A AuthMS API Wiki API Reference iam.tianv.com →

Identity Service

Port 11001 · 261 endpoints · micro-services/identity-service/

API Key

MethodPathSummary
GET/admin/auth/api-keys管理员查询 API Key 列表detail →
GET/admin/auth/api-keys/anomalies安全异常检测detail →
POST/admin/auth/api-keys/batch-revoke批量吊销 API Keydetail →
POST/admin/auth/api-keys/cleanup-audit-logs清理旧审计日志detail →
GET/admin/auth/api-keys/expiring获取即将过期的 API Keydetail →
GET/admin/auth/api-keys/stats管理员 API Key 统计detail →
DELETE/admin/auth/api-keys/{id}/force管理员强制吊销 API Keydetail →
GET/auth/api-keys查询 API Key 列表detail →
POST/auth/api-keys创建 API Keydetail →
DELETE/auth/api-keys/{id}吊销 API Keydetail →
GET/auth/api-keys/{id}获取 API Key 详情detail →
GET/auth/api-keys/{id}/audit-logs获取 API Key 审计日志detail →
POST/auth/api-keys/{id}/ip-restrictions添加 IP 限制detail →
DELETE/auth/api-keys/{id}/ip-restrictions/{restriction_id}删除 IP 限制detail →
POST/auth/api-keys/{id}/rotate轮换 API Keydetail →
PUT/auth/api-keys/{id}/scopes更新 API Key 权限范围detail →
PUT/auth/api-keys/{id}/status启用/禁用 API Keydetail →
GET/auth/api-keys/{id}/usage获取 API Key 使用统计detail →
GET/auth/api-keys/{id}/usage-stats获取 API Key 使用统计detail →
POST/internal/identity/validate-key验证 API Key(内部)detail →

Admin

MethodPathSummary
GET/admin/users/{user_id}/oauth-connections管理员查看用户OAuth连接detail →

Admin/Agents

MethodPathSummary
GET/admin/agentsList Agentsdetail →
POST/admin/agentsCreate Agentdetail →
DELETE/admin/agents/{id}Revoke Agentdetail →
GET/admin/agents/{id}Get Agentdetail →
PUT/admin/agents/{id}Update Agentdetail →

Admin/IoTs

MethodPathSummary
GET/admin/iotsList Devicesdetail →
POST/admin/iotsCreate Devicedetail →
DELETE/admin/iots/{id}Revoke Devicedetail →
GET/admin/iots/{id}Get Devicedetail →

Admin/Robots

MethodPathSummary
GET/admin/robotsList Robotsdetail →
POST/admin/robotsCreate Robotdetail →
DELETE/admin/robots/{id}Delete Robotdetail →
GET/admin/robots/{id}Get Robotdetail →
PUT/admin/robots/{id}Update Robotdetail →
POST/admin/robots/{id}/commissionCommission Robotdetail →
POST/admin/robots/{id}/decommissionDecommission Robotdetail →
POST/admin/robots/{id}/intentIssue Intent Tokendetail →
POST/admin/robots/{id}/intent/revokeRevoke Intent Tokendetail →

IoTs

MethodPathSummary
GET/iotsList User Devicesdetail →
POST/iots/pairPair Devicedetail →
DELETE/iots/{id}Unpair Devicedetail →
POST/iots/{id}/transferTransfer Devicedetail →

NHI管理

MethodPathSummary
GET/admin/policies/nhi获取NHI策略detail →
PUT/admin/policies/nhi更新NHI策略detail →

OAuth

MethodPathSummary
GET/admin/users/{user_id}/oauth-connections管理员查看用户OAuth连接detail →

OAuth授权

MethodPathSummary
POST/auth/oidc/backchannel-logoutOIDC后通道登出detail →
POST/auth/oidc/logoutRP发起登出detail →
GET/auth/oidc/session-iframeOIDC会话状态iframedetail →

SAML

MethodPathSummary
POST/saml/{provider_id}/acs断言消费服务detail →
GET/saml/{provider_id}/loginSP-initiated SSOdetail →
GET/saml/{provider_id}/metadata获取SP元数据detail →
GET/saml/{provider_id}/slo单点登出detail →
GET/saml/{provider_id}/slo/spSP发起的SAML单点登出detail →

SAML Admin

MethodPathSummary
GET/admin/saml/providers列出SAML IdPdetail →
POST/admin/saml/providers注册SAML IdPdetail →
DELETE/admin/saml/providers/{id}删除SAML IdPdetail →
GET/admin/saml/providers/{id}获取SAML IdP详情detail →
PUT/admin/saml/providers/{id}更新SAML IdPdetail →
PUT/admin/saml/providers/{id}/attribute-mapping更新属性映射detail →

