties": {
                    "allowedFactorTypes": {
                        "description": "Types that may count. Empty means every factor enabled on the realm.",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    },
                    "denyReason": {
                        "description": "mode DENY only. Audit trail only, never shown to the person: a refusal\nthat explains itself to whoever triggered it is a probing oracle.",
                        "type": "string"
                    },
                    "hardwareBound": {
                        "description": "With PHISHING_RESISTANT, the `phrh` level: the authenticator must not be\nbackup-eligible, because NIST caps syncable authenticators at AAL2.",
                        "type": "boolean"
                    },
                    "minFactors": {
                        "description": "Distinct classes required beyond the primary's own. 0 means the mode's\ndefault, which for ANY_FACTOR is 1.",
                        "format": "int32",
                        "type": "integer"
                    },
                    "mode": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Requirement.Mode"
                    },
                    "reauthAfter": {
                        "description": "A factor verified longer ago than this does not count. 0 falls back to\nSessionPolicy.factor_reauth. Compared against the factor's own\nverification instant, not the session's login instant — a factor can be\nolder or newer than the primary.",
                        "type": "string"
                    },
                    "requiredFactorTypes": {
                        "description": "Types that must ALL be present (mode TYPES).",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    },
                    "skipIfDeviceTrusted": {
                        "description": "Whether a trusted device satisfies this requirement without a factor.\nNever honoured for PHISHING_RESISTANT or DENY, and never when the\nrequest demanded a fresh factor.",
                        "type": "boolean"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.Requirement.Mode": {
                "default": "NONE",
                "description": " - NONE: NONE — the primary alone is enough.\n - ANY_FACTOR: ANY_FACTOR — the distinct CLASSES proven must reach 1 + min_factors.\nClasses, not authenticators: a password and an e-mailed code are two\nsteps and one class each, and AAL2 wants two kinds of thing.\n - TYPES: TYPES — every type in required_factor_types must be present.\n - PHISHING_RESISTANT: PHISHING_RESISTANT — at least one counted factor must be\nphishing-resistant, which by construction means WebAuthn.\n - DENY: DENY — this login is refused. Never valid as a floor: a realm nobody\ncan log into is a misconfiguration, not a policy.",
                "enum": [
                    "NONE",
                    "ANY_FACTOR",
                    "TYPES",
                    "PHISHING_RESISTANT",
                    "DENY"
                ],
                "type": "string"
            },
            "authwise.types.core.v1alpha1.RiskPolicy": {
                "properties": {
                    "externalEndpointName": {
                        "description": "The Endpoint running AuthwiseRiskService, for EXTERNAL and BOTH.",
                        "type": "string"
                    },
                    "failMode": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.RiskPolicy.FailMode"
                    },
                    "highAt": {
                        "format": "int32",
                        "type": "integer"
                    },
                    "mediumAt": {
                        "format": "int32",
                        "type": "integer"
                    },
                    "mode": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.RiskPolicy.Mode"
                    },
                    "timeout": {
                        "description": "Default 500ms.",
                        "type": "string"
                    },
                    "timezone": {
                        "description": "IANA zone the hours are in, and what `time.hour` / `time.weekday` are\ncomputed in. Default UTC.",
                        "type": "string"
                    },
                    "weights": {
                        "additionalProperties": {
                            "format": "int32",
                            "type": "integer"
                        },
                        "description": "Builtin signal weights, overriding the shipped defaults per signal.",
                        "type": "object"
                    },
                    "workingHoursEnd": {
                        "format": "int32",
                        "type": "integer"
                    },
                    "workingHoursStart": {
                        "description": "The realm's working hours, for the `off_hours` signal: a sign-in outside\n[working_hours_start, working_hours_end) in `timezone` is off hours. Both\nzero means no window, and the signal is not asserted (kit#541).",
                        "format": "int32",
                        "type": "integer"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.RiskPolicy.FailMode": {
                "default": "CLOSED",
                "description": " - CLOSED: CLOSED — an unavailable evaluator reports `high`. The default: an\nevaluator that cannot be reached has not said the login is safe.",
                "enum": [
                    "CLOSED",
                    "OPEN"
                ],
                "type": "string"
            },
            "authwise.types.core.v1alpha1.RiskPolicy.Mode": {
                "default": "OFF",
                "description": " - BOTH: BOTH takes the higher of the two levels.",
                "enum": [
                    "OFF",
                    "BUILTIN",
                    "EXTERNAL",
                    "BOTH"
                ],
                "type": "string"
            },
            "authwise.types.core.v1alpha1.RoutingRule": {
                "description": "RoutingRule sends an identifier matching it to its target.",
                "properties": {
                    "condition": {
                        "description": "A CEL expression over identifier, local_part and domain (strings)\nreturning bool. When domains are also set, both must hold.",
                        "type": "string"
                    },
                    "domains": {
                        "description": "Lower-case ASCII (IDNA A-labels). Exact, or \"*.example.com\" for any\nsubdomain of example.com (not example.com itself). The identifier's\ndomain is the part after its last '@'.",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    },
                    "name": {
                        "description": "Unique within the selector; recorded on the login's audit row as\nrouting_rule.",
                        "type": "string"
                    },
                    "target": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.RoutingTarget"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.RoutingTarget": {
                "description": "RoutingTarget is where a routed identifier authenticates.",
                "properties": {
                    "providerName": {
                        "description": "Optional; a provider name (tenants/{t}/realms/{r}/providers/{p}) in\nthat realm. Empty: the realm's own selection applies — username and\npassword when present, else its only provider, else a choice.",
                        "type": "string"
                    },
                    "realmName": {
                        "description": "Required; one of the selector's realm_names.",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.SEARCH_OPERATOR_TYPE": {
                "default": "StringEquals",
                "enum": [
                    "StringEquals",
                    "StringNotEquals",
                    "StringMatch",
                    "StringIn",
                    "StringNotIn",
                    "NumberEquals",
                    "NumberNotEquals",
                    "NumberIn"
                ],
                "type": "string"
            },
            "authwise.types.core.v1alpha1.SamlRelyingPartyConfig": {
                "description": "SamlRelyingPartyConfig configures the IdP role: kit issuing assertions to a\npartner service provider (kit#490).\n\nIt sits on a Client with grant_type saml_idp, because a relying SP is the\nSAML twin of an OAuth client — it is who the login is FOR. Everything an\nInteractiveClientConfig says about redirect URIs, acs_urls says about\nassertion consumer services, and the same exact-match rule applies: a\ndestination we will send a signed assertion to is a destination anyone who\ncan write this config can send a user's identity to.\n\n--- The partner (the relying SP) ---",
                "properties": {
                    "acsBinding": {
                        "description": "How we deliver the Response: HTTP-POST (the default) or HTTP-Redirect.",
                        "type": "string"
                    },
                    "acsUrls": {
                        "description": "Allowed AssertionConsumerService locations, matched exactly. The first is\nthe default, used for an IdP-initiated login and for a request that names\nno ACS.",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    },
                    "allowIdpInitiated": {
                        "description": "Accept a login started at our end with no AuthnRequest at all. Defaults\nfalse: it means issuing an assertion for a destination nobody asked\nabout, so it needs a default ACS and a deliberate decision.",
                        "type": "boolean"
                    },
                    "assertionLifetimeSeconds": {
                        "description": "How long the assertion is good for. Defaults to 300.",
                        "format": "int32",
                        "type": "integer"
                    },
                    "claimMap": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.ClaimMap"
                    },
                    "defaultRelayState": {
                        "description": "RelayState sent with an IdP-initiated Response, which is how a partner\nknows where to land the user.",
                        "type": "string"
                    },
                    "encryptAssertions": {
                        "type": "boolean"
                    },
                    "nameIdFormat": {
                        "description": "NameID Format we issue. Empty uses the unspecified format carrying the\nsame subject an OIDC client would get.",
                        "type": "string"
                    },
                    "nameIdSource": {
                        "description": "Which value becomes the NameID. Empty uses the default for the format.",
                        "type": "string"
                    },
                    "sessionNotOnOrAfterSeconds": {
                        "description": "SessionNotOnOrAfter on the AuthnStatement. Zero omits it, leaving the\npartner's own session policy in charge.",
                        "format": "int32",
                        "type": "integer"
                    },
                    "signAssertions": {
                        "type": "boolean"
                    },
                    "signResponse": {
                        "description": "Defaults true. At least one of sign_response, sign_assertions or\nencrypt_assertions must hold, which the library enforces.",
                        "type": "boolean"
                    },
                    "signingCertificateId": {
                        "description": "Certificate resource name kit signs with. Required: an IdP that signs\nnothing issues assertions anyone can forge.",
                        "type": "string"
                    },
                    "spEncryptionCertificateId": {
                        "description": "Certificate resource name we encrypt assertions to. Required if\nencrypt_assertions.",
                        "type": "string"
                    },
                    "spEntityId": {
                        "description": "Expected Issuer on their AuthnRequest, and the Audience our assertion is\nrestricted to. An AuthnRequest from anyone else is refused.",
                        "type": "string"
                    },
                    "spMetadataImportedAt": {
                        "description": "Output only.",
                        "format": "date-time",
                        "readOnly": true,
                        "type": "string"
                    },
                    "spMetadataXml": {
                        "description": "The last metadata document imported, kept so a re-import can be diffed\nagainst it rather than applied blind.",
                        "type": "string"
                    },
                    "spSigningCertificateId": {
                        "description": "Certificate resource name holding their signing certificate. Required if\nwant_authn_requests_signed; every inbound signature is checked against\nthis one and nothing else.",
                        "type": "string"
                    },
                    "wantAuthnRequestsSigned": {
                        "description": "Require the partner to sign their AuthnRequest. Off by default because\nmost SPs do not sign, and the request carries nothing an unsigned one\ncould abuse that the ACS allow-list does not already close.",
                        "type": "boolean"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.Scope": {
                "properties": {
                    "auto": {
                        "type": "boolean"
                    },
                    "kind": {
                        "type": "string"
                    },
                    "name": {
                        "description": "The resource name, which for this resource is also its KEY. Unlike every\nother resource in this file it is client-supplied and REQUIRED on create:\nthere is no generated id for the server to render a name from, so the\ncreate service reads this field and uses it as the row's key. It is\nignored on update — renaming is not an operation.\n\nThis comment must never contain the phrase protoc-gen-openapiv2 keys\nreadOnly off — it matches the words wherever they appear, not only at\nthe start, so even quoting them here to say \"not that\" marked all four\nof these fields read-only and would have broken every create. Making\nthe surface uniform means giving create a separate client-specified id\nfield (AIP-133); it is a change to the create surface, not a comment.",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.ScopesConfig": {
                "properties": {
                    "authorization": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.AuthorizationConfig"
                    },
                    "openid": {
                        "type": "boolean"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.SearchPredicate": {
