APINHI

Add an NHI source

Add a source. The credentials are checked against the provider first; a failure returns 400 and stores nothing.

POST
/nhi/sources

Add a source. The credentials are checked against the provider first; a failure returns 400 and stores nothing.

Authorization

ApiKeyAuth
headerAuthorizationBearer <token>

Bearer token authentication. Send an API key (a saai_api_-prefixed token) as Authorization: Bearer <token>.

Required permission

manage_nhi

Request Body

application/json
  1. body

Request body for creating a source. The provider is the config's provider tag. Credentials are validated before the source is stored; a source that cannot authenticate is never created.

name*string
Length1 <= length <= 255
config*

Provider-specific config, discriminated on provider.

Response Body

The request has succeeded and a new resource has been created as a result.

application/json
  1. response

A connected directory. Credentials are never returned.

id*uuid
Formatuuid
provider*"microsoft_entra"

A directory that owns non-human identities.

Value in"microsoft_entra"
name*string
Length1 <= length <= 255
external_id*string

The provider's canonical ID for the directory. For Entra, the tenant ID.

status*NhiSourceStatus

Whether the stored credentials last authenticated successfully.

Value in"connected""error"
last_checked_at?string

When the credentials were last checked; absent until the first check.

Formatdate-time
config*

Provider-specific config, discriminated on provider.

created_at*string
Formatdate-time
updated_at*string
Formatdate-time
curl -X POST "https://example.com/nhi/sources" \  -H "Content-Type: application/json" \  -d '{    "name": "string",    "config": {      "provider": "microsoft_entra",      "tenant_id": "string",      "client_id": "string",      "client_secret": "string"    }  }'
{  "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",  "provider": "microsoft_entra",  "name": "string",  "external_id": "string",  "status": "connected",  "last_checked_at": "2019-08-24T14:15:22Z",  "config": {    "provider": "microsoft_entra",    "tenant_id": "string",    "client_id": "string",    "has_client_secret": true  },  "created_at": "2019-08-24T14:15:22Z",  "updated_at": "2019-08-24T14:15:22Z"}