{
    "components": {
        "schemas": {
            "authwise.tenancy.v1alpha1.ListMyTenantsResponse": {
                "properties": {
                    "nextPageToken": {
                        "type": "string"
                    },
                    "tenantMemberships": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.TenantMembership"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.tenancy.v1alpha1.ListTenantMembershipsResponse": {
                "properties": {
                    "nextPageToken": {
                        "type": "string"
                    },
                    "tenantMemberships": {
                        "items": {
                            "$ref": "#/components/schemas/authwise.types.core.v1alpha1.TenantMembership"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.Branding": {
                "description": "Branding is a tenant's brand, by reference to its own assets. kit never\nrenders it; the admin console and the mail brand resolver do.",
                "properties": {
                    "logoAssetId": {
                        "description": "The id segment of an Asset in this tenant whose mime_type is an image\ntype (authwise.io/Asset). Refused when it names no such asset in this\ntenant; deleting the asset is refused while this names it.",
                        "type": "string"
                    },
                    "logoDarkAssetId": {
                        "description": "The same, for a dark colour scheme. Optional: a reader falls back to\nlogo_asset_id. Refused without logo_asset_id — a dark variant of no\nlogo is not a logo.",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.Classification": {
                "default": "CLASSIFICATION_UNSPECIFIED",
                "description": "Classification records which product a Tenant belongs to. The Tenant\nis the isolation boundary in Authwise's product split, so the value\nlives on the Tenant and nowhere else.\n\nCLASSIFICATION_UNSPECIFIED is the protobuf zero value; it is rejected\nby validation and never persists. CLASSIFICATION_WORKPLACE marks the\nhigh-trust population (employees, SSO, MFA, SCIM, no open signup) —\nthe workplace product. CLASSIFICATION_OMNI marks the open-\npopulation, self-signup-friendly tier — the omni product.",
                "enum": [
                    "CLASSIFICATION_UNSPECIFIED",
                    "CLASSIFICATION_WORKPLACE",
                    "CLASSIFICATION_OMNI"
                ],
                "type": "string"
            },
            "authwise.types.core.v1alpha1.CorsConfig": {
                "properties": {
                    "allowedOrigins": {
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    },
                    "allowedOriginsRegexp": {
                        "items": {
                            "type": "string"
                        },
                        "type": "array"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.Tenant": {
                "properties": {
                    "classification": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Classification"
                    },
                    "config": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.TenantConfig"
                    },
                    "displayName": {
                        "type": "string"
                    },
                    "labels": {
                        "additionalProperties": {
                            "type": "string"
                        },
                        "type": "object"
                    },
                    "name": {
                        "description": "Output only. The resource name, rendered from the row's id: the address\nused to GET, PATCH and DELETE this row, not a label. A value sent on\ncreate or update is ignored — the server always builds it from the id.\nFor a human-readable label, use display_name.",
                        "readOnly": true,
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "authwise.types.core.v1alpha1.TenantConfig": {
                "properties": {
                    "accessTokenExpireSeconds": {
                        "format": "int32",
                        "type": "integer"
                    },
                    "branding": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Branding"
                    },
                    "cors": {
                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.CorsConfig"
                    },
                    "interactionForwardUri": {
                        "type": "string"
                    },
                    "refreshTokenAbsoluteExpireSeconds": {
                        "format": "int32",
                        "type": "integer"
                    },
                    "refreshTokenExpireSeconds": {
                        "format": "int32",
                        "type": "integer"
                    }
                },
                "title": "TODO - config split between this and issuer",
                "type": "object"
            },
            "authwise.types.core.v1alpha1.TenantMembership": {
                "description": "TenantMembership is a SEAT: it joins a console-realm subject (typically a\nuser, but also clients via client_credentials) to a customer tenant, and\nsays the subject may interact with that tenant at all. It says nothing\nabout what they may do inside it — that is what access bindings say.\n\nSince kit#501 this message is a PROJECTION, not a table. A seat is an\naccess binding of a role carrying the `tenancy.member` permission, anchored\nat the tenant or at the platform root; `tenant_memberships` is gone. The\nwire shape is unchanged, and so is every semantic below it. See\ndocswip/TENANCY.md Part 5.",
                "properties": {
                    "createdAt": {
                        "format": "date-time",
                        "title": "@gotags: yaml:\"created_at\"",
                        "type": "string"
                    },
                    "createdBy": {
                        "title": "@gotags: yaml:\"created_by\"",
                        "type": "string"
                    },
                    "kind": {