                "properties": {
                    "name": {
                        "type": "string"
                    },
                    "numberArrayValue": {
                        "items": {
                            "format": "double",
                            "type": "number"
                        },
                        "type": "array"
                    },
                    "numberValue": {
                        "format": "double",
                        "type": "number"
                    },
                    "operator": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.SEARCH_OPERATOR_TYPE"
                    },
                    "stringArrayValue": {
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    },
                    "stringValue": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.SearchPredicateDescriptor": {
                "properties": {
                    "label": {
                        "type": "string"
                    },
                    "name": {
                        "type": "string"
                    },
                    "operators": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.SEARCH_OPERATOR_TYPE"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.Secret": {
                "properties": {
                    "description": {
                        "type": "string"
                    },
                    "displayName": {
                        "type": "string"
                    },
                    "labels": {
                        "additionalProperties": {
                            "type": "string"
                        },
                        "type": "object"
                    },
                    "name": {
                        "description": "Output only. The resource name, rendered from the row's id: the address\nused to GET, PATCH and DELETE this row, not a label. A value sent on\ncreate or update is ignored — the server always builds it from the id.\nFor a human-readable label, use display_name.",
                        "readOnly": true,
                        "type": "string"
                    },
                    "source": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.SecretSource"
                    },
                    "updatedAt": {
                        "description": "Output only.\n\n@gotags: yaml:\"updated_at,omitempty\"",
                        "format": "date-time",
                        "readOnly": true,
                        "type": "string"
                    },
                    "version": {
                        "description": "Output only. 1 at creation, bumped by AddSecretVersion. It is bound into\nthe envelope, so restoring an older envelope over a newer version fails\nto open rather than silently reinstating a rotated-away credential.",
                        "format": "int32",
                        "readOnly": true,
                        "type": "integer"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.SecretPayload": {
                "description": "SecretPayload is the material, on the way in only. It is carried by\nCreateSecretRequest and AddSecretVersionRequest and by nothing that is ever\nreturned.",
                "properties": {
                    "binary": {
                        "format": "byte",
                        "type": "string"
                    },
                    "text": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.SecretRef": {
                "description": "SecretRef names a Secret a config object uses (kit#370,\ndocswip/SECRETS.md §2.2). A config object never holds a credential; it\nholds one of these, and the Secret decides where the material lives.\n\nA message rather than a string so reference admission can find every\nreference in any config proto by type — a new field of this type is gated\nwithout a new decorator — and so it can grow a version pin.",
                "properties": {
                    "name": {
                        "description": "tenants/{tenant}/secrets/{secret}. The tenant must be the tenant of the\nobject holding the reference; the writer must hold identity.secrets.use.",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.SecretSource": {
                "description": "SecretSource says where a Secret's material lives.",
                "properties": {
                    "external": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.SecretSourceExternal"
                    },
                    "inline": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.SecretSourceInline"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.SecretSourceExternal": {
                "properties": {
                    "key": {
                        "description": "The key within that store: a file name for a file store, the suffix of\nthe variable for an env store.",
                        "type": "string"
                    },
                    "store": {
                        "description": "A store declared under secrets.stores in the install's config.",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.SecretSourceInline": {
                "type": "object"
            },
            "authwise.types.core.v1alpha1.SessionPolicy": {
                "properties": {
                    "absolute": {
                        "description": "The session's absolute end, measured from its creation. Default 12h,\nwhich is the cache's own TTL and NIST's AAL3 ceiling; a realm may\nshorten it and may not lengthen it past that outer bound.",
                        "type": "string"
                    },
                    "factorReauth": {
                        "description": "The reauth_after applied when a rule names none. Default 12h.",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.SingleRealmProviderSelector": {
                "properties": {
                    "realmName": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.SmsPolicy": {
                "description": "SmsPolicy is where a realm sends SMS (§35.5).",
                "properties": {
                    "allowedRegions": {
                        "description": "allowed_regions, when not empty, is the only ISO 3166-1 alpha-2\nregions an SMS goes to. Empty is every region.",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    },
                    "deniedRegions": {
                        "description": "denied_regions are never sent to; a region in both lists is denied.",
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    },
                    "sendsPerPrefixPerHour": {
                        "description": "sends_per_prefix_per_hour caps SMS sends per country calling code per\nrealm per hour — pumping concentrates on a few premium ranges, and the\nrealm ceiling alone lets one prefix spend all of it. Zero (or negative)\nis no per-prefix cap, so `sms: {}` reads exactly as no block at all; a\nrealm opts in with a number (100 is a reasonable start).",
                        "format": "int32",
                        "type": "integer"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.Theme": {
                "properties": {
                    "content": {
                        "type": "object"
                    },
                    "contentSchema": {
                        "title": "@gotags: yaml:\"content_schema\"",
                        "type": "string"
                    },
                    "displayName": {
                        "type": "string"
                    },
                    "labels": {
                        "additionalProperties": {
                            "type": "string"
                        },
                        "type": "object"
                    },
                    "layout": {
                        "description": "The login UI layout this theme is authored for: center, landscape or\nfull, or another key the deployment hosts (GET /api/v1/ui/layouts lists\nthem). The theme service catalog proxies an issuer whose active theme\nnames this layout to that layout's container, and the stylesheet\ntemplate is written against that layout's variables. Fixed at\ncreation: an update that changes it is refused. Empty on create means\ncenter.",
                        "type": "string"
                    },
                    "name": {
                        "description": "Output only. The resource name, rendered from the row's id: the address\nused to GET, PATCH and DELETE this row, not a label. A value sent on\ncreate or update is ignored — the server always builds it from the id.\nFor a human-readable label, use display_name.",
                        "readOnly": true,
                        "type": "string"
                    },
                    "placeholderContent": {
                        "title": "@gotags: yaml:\"placeholder_content\"",
                        "type": "object"
                    },
                    "placeholderStylesheetAttributes": {
                        "title": "@gotags: yaml:\"placeholder_stylesheet_attributes\"",
                        "type": "object"
                    },
                    "stylesheet": {
                        "type": "string"
                    },
                    "stylesheetAttributes": {
                        "type": "object"
                    },
                    "stylesheetAttributesSchema": {
                        "title": "@gotags: yaml:\"stylesheet_attributes_schema\"",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.User": {
                "properties": {
                    "birthdate": {
                        "type": "string"
                    },
                    "credentialsChangedAt": {
                        "description": "Output only. When the account's credential last changed — a password\nset or reset through a one-time link (kit#385). Unset means never since\nthat release. A sign-in from before it has ended (kit#386). A value sent\non create or update is ignored.\n\n@gotags: yaml:\"credentials_changed_at\"",
                        "format": "date-time",
                        "readOnly": true,
                        "type": "string"
                    },
                    "displayName": {
                        "type": "string"
                    },
                    "email": {
                        "description": "Output only. The address kit reaches this person at, DERIVED on every\nread and never stored (USER_IDENTIFIERS.md D14, kit#666): the account's\nmost recently used proven e-mail row — a channel row kit wrote at the\nend of a proof, or the password login name when it is an address — else\nthe most recent federated link's assertion, else empty. Refused on\ncreate and update with InvalidArgument whatever the value (kit#662);\nan address is added by proving it (an invitation, the account page).",
                        "readOnly": true,
                        "type": "string"
                    },
                    "emailVerified": {
                        "description": "Output only. True when email is a proven row; for an upstream's\nassertion, true only when that provider carries\ntrust_upstream_email_verified. Refused on create and update (kit#662).\n\n@gotags: yaml:\"email_verified\"",
                        "readOnly": true,
                        "type": "boolean"
                    },
                    "enrollment": {
                        "description": "enrollment is DERIVED and never stored (kit#324): \"active\" once the\naccount has a credential, otherwise \"invited\" while an invitation is\nlive, \"expired\" once one has lapsed, and \"none\" when there is no\ncredential and no invitation at all. It answers whether the account can\nbe signed into, which status alone does not — an invited user who has\nnever signed in reads as \"active\" by status, which is misleading in\nexactly the situation an operator is most likely looking at.\n\nRead-only over the API, on the same terms as origin: it is computed at\nread time from user_identifiers and recoveries, so a differing value on\nupdate is refused rather than ignored. Every response carrying a User\ncarries it, write verbs included (kit#343) — it was briefly absent from\nCreate and Update on the grounds that those describe a write rather than\nthe world after it, but status and origin come back on those verbs too,\nso the exception only meant a client rendering the reply saw a blank\nbadge with nothing to explain it.",
                        "type": "string"
                    },
                    "extraFields": {
                        "title": "@gotags: yaml:\"extra_fields\"",
                        "type": "object"
                    },
                    "familyName": {
                        "title": "@gotags: yaml:\"family_name\"",
                        "type": "string"
                    },
                    "gender": {
                        "type": "string"
                    },
                    "givenName": {
                        "title": "@gotags: yaml:\"given_name\"",
                        "type": "string"
                    },
                    "labels": {
                        "additionalProperties": {
                            "type": "string"
                        },
                        "type": "object"
                    },
                    "locale": {
                        "type": "string"
                    },
                    "metadata": {
                        "type": "object"
                    },
                    "middleName": {
                        "title": "@gotags: yaml:\"middle_name\"",
                        "type": "string"
                    },
                    "name": {
                        "description": "Output only. The resource name, rendered from the row's id: the address\nused to GET, PATCH and DELETE this row, not a label. A value sent on\ncreate or update is ignored — the server always builds it from the id.\nFor a human-readable label, use display_name.",
                        "readOnly": true,
                        "type": "string"
                    },
                    "nickname": {
                        "type": "string"
                    },
                    "origin": {
                        "description": "origin is write-once and read-only over the API: it records what\ncreated the account (local, invited, federated, scim, directory,\nbootstrap). Sending a different value on update is refused rather than\nignored, so a client is told its edit did not apply.",
                        "type": "string"
                    },
                    "phoneNumber": {
                        "description": "Output only. Derived like email (D14, kit#666): the most recently used\nproven phone row, else the most recent federated link's assertion.\nRefused on create and update with InvalidArgument whatever the value.\n\n@gotags: yaml:\"phone_number\"",
                        "readOnly": true,
                        "type": "string"
                    },
                    "phoneNumberVerified": {
