openapi: 3.1.0
info:
  title: Indigo Certificate Management Service - Reseller API
  description: |-
    This API provides operations for certificate resellers to manage creation and
    verification of certificates for customer accounts. <br />

    <h3>Authentication</h3>
    <p>The reseller API is protected by a machine-to-machine OAuth2 flow.
    Clients use a long-lived client_id and client_secret to perform a
    credential exchange with Auth0 to obtain a short-lived access token.
    The access token is then used to authenticate with this API.</p>
    <p>Example token request (line breaks added for readability):</p>
    <p><code>curl --request POST</code><br />
    <code>--url https://hues-pte.us.auth0.com/oauth/token</code><br />
    <code>--header 'content-type: application/json'</code><br />
    <code>--data '{</code><br />
    <code>&nbsp;&nbsp;"client_id":"YOUR_CLIENT_ID",</code><br />
    <code>&nbsp;&nbsp;"client_secret":"YOUR_CLIENT_SECRET",</code><br />
    <code>&nbsp;&nbsp;"audience":"https://reseller.cms.pte.identrust.com/reseller",</code><br />
    <code>&nbsp;&nbsp;"grant_type":"client_credentials"</code><br />
    <code>}'</code></p>
  version: 1.0.155
servers:
  - url: https://reseller-cms-pte.identrust.com
    description: Generated server url
security:
  - OAuth2Reseller: []
tags:
  - name: Authorizations
    description: Operations to create, view, and delete order authorizations
  - name: Certificates
    description: Certificate API operations
  - name: EAB Credential
    description: EAB Credential Operations
  - name: Account
    description: Account Operations
  - name: Challenges
    description: Business operations to choose domain challenges or delete the order associated to it.
  - name: Account Group
    description: Reseller account group operations
  - name: Orders
    description: Operations to create, view, and delete orders
  - name: Policy
    description: Reseller issuance policy operations
paths:
  /v1/policy/{lookup}:
    get:
      tags:
        - Policy
      summary: Get reseller issuance policy by lookup
      operationId: getPolicyByLookup
      parameters:
        - name: lookup
          in: path
          required: true
          schema:
            type: string
      responses:
        "200":
          description: Policy returned.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/IssuancePolicyRecord'
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "404":
          description: Issuance policy not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
    put:
      tags:
        - Policy
      summary: Update reseller issuance policy
      operationId: updatePolicy
      parameters:
        - name: lookup
          in: path
          required: true
          schema:
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/IssuancePolicy'
        required: true
      responses:
        "200":
          description: Policy updated.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/IssuancePolicyRecord'
        "400":
          description: Malformed request.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "404":
          description: Issuance policy not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
    delete:
      tags:
        - Policy
      summary: Delete reseller issuance policy
      operationId: deletePolicy
      parameters:
        - name: lookup
          in: path
          required: true
          schema:
            type: string
      responses:
        "200":
          description: Policy deleted.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SuccessResponse'
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "404":
          description: Issuance policy not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
  /v1/account-group/{group_lookup}:
    get:
      tags:
        - Account Group
      summary: Get reseller account group by lookup
      operationId: getAccountGroup
      parameters:
        - name: group_lookup
          in: path
          required: true
          schema:
            type: string
      responses:
        "200":
          description: Account group returned.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AccountGroupRecord'
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "404":
          description: Account group not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
    put:
      tags:
        - Account Group
      summary: Update reseller account group
      operationId: updateAccountGroup
      parameters:
        - name: group_lookup
          in: path
          required: true
          schema:
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ResellerAccountGroupRequest'
        required: true
      responses:
        "200":
          description: Account group updated.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AccountGroupRecord'
        "400":
          description: Malformed request.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "404":
          description: Account group not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
    delete:
      tags:
        - Account Group
      summary: Delete reseller account group
      operationId: deleteAccountGroup
      parameters:
        - name: group_lookup
          in: path
          required: true
          schema:
            type: string
      responses:
        "200":
          description: Account group deleted.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SuccessResponse'
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "404":
          description: Account group not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
  /v1/validate-csr:
    post:
      tags:
        - Certificates
      summary: Validate CSR
      description: Validate the provided CSR and return the result.
      operationId: validateCsr
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ResellerValidateCsrRequest'
        required: true
      responses:
        "200":
          description: CSR is valid
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "400":
          description: CSR is invalid
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
  /v1/policy:
    get:
      tags:
        - Policy
      summary: List reseller issuance policies
      operationId: getPolicies
      parameters:
        - name: limit
          in: query
          description: Maximum number of results to return.
          required: false
          schema:
            type: string
            default: ""
          example: 100
        - name: cursor
          in: query
          description: Cursor from a previous response to fetch the next page.
          required: false
          schema:
            type: string
            default: ""
          example: AbCdEf123456
      responses:
        "200":
          description: Policies returned.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PolicyList'
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
    post:
      tags:
        - Policy
      summary: Create reseller issuance policy
      operationId: createPolicy
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/IssuancePolicy'
        required: true
      responses:
        "200":
          description: Policy created.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/IssuancePolicyRecord'
        "400":
          description: Malformed request.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
  /v1/order:
    post:
      tags:
        - Orders
      summary: Create order
      description: Create a new order for the account referenced Account ID.
