/** * Agilicus API * Agilicus is API-first. Modern software is controlled by other software, is open, is available for you to use the way you want, securely, simply. The OpenAPI Specification in YAML format is available on [www](https://www.agilicus.com/www/api/agilicus-openapi.yaml) for importing to other tools. A rendered, online viewable and usable version of this specification is available at [api](https://www.agilicus.com/api). You may try the API inline directly in the web page. To do so, first obtain an Authentication Token (the simplest way is to install the Python SDK, and then run `agilicus-cli --issuer https://MYISSUER get-token`). You will need an org-id for most calls (and can obtain from `agilicus-cli --issuer https://MYISSUER list-orgs`). The `MYISSUER` will typically be `auth.MYDOMAIN`, and you will see it as you sign-in to the administrative UI. This API releases on Bearer-Token authentication. To obtain a valid bearer token you will need to Authenticate to an Issuer with OpenID Connect (a superset of OAUTH2). Your \"issuer\" will look like https://auth.MYDOMAIN. For example, when you signed-up, if you said \"use my own domain name\" and assigned a CNAME of cloud.example.com, then your issuer would be https://auth.cloud.example.com. If you selected \"use an Agilicus supplied domain name\", your issuer would look like https://auth.myorg.agilicus.cloud. For test purposes you can use our [Python SDK](https://pypi.org/project/agilicus/) and run `agilicus-cli --issuer https://auth.MYDOMAIN get-token`. This API may be used in any language runtime that supports OpenAPI 3.0, or, you may use our [Python SDK](https://pypi.org/project/agilicus/), our [Typescript SDK](https://www.npmjs.com/package/@agilicus/angular), or our [Golang SDK](https://git.agilicus.com/pub/sdk-go). 100% of the activities in our system our API-driven, from our web-admin, through our progressive web applications, to all internals: there is nothing that is not accessible. For more information, see [developer resources](https://www.agilicus.com/developer). * * The version of the OpenAPI document: 2025.12.16 * Contact: dev@agilicus.com * * NOTE: This class is auto generated by OpenAPI Generator (https://openapi-generator.tech). * https://openapi-generator.tech * Do not edit the class manually. */ import { ResourcePermissionSpec } from './resourcePermissionSpec'; import { User } from './user'; import { HostPermissions } from './hostPermissions'; export interface _Token { /** * Unique identifier */ readonly sub?: string; /** * User\'s email address */ sub_email?: string; /** * Unique identifier */ readonly org?: string; /** * The organisation at the root of the hierachy for which this token provides permissions. */ readonly root_org?: string; /** * An associative array mapping an application to a list of roles */ roles?: { [key: string]: Array | undefined; }; /** * Unique identifier */ readonly jti?: string; /** * token issue date */ readonly iat?: string; /** * token expiry date */ readonly exp?: string; /** * array of valid hosts */ hosts?: Array; /** * token audience */ readonly aud?: Array; /** * Unique identifier */ readonly session?: string; /** * The list of scopes associated with this access token. Note that these scopes do not indicate whether that permission has been granted. Whether or not the permission has been granted to this token depends on the scope being associated with the token AND whether the user has that permission to begin with. */ scopes?: Array; /** * The id of the user who created this token, if different from the token\'s sub. */ readonly creating_sub?: string; /** * The id of the org of the user who created this token, if that user is different from the token\'s sub. */ readonly creating_org?: string; /** * Whether or not this token was created by a user masquerading as the sub of this token. A masquerading token is constrained in what it can do compared to a normal one: certain operations cannot be performed unless the user has fully authenticated. */ readonly masquerading?: boolean; /** * The resource permissions associated with this token. The token determines te permissions by cross referencing the user\'s permissions with the requested scopes. This list contains only permissions a user has, and only permissions requested by the token\'s scopes. */ resource_permissions?: Array; user?: User; /** * Time since the epoch, in seconds, when a multifactor challenge associated with this token was last succesfully performed. If not set then no successfully multifactor challenge is associated with this token. */ last_mfa_time?: number; /** * This token is specifically a refresh token, and can refresh the specified token jti which is this property. */ readonly refresh_token_jti?: string; } export interface Token extends _Token { _builtin_original?: _Token; _remove_builtin_extensions?: () => void; } export declare class TokenImpl implements _Token { _builtin_original?: _Token; readonly sub: string | undefined; sub_email: string | undefined; readonly org: string | undefined; readonly root_org: string | undefined; roles: { [key: string]: Array | undefined; } | undefined; readonly jti: string | undefined; readonly iat: string | undefined; readonly exp: string | undefined; hosts: Array | undefined; readonly aud: Array | undefined; readonly session: string | undefined; scopes: Array | undefined; readonly creating_sub: string | undefined; readonly creating_org: string | undefined; readonly masquerading: boolean | undefined; resource_permissions: Array | undefined; user: User | undefined; last_mfa_time: number | undefined; readonly refresh_token_jti: string | undefined; constructor(base: _Token); _remove_builtin_extensions(): void; } export declare function newTokenImpl(base: _Token): TokenImpl;