                        "description": "Output only. True only for a proven phone row; an upstream's phone is\nnever verified. Refused on create and update (kit#662).\n\n@gotags: yaml:\"phone_number_verified\"",
                        "readOnly": true,
                        "type": "boolean"
                    },
                    "picture": {
                        "type": "string"
                    },
                    "preferredUsername": {
                        "title": "@gotags: yaml:\"preferred_username\"",
                        "type": "string"
                    },
                    "profile": {
                        "type": "string"
                    },
                    "status": {
                        "description": "Lifecycle slugs (kit#304), carried as strings rather than proto enums\nso the wire form matches the stored column and the typesafe values in\npkg/lib/lifecycle exactly, with no third numbering to keep in step.\n\nstatus is \"active\" or \"disabled\"; only active may authenticate. An\nempty value on the wire means \"unchanged\" — the server keeps whatever\nthe row already has — so an older client cannot blank it by omission.",
                        "type": "string"
                    },
                    "updatedAt": {
                        "format": "date-time",
                        "title": "@gotags: yaml:\"updated_at\"",
                        "type": "string"
                    },
                    "website": {
                        "type": "string"
                    },
                    "zoneinfo": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.UserIdentifierKind": {
                "default": "USER_IDENTIFIER_KIND_UNSPECIFIED",
                "description": "What a user_identifiers row means, derived from the provider it names and\nnever stored (docswip/USER_IDENTIFIERS.md D1): a local login name with a\npassword, a link to an upstream subject, or a bound channel address. On\nthe identifiers projection only — the row itself stays off every\ngenerated surface (kit#320, defect D11).",
                "enum": [
                    "USER_IDENTIFIER_KIND_UNSPECIFIED",
                    "USER_IDENTIFIER_KIND_PASSWORD",
                    "USER_IDENTIFIER_KIND_FEDERATED",
                    "USER_IDENTIFIER_KIND_CHANNEL"
                ],
                "type": "string"
            },
            "google.protobuf.Any": {
                "additionalProperties": {},
                "description": "`Any` contains an arbitrary serialized protocol buffer message along with a\nURL that describes the type of the serialized message.\n\nProtobuf library provides support to pack/unpack Any values in the form\nof utility functions or additional generated methods of the Any type.\n\nExample 1: Pack and unpack a message in C++.\n\n    Foo foo = ...;\n    Any any;\n    any.PackFrom(foo);\n    ...\n    if (any.UnpackTo(\u0026foo)) {\n      ...\n    }\n\nExample 2: Pack and unpack a message in Java.\n\n    Foo foo = ...;\n    Any any = Any.pack(foo);\n    ...\n    if (any.is(Foo.class)) {\n      foo = any.unpack(Foo.class);\n    }\n\nExample 3: Pack and unpack a message in Python.\n\n    foo = Foo(...)\n    any = Any()\n    any.Pack(foo)\n    ...\n    if any.Is(Foo.DESCRIPTOR):\n      any.Unpack(foo)\n      ...\n\nExample 4: Pack and unpack a message in Go\n\n     foo := \u0026pb.Foo{...}\n     any, err := anypb.New(foo)\n     if err != nil {\n       ...\n     }\n     ...\n     foo := \u0026pb.Foo{}\n     if err := any.UnmarshalTo(foo); err != nil {\n       ...\n     }\n\nThe pack methods provided by protobuf library will by default use\n'type.googleapis.com/full.type.name' as the type URL and the unpack\nmethods only use the fully qualified type name after the last '/'\nin the type URL, for example \"foo.bar.com/x/y.z\" will yield type\nname \"y.z\".\n\n\nJSON\n\nThe JSON representation of an `Any` value uses the regular\nrepresentation of the deserialized, embedded message, with an\nadditional field `@type` which contains the type URL. Example:\n\n    package google.profile;\n    message Person {\n      string first_name = 1;\n      string last_name = 2;\n    }\n\n    {\n      \"@type\": \"type.googleapis.com/google.profile.Person\",\n      \"firstName\": \u003cstring\u003e,\n      \"lastName\": \u003cstring\u003e\n    }\n\nIf the embedded message type is well-known and has a custom JSON\nrepresentation, that representation will be embedded adding a field\n`value` which holds the custom JSON in addition to the `@type`\nfield. Example (for message [google.protobuf.Duration][]):\n\n    {\n      \"@type\": \"type.googleapis.com/google.protobuf.Duration\",\n      \"value\": \"1.212s\"\n    }",
                "properties": {
                    "@type": {
                        "description": "A URL/resource name that uniquely identifies the type of the serialized\nprotocol buffer message. This string must contain at least\none \"/\" character. The last segment of the URL's path must represent\nthe fully qualified name of the type (as in\n`path/google.protobuf.Duration`). The name should be in a canonical form\n(e.g., leading \".\" is not accepted).\n\nIn practice, teams usually precompile into the binary all types that they\nexpect it to use in the context of Any. However, for URLs which use the\nscheme `http`, `https`, or no scheme, one can optionally set up a type\nserver that maps type URLs to message definitions as follows:\n\n* If no scheme is provided, `https` is assumed.\n* An HTTP GET on the URL must yield a [google.protobuf.Type][]\n  value in binary format, or produce an error.\n* Applications are allowed to cache lookup results based on the\n  URL, or have them precompiled into a binary to avoid any\n  lookup. Therefore, binary compatibility needs to be preserved\n  on changes to types. (Use versioned type names to manage\n  breaking changes.)\n\nNote: this functionality is not currently available in the official\nprotobuf release, and it is not used for type URLs beginning with\ntype.googleapis.com.\n\nSchemes other than `http`, `https` (or the empty scheme) might be\nused with implementation specific semantics.",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "google.protobuf.NullValue": {
                "default": "NULL_VALUE",
                "description": "`NullValue` is a singleton enumeration to represent the null value for the\n`Value` type union.\n\n The JSON representation for `NullValue` is JSON `null`.\n\n - NULL_VALUE: Null value.",
                "enum": [
                    "NULL_VALUE"
                ],
                "type": "string"
            },
            "google.rpc.Status": {
                "properties": {
                    "code": {
                        "format": "int32",
                        "type": "integer"
                    },
                    "details": {
                        "items": {
                            "$ref": "#/components/schemas/google.protobuf.Any"
                        },
                        "type": "array"
                    },
                    "message": {
                        "type": "string"
                    }
                },
                "type": "object"
            }
        },
        "securitySchemes": {
            "Authwise": {
                "type": "openIdConnect",
                "openIdConnectUrl": "/.well-known/openid-configuration"
            }
        }
    },
    "info": {
        "title": "authwise/identity/v1alpha1/grpc.proto",
        "version": "version not set"
    },
    "openapi": "3.0.3",
    "paths": {
        "/v1/files/tenants/{tenantId}/assets/{assetId}": {
            "delete": {
                "operationId": "AuthwiseIdentityService_RemoveAsset",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "assetId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "type": "object"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Assets"
                ]
            }
        },
        "/v1/tenants/{tenantId}/assets": {
            "get": {
                "operationId": "AuthwiseIdentityService_ListAssets",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageSize",
                        "schema": {
                            "format": "int32",
                            "type": "integer"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageToken",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "filter",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "orderBy",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.ListAssetsResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Assets"
                ]
            },
            "post": {
                "operationId": "AuthwiseIdentityService_CreateAsset",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Asset"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "asset"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Asset"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Assets"
                ]
            }
        },
        "/v1/tenants/{tenantId}/assets/{assetId}": {
            "delete": {
                "operationId": "AuthwiseIdentityService_DeleteAsset",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "assetId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "type": "object"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Assets"
                ]
            },
            "get": {
                "operationId": "AuthwiseIdentityService_GetAsset",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "assetId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Asset"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Assets"
                ]
            },
            "patch": {
                "operationId": "AuthwiseIdentityService_PatchAsset",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "assetId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "asset": {
                                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Asset"
                                    },
                                    "updateMask": {
                                        "type": "string"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Asset"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Assets"
                ]
            },
            "put": {
                "operationId": "AuthwiseIdentityService_UpdateAsset",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "assetId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Asset"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "asset"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Asset"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Assets"
                ]
            }
        },
        "/v1/tenants/{tenantId}/certificates": {
            "get": {
                "operationId": "AuthwiseIdentityService_ListCertificates",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageSize",
                        "schema": {
                            "format": "int32",
                            "type": "integer"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageToken",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "filter",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "orderBy",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.ListCertificatesResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Certificates"
                ]
            },
            "post": {
                "operationId": "AuthwiseIdentityService_CreateCertificate",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Certificate"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "certificate"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Certificate"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Certificates"
                ]
            }
        },
        "/v1/tenants/{tenantId}/certificates/{certificateId}": {
            "delete": {
                "operationId": "AuthwiseIdentityService_DeleteCertificate",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "certificateId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "type": "object"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Certificates"
                ]
            },
            "get": {
                "operationId": "AuthwiseIdentityService_GetCertificate",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "certificateId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Certificate"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Certificates"
                ]
            },
            "patch": {
                "operationId": "AuthwiseIdentityService_PatchCertificate",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "certificateId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "certificate": {
                                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Certificate"
                                    },
                                    "updateMask": {
                                        "type": "string"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Certificate"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Certificates"
                ]
            },
            "put": {
                "operationId": "AuthwiseIdentityService_UpdateCertificate",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "certificateId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Certificate"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "certificate"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Certificate"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Certificates"
                ]
            }
        },
        "/v1/tenants/{tenantId}/certificates/{certificateId}:rotate": {
            "post": {
                "operationId": "AuthwiseIdentityService_RotateCertificate",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "certificateId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "displayName": {
                                        "description": "Display name for the successor. Empty derives one from the predecessor's.",
                                        "type": "string"
                                    },
                                    "keySize": {
                                        "description": "RSA modulus of the successor. Empty uses the mint default.",
                                        "format": "int32",
                                        "type": "integer"
                                    },
                                    "validityDays": {
                                        "description": "Validity of the successor. Empty uses the mint default.",
                                        "format": "int32",
                                        "type": "integer"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.RotateCertificateResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Certificates"
                ]
            }
        },
        "/v1/tenants/{tenantId}/domains": {
            "get": {
                "operationId": "AuthwiseIdentityService_ListDomains",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageSize",