      operationId: createNewOrder
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ResellerOrderRequest'
        required: true
      responses:
        "201":
          description: New order was created.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Order'
        "400":
          description: Order arguments were invalid.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
        "404":
          description: User does not exist.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
        "410":
          description: User requesting the order was terminated.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
  /v1/order/{order_lookup}/finalize:
    post:
      tags:
        - Orders
      summary: Finalize order
      description: Finalize the certificate order and return a reference for downloading the certificate
      operationId: finalizeOrder
      parameters:
        - name: order_lookup
          in: path
          description: The order lookup value
          required: true
          schema:
            type: string
            default: ""
          example: order123
      responses:
        "202":
          description: The finalization request has been accepted. Poll /certificate/{certificate_lookup} to download issued certificate
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Order'
        "208":
          description: The finalization request was already submitted and accepted. The current order state is returned.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Order'
        "404":
          description: Order does not exist.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
        "410":
          description: The requested order was canceled.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
  /v1/challenge/{challenge_lookup}:
    post:
      tags:
        - Challenges
      summary: Create verification challenges
      description: Certificate Management Service should validate the selected challenge, referenced by the provided lookup value
      operationId: chooseChallengeForVerification
      parameters:
        - name: challenge_lookup
          in: path
          description: The challenge lookup value
          required: true
          schema:
            type: string
            default: ""
          example: challenge123
      responses:
        "200":
          description: The was state was updated to allow for verification.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Challenge'
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "404":
          description: Challenge or its associated authorization or account was not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
        "410":
          description: The verification has already been attempted. Response includes the current state of the challenge
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
    delete:
      tags:
        - Challenges
      summary: Delete challenge
      description: Deactivate the authorization associated to the challenge referenced by this lookup value and cancel the order to which it is associated
      operationId: deactivateChallenge
      parameters:
        - name: challenge_lookup
          in: path
          description: The challenge lookup value
          required: true
          schema:
            type: string
            default: ""
          example: challenge123
      responses:
        "200":
          description: The authorization was deactivated and the order was canceled.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Authorization'
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "404":
          description: Authorization was not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
        "410":
          description: The authorization was already deactivated, the order was already canceled, or the account was terminated.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
  /v1/certificates/{order_lookup}/revocation:
    post:
      tags:
        - Certificates
      summary: Revoke certificate by order lookup
      description: Revoke the certificate associated with the provided order lookup.
      operationId: revokeCertificate
      parameters:
        - name: order_lookup
          in: path
          description: The order lookup code for the certificate.
          required: true
          schema:
            type: string
            default: ""
          example: order12345
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ResellerRevokeCertificateRequest'
        required: true
      responses:
        "202":
          description: Request for revocation of certificate has been accepted
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CertificateMetadata'
        "208":
          description: The revocation request was already submitted and accepted. The current order state is returned.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Order'
                additionalProperties:
                  default: ""
                default: ""
        "400":
          description: Malformed revocation request.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "404":
          description: Certificate was not found or not subject to revocation.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
  /v1/authz/{auth_lookup}/challenges:
    post:
      tags:
        - Authorizations
      summary: Create challenge codes
      description: Create or return challenge codes for the specified authorization.
      operationId: generateChallenges
      parameters:
        - name: auth_lookup
          in: path
          description: The authorization lookup value
          required: true
          schema:
            type: string
            default: ""
          example: auth123
      responses:
        "200":
          description: Challenges are generated.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Challenges'
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "404":
          description: Authorization was not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
  /v1/account:
    get:
      tags:
        - Account
      summary: List accounts
      description: List root accounts with optional filters and pagination.
      operationId: listAccounts
      parameters:
        - name: customer_email
          in: query
          description: Filter by customer email address.
          required: false
          schema:
            type: string
            default: ""
          example: customer@example.com
        - name: is_suspended
          in: query
          description: Filter by suspended status.
          required: false
          schema:
            type: string
            default: ""
          example: true
        - name: limit
          in: query
          description: Maximum number of results to return.
          required: false
          schema:
            type: string
            default: ""
          example: 100
        - name: cursor
          in: query
          description: Cursor from a previous response to fetch the next page.
          required: false
          schema:
            type: string
            default: ""
          example: AbCdEf123456
      responses:
        "200":
          description: Accounts retrieved.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AccountList'
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
    post:
      tags:
        - Account
      summary: Create account
      description: Create a new root account for the given customer email. Optionally assign the account to one or more account groups.
      operationId: createAccount
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ResellerAccountRequest'
        required: true
      responses:
        "201":
          description: New account was created.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Account'
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "409":
          description: Account conflicts.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
        "404":
          description: Referenced account group not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
  /v1/account/{lookup}/eab-credential:
    get:
      tags:
        - EAB Credential
      summary: List EAB credentials for account
      description: List EAB credentials (ACME accounts) associated with the root account identified by the given lookup.
      operationId: listEabCredentialsForAccount
      parameters:
        - name: lookup
          in: path
          description: Lookup code of the root account
          required: true
          schema:
            type: string
            default: ""
          example: lookup123
        - name: limit
          in: query
          description: Maximum number of results to return.
          required: false
          schema:
            type: string
            default: ""
          example: 100
        - name: cursor
          in: query
          description: Cursor from a previous response to fetch the next page.
