{
  "openapi": "3.0.1",
  "info": {
    "title": "Authentication",
    "version": "v1.1"
  },
  "tags": [
    {
      "name": "OAuth"
    }
  ],
  "paths": {
    "/oauth/token": {
      "post": {
        "tags": [
          "OAuth"
        ],
        "operationId": "generateToken",
        "summary": "Generate a JWT bearer token",
        "description": "Use this endpoint to create a new JWT bearer token that can be used to make subsequent API requests.",
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "client_id": {
                    "type": "string",
                    "description": "The unique Client ID provided by Snapdocs."
                  },
                  "client_secret": {
                    "type": "string",
                    "format": "password",
                    "description": "The unique Client Secret provided by Snapdocs."
                  },
                  "grant_type": {
                    "type": "string",
                    "description": "Indicates the type of grant being presented in exchange for an access token.",
                    "example": "client_credentials"
                  },
                  "audience": {
                    "type": "string",
                    "description": "The API you intend to call using a token generated by this request.",
                    "example": "https://evault-user-login.snapdocs.com/api/federated_apps/",
                    "enum": [
                      "https://evault-user-login.snpd.io/api/federated_apps/",
                      "https://evault-user-login.snapdocs.com/api/federated_apps/"
                    ]
                  },
                  "scope": {
                    "type": "string",
                    "description": "the authorization code used to control the access to API endpoints",
                    "example": "documents:read mers:basic"
                  }
                },
                "required": [
                  "client_id",
                  "client_secret",
                  "grant_type",
                  "audience"
                ]
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "successful",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "access_token": {
                      "type": "string",
                      "description": "The access token string as issued by the authorization server. Use this as a Bearer token in your subsequent API requests."
                    },
                    "scope": {
                      "type": "string",
                      "description": "The scope granted to the application."
                    },
                    "expires_in": {
                      "type": "integer",
                      "description": "The duration of time the access token is granted for."
                    },
                    "token_type": {
                      "type": "string",
                      "description": "The type of token this is, typically just the string \"Bearer\"."
                    }
                  }
                },
                "example": {
                  "access_token": "eyJraWQiOiJTeF9KenFHME04Rnd...",
                  "scope": "documents:basic",
                  "expires_in": 7200,
                  "token_type": "Bearer"
                }
              }
            }
          },
          "400": {
            "description": "Bad Request",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "error": {
                      "type": "string"
                    },
                    "error_description": {
                      "type": "string"
                    }
                  }
                },
                "example": {
                  "error": "invalid_request",
                  "error_description": "Missing required parameter: grant_type"
                }
              }
            }
          },
          "401": {
            "description": "Unauthorized",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "error": {
                      "type": "string"
                    },
                    "error_description": {
                      "type": "string"
                    }
                  }
                },
                "example": {
                  "error": "access_denied",
                  "error_description": "Unauthorized"
                }
              }
            }
          }
        }
      }
    }
  },
  "servers": [
    {
      "url": "https://login.demo-eks.snpd.io",
      "description": "Snapdocs eVault demo environment endpoint for authentication."
    },
    {
      "url": "https://login.snapdocs.com",
      "description": "Snapdocs eVault production environment endpoint for authentication."
    }
  ],
  "components": {
    "schemas": {}
  }
}