                        "schema": {
                            "format": "int32",
                            "type": "integer"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageToken",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "filter",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "orderBy",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.ListDomainsResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Domains"
                ]
            },
            "post": {
                "operationId": "AuthwiseIdentityService_CreateDomain",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Domain"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "domain"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Domain"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Domains"
                ]
            }
        },
        "/v1/tenants/{tenantId}/domains/{domainId}": {
            "delete": {
                "operationId": "AuthwiseIdentityService_DeleteDomain",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "domainId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "type": "object"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Domains"
                ]
            },
            "get": {
                "operationId": "AuthwiseIdentityService_GetDomain",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "domainId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Domain"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Domains"
                ]
            },
            "patch": {
                "operationId": "AuthwiseIdentityService_PatchDomain",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "domainId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "domain": {
                                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Domain"
                                    },
                                    "updateMask": {
                                        "type": "string"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Domain"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Domains"
                ]
            },
            "put": {
                "operationId": "AuthwiseIdentityService_UpdateDomain",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "domainId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Domain"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "domain"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Domain"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Domains"
                ]
            }
        },
        "/v1/tenants/{tenantId}/endpoints": {
            "get": {
                "operationId": "AuthwiseIdentityService_ListEndpoints",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageSize",
                        "schema": {
                            "format": "int32",
                            "type": "integer"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageToken",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "filter",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "orderBy",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.ListEndpointsResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Integrations"
                ]
            },
            "post": {
                "operationId": "AuthwiseIdentityService_CreateEndpoint",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Endpoint"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "endpoint"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Endpoint"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Integrations"
                ]
            }
        },
        "/v1/tenants/{tenantId}/endpoints/{endpointId}": {
            "delete": {
                "operationId": "AuthwiseIdentityService_DeleteEndpoint",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "endpointId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "type": "object"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Integrations"
                ]
            },
            "get": {
                "operationId": "AuthwiseIdentityService_GetEndpoint",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "endpointId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Endpoint"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Integrations"
                ]
            },
            "patch": {
                "operationId": "AuthwiseIdentityService_PatchEndpoint",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "endpointId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "endpoint": {
                                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Endpoint"
                                    },
                                    "updateMask": {
                                        "type": "string"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Endpoint"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Integrations"
                ]
            },
            "put": {
                "operationId": "AuthwiseIdentityService_UpdateEndpoint",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "endpointId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Endpoint"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "endpoint"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Endpoint"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Integrations"
                ]
            }
        },
        "/v1/tenants/{tenantId}/endpoints/{endpointId}:check": {
            "post": {
                "operationId": "AuthwiseIdentityService_CheckEndpoint",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "endpointId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.CheckEndpointResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Integrations"
                ]
            }
        },
        "/v1/tenants/{tenantId}/endpoints/{endpointId}:referrers": {
            "get": {
                "operationId": "AuthwiseIdentityService_ListEndpointReferrers",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "endpointId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.ListEndpointReferrersResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Integrations"
                ]
            }
        },
        "/v1/tenants/{tenantId}/events": {
            "get": {
                "operationId": "AuthwiseIdentityService_ListEvents",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageSize",
                        "schema": {
                            "format": "int32",
                            "type": "integer"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageToken",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "filter",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "orderBy",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.ListEventsResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Events"
                ]
            }
        },
        "/v1/tenants/{tenantId}/events/{eventId}": {
            "get": {
                "operationId": "AuthwiseIdentityService_GetEvent",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "eventId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Event"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Events"
                ]
            }
        },
        "/v1/tenants/{tenantId}/events:search": {
            "post": {
                "operationId": "AuthwiseIdentityService_SearchEvents",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "criteria": {
                                        "items": {
                                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.SearchPredicate"
                                        },
                                        "type": "array"
                                    },
                                    "filter": {
                                        "type": "string"
                                    },
                                    "orderBy": {
                                        "type": "string"
                                    },
                                    "pageSize": {
                                        "format": "int32",
                                        "type": "integer"
                                    },
                                    "pageToken": {
                                        "type": "string"
                                    },
                                    "readMask": {
                                        "type": "string"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.SearchEventsResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Events"
                ]
            }
        },
        "/v1/tenants/{tenantId}/events:searchHistogram": {
            "post": {
                "operationId": "AuthwiseIdentityService_EventSearchHistogram",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "criteria": {
                                        "items": {
                                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.SearchPredicate"
                                        },
                                        "type": "array"
                                    },
                                    "histogram": {
                                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.HistogramSpec"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.EventSearchHistogramResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Events"
                ]
            }
        },
        "/v1/tenants/{tenantId}/events:searchPredicates": {
            "get": {
                "operationId": "AuthwiseIdentityService_EventSearchPredicates",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.EventSearchPredicatesResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Events"
                ]
            }
        },
        "/v1/tenants/{tenantId}/issuers": {
            "get": {
                "operationId": "AuthwiseIdentityService_ListIssuers",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageSize",
                        "schema": {
                            "format": "int32",
                            "type": "integer"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageToken",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "filter",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "orderBy",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.ListIssuersResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Issuers"
                ]
            },
            "post": {
                "operationId": "AuthwiseIdentityService_CreateIssuer",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Issuer"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "issuer"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Issuer"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Issuers"
                ]
            }
        },
        "/v1/tenants/{tenantId}/issuers/{issuerId}": {
            "delete": {
                "operationId": "AuthwiseIdentityService_DeleteIssuer",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "type": "object"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Issuers"
                ]
            },
            "get": {
                "operationId": "AuthwiseIdentityService_GetIssuer",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Issuer"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Issuers"
                ]
            },
            "patch": {
                "operationId": "AuthwiseIdentityService_PatchIssuer",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "issuer": {
                                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Issuer"
                                    },
                                    "updateMask": {
                                        "type": "string"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Issuer"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Issuers"
                ]
            },
            "put": {
                "operationId": "AuthwiseIdentityService_UpdateIssuer",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Issuer"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "issuer"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Issuer"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Issuers"
                ]
            }
        },
        "/v1/tenants/{tenantId}/issuers/{issuerId}/appearance-profiles": {
            "get": {
                "operationId": "AuthwiseIdentityService_ListAppearanceProfiles",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageSize",
                        "schema": {
                            "format": "int32",
                            "type": "integer"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageToken",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "filter",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "orderBy",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.ListAppearanceProfilesResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Themes and Appearance Profiles"
                ]
            },
            "post": {
                "operationId": "AuthwiseIdentityService_CreateAppearanceProfile",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.AppearanceProfile"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "appearanceProfile"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.AppearanceProfile"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Themes and Appearance Profiles"
                ]
            }
        },
        "/v1/tenants/{tenantId}/issuers/{issuerId}/appearance-profiles/{appearanceProfileId}": {
            "delete": {
                "operationId": "AuthwiseIdentityService_DeleteAppearanceProfile",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "appearanceProfileId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "type": "object"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Themes and Appearance Profiles"
                ]
            },
            "get": {
                "operationId": "AuthwiseIdentityService_GetAppearanceProfile",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "appearanceProfileId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.AppearanceProfile"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Themes and Appearance Profiles"
                ]
            },
            "patch": {
                "operationId": "AuthwiseIdentityService_PatchAppearanceProfile",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "appearanceProfileId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "appearanceProfile": {
                                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.AppearanceProfile"
                                    },
                                    "updateMask": {
                                        "type": "string"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.AppearanceProfile"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Themes and Appearance Profiles"