          required: false
          schema:
            type: string
            default: ""
          example: AbCdEf123456
      responses:
        "200":
          description: EAB credentials retrieved.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/EabCredentialList'
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "404":
          description: Root account not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
    post:
      tags:
        - EAB Credential
      summary: Create EAB credential
      description: Create a new EAB credential (ACME account) under the root account identified by the given lookup.
      operationId: createEabCredential
      parameters:
        - name: lookup
          in: path
          description: Lookup code of the root account
          required: true
          schema:
            type: string
            default: ""
          example: lookup123
      responses:
        "201":
          description: EAB credential created.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/EABAuthorization'
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "404":
          description: Root account not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
  /v1/account-group:
    get:
      tags:
        - Account Group
      summary: List reseller account groups
      operationId: getAccountGroups
      parameters:
        - name: limit
          in: query
          description: Maximum number of results to return.
          required: false
          schema:
            type: string
            default: ""
          example: 100
        - name: cursor
          in: query
          description: Cursor from a previous response to fetch the next page.
          required: false
          schema:
            type: string
            default: ""
          example: AbCdEf123456
      responses:
        "200":
          description: Account groups returned.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AccountGroupList'
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
    post:
      tags:
        - Account Group
      summary: Create reseller account group
      operationId: createAccountGroup
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ResellerAccountGroupRequest'
        required: true
      responses:
        "200":
          description: Account group created.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AccountGroupRecord'
        "400":
          description: Malformed request.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
  /v1/account-group/{group_lookup}/policy/{policy_lookup}:
    post:
      tags:
        - Account Group
      summary: Assign policy to reseller account group
      operationId: addAccountGroupPolicy
      parameters:
        - name: group_lookup
          in: path
          required: true
          schema:
            type: string
        - name: policy_lookup
          in: path
          required: true
          schema:
            type: string
      responses:
        "200":
          description: Policy assigned.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SuccessResponse'
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "404":
          description: Account group or policy not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
    delete:
      tags:
        - Account Group
      summary: Remove policy from reseller account group
      operationId: removeAccountGroupPolicy
      parameters:
        - name: group_lookup
          in: path
          required: true
          schema:
            type: string
        - name: policy_lookup
          in: path
          required: true
          schema:
            type: string
      responses:
        "200":
          description: Policy removed.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SuccessResponse'
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "404":
          description: Account group or policy not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
  /v1/account-group/{group_lookup}/member:
    get:
      tags:
        - Account Group
      summary: List members for reseller account group
      operationId: getAccountGroupMembers
      parameters:
        - name: group_lookup
          in: path
          required: true
          schema:
            type: string
        - name: limit
          in: query
          description: Maximum number of results to return.
          required: false
          schema:
            type: string
            default: ""
          example: 100
        - name: cursor
          in: query
          description: Cursor from a previous response to fetch the next page.
          required: false
          schema:
            type: string
            default: ""
          example: AbCdEf123456
      responses:
        "200":
          description: Account group members returned.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AccountGroupMemberList'
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "404":
          description: Account group not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
    post:
      tags:
        - Account Group
      summary: Add members to reseller account group
      operationId: addAccountGroupMembers
      parameters:
        - name: group_lookup
          in: path
          required: true
          schema:
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ResellerAccountGroupMembersRequest'
        required: true
      responses:
        "200":
          description: Members added.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SuccessResponse'
        "400":
          description: Malformed request.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "404":
          description: Account group or account(s) not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
    delete:
      tags:
        - Account Group
      summary: Remove members from reseller account group
      operationId: removeAccountGroupMembers
      parameters:
        - name: group_lookup
          in: path
          required: true
          schema:
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ResellerAccountGroupMembersRequest'
        required: true
      responses:
        "200":
          description: Members removed.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SuccessResponse'
        "400":
          description: Malformed request.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "404":
          description: Account group or account(s) not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
  /v1/account/{lookup}:
    get:
      tags:
        - Account
      summary: Get account
      description: Retrieve a reseller account by its lookup code, including child EAB credentials and group memberships.
      operationId: getAccount
      parameters:
        - name: lookup
          in: path
          description: Account lookup code.
          required: true
          schema:
            type: string
            default: ""
          example: lookup123
      responses:
        "200":
          description: Account found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AccountWithGroups'
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "404":
          description: Account not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
    delete:
      tags:
        - Account
      summary: Delete account
      description: Delete the account identified by the provided lookup code.
      operationId: deleteAccount
      parameters:
        - name: lookup
          in: path
          description: Lookup code of the account to be deleted
          required: true
          schema:
            type: string
            default: ""
          example: lookup123
      responses:
        "200":
          description: Account was deleted.
          content:
            '*/*':
              schema:
                $ref: '#/components/schemas/SuccessResponse'
        "401":
          description: Unauthorized
          content:
            '*/*':
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            '*/*':
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "404":
          description: Account not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
    patch:
      tags:
        - Account
      summary: Update account
      description: 'Apply one or more partial updates to the account identified by the provided lookup. Supported fields: customer_email, suspended.'