                        "description": "The seat role, rendered in the OWNER / MEMBER / OPERATOR vocabulary.\n\nOn READ all three occur: OWNER is `tenancy.owner`, OPERATOR is a\nroot-anchored `tenancy.operator` binding reaching this tenant, and MEMBER\nis `tenancy.member` or any other role carrying the permission.\n\nOn WRITE only OWNER and MEMBER are accepted. Operator status is an estate\nproperty conferred by the tenancy admin's GrantOperator, never by a seat\nwrite, so OPERATOR is rejected here with INVALID_ARGUMENT.\n\n@gotags: yaml:\"kind\"",
                        "type": "string"
                    },
                    "name": {
                        "description": "Output only. The resource name, \"tenants/{tenantId}/tenant-memberships/\n{userId}\": the address used to GET, PATCH and DELETE this seat. The last\nsegment is the SUBJECT id, because the (subject, tenant) pair is what\nidentifies a seat here — a subject holds one seat at a tenant whatever\nrole carries it. The binding underneath has an id of its own, which this\nsurface deliberately does not expose; a caller that wants to address the\nrow goes to the Access API. A value sent on create or update is ignored.",
                        "readOnly": true,
                        "type": "string"
                    },
                    "targetTenantId": {
                        "title": "@gotags: yaml:\"target_tenant_id\"",
                        "type": "string"
                    },
                    "updatedAt": {
                        "format": "date-time",
                        "title": "@gotags: yaml:\"updated_at\"",
                        "type": "string"
                    },
                    "userId": {
                        "title": "@gotags: yaml:\"user_id\"",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "google.protobuf.Any": {
                "additionalProperties": {},
                "description": "`Any` contains an arbitrary serialized protocol buffer message along with a\nURL that describes the type of the serialized message.\n\nProtobuf library provides support to pack/unpack Any values in the form\nof utility functions or additional generated methods of the Any type.\n\nExample 1: Pack and unpack a message in C++.\n\n    Foo foo = ...;\n    Any any;\n    any.PackFrom(foo);\n    ...\n    if (any.UnpackTo(\u0026foo)) {\n      ...\n    }\n\nExample 2: Pack and unpack a message in Java.\n\n    Foo foo = ...;\n    Any any = Any.pack(foo);\n    ...\n    if (any.is(Foo.class)) {\n      foo = any.unpack(Foo.class);\n    }\n\nExample 3: Pack and unpack a message in Python.\n\n    foo = Foo(...)\n    any = Any()\n    any.Pack(foo)\n    ...\n    if any.Is(Foo.DESCRIPTOR):\n      any.Unpack(foo)\n      ...\n\nExample 4: Pack and unpack a message in Go\n\n     foo := \u0026pb.Foo{...}\n     any, err := anypb.New(foo)\n     if err != nil {\n       ...\n     }\n     ...\n     foo := \u0026pb.Foo{}\n     if err := any.UnmarshalTo(foo); err != nil {\n       ...\n     }\n\nThe pack methods provided by protobuf library will by default use\n'type.googleapis.com/full.type.name' as the type URL and the unpack\nmethods only use the fully qualified type name after the last '/'\nin the type URL, for example \"foo.bar.com/x/y.z\" will yield type\nname \"y.z\".\n\n\nJSON\n\nThe JSON representation of an `Any` value uses the regular\nrepresentation of the deserialized, embedded message, with an\nadditional field `@type` which contains the type URL. Example:\n\n    package google.profile;\n    message Person {\n      string first_name = 1;\n      string last_name = 2;\n    }\n\n    {\n      \"@type\": \"type.googleapis.com/google.profile.Person\",\n      \"firstName\": \u003cstring\u003e,\n      \"lastName\": \u003cstring\u003e\n    }\n\nIf the embedded message type is well-known and has a custom JSON\nrepresentation, that representation will be embedded adding a field\n`value` which holds the custom JSON in addition to the `@type`\nfield. Example (for message [google.protobuf.Duration][]):\n\n    {\n      \"@type\": \"type.googleapis.com/google.protobuf.Duration\",\n      \"value\": \"1.212s\"\n    }",
                "properties": {
                    "@type": {
                        "description": "A URL/resource name that uniquely identifies the type of the serialized\nprotocol buffer message. This string must contain at least\none \"/\" character. The last segment of the URL's path must represent\nthe fully qualified name of the type (as in\n`path/google.protobuf.Duration`). The name should be in a canonical form\n(e.g., leading \".\" is not accepted).\n\nIn practice, teams usually precompile into the binary all types that they\nexpect it to use in the context of Any. However, for URLs which use the\nscheme `http`, `https`, or no scheme, one can optionally set up a type\nserver that maps type URLs to message definitions as follows:\n\n* If no scheme is provided, `https` is assumed.\n* An HTTP GET on the URL must yield a [google.protobuf.Type][]\n  value in binary format, or produce an error.\n* Applications are allowed to cache lookup results based on the\n  URL, or have them precompiled into a binary to avoid any\n  lookup. Therefore, binary compatibility needs to be preserved\n  on changes to types. (Use versioned type names to manage\n  breaking changes.)\n\nNote: this functionality is not currently available in the official\nprotobuf release, and it is not used for type URLs beginning with\ntype.googleapis.com.\n\nSchemes other than `http`, `https` (or the empty scheme) might be\nused with implementation specific semantics.",
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "google.rpc.Status": {
                "properties": {
                    "code": {
                        "format": "int32",
                        "type": "integer"
                    },
                    "details": {
                        "items": {
                            "$ref": "#/components/schemas/google.protobuf.Any"
                        },
                        "type": "array"
                    },
                    "message": {
                        "type": "string"
                    }
                },
                "type": "object"
            }
        },
        "securitySchemes": {
            "Authwise": {
                "type": "openIdConnect",
                "openIdConnectUrl": "/.well-known/openid-configuration"
