al:alarm-type-id | “ | Base identity for alarm types. A unique identification of the alarm, not including the resource. Different resources can share alarm types. If the resource reports the same alarm type, it is considered to be the same alarm. The alarm type is a simplification of the different X.733 and 3GPP Alarm IRP correlation mechanisms, and it allows for hierarchical extensions. A string-based qualifier can be used in addition to the identity in order to have different alarm types based on information not known at design time, such as values in textual SNMP Notification varbinds. Standards and vendors can define sub-identities to clearly identify specific alarm types. This identity is abstract and MUST NOT be used for alarms. |
alde:deprecated-configuration | alde:system | Usage of deprecated configuration |
alde:expiry | alde:system | Expiry (i.e., expiration) of some resource has or will soon occur |
alde:external-service | al:alarm-type-id | Alarms related to usages of external services |
alde:failed-authentication | alde:external-service | Authentication failed when establishing a connection to the external service |
alde:failed-communication | alde:external-service | A failure to communicate with an external service |
alde:failed-connection | alde:external-service | A failure to connect to an external service |
alde:slow-connection | alde:external-service | Communication with the external service is slower than acceptable |
alde:system | al:alarm-type-id | Alarms related to the internals of Curity |
apps:apps-service | sc:profile-identity | The Applications service identity |
as:authorization-actions.oauth | sc:authorization-actions | All oauth-related actions that can be authorized by an authorization manager |
as:authorization-actions.oauth.user-read | as:authorization-actions.oauth | The action that is used for all user read operations in the user info endpoint that an authorization manager may authorize |
as:oauth-service | sc:profile-identity | The OAuth service identity |
auth:authentication-service | sc:profile-identity | The Authentication service identity |
base:assisted-token-endpoint-identity | base:flow-identity | This is the base identity for all assisted token endpoint flows |
base:authorize-endpoint-identity | base:flow-identity | This is the base identity for all authorize endpoint flows |
base:backchannel-authentication-identity | base:flow-identity | The is the base identity for backchannel authentication (CIBA) flow endpoints |
base:device-authorization-identity | base:flow-identity | This is the base identity for device authorization flow endpoints |
base:flow-identity | “ | This is the base for all oauth flows |
base:introspect-endpoint-identity | base:flow-identity | This is the base identity for all introspection endpoint flows |
base:oauth-assisted-token | base:assisted-token-endpoint-identity | The Assisted token flow on the assisted token endpoint |
base:oauth-authorize-authorization-code | base:authorize-endpoint-identity | The Authorization Code flow on the authorization endpoint |
base:oauth-authorize-implicit | base:authorize-endpoint-identity | The Implicit flow on the authorization endpoint |
base:oauth-backchannel-authentication | base:backchannel-authentication-identity | The backchannel authentication endpoint for initiating a CIBA flow |
base:oauth-device-authorization | base:device-authorization-identity | The device code issuance flow of device verification |
base:oauth-introspect | base:introspect-endpoint-identity | The introspect token flow on the introspection endpoint |
base:oauth-introspect-application-jwt | base:introspect-endpoint-identity | The introspect token flow on the introspection endpoint (serving Content-Type ‘application/jwt’) |
base:oauth-token-assertion | base:token-endpoint-identity | The Assertion grant type on the token endpoint |
base:oauth-token-authorization-code | base:token-endpoint-identity | The Authorization Code flow grant type on the token endpoint |
base:oauth-token-backchannel-authentication | base:token-endpoint-identity | The Backchannel Authentication (CIBA) grant type on the token endpoint |
base:oauth-token-client-credentials | base:token-endpoint-identity | The Client Credentials grant type on the token endpoint |
base:oauth-token-device-code | base:token-endpoint-identity | The Device Code grant type on the token endpoint |
base:oauth-token-oauth-token-exchange | base:token-endpoint-identity | The OAuth 2.0 Token Exchange grant type on the token endpoint |
base:oauth-token-pre-authorized-code | base:token-endpoint-identity | The Pre-Authorized Code flow grant type on the token endpoint |
base:oauth-token-refresh | base:token-endpoint-identity | The Refresh token grant type on the token endpoint |
base:oauth-token-resource-owner-password-credentials | base:token-endpoint-identity | The OAuth Resource Owner Password credentials grant type on the token endpoint |
base:oauth-token-token-exchange | base:token-endpoint-identity | The Token Exchange grant type on the token endpoint |
base:openid-authorize-hybrid | base:authorize-endpoint-identity | The Hybrid flow on the authorization endpoint |
base:openid-session-logout | base:session-endpoint-identity | The Logout token flow on the session endpoint |
base:openid-userinfo | base:userinfo-endpoint-identity | The UserInfo flow on the userinfo endpoint |
base:session-endpoint-identity | base:flow-identity | This is the base identity for all the session endpoint flows |