SCIM

MethodPathSummary
GET/scim/Groups列出SCIM组detail →
POST/scim/Groups创建SCIM组detail →
DELETE/scim/Groups/{id}删除SCIM组detail →
GET/scim/Groups/{id}获取SCIM组detail →
PATCH/scim/Groups/{id}部分更新SCIM组detail →
PUT/scim/Groups/{id}更新SCIM组detail →
GET/scim/ResourceTypesSCIM资源类型detail →
GET/scim/SchemasSCIM Schemasdetail →
GET/scim/ServiceProviderConfigSCIM服务提供商配置detail →
GET/scim/Users列出SCIM用户detail →
POST/scim/Users创建SCIM用户detail →
DELETE/scim/Users/{id}删除SCIM用户detail →
GET/scim/Users/{id}获取SCIM用户detail →
PATCH/scim/Users/{id}部分更新SCIM用户detail →
PUT/scim/Users/{id}更新SCIM用户detail →

WebAuthn

MethodPathSummary
GET/auth/me/webauthn-credentials获取已注册的Passkey列表detail →
DELETE/auth/me/webauthn-credentials/{id}删除Passkeydetail →
POST/auth/webauthn/authenticate/begin开始Passkey公开认证detail →
POST/auth/webauthn/authenticate/complete完成Passkey公开认证detail →
POST/auth/webauthn/login/begin开始Passkey登录detail →
POST/auth/webauthn/login/complete完成Passkey登录detail →
POST/auth/webauthn/register/begin开始Passkey注册detail →
POST/auth/webauthn/register/complete完成Passkey注册detail →

internal

MethodPathSummary
POST/internal/seed-providerSeed SAML provider (dev only)detail →

会话与设备

MethodPathSummary
GET/auth/me/authenticator/backupdetail →
POST/auth/me/authenticator/backupdetail →
DELETE/auth/me/authenticator/backup/{id}detail →
GET/auth/me/authenticator/devicesdetail →
DELETE/auth/me/authenticator/devices/{id}移除认证器设备detail →
POST/auth/qr-login/cancel取消二维码登录detail →
POST/auth/qr-login/confirm确认二维码登录detail →
POST/auth/qr-login/initiate发起二维码登录detail →
POST/auth/qr-login/scan扫描二维码登录detail →
GET/auth/qr-login/status查询二维码登录状态detail →
DELETE/devices移除所有设备detail →
GET/devices获取用户设备列表detail →
DELETE/devices/{id}移除设备detail →
PUT/devices/{id}/trust信任/取消信任设备detail →

多因素认证

MethodPathSummary
POST/auth/mfa/verify-challenge验证MFA挑战detail →

安全

MethodPathSummary
GET/admin/security/risk-events风险事件列表detail →
GET/admin/security/risk-events/aggregation风险事件聚合detail →

安全策略

MethodPathSummary
GET/admin/security/auth-config获取认证配置detail →
PUT/admin/security/auth-config更新认证配置detail →
GET/admin/security/password-policy获取密码策略detail →
PUT/admin/security/password-policy更新密码策略detail →
GET/admin/security/password-stats获取密码统计detail →

未成年人管理

MethodPathSummary
POST/admin/users/{user_id}/children-consent/deny拒绝儿童同意detail →
POST/admin/users/{user_id}/children-consent/verify验证儿童同意detail →

角色权限

MethodPathSummary
GET/admin/abac-policies查询ABAC策略列表detail →
POST/admin/abac-policies创建ABAC策略detail →
DELETE/admin/abac-policies/{id}删除ABAC策略detail →
GET/admin/abac-policies/{id}获取ABAC策略详情detail →
PUT/admin/abac-policies/{id}更新ABAC策略detail →
POST/admin/relationships/check检查关系权限detail →
GET/admin/relationships/expand展开关系树detail →
GET/admin/role-activations查询角色激活记录detail →
POST/admin/role-activations/{id}/approve批准角色激活detail →
POST/admin/role-activations/{id}/revoke撤销角色激活detail →
GET/auth/me/role-activations查询我的角色激活detail →
POST/auth/me/role-activations请求角色激活detail →
POST/internal/pim/cleanup-expired清理过期角色激活detail →

认证策略管理

MethodPathSummary
GET/admin/auth-policies获取租户认证策略列表detail →
DELETE/admin/auth-policies/{tenant_id}删除租户认证策略detail →
GET/admin/auth-policies/{tenant_id}获取租户认证策略detail →
PUT/admin/auth-policies/{tenant_id}更新租户认证策略detail →