      operationId: updateAccount
      parameters:
        - name: lookup
          in: path
          description: Lookup code of the account to update
          required: true
          schema:
            type: string
            default: ""
          example: lookup123
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ResellerUpdateAccountRequest'
        required: true
      responses:
        "200":
          description: Account updated.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SuccessResponse'
        "400":
          description: Malformed update request.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "404":
          description: Account not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
        "409":
          description: Conflict when updating account.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
  /v1/account-group/{origin_group_lookup}/{destination_group_lookup}/member:
    patch:
      tags:
        - Account Group
      summary: Move members from one reseller account group to another one
      operationId: moveAccountGroupMembers
      parameters:
        - name: origin_group_lookup
          in: path
          required: true
          schema:
            type: string
        - name: destination_group_lookup
          in: path
          required: true
          schema:
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ResellerAccountGroupMembersRequest'
        required: true
      responses:
        "200":
          description: Members moved.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SuccessResponse'
        "400":
          description: Malformed request.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "404":
          description: Account group or account(s) not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
  /v1/order/{order_lookup}:
    get:
      tags:
        - Orders
      summary: Get order
      description: Return the current state of the order referenced by the lookup value.
      operationId: getOrder
      parameters:
        - name: order_lookup
          in: path
          description: The order lookup value
          required: true
          schema:
            type: string
            default: ""
          example: order123
      responses:
        "200":
          description: Order found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Order'
        "404":
          description: Order was not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
        "410":
          description: The requested order has expired.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
    delete:
      tags:
        - Orders
      summary: Cancel order
      description: Cancel the order referenced by the lookup value. The order will be marked as deleted and all associated authorizations will be deactivated.
      operationId: deactivateOrder
      parameters:
        - name: order_lookup
          in: path
          description: The order lookup value
          required: true
          schema:
            type: string
            default: ""
          example: order123
      responses:
        "200":
          description: The order was canceled.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Order'
        "404":
          description: Order was not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
        "410":
          description: The authorization was already deactivated, the order was already canceled, or the account was terminated.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
  /v1/eab-credential:
    get:
      tags:
        - EAB Credential
      summary: List all EAB credentials
      description: List all EAB credentials for the reseller with pagination.
      operationId: listEabCredentials
      parameters:
        - name: limit
          in: query
          description: Maximum number of results to return.
          required: false
          schema:
            type: string
            default: ""
          example: 100
        - name: cursor
          in: query
          description: Cursor from a previous response to fetch the next page.
          required: false
          schema:
            type: string
            default: ""
          example: AbCdEf123456
      responses:
        "200":
          description: EAB credentials retrieved.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/EabCredentialList'
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
  /v1/eab-credential/{kid}:
    get:
      tags:
        - EAB Credential
      summary: Get EAB credential
      description: Retrieve a single EAB credential by its KID.
      operationId: getEabCredential
      parameters:
        - name: kid
          in: path
          description: EAB Key ID
          required: true
          schema:
            type: string
            default: ""
          example: d2ad73bb-066f-11ef-a779-0242ac160002
      responses:
        "200":
          description: EAB credential found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Account'
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "404":
          description: EAB credential not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
    delete:
      tags:
        - EAB Credential
      summary: Delete EAB credential
      description: Delete the EAB credential identified by the given KID.
      operationId: deleteEabCredential
      parameters:
        - name: kid
          in: path
          description: EAB Key ID to delete
          required: true
          schema:
            type: string
            default: ""
          example: d2ad73bb-066f-11ef-a779-0242ac160002
      responses:
        "200":
          description: EAB credential deleted.
          content:
            '*/*':
              schema:
                $ref: '#/components/schemas/SuccessResponse'
        "401":
          description: Unauthorized
          content:
            '*/*':
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            '*/*':
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "404":
          description: EAB credential not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
  /v1/certificates:
    get:
      tags:
        - Certificates
      summary: List certificates
      description: List certificates for the specified customer email.
      operationId: listCertificates
      parameters:
        - name: customer_email
          in: query
          description: The customer email associated with the certificates.
          required: false
          schema:
            type: string
            default: ""
          example: customer@example.com
        - name: account_lookup
          in: query
          description: The root account lookup associated with the certificates.
          required: false
          schema:
            type: string
            default: ""
          example: customer@example.com
        - name: eab_kid
          in: query
          description: The EAB KID associated with the certificates.
          required: false
          schema:
            type: string
            default: ""
          example: customer@example.com
        - name: certificate_status
          in: query
          description: 'Use this parameter to specify one or multiple comma-separated certificate statuses to filter by. <br />Possible values: pending, issued, cancelled, revoked, expired.'
          required: false
          schema:
            type: string
            default: ""
          example: issued,cancelled
        - name: limit
          in: query
          description: Use this parameter to specify a pagination limit.
          required: false
          schema:
            type: string
            default: ""
          example: 100
        - name: cursor
          in: query
          description: Cursor from a previous response to fetch the next page.
          required: false
          schema:
            type: string
            default: ""
          example: AbCdEf123456
      responses:
        "200":
          description: Successful retrieval of certificates
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CertificateSummaryList'
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "404":
          description: Certificates were not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
  /v1/certificates/{order_lookup}:
    get:
      tags:
        - Certificates
      summary: Get certificate by order lookup
      description: Retrieve a certificate using its order lookup identifier.
      operationId: getCertificateByOrderLookup
      parameters:
        - name: order_lookup
          in: path
          description: The order lookup code for the certificate.