                ]
            },
            "put": {
                "operationId": "AuthwiseIdentityService_UpdateAppearanceProfile",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "appearanceProfileId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.AppearanceProfile"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "appearanceProfile"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.AppearanceProfile"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Themes and Appearance Profiles"
                ]
            }
        },
        "/v1/tenants/{tenantId}/issuers/{issuerId}/appearance-profiles/{appearanceProfileId}:makeDefault": {
            "post": {
                "operationId": "AuthwiseIdentityService_MakeDefaultAppearanceProfile",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "appearanceProfileId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.MakeDefaultAppearanceProfileResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Themes and Appearance Profiles"
                ]
            }
        },
        "/v1/tenants/{tenantId}/issuers/{issuerId}/audiences": {
            "get": {
                "operationId": "AuthwiseIdentityService_ListAudiences",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageSize",
                        "schema": {
                            "format": "int32",
                            "type": "integer"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageToken",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "filter",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "orderBy",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.ListAudiencesResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Audiences"
                ]
            },
            "post": {
                "operationId": "AuthwiseIdentityService_CreateAudience",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Audience"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "audience"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Audience"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Audiences"
                ]
            }
        },
        "/v1/tenants/{tenantId}/issuers/{issuerId}/audiences/{audienceId}": {
            "delete": {
                "operationId": "AuthwiseIdentityService_DeleteAudience",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "audienceId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "type": "object"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Audiences"
                ]
            },
            "get": {
                "operationId": "AuthwiseIdentityService_GetAudience",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "audienceId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Audience"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Audiences"
                ]
            },
            "patch": {
                "operationId": "AuthwiseIdentityService_PatchAudience",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "audienceId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "audience": {
                                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Audience"
                                    },
                                    "updateMask": {
                                        "type": "string"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Audience"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Audiences"
                ]
            },
            "put": {
                "operationId": "AuthwiseIdentityService_UpdateAudience",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "audienceId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Audience"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "audience"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Audience"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Audiences"
                ]
            }
        },
        "/v1/tenants/{tenantId}/issuers/{issuerId}/audiences/{audienceId}/scopes": {
            "get": {
                "operationId": "AuthwiseIdentityService_ListScopes",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "audienceId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageSize",
                        "schema": {
                            "format": "int32",
                            "type": "integer"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageToken",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "filter",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "orderBy",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.ListScopesResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Scopes"
                ]
            },
            "post": {
                "operationId": "AuthwiseIdentityService_CreateScope",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "audienceId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Scope"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "scope"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Scope"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Scopes"
                ]
            }
        },
        "/v1/tenants/{tenantId}/issuers/{issuerId}/audiences/{audienceId}/scopes/{scopeId}": {
            "delete": {
                "operationId": "AuthwiseIdentityService_DeleteScope",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "audienceId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "scopeId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "type": "object"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Scopes"
                ]
            },
            "get": {
                "operationId": "AuthwiseIdentityService_GetScope",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "audienceId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "scopeId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Scope"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Scopes"
                ]
            },
            "patch": {
                "operationId": "AuthwiseIdentityService_PatchScope",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "audienceId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "scopeId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "scope": {
                                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Scope"
                                    },
                                    "updateMask": {
                                        "type": "string"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Scope"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Scopes"
                ]
            },
            "put": {
                "operationId": "AuthwiseIdentityService_UpdateScope",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "audienceId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "scopeId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Scope"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "scope"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Scope"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Scopes"
                ]
            }
        },
        "/v1/tenants/{tenantId}/issuers/{issuerId}/audiences/{audienceId}/scopes/{scopeId}:associateAccessPermissions": {
            "post": {
                "operationId": "AuthwiseIdentityService_AssociateAccessPermissionsToScope",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "audienceId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "scopeId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "association": {
                                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.AssociationRequest"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "type": "object"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Scopes"
                ]
            }
        },
        "/v1/tenants/{tenantId}/issuers/{issuerId}/audiences/{audienceId}/scopes/{scopeId}:listAccessPermissions": {
            "get": {
                "operationId": "AuthwiseIdentityService_ListAccessPermissionsByScope",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "audienceId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "scopeId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageSize",
                        "schema": {
                            "format": "int32",
                            "type": "integer"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageToken",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "filter",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "orderBy",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.ListAccessPermissionsByScopeResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Scopes"
                ]
            }
        },
        "/v1/tenants/{tenantId}/issuers/{issuerId}/clients": {
            "get": {
                "operationId": "AuthwiseIdentityService_ListClients",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageSize",
                        "schema": {
                            "format": "int32",
                            "type": "integer"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageToken",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "filter",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "orderBy",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.ListClientsResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Clients"
                ]
            },
            "post": {
                "operationId": "AuthwiseIdentityService_CreateClient",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Client"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "client"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Client"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Clients"
                ]
            }
        },
        "/v1/tenants/{tenantId}/issuers/{issuerId}/clients/{clientId}": {
            "delete": {
                "operationId": "AuthwiseIdentityService_DeleteClient",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "clientId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "type": "object"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Clients"
                ]
            },
            "get": {
                "operationId": "AuthwiseIdentityService_GetClient",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "clientId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Client"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Clients"
                ]
            },
            "patch": {
                "operationId": "AuthwiseIdentityService_PatchClient",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "clientId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "client": {
                                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Client"
                                    },
                                    "updateMask": {
                                        "type": "string"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Client"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Clients"
                ]
            },
            "put": {
                "operationId": "AuthwiseIdentityService_UpdateClient",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "clientId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Client"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "client"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Client"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Clients"
                ]
            }
        },
        "/v1/tenants/{tenantId}/issuers/{issuerId}/clients/{clientId}/client-secrets": {
            "get": {
                "operationId": "AuthwiseIdentityService_ListClientSecrets",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "clientId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageSize",
                        "schema": {
                            "format": "int32",
                            "type": "integer"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageToken",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "filter",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "orderBy",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.ListClientSecretsResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Client Secrets"
                ]
            }
        },
        "/v1/tenants/{tenantId}/issuers/{issuerId}/clients/{clientId}/client-secrets/{clientSecretId}": {
            "delete": {
                "operationId": "AuthwiseIdentityService_DeleteClientSecret",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "clientId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "clientSecretId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "type": "object"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Client Secrets"
                ]
            },
            "get": {
                "operationId": "AuthwiseIdentityService_GetClientSecret",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "clientId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "clientSecretId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.ClientSecret"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Client Secrets"
                ]
            },
            "patch": {
                "operationId": "AuthwiseIdentityService_PatchClientSecret",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "clientId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "clientSecretId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "clientSecret": {
                                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.ClientSecret"
                                    },
                                    "updateMask": {
                                        "type": "string"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.ClientSecret"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Client Secrets"
                ]
            },
            "put": {
                "operationId": "AuthwiseIdentityService_UpdateClientSecret",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "clientId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "clientSecretId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.ClientSecret"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "clientSecret"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.ClientSecret"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Client Secrets"
                ]
            }
        },
        "/v1/tenants/{tenantId}/issuers/{issuerId}/clients/{clientId}/client-secrets:mint": {
            "post": {
                "operationId": "AuthwiseIdentityService_MintClientSecret",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "clientId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "expiresAt": {
                                        "description": "When the secret stops authenticating. Must be in the future; empty means it never expires.",
                                        "format": "date-time",