账户管理

MethodPathSummary
POST/admin/impersonate管理员模拟用户登录detail →
GET/admin/users查询用户列表detail →
POST/admin/users创建用户detail →
POST/admin/users/batch批量创建用户detail →
POST/admin/users/batch/status批量更新用户状态detail →
POST/admin/users/merge合并用户detail →
DELETE/admin/users/{user_id}删除用户detail →
GET/admin/users/{user_id}获取用户详情detail →
PUT/admin/users/{user_id}更新用户信息detail →
POST/admin/users/{user_id}/account-unlocks解锁账户detail →
GET/admin/users/{user_id}/identities获取用户身份列表detail →
POST/admin/users/{user_id}/identities添加用户身份detail →
DELETE/admin/users/{user_id}/identities/{identity_id}移除用户身份detail →
PUT/admin/users/{user_id}/identities/{identity_id}/set-primary设置主身份detail →
POST/admin/users/{user_id}/identities/{identity_id}/verifications验证用户身份detail →
POST/admin/users/{user_id}/impersonate管理员模拟用户detail →
GET/admin/users/{user_id}/login-histories获取登录历史detail →
GET/admin/users/{user_id}/security-status获取安全状态detail →
PUT/admin/users/{user_id}/status更新用户状态detail →
DELETE/auth/me停用当前账户detail →
GET/auth/me/audit-logs获取我的审计日志detail →
GET/auth/me/children-consent获取儿童隐私同意状态detail →
DELETE/auth/me/consent撤销用户同意detail →
POST/auth/me/consent记录用户同意detail →
GET/auth/me/consent-history获取同意历史记录detail →
POST/auth/me/delete-account永久删除账户 (GDPR 被遗忘权/账户删除)detail →
GET/auth/me/devices获取我的设备列表detail →
DELETE/auth/me/devices/{device_id}移除设备detail →
PUT/auth/me/devices/{device_id}/trust信任/取消信任设备detail →
POST/auth/me/email/change变更邮箱地址detail →
POST/auth/me/email/verify验证邮箱变更detail →
POST/auth/me/export-data导出我的数据 (GDPR DSAR)detail →
GET/auth/me/memberships获取我的租户成员状态detail →
POST/auth/me/phone/change变更手机号detail →
POST/auth/me/phone/verify验证手机号变更detail →
GET/auth/me/recovery-contacts获取恢复联系人列表detail →
POST/auth/me/recovery-contacts添加恢复联系人detail →
DELETE/auth/me/recovery-contacts/{contact_id}移除恢复联系人detail →
GET/auth/me/saml-links获取SAML关联账户列表detail →
DELETE/auth/me/saml-links/{id}解绑SAML关联账户detail →
GET/auth/me/security-events获取安全事件列表detail →
POST/auth/me/security-events/{event_id}/dismiss关闭安全事件提醒detail →
DELETE/auth/me/sessions登出所有会话detail →
GET/auth/me/sessions获取我的会话列表detail →
DELETE/auth/me/sessions/{session_id}登出指定会话detail →
POST/auth/me/stop-impersonation结束模拟会话detail →
DELETE/internal/identity/erase-user/{user_id}内部硬删除用户detail →
POST/internal/maker-checker/record记录双人复核detail →

身份提供商

MethodPathSummary
GET/admin/identity-providers列出身份提供商detail →
POST/admin/identity-providers创建身份提供商detail →
POST/admin/identity-providers/import-oidc-discovery导入OIDC Discoverydetail →
POST/admin/identity-providers/import-saml-metadata导入SAML Metadatadetail →
DELETE/admin/identity-providers/{id}删除身份提供商detail →
GET/admin/identity-providers/{id}获取身份提供商详情detail →
PUT/admin/identity-providers/{id}更新身份提供商detail →
POST/admin/identity-providers/{id}/activate启用身份提供商detail →
GET/admin/identity-providers/{id}/attribute-mapping获取属性映射detail →
PUT/admin/identity-providers/{id}/attribute-mapping更新属性映射detail →
GET/admin/identity-providers/{id}/certificates列出证书detail →
POST/admin/identity-providers/{id}/certificates上传证书detail →
DELETE/admin/identity-providers/{id}/certificates/{cert_id}删除证书detail →
POST/admin/identity-providers/{id}/certificates/{cert_id}/rotate证书轮转detail →
POST/admin/identity-providers/{id}/deactivate停用身份提供商detail →
GET/admin/identity-providers/{id}/jit-config获取JIT配置detail →
PUT/admin/identity-providers/{id}/jit-config更新JIT配置detail →
GET/admin/identity-providers/{id}/stats获取提供商统计detail →
POST/admin/identity-providers/{id}/test测试身份提供商连接detail →
GET/admin/identity-providers/{id}/users获取提供商关联用户detail →