          required: true
          schema:
            type: string
            default: ""
          example: order12345
      responses:
        "200":
          description: Successful retrieval of the certificate
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CertificateMetadata'
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "404":
          description: Certificate was not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
  /v1/certificates/{order_lookup}/linting:
    get:
      tags:
        - Certificates
      summary: Get certificate linting results by certificate order Lookup
      description: Retrieve the linting results for a certificate using its order lookup identifier.
      operationId: getCertificateLintingResultsByOrderLookup
      parameters:
        - name: order_lookup
          in: path
          description: The order lookup code for the certificate.
          required: true
          schema:
            type: string
            default: ""
          example: order12345
      responses:
        "200":
          description: Successful retrieval of the certificate linting results
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "404":
          description: Certificate was not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
  /v1/certificates/{order_lookup}/json:
    get:
      tags:
        - Certificates
      summary: Get certificate
      description: Retrieve a certificate using its order lookup identifier in JSON format.
      operationId: getCertificateAsJson
      parameters:
        - name: order_lookup
          in: path
          description: The order lookup code for the certificate.
          required: true
          schema:
            type: string
            default: ""
          example: order12345
        - name: include_chain
          in: query
          description: Whether to include the certificate chain.
          required: false
          schema:
            type: boolean
            default: false
          example: true
      responses:
        "200":
          description: Successful retrieval of the certificate and CA bundle as JSON
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CertificateJson'
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "404":
          description: Certificate was not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
  /v1/certificates/{order_lookup}/download:
    get:
      tags:
        - Certificates
      summary: Download certificate
      description: Download the certificate associated with the provided order lookup as a ZIP file.
      operationId: downloadCertificateAsZip
      parameters:
        - name: order_lookup
          in: path
          description: The order lookup code for the certificate.
          required: true
          schema:
            type: string
            default: ""
          example: order12345
        - name: include_chain
          in: query
          description: Whether to include the certificate chain.
          required: false
          schema:
            type: boolean
            default: false
          example: true
        - name: file_type
          in: query
          description: The file type for the certificate.
          required: false
          schema:
            type: string
            default: ""
          example: PEM
      responses:
        "200":
          description: Successful download of the certificate ZIP file
          content:
            application/zip:
              schema:
                type: string
                format: binary
                additionalProperties:
                  default: ""
                default: ""
        "401":
          description: Unauthorized
          content:
            application/zip:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/zip:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "404":
          description: Certificate was not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
  /v1/authz/{auth_lookup}:
    get:
      tags:
        - Authorizations
      summary: Get challenge codes
      description: Return challenge codes for the specified authorization.
      operationId: getAuthorization
      parameters:
        - name: auth_lookup
          in: path
          description: The authorization lookup value
          required: true
          schema:
            type: string
            default: ""
          example: auth123
      responses:
        "200":
          description: Challenges are returned.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Authorization'
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "404":
          description: Authorization was not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
    delete:
      tags:
        - Authorizations
      summary: Deactivate authorization
      description: Deactivate the authorization referenced by this lookup value and cancel the order to which it is associated
      operationId: deactivateAuthorization
      parameters:
        - name: auth_lookup
          in: path
          description: The authorization lookup value
          required: true
          schema:
            type: string
            default: ""
          example: auth123
      responses:
        "200":
          description: The authorization was deactivated and the order was canceled.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Authorization'
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "404":
          description: Authorization was not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
        "410":
          description: The authorization was already deactivated, the order was already canceled, or the account was terminated.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
  /v1/account-group/{group_lookup}/policy:
    get:
      tags:
        - Account Group
      summary: List policies assigned to reseller account group
      operationId: getAccountGroupPolicies
      parameters:
        - name: group_lookup
          in: path
          required: true
          schema:
            type: string
        - name: limit
          in: query
          description: Maximum number of results to return.
          required: false
          schema:
            type: string
            default: ""
          example: 100
        - name: cursor
          in: query
          description: Cursor from a previous response to fetch the next page.