base:token-endpoint-identity | base:flow-identity | This is the base identity for all token endpoint flows |
base:userinfo-endpoint-identity | base:flow-identity | This is the base identity for all userinfo endpoint flows |
base:verifiable-credential-endpoint-identity | base:flow-identity | This is the base identity for all verifiable credential issuance endpoint flows |
base:verifiable-credential-issuance-jwt_vc_json | base:verifiable-credential-endpoint-identity | Verifiable credential issuance using the ‘jwt_vc_json’ format |
base:verifiable-credential-issuance-vc_sd_jwt | base:verifiable-credential-endpoint-identity | Verifiable credential issuance using the ‘vc+sd-jwt’ format |
sc:authorization-actions | “ | All actions that can be authorized by an authorization manager |
sc:profile-identity | “ | This is the base identity for all profiles |
si:saml-idp-service | sc:profile-identity | The SAML IDP service |
um:authorization-actions.user-management | sc:authorization-actions | All user-management-related actions that can be authorized by an authorization manager |
um:authorization-actions.user-management.admin | um:authorization-actions.user-management | The actions that an admin may perform in the user management service that an authorization manager may authorize |
um:authorization-actions.user-management.admin.read | um:authorization-actions.user-management.admin | The action that is used for all read-only operations in the user management service that an authorization manager may authorize |
um:authorization-actions.user-management.admin.write | um:authorization-actions.user-management.admin | The action that is used for all write operations in the user management service that an authorization manager may authorize |
um:authorization-actions.user-management.delegations | um:authorization-actions.user-management | The actions that may be performed in the delegations endpoint that an authorization manager may authorize |
um:authorization-actions.user-management.delegations.admin | um:authorization-actions.user-management.delegations | The actions that an admin may perform in the delegations endpoint that an authorization manager may authorize |
um:authorization-actions.user-management.delegations.admin.read | um:authorization-actions.user-management.delegations.admin | The actions that is used for all admin read operations in the delegations endpoint that an authorization manager may authorize |
um:authorization-actions.user-management.delegations.admin.write | um:authorization-actions.user-management.delegations.admin | The actions that is used for all admin write operations in the delegations endpoint that an authorization manager may authorize |
um:authorization-actions.user-management.delegations.user | um:authorization-actions.user-management.delegations | The action that is used for all read-only operations in the delegations endpoint service that an authorization manager may authorize |
um:authorization-actions.user-management.delegations.user.read | um:authorization-actions.user-management.delegations.user | The actions that is used for all user read operations in the delegations endpoint that an authorization manager may authorize |
um:authorization-actions.user-management.delegations.user.write | um:authorization-actions.user-management.delegations.user | The actions that is used for all user write operations in the delegations endpoint that an authorization manager may authorize |
um:authorization-actions.user-management.read | sc:authorization-actions | The action that is used for read-only operations for any type of user |
um:authorization-actions.user-management.users | um:authorization-actions.user-management | The actions that may be performed in the users endpoint that an authorization manager may authorize |
um:authorization-actions.user-management.users.admin | um:authorization-actions.user-management.users | The actions that an admin may perform in the users endpoint that an authorization manager may authorize |
um:authorization-actions.user-management.users.admin.read | um:authorization-actions.user-management.users.admin | The actions that is used for all admin read operations in the users endpoint that an authorization manager may authorize |
um:authorization-actions.user-management.users.admin.write | um:authorization-actions.user-management.users.admin | The actions that is used for all admin write operations in the users endpoint that an authorization manager may authorize |
um:authorization-actions.user-management.users.user | um:authorization-actions.user-management.users | The action that is used for all read-only operations in the users endpoint service that an authorization manager may authorize |
um:authorization-actions.user-management.users.user.read | um:authorization-actions.user-management.users.user | The actions that is used for all user read operations in the users endpoint that an authorization manager may authorize |
um:authorization-actions.user-management.users.user.write | um:authorization-actions.user-management.users.user | The actions that is used for all user write operations in the users endpoint that an authorization manager may authorize |
um:authorization-actions.user-management.write | sc:authorization-actions | The action that is used for write-only operations for any type of user |
um:user-management-service | sc:profile-identity | The User Management service identity |