                                        "type": "string"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.MintClientSecretResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Client Secrets"
                ]
            }
        },
        "/v1/tenants/{tenantId}/issuers/{issuerId}/clients/{clientId}:exportSamlMetadata": {
            "get": {
                "operationId": "AuthwiseIdentityService_ExportClientSamlMetadata",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "clientId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "description": "Issuer resource name to render for. Required when the tenant has more than one issuer.",
                        "in": "query",
                        "name": "issuer",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.ExportClientSamlMetadataResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Clients"
                ]
            }
        },
        "/v1/tenants/{tenantId}/issuers/{issuerId}/clients/{clientId}:importSamlMetadata": {
            "post": {
                "operationId": "AuthwiseIdentityService_ImportClientSamlMetadata",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "issuerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "clientId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "dryRun": {
                                        "description": "Report what would change and write nothing. No certificates are created.",
                                        "type": "boolean"
                                    },
                                    "metadataXml": {
                                        "description": "The partner's metadata document, as published.",
                                        "type": "string"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.ImportClientSamlMetadataResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Clients"
                ]
            }
        },
        "/v1/tenants/{tenantId}/message-keys": {
            "get": {
                "operationId": "AuthwiseIdentityService_ListMessageKeys",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.ListMessageKeysResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Messaging"
                ]
            }
        },
        "/v1/tenants/{tenantId}/message-templates": {
            "get": {
                "operationId": "AuthwiseIdentityService_ListMessageTemplates",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageSize",
                        "schema": {
                            "format": "int32",
                            "type": "integer"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageToken",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "filter",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "orderBy",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.ListMessageTemplatesResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Messaging"
                ]
            },
            "post": {
                "operationId": "AuthwiseIdentityService_CreateMessageTemplate",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.MessageTemplate"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "messageTemplate"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.MessageTemplate"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Messaging"
                ]
            }
        },
        "/v1/tenants/{tenantId}/message-templates/{messageTemplateId}": {
            "delete": {
                "operationId": "AuthwiseIdentityService_DeleteMessageTemplate",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "messageTemplateId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "type": "object"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Messaging"
                ]
            },
            "get": {
                "operationId": "AuthwiseIdentityService_GetMessageTemplate",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "messageTemplateId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.MessageTemplate"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Messaging"
                ]
            },
            "patch": {
                "operationId": "AuthwiseIdentityService_PatchMessageTemplate",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "messageTemplateId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "messageTemplate": {
                                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.MessageTemplate"
                                    },
                                    "updateMask": {
                                        "type": "string"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.MessageTemplate"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Messaging"
                ]
            },
            "put": {
                "operationId": "AuthwiseIdentityService_UpdateMessageTemplate",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "messageTemplateId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.MessageTemplate"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "messageTemplate"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.MessageTemplate"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Messaging"
                ]
            }
        },
        "/v1/tenants/{tenantId}/message-templates/{messageTemplateId}/revisions": {
            "get": {
                "operationId": "AuthwiseIdentityService_ListMessageTemplateRevisions",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "messageTemplateId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.ListMessageTemplateRevisionsResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Messaging"
                ]
            }
        },
        "/v1/tenants/{tenantId}/message-templates/{messageTemplateId}:publish": {
            "post": {
                "operationId": "AuthwiseIdentityService_PublishMessageTemplate",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "messageTemplateId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "revisionId": {
                                        "description": "Publish this earlier revision instead of the draft — a revert. One of this template's own revisions, by id (the last segment of its name). Empty publishes the draft. A revert leaves the draft alone.",
                                        "type": "string"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.PublishMessageTemplateResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Messaging"
                ]
            }
        },
        "/v1/tenants/{tenantId}/message-templates:render": {
            "post": {
                "operationId": "AuthwiseIdentityService_RenderMessageTemplate",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "channel": {
                                        "description": "Defaults to \"email\", the only channel that renders.",
                                        "type": "string"
                                    },
                                    "draft": {
                                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.MessageTemplate"
                                    },
                                    "issuer": {
                                        "description": "Which of the tenant's issuers to brand the message for: its id (i-…). The brand is resolved the way a real send on that issuer resolves it — the issuer's default appearance profile, then the tenant's display name and logo, then the issuer's host — and Issuer.URL is that issuer's. Empty picks the tenant's first issuer by id; the response names the one used. Ceremony values (links, codes, roles, times) stay sample. kit#701.",
                                        "type": "string"
                                    },
                                    "key": {
                                        "type": "string"
                                    },
                                    "locale": {
                                        "description": "The locale to render in. Negotiated like a real send, so asking for one that is not stocked returns the one actually used in the response rather than an error.",
                                        "type": "string"
                                    },
                                    "source": {
                                        "description": "What to render: \"published\" (the default, and what an empty value means) is what a recipient receives today; \"draft\" is each stored copy's unpublished draft where it has one, falling back to what is published where it has none. An inline `draft` is laid over either. kit#153.",
                                        "type": "string"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.RenderMessageTemplateResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Messaging"
                ]
            }
        },
        "/v1/tenants/{tenantId}/message-templates:sendTest": {
            "post": {
                "operationId": "AuthwiseIdentityService_SendTestMessage",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "channel": {
                                        "type": "string"
                                    },
                                    "draft": {
                                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.MessageTemplate"
                                    },
                                    "issuer": {
                                        "description": "Which of the tenant's issuers to brand the message for: its id (i-…). The brand is resolved the way a real send on that issuer resolves it — the issuer's default appearance profile, then the tenant's display name and logo, then the issuer's host — and Issuer.URL is that issuer's. Empty picks the tenant's first issuer by id; the response names the one used. Ceremony values (links, codes, roles, times) stay sample. kit#701.",
                                        "type": "string"
                                    },
                                    "key": {
                                        "type": "string"
                                    },
                                    "locale": {
                                        "type": "string"
                                    },
                                    "recipientAddress": {
                                        "description": "Where to send it. Must be the calling administrator's own verified address: a test send is a way to see the message in a real client, not a way to use the admin API to mail somebody else.",
                                        "type": "string"
                                    },
                                    "source": {
                                        "description": "What to render: \"published\" (the default, and what an empty value means) is what a recipient receives today; \"draft\" is each stored copy's unpublished draft where it has one, falling back to what is published where it has none. An inline `draft` is laid over either. kit#153.",
                                        "type": "string"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.SendTestMessageResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Messaging"
                ]
            }
        },
        "/v1/tenants/{tenantId}/realms": {
            "get": {
                "operationId": "AuthwiseIdentityService_ListRealms",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageSize",
                        "schema": {
                            "format": "int32",
                            "type": "integer"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageToken",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "filter",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "orderBy",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.ListRealmsResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Realms"
                ]
            },
            "post": {
                "operationId": "AuthwiseIdentityService_CreateRealm",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Realm"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "realm"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Realm"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Realms"
                ]
            }
        },
        "/v1/tenants/{tenantId}/realms/{realmId}": {
            "delete": {
                "operationId": "AuthwiseIdentityService_DeleteRealm",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "type": "object"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Realms"
                ]
            },
            "get": {
                "operationId": "AuthwiseIdentityService_GetRealm",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Realm"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Realms"
                ]
            },
            "patch": {
                "operationId": "AuthwiseIdentityService_PatchRealm",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "realm": {
                                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Realm"
                                    },
                                    "updateMask": {
                                        "type": "string"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Realm"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Realms"
                ]
            },
            "put": {
                "operationId": "AuthwiseIdentityService_UpdateRealm",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Realm"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "realm"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Realm"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Realms"
                ]
            }
        },
        "/v1/tenants/{tenantId}/realms/{realmId}/factors": {
            "get": {
                "operationId": "AuthwiseIdentityService_ListFactors",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageSize",
                        "schema": {
                            "format": "int32",
                            "type": "integer"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageToken",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "filter",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "orderBy",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.ListFactorsResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Factors"
                ]
            },
            "post": {
                "operationId": "AuthwiseIdentityService_CreateFactor",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Factor"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "factor"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Factor"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Factors"
                ]
            }
        },
        "/v1/tenants/{tenantId}/realms/{realmId}/factors/{factorId}": {
            "delete": {
                "operationId": "AuthwiseIdentityService_DeleteFactor",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "factorId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "type": "object"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Factors"