            }
        }
    },
    "info": {
        "title": "authwise/tenancy/v1alpha1/grpc.proto",
        "version": "version not set"
    },
    "openapi": "3.0.3",
    "paths": {
        "/v1/tenants": {
            "get": {
                "operationId": "AuthwiseTenancyService_ListMyTenants",
                "parameters": [
                    {
                        "in": "query",
                        "name": "pageSize",
                        "schema": {
                            "format": "int32",
                            "type": "integer"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageToken",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.tenancy.v1alpha1.ListMyTenantsResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Tenants"
                ]
            }
        },
        "/v1/tenants/{tenantId}": {
            "get": {
                "operationId": "AuthwiseTenancyService_GetTenant",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Tenant"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Tenants"
                ]
            },
            "patch": {
                "operationId": "AuthwiseTenancyService_PatchTenant",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "tenant": {
                                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Tenant"
                                    },
                                    "updateMask": {
                                        "type": "string"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Tenant"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Tenants"
                ]
            },
            "put": {
                "operationId": "AuthwiseTenancyService_UpdateTenant",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Tenant"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "tenant"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.Tenant"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Tenants"
                ]
            }
        },
        "/v1/tenants/{tenantId}/tenant-memberships": {
            "get": {
                "operationId": "AuthwiseTenancyService_ListTenantMemberships",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageSize",
                        "schema": {
                            "format": "int32",
                            "type": "integer"
                        }
                    },
                    {
                        "in": "query",
                        "name": "pageToken",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "filter",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "orderBy",
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.tenancy.v1alpha1.ListTenantMembershipsResponse"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Tenant Memberships"
                ]
            },
            "post": {
                "operationId": "AuthwiseTenancyService_CreateTenantMembership",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/authwise.types.core.v1alpha1.TenantMembership"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "tenantMembership"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.TenantMembership"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Tenant Memberships"
                ]
            }
        },
        "/v1/tenants/{tenantId}/tenant-memberships/{tenantMembershipId}": {
            "delete": {
                "operationId": "AuthwiseTenancyService_DeleteTenantMembership",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "tenantMembershipId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "type": "object"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Tenant Memberships"
                ]
            },
            "get": {
                "operationId": "AuthwiseTenancyService_GetTenantMembership",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "tenantMembershipId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "query",
                        "name": "readMask",
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.TenantMembership"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Tenant Memberships"
                ]
            },
            "patch": {
                "operationId": "AuthwiseTenancyService_PatchTenantMembership",
                "parameters": [
                    {
                        "in": "path",
                        "name": "tenantId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "in": "path",
                        "name": "tenantMembershipId",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "content": {
                        "application/json": {
                            "schema": {
                                "properties": {
                                    "tenantMembership": {
                                        "$ref": "#/components/schemas/authwise.types.core.v1alpha1.TenantMembership"
                                    },
                                    "updateMask": {
                                        "type": "string"
                                    }
                                },
                                "type": "object"
                            }
                        }
                    },
                    "required": true,
                    "x-originalParamName": "body"
                },
                "responses": {
                    "200": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/authwise.types.core.v1alpha1.TenantMembership"
                                }
                            }
                        },
                        "description": "A successful response."
                    },
                    "default": {
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/google.rpc.Status"
                                }
                            }
                        },
                        "description": "An unexpected error response."
                    }
                },
                "tags": [
                    "Tenant Memberships"
                ]
            }
        }
    },
    "security": [
        {
            "Authwise": []
        }
    ],
    "tags": [
        {
            "name": "AuthwiseTenancyService"
        }
    ]
}