          required: false
          schema:
            type: string
            default: ""
          example: AbCdEf123456
      responses:
        "200":
          description: Policies returned.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PolicyList'
        "401":
          description: Unauthorized
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "403":
          description: Forbidden
          content:
            application/json:
              schema:
                type: string
                additionalProperties:
                  default: ""
                default: ""
        "404":
          description: Account group not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                additionalProperties:
                  default: ""
                default: ""
      security:
        - OAuth2Reseller: []
components:
  schemas:
    IssuancePolicy:
      type: object
      properties:
        version:
          type: integer
          format: int32
        name:
          type: string
        description:
          type: string
        limits:
          type: array
          items:
            $ref: '#/components/schemas/IssuancePolicyLimit'
    IssuancePolicyFilters:
      type: object
      properties:
        api:
          type: array
          items:
            type: string
            enum:
              - ACME
              - RESELLER
        certificate_profile:
          type: string
          default: ""
          description: Optional certificate profile filter for policy applicability. Case-insensitive
          example: TLS-90d
        client_tags:
          type: array
          default: ""
          description: Optional client tag filter. Policy applies when any tag overlaps the order request client_tags
          example:
            - UI
            - CLI
          items:
            type: string
    IssuancePolicyLimit:
      type: object
      properties:
        property:
          type: string
          enum:
            - orders_created
            - valid_certificates
        interval:
          type: string
        limit:
          type: integer
          format: int32
        wildcard_limit:
          type: integer
          format: int32
        domain_limit:
          type: integer
          format: int32
        exclude_expiring_within_days:
          type: integer
          format: int32
        filters:
          $ref: '#/components/schemas/IssuancePolicyFilters'
    ErrorResponse:
      type: object
      properties:
        error_code:
          type: string
          default: ""
          description: Error code representing the type of error
        error_text:
          type: string
          default: ""
          description: Detailed error message
        policy_name:
          type: string
          default: ""
          description: Name of the issuance policy that triggered the violation
        policy_description:
          type: string
          default: ""
          description: Description of the issuance policy that triggered the violation
    IssuancePolicyRecord:
      type: object
      properties:
        lookup:
          type: string
        policy:
          $ref: '#/components/schemas/IssuancePolicy'
        created:
          type: string
          format: date-time
        modified:
          type: string
          format: date-time
        deleted:
          type: string
          format: date-time
    ResellerAccountGroupRequest:
      type: object
      properties:
        description:
          type: string
          default: ""
          description: Optional description of the account group
          example: Tier 1 accounts
        group_name:
          type: string
          default: ""
          description: Name of the account group
          example: Enterprise Accounts
          minLength: 1
      required:
        - group_name
    AccountGroupRecord:
      type: object
      properties:
        id:
          type: integer
          format: int64
        lookup:
          type: string
        description:
          type: string
        created:
          type: string
          format: date-time
        modified:
          type: string
          format: date-time
        deleted:
          type: string
          format: date-time
        reseller_id:
          type: integer
          format: int32
        group_name:
          type: string
    ResellerValidateCsrRequest:
      type: object
      properties:
        csr:
          type: string
          default: ""
          description: CSR (Certificate Signing Request) to be validated
          example: |-
            -----BEGIN CERTIFICATE REQUEST-----
            ...
            -----END CERTIFICATE REQUEST-----
    ResellerOrderRequest:
      type: object
      properties:
        csr:
          type: string
          default: ""
          description: CSR (Certificate Signing Request) for the order
          example: |-
            -----BEGIN CERTIFICATE REQUEST-----
            ...
            -----END CERTIFICATE REQUEST-----
          minLength: 1
        customer_email:
          type: string
          default: ""
          description: Email address of the customer for whom the order is being created. Exactly one of customer_email or account_lookup must be provided
          example: customer@example.com
        account_lookup:
          type: string
          default: ""
          description: Root account lookup for the customer account. Exactly one of customer_email or account_lookup must be provided
          example: a1b2c3d4e5f6g7h8i9j0k1
        profile_code:
          type: string
          default: ""
          description: Profile code for the order
          example: TLS_STANDARD
          minLength: 1
        start_time:
          type: string
          default: ""
          description: Start time for the order validity
          example: "2024-01-01T00:00:00Z"
        end_time:
          type: string
          default: ""
          description: End time for the order validity
          example: "2024-12-31T23:59:59Z"
        subject_alternative_names:
          type: array
          default: []
          description: List of subject alternative names for the order
          example:
            - type: DNSName
              value: www.example.com
            - type: IPAddress
              value: 127.0.0.1
          items:
            $ref: '#/components/schemas/SubjectAlternativeName'
        client_tags:
          type: array
          default: []
          description: Optional client-defined tags for grouping/reporting orders
          example:
            - UI
            - CLI
            - API
          items:
            type: string
      required:
        - csr
        - profile_code
    SubjectAlternativeName:
      type: object
      properties:
        type:
          type: string
          default: ""
          description: 'Type of the subject alternative name, one of: ''DNSName'', ''IPAddress'''
          enum:
            - DNSName
            - IPAddress
          example: DNSName
        value:
          type: string
          default: ""
          description: Value of the subject alternative name
          example: www.example.com
    Authorization:
      type: object
      properties:
        expired:
          type: boolean
        lookup:
          type: string
          default: ""
          description: Unique identifier for the authorization
          example: auth12345
        token:
          type: string
          default: ""
          description: Token used for authorization
          example: <token>
        expires_on:
          type:
            - string
            - "null"
          format: date-time
          description: Expiration date of the authorization token
          example: "2024-12-31T23:59:59Z"
          default: null
        challenges:
          $ref: '#/components/schemas/Challenges'
        deleted_on:
          type:
            - string
            - "null"
          format: date-time
          description: Date when the authorization was deleted
          example: "2024-01-01T00:00:00Z"
          default: null
        revoked_on:
          type:
            - string
            - "null"
          format: date-time
          description: Date when the authorization was revoked
          example: "2024-01-01T00:00:00Z"
          default: null
        wildcard:
          type: boolean
          default: false
          description: Whether this authorization is for a wildcard identifier
          example: true
        status:
          type:
            - string
            - "null"
          description: Status of the authorization
          enum:
            - PENDING
            - VALID
            - INVALID
            - REVOKED
            - DEACTIVATED
            - EXPIRED
          example: VALID
          default: null
    CertOrder:
      type: object
      properties:
        order_lookup:
          type: string
          default: ""
          description: Unique identifier for the certificate order
          example: order12345
        expires:
          type:
            - string
            - "null"
          format: date-time
          description: Expiration date of the certificate order
          example: "2024-12-31T23:59:59Z"
          default: null
        profile_code:
          type: string
          default: ""
          description: Profile code associated with the certificate order
          example: profile123
        revoked:
          type:
            - string
            - "null"
          format: date-time
          description: Revocation timestamp of the certificate order
          example: "2024-12-31T23:59:59Z"
          default: null
        revocation_reason:
          type: string
          default: ""
          description: Reason for revocation of the certificate order
          example: UNSPECIFIED
        csr:
          type: string
          default: ""
          description: Certificate Signing Request (CSR) associated with the order
          example: |-
            -----BEGIN CERTIFICATE REQUEST-----
            ...