                ]
            },
            "get": {
                "operationId": "AuthwiseIdentityService_GetFactor",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "factorId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Factor"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Factors"
                ]
            },
            "patch": {
                "operationId": "AuthwiseIdentityService_PatchFactor",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "factorId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "factor": {
                                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Factor"
                                    },
                                    "updateMask": {
                                        "type": "string"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Factor"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Factors"
                ]
            },
            "put": {
                "operationId": "AuthwiseIdentityService_UpdateFactor",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "factorId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Factor"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "factor"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Factor"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Factors"
                ]
            }
        },
        "/v1/tenants/{tenantId}/realms/{realmId}/groups": {
            "get": {
                "operationId": "AuthwiseIdentityService_ListGroups",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageSize",
                        "schema": {
                            "format": "int32",
                            "type": "integer"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageToken",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "filter",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "orderBy",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.ListGroupsResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Groups"
                ]
            },
            "post": {
                "operationId": "AuthwiseIdentityService_CreateGroup",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Group"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "group"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Group"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Groups"
                ]
            }
        },
        "/v1/tenants/{tenantId}/realms/{realmId}/groups/{groupId}": {
            "delete": {
                "operationId": "AuthwiseIdentityService_DeleteGroup",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "groupId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "type": "object"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Groups"
                ]
            },
            "get": {
                "operationId": "AuthwiseIdentityService_GetGroup",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "groupId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Group"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Groups"
                ]
            },
            "patch": {
                "operationId": "AuthwiseIdentityService_PatchGroup",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "groupId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "group": {
                                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Group"
                                    },
                                    "updateMask": {
                                        "type": "string"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Group"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Groups"
                ]
            },
            "put": {
                "operationId": "AuthwiseIdentityService_UpdateGroup",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "groupId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Group"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "group"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Group"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Groups"
                ]
            }
        },
        "/v1/tenants/{tenantId}/realms/{realmId}/groups/{groupId}:associateUsers": {
            "post": {
                "operationId": "AuthwiseIdentityService_AssociateUsersToGroup",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "groupId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "association": {
                                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.AssociationRequest"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "type": "object"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Groups"
                ]
            }
        },
        "/v1/tenants/{tenantId}/realms/{realmId}/groups/{groupId}:listUsers": {
            "get": {
                "operationId": "AuthwiseIdentityService_ListUsersByGroup",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "groupId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageSize",
                        "schema": {
                            "format": "int32",
                            "type": "integer"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageToken",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "filter",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "orderBy",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.ListUsersByGroupResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Groups"
                ]
            }
        },
        "/v1/tenants/{tenantId}/realms/{realmId}/providers": {
            "get": {
                "operationId": "AuthwiseIdentityService_ListProviders",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageSize",
                        "schema": {
                            "format": "int32",
                            "type": "integer"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageToken",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "filter",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "orderBy",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.ListProvidersResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Providers"
                ]
            },
            "post": {
                "operationId": "AuthwiseIdentityService_CreateProvider",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Provider"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "provider"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Provider"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Providers"
                ]
            }
        },
        "/v1/tenants/{tenantId}/realms/{realmId}/providers/{providerId}": {
            "delete": {
                "operationId": "AuthwiseIdentityService_DeleteProvider",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "providerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "type": "object"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Providers"
                ]
            },
            "get": {
                "operationId": "AuthwiseIdentityService_GetProvider",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "providerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Provider"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Providers"
                ]
            },
            "patch": {
                "operationId": "AuthwiseIdentityService_PatchProvider",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "providerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "provider": {
                                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Provider"
                                    },
                                    "updateMask": {
                                        "type": "string"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Provider"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Providers"
                ]
            },
            "put": {
                "operationId": "AuthwiseIdentityService_UpdateProvider",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "providerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Provider"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "provider"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Provider"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Providers"
                ]
            }
        },
        "/v1/tenants/{tenantId}/realms/{realmId}/providers/{providerId}:exportSamlMetadata": {
            "get": {
                "operationId": "AuthwiseIdentityService_ExportProviderSamlMetadata",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "providerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "description": "Issuer resource name to render for. Required when the tenant has more than one issuer.",
                        "in": "query",
                        "name": "issuer",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.ExportProviderSamlMetadataResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Providers"
                ]
            }
        },
        "/v1/tenants/{tenantId}/realms/{realmId}/providers/{providerId}:importSamlMetadata": {
            "post": {
                "operationId": "AuthwiseIdentityService_ImportProviderSamlMetadata",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "providerId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "dryRun": {
                                        "description": "Report what would change and write nothing. No certificates are created.",
                                        "type": "boolean"
                                    },
                                    "metadataXml": {
                                        "description": "The partner's metadata document, as published.",
                                        "type": "string"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.ImportProviderSamlMetadataResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Providers"
                ]
            }
        },
        "/v1/tenants/{tenantId}/realms/{realmId}/users": {
            "get": {
                "operationId": "AuthwiseIdentityService_ListUsers",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageSize",
                        "schema": {
                            "format": "int32",
                            "type": "integer"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageToken",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "filter",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "orderBy",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.ListUsersResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Users"
                ]
            },
            "post": {
                "operationId": "AuthwiseIdentityService_CreateUser",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.User"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "user"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.User"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Users"
                ]
            }
        },
        "/v1/tenants/{tenantId}/realms/{realmId}/users/{userId}": {
            "delete": {
                "operationId": "AuthwiseIdentityService_DeleteUser",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "userId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "type": "object"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Users"
                ]
            },
            "get": {
                "operationId": "AuthwiseIdentityService_GetUser",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "userId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.User"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Users"
                ]
            },
            "patch": {
                "operationId": "AuthwiseIdentityService_PatchUser",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "userId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "updateMask": {
                                        "type": "string"
                                    },
                                    "user": {
                                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.User"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.User"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Users"
                ]
            },
            "put": {
                "operationId": "AuthwiseIdentityService_UpdateUser",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "userId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.User"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "user"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.User"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Users"
                ]
            }
        },
        "/v1/tenants/{tenantId}/realms/{realmId}/users/{userId}:listAuthenticators": {
            "get": {
                "operationId": "AuthwiseIdentityService_ListUserAuthenticators",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "userId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.ListUserAuthenticatorsResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Users"
                ]
            }
        },
        "/v1/tenants/{tenantId}/realms/{realmId}/users/{userId}:listDevices": {
            "get": {
                "operationId": "AuthwiseIdentityService_ListUserDevices",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "userId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.ListUserDevicesResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Users"
                ]
            }
        },
        "/v1/tenants/{tenantId}/realms/{realmId}/users/{userId}:listGroups": {
            "get": {
                "operationId": "AuthwiseIdentityService_ListGroupsByUser",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "userId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageSize",
                        "schema": {
                            "format": "int32",
                            "type": "integer"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageToken",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "filter",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "orderBy",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.ListGroupsByUserResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Users"
                ]
            }
        },
        "/v1/tenants/{tenantId}/realms/{realmId}/users/{userId}:listIdentifiers": {
            "get": {
                "operationId": "AuthwiseIdentityService_ListUserIdentifiers",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "userId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.ListUserIdentifiersResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Users"
                ]
            }
        },
        "/v1/tenants/{tenantId}/realms/{realmId}/users/{userId}:removeIdentifier": {
            "post": {
                "operationId": "AuthwiseIdentityService_RemoveUserIdentifier",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "userId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "identifier": {