身份认证

MethodPathSummary
PUT/admin/users/{user_id}/password修改密码detail →
POST/admin/users/{user_id}/password-resets重置密码detail →
GET/admin/users/{user_id}/password-status获取用户密码状态detail →
POST/auth/anonymous匿名认证detail →
GET/auth/captcha/challenge获取CAPTCHA挑战detail →
POST/auth/forgot-password忘记密码detail →
POST/auth/generate-ticket生成一次性票据detail →
POST/auth/id-token/signinID Token登录detail →
POST/auth/login用户登录detail →
POST/auth/login/email-code邮箱验证码登录detail →
POST/auth/login/phone-code手机验证码登录detail →
GET/auth/magic-link/callback魔法链接回调 (GET→POST 双步跳转)detail →
POST/auth/magic-link/callback魔法链接回调 (GET→POST 双步跳转)detail →
POST/auth/magic-link/request请求发送魔法链接detail →
GET/auth/me获取当前登录用户信息detail →
PUT/auth/me更新当前用户信息detail →
GET/auth/me/email-verification-status检查邮箱验证状态detail →
PUT/auth/me/password修改当前用户密码detail →
POST/auth/me/password-strength检查密码强度detail →
GET/auth/me/permissions获取当前用户权限detail →
GET/auth/me/phone-verification-status检查手机号验证状态detail →
POST/auth/me/switch-tenant切换当前租户detail →
GET/auth/me/tenants获取当前用户租户detail →
GET/auth/oauth/accounts获取用户OAuth账号列表detail →
POST/auth/oauth/bind绑定OAuth账号detail →
GET/auth/oauth/providers获取OAuth提供商列表detail →
POST/auth/oauth/unbind解绑OAuth账号detail →
GET/auth/oauth/{provider}发起OAuth登录detail →
GET/auth/oauth/{provider}/callbackOAuth回调detail →
POST/auth/re-authenticate重新认证(Step-up)detail →
POST/auth/recover-account通过恢复联系人初始化账户恢复detail →
POST/auth/recover-account/reset通过恢复码重置密码detail →
POST/auth/recovery/complete完成账户恢复detail →
POST/auth/recovery/request发起账户恢复detail →
POST/auth/recovery/verify验证账户恢复码detail →
POST/auth/refresh刷新访问令牌detail →
POST/auth/register用户注册detail →
GET/auth/register/check-email检查邮箱是否可用detail →
POST/auth/register/check-email检查邮箱是否可用detail →
GET/auth/register/check-username检查用户名是否可用detail →
POST/auth/register/check-username检查用户名是否可用detail →
POST/auth/register/email-code邮箱验证码注册detail →
POST/auth/register/invitation邀请注册detail →
POST/auth/register/oauthOAuth补充注册detail →
POST/auth/register/phone-code手机验证码注册detail →
POST/auth/register/reapply重新申请注册detail →
POST/auth/resend-sms-code重新发送短信验证码detail →
POST/auth/resend-verification-email重新发送邮箱验证邮件detail →
POST/auth/reset-password重置密码detail →
POST/auth/send-login-code发送登录验证码detail →
POST/auth/send-sms-code发送短信验证码detail →
POST/auth/send-verification-email发送邮箱验证邮件detail →
POST/auth/sso/callback企业SSO回调detail →
POST/auth/sso/initiate启动企业SSO登录detail →
POST/auth/ticket/signin票据签名登录detail →
POST/auth/verify-email验证邮箱地址detail →
POST/auth/verify-phone验证手机号detail →
POST/auth/verify-reset-code验证重置验证码detail →
POST/auth/web3/verify验证Web3钱包签名detail →
POST/internal/identity/verify-password验证密码detail →
POST/internal/record-login-failure记录登录失败detail →
POST/internal/record-login-success记录登录成功detail →
GET/public/auth-config/by-domain/{domain}根据域名获取租户认证配置(公开)detail →
GET/public/auth-config/by-identifier根据标识符发现租户detail →
GET/public/auth-config/by-slug/{slug}根据租户标识获取认证配置(公开)detail →
GET/public/auth-config/{tenant_id}获取租户认证配置(公开)detail →
POST/public/password-strength检查密码强度(公开)detail →
GET/public/tenants/discover发现公开可加入的租户detail →

身份认证 - 内部接口

MethodPathSummary
GET/public/key-exchangeECDH 密钥交换detail →