        replaces:
          type: string
          default: ""
          description: Lookup of the order that this order replaces, if any
          example: order12345-replaced
        extended_info:
          $ref: '#/components/schemas/CertOrderExtendedInfo'
    CertOrderExtendedInfo:
      type: object
      properties:
        start_time:
          type: string
          default: ""
          description: Start time of the certificate order
          example: "2024-01-01T00:00:00Z"
        end_time:
          type: string
          default: ""
          description: End time of the certificate order
          example: "2024-12-31T23:59:59Z"
        client_tags:
          type: array
          default: ""
          description: Optional client-defined tags associated with this order
          example:
            - UI
            - CLI
            - API
          items:
            type: string
    Challenge:
      type: object
      properties:
        type:
          type:
            - string
            - "null"
          description: Type of challenge used for domain validation
          enum:
            - DNS
            - HTTP
            - EMAIL
            - CAA
            - JURISDICTION
          example: DNS
          default: null
        lookup:
          type: string
          default: ""
          description: Unique identifier for the challenge
          example: challenge12345
        token:
          type: string
          default: ""
          description: Token used for challenge validation
          example: <token>
        status:
          type:
            - string
            - "null"
          description: Status of the challenge
          enum:
            - PENDING
            - SELECTED
            - ATTEMPTED
            - PASSED
            - FAILED
          example: PASSED
          default: null
        validation_date:
          type:
            - string
            - "null"
          format: date-time
          description: Date when the challenge was validated
          example: "2024-12-31T23:59:59Z"
          default: null
        challenge_reference:
          type: string
          default: ""
          description: Reference for the challenge
          example: DNS
    Challenges:
      type: object
      properties:
        domain:
          type: string
        challenge_list:
          type: array
          items:
            $ref: '#/components/schemas/Challenge'
    Order:
      type: object
      properties:
        cert_order:
          type: "null"
          $ref: '#/components/schemas/CertOrder'
          description: Certificate order details
          default: null
        authorizations:
          type: array
          default: ""
          description: List of authorizations associated with the order
          items:
            $ref: '#/components/schemas/Authorization'
        event_history:
          type: array
          default: ""
          description: Order state flow history
          items:
            $ref: '#/components/schemas/OrderStateFlow'
        order_status:
          type:
            - string
            - "null"
          description: Retrieve the order status
          enum:
            - PENDING
            - READY
            - PROCESSING
            - VALID
            - INVALID
          example: PENDING
          default: null
    OrderStateFlow:
      type: object
      properties:
        state:
          type: string
          enum:
            - ACCOUNT_CREATED
            - ACCOUNT_REVOKED
            - ORDER_CERTIFICATE
            - ORDER_HIGH_RISK_CHECK
            - CHALLENGES_PROVIDED
            - CHALLENGES_SELECTED
            - VERIFY_CHALLENGES
            - CHALLENGE_VERIFICATION
            - DOMAIN_VERIFICATION
            - CAA_VERIFICATION
            - JURISDICTION_FILTER
            - CHALLENGES_AWAIT
            - CHALLENGES_PASSED
            - FINALIZATION_REQUESTED
            - CERTIFICATE_REQUESTED
            - VERIFY_ISSUANCE
            - LINTING_FAILED
            - ISSUANCE_FAILED
            - CERTIFICATE_PROVIDED
            - PUBLISH_CERTIFICATE
            - PUSH_CERTIFICATE
            - PUSH_CERTIFICATE_FAILED
            - ORDER_COMPLETED
            - CERTIFICATE_REVOKED
            - PUSH_REVOKED
            - PUSH_REVOKED_FAILED
            - ORDER_CANCELED
        event:
          type: string
          format: date-time
        state_log:
          type: string
    ResellerRevokeCertificateRequest:
      type: object
      properties:
        revocation_reason:
          type: string
          default: ""
          description: Valid RFC5280 revocation reason. One of NOT_REVOKED, UNSPECIFIED, KEY_COMPROMISE, CA_COMPROMISE, AFFILIATION_CHANGED, SUPERSEDED, CESSATION_OF_OPERATION, CERTIFICATE_HOLD, REMOVE_FROM_CRL, PRIVILEGES_WITHDRAWN, AA_COMPROMISE.
          example: UNSPECIFIED
        revocation_date:
          type: string
          default: ""
          description: ISO 8601 date-time indicating when the certificate should be considered revoked. Defaults to current date/time if omitted.