                                        "description": "The identifier exactly as ListUserIdentifiers reports it.",
                                        "type": "string"
                                    },
                                    "providerId": {
                                        "description": "The provider the identifier signs in through.",
                                        "type": "string"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.RemoveUserIdentifierResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Users"
                ]
            }
        },
        "/v1/tenants/{tenantId}/realms/{realmId}/users/{userId}:resetPassword": {
            "post": {
                "operationId": "AuthwiseIdentityService_ResetUserPassword",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "userId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "locale": {
                                        "description": "BCP 47 tag the e-mail is written in. Optional; empty uses the user's locale, then the realm's, then en.",
                                        "type": "string"
                                    },
                                    "ttl": {
                                        "description": "How long the link stays usable. Empty is 24 hours; at most 7 days.",
                                        "type": "string"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.ResetUserPasswordResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Users"
                ]
            }
        },
        "/v1/tenants/{tenantId}/realms/{realmId}/users/{userId}:revokeAuthenticator": {
            "post": {
                "operationId": "AuthwiseIdentityService_RevokeUserAuthenticator",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "userId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "authenticatorId": {
                                        "type": "string"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "type": "object"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Users"
                ]
            }
        },
        "/v1/tenants/{tenantId}/realms/{realmId}/users/{userId}:revokeDevice": {
            "post": {
                "operationId": "AuthwiseIdentityService_RevokeUserDevice",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "userId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "deviceId": {
                                        "type": "string"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "type": "object"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Users"
                ]
            }
        },
        "/v1/tenants/{tenantId}/realms/{realmId}/users:invite": {
            "post": {
                "operationId": "AuthwiseIdentityService_InviteUser",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "displayName": {
                                        "type": "string"
                                    },
                                    "familyName": {
                                        "type": "string"
                                    },
                                    "givenName": {
                                        "type": "string"
                                    },
                                    "identifier": {
                                        "description": "The login identifier to establish, normally an email address. Required.",
                                        "type": "string"
                                    },
                                    "locale": {
                                        "description": "BCP 47 tag the invitation is written in (kit#344). Optional; empty uses the user's locale, then en. Recorded on a newly created user.",
                                        "type": "string"
                                    },
                                    "providerId": {
                                        "description": "Provider to attach the identifier to. Optional when the realm has exactly one username/password provider.",
                                        "type": "string"
                                    },
                                    "reissue": {
                                        "description": "Re-mint a fresh token for an existing unredeemed invitation, invalidating the previous accept URL.",
                                        "type": "boolean"
                                    },
                                    "roles": {
                                        "description": "Role names to assign in the realm's audiences. Access bindings are NOT granted here.",
                                        "items": {
                                            "type": "string"
                                        },
                                        "type": "array"
                                    },
                                    "ttl": {
                                        "description": "How long the invitation stays redeemable. Empty uses the realm policy's invitation_ttl, then the surface default.",
                                        "type": "string"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.InviteUserResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Users"
                ]
            }
        },
        "/v1/tenants/{tenantId}/realms/{realmId}/users:search": {
            "post": {
                "operationId": "AuthwiseIdentityService_SearchUsers",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "criteria": {
                                        "items": {
                                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.SearchPredicate"
                                        },
                                        "type": "array"
                                    },
                                    "filter": {
                                        "type": "string"
                                    },
                                    "orderBy": {
                                        "type": "string"
                                    },
                                    "pageSize": {
                                        "format": "int32",
                                        "type": "integer"
                                    },
                                    "pageToken": {
                                        "type": "string"
                                    },
                                    "readMask": {
                                        "type": "string"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.SearchUsersResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Users"
                ]
            }
        },
        "/v1/tenants/{tenantId}/realms/{realmId}/users:searchHistogram": {
            "post": {
                "operationId": "AuthwiseIdentityService_UserSearchHistogram",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "criteria": {
                                        "items": {
                                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.SearchPredicate"
                                        },
                                        "type": "array"
                                    },
                                    "histogram": {
                                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.HistogramSpec"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.UserSearchHistogramResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Users"
                ]
            }
        },
        "/v1/tenants/{tenantId}/realms/{realmId}/users:searchPredicates": {
            "get": {
                "operationId": "AuthwiseIdentityService_UserSearchPredicates",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.UserSearchPredicatesResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Users"
                ]
            }
        },
        "/v1/tenants/{tenantId}/realms/{realmId}:authenticationContextSchema": {
            "get": {
                "operationId": "AuthwiseIdentityService_GetRealmAuthenticationContextSchema",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "realmId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.RealmAuthenticationContextSchema"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Realms"
                ]
            }
        },
        "/v1/tenants/{tenantId}/secrets": {
            "get": {
                "operationId": "AuthwiseIdentityService_ListSecrets",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageSize",
                        "schema": {
                            "format": "int32",
                            "type": "integer"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageToken",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "filter",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "orderBy",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.ListSecretsResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Secrets"
                ]
            },
            "post": {
                "operationId": "AuthwiseIdentityService_CreateSecret",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "payload": {
                                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.SecretPayload"
                                    },
                                    "secret": {
                                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Secret"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Secret"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Secrets"
                ]
            }
        },
        "/v1/tenants/{tenantId}/secrets/{secretId}": {
            "delete": {
                "operationId": "AuthwiseIdentityService_DeleteSecret",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "secretId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "type": "object"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Secrets"
                ]
            },
            "get": {
                "operationId": "AuthwiseIdentityService_GetSecret",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "secretId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Secret"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Secrets"
                ]
            },
            "patch": {
                "operationId": "AuthwiseIdentityService_PatchSecret",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "secretId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "secret": {
                                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Secret"
                                    },
                                    "updateMask": {
                                        "type": "string"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Secret"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Secrets"
                ]
            },
            "put": {
                "operationId": "AuthwiseIdentityService_UpdateSecret",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "secretId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Secret"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "secret"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Secret"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Secrets"
                ]
            }
        },
        "/v1/tenants/{tenantId}/secrets/{secretId}:addVersion": {
            "post": {
                "operationId": "AuthwiseIdentityService_AddSecretVersion",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "secretId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "payload": {
                                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.SecretPayload"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Secret"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Secrets"
                ]
            }
        },
        "/v1/tenants/{tenantId}/themes": {
            "get": {
                "operationId": "AuthwiseIdentityService_ListThemes",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageSize",
                        "schema": {
                            "format": "int32",
                            "type": "integer"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageToken",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "filter",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "orderBy",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.identity.v1alpha1.ListThemesResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Themes and Appearance Profiles"
                ]
            },
            "post": {
                "operationId": "AuthwiseIdentityService_CreateTheme",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Theme"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "theme"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Theme"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Themes and Appearance Profiles"
                ]
            }
        },
        "/v1/tenants/{tenantId}/themes/{themeId}": {
            "delete": {
                "operationId": "AuthwiseIdentityService_DeleteTheme",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "themeId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "type": "object"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Themes and Appearance Profiles"
                ]
            },
            "get": {
                "operationId": "AuthwiseIdentityService_GetTheme",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "themeId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Theme"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Themes and Appearance Profiles"
                ]
            },
            "patch": {
                "operationId": "AuthwiseIdentityService_PatchTheme",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "themeId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "theme": {
                                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Theme"
                                    },
                                    "updateMask": {
                                        "type": "string"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Theme"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Themes and Appearance Profiles"
                ]
            },
            "put": {
                "operationId": "AuthwiseIdentityService_UpdateTheme",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "themeId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Theme"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "theme"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Theme"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Themes and Appearance Profiles"
                ]
            }
        }
    },
    "security": [
        {
            "Authwise": []
        }
    ],
    "tags": [
        {
            "name": "AuthwiseIdentityService"
        }
    ]
}