          example: "2018-06-15T14:07:09Z"
    CertificateMetadata:
      type: object
      properties:
        revoked:
          type: string
          format: date-time
        expired:
          type: boolean
        domainCount:
          type: integer
          format: int64
        wildcardDomainCount:
          type: integer
          format: int64
        serial_number:
          type: string
        cert_order_lookup:
          type: string
        issued:
          type: string
          format: date-time
        revocation_reason:
          type: string
        fingerprint:
          type: string
          format: byte
        sha1_thumbprint:
          type: string
          format: byte
        expires:
          type: string
          format: date-time
    ResellerAccountRequest:
      type: object
      properties:
        customer_email:
          type: string
          format: email
          default: ""
          description: Email address of the customer for whom the account is being created
          example: customer@example.com
          minLength: 1
        group_lookups:
          type: array
          default: []
          description: Optional list of reseller account-group lookups to assign the account to
          example:
            - groupA
            - groupB
          items:
            type: string
      required:
        - customer_email
    Account:
      type: object
      properties:
        lookup:
          type: string
          default: ""
          description: Lookup identifier for the account
          example: a1b2c3d4
        suspended:
          type: boolean
          default: false
          description: Indicates if the account is suspended
          example: false
        reseller_code:
          type: string
          default: ""
          description: Reseller code associated with the account
          example: reseller123
        customer_email:
          type: string
          default: ""
          description: Email address associated with the account
          example: customer@example.com
        hmac_key:
          type: string
          default: ""
          description: HMAC key for the account
          example: hmacKey123
    EABAuthorization:
      type: object
      properties:
        eab_kid:
          type: string
        eab_hmac_key:
          type: string
    SuccessResponse:
      type: object
      properties:
        message_text:
          type: string
          default: ""
          description: Status of the operation
          example: success
    ResellerAccountGroupMembersRequest:
      type: object
      properties:
        members:
          type: array
          default: []
          description: List of account lookups to add to, remove from, or transfer between the account group(s)
          example:
            - accountA
            - accountB
          items:
            type: string
            minLength: 1
          minItems: 1
      required:
        - members
    ResellerUpdateAccountRequest:
      type: object
      properties:
        customer_email:
          type: string
          format: email
          default: ""
          description: Updated email address for the account
          example: new@example.com
        suspended:
          type: boolean
          default: false
          description: Updated suspension status for the account
          example: true
    PaginationInfo:
      type: object
      properties:
        next_cursor:
          type: string
          default: ""
          description: Opaque cursor for the next page
        has_more:
          type: boolean
          default: false
          description: True when additional results are available
    PolicyList:
      type: object
      properties:
        policies:
          type: array
          default: ""
          description: List of issuance policies
          items:
            $ref: '#/components/schemas/IssuancePolicyRecord'
        pagination:
          $ref: '#/components/schemas/PaginationInfo'
          default: ""
          description: Pagination metadata for this response
    EabCredentialList:
      type: object
      properties:
        eab_credentials:
          type: array
          default: ""
          description: List of EAB credentials
          items:
            $ref: '#/components/schemas/EABAuthorization'
        pagination:
          $ref: '#/components/schemas/PaginationInfo'
          default: ""
          description: Pagination metadata for this response
    CertificateSummary:
      type: object
      properties:
        cert_order_lookup:
          type: string
        status:
          type: string
          enum:
            - PENDING
            - CANCELLED
            - REVOKED
            - EXPIRED
            - ISSUED
            - REPLACED
            - REJECTED
        serial_number:
          type: string
        revocation_reason:
          type: string
        fingerprint:
          type: string
          format: byte
        eab_kid:
          type: string
        issued:
          type: string
          format: date-time
        issuer:
          type: string
        sha1_thumbprint:
          type: string
          format: byte
        expires:
          type: string
          format: date-time
        revoked:
          type: string
          format: date-time
    CertificateSummaryList:
      type: object
      properties:
        certificates:
          type: array
          default: ""
          description: List of certificate summaries
          items:
            $ref: '#/components/schemas/CertificateSummary'
        pagination:
          $ref: '#/components/schemas/PaginationInfo'
          default: ""
          description: Pagination metadata for this response
    CertificateJson:
      type: object
      properties:
        certificates:
          type: string
    AccountList:
      type: object
      properties:
        accounts:
          type: array
          default: ""
          description: List of accounts
          items:
            $ref: '#/components/schemas/Account'
        pagination:
          $ref: '#/components/schemas/PaginationInfo'
          default: ""
          description: Pagination metadata for this response
    AccountWithGroups:
      type: object
      properties:
        account:
          $ref: '#/components/schemas/Account'
          default: ""
          description: The parent (root) account
        groups:
          type: array
          default: ""
          description: Account groups this account belongs to
          items:
            type: object
            additionalProperties:
              type: string
    AccountGroupList:
      type: object
      properties:
        account_groups:
          type: array
          default: ""
          description: List of account groups
          items:
            $ref: '#/components/schemas/AccountGroupRecord'
        pagination:
          $ref: '#/components/schemas/PaginationInfo'
          default: ""
          description: Pagination metadata for this response
    AccountGroupMemberList:
      type: object
      properties:
        members:
          type: array
          default: ""
          description: List of member accounts
          items:
            $ref: '#/components/schemas/Account'
        pagination:
          $ref: '#/components/schemas/PaginationInfo'
          default: ""
          description: Pagination metadata for this response
  securitySchemes:
    OAuth2Reseller:
      type: http
      scheme: bearer
      bearerFormat: JWT
