Add an NHI source
Add a source. The credentials are checked against the provider first; a failure returns 400 and stores nothing.
Add a source. The credentials are checked against the provider first; a failure returns 400 and stores nothing.
ApiKeyAuthAuthorizationBearer <token>Bearer token authentication. Send an API key (a saai_api_-prefixed token) as Authorization: Bearer <token>.
Required permission
manage_nhiapplication/json- body
Request body for creating a source. The provider is the config's provider
tag. Credentials are validated before the source is stored; a source that
cannot authenticate is never created.
name*string1 <= length <= 255config*Provider-specific config, discriminated on provider.
The request has succeeded and a new resource has been created as a result.
application/json- response
A connected directory. Credentials are never returned.
id*uuiduuidprovider*"microsoft_entra"A directory that owns non-human identities.
"microsoft_entra"name*string1 <= length <= 255external_id*stringThe provider's canonical ID for the directory. For Entra, the tenant ID.
status*NhiSourceStatusWhether the stored credentials last authenticated successfully.
"connected""error"last_checked_at?stringWhen the credentials were last checked; absent until the first check.
date-timeconfig*Provider-specific config, discriminated on provider.
created_at*stringdate-timeupdated_at*stringdate-timecurl -X POST "https://example.com/nhi/sources" \ -H "Content-Type: application/json" \ -d '{ "name": "string", "config": { "provider": "microsoft_entra", "tenant_id": "string", "client_id": "string", "client_secret": "string" } }'{ "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "provider": "microsoft_entra", "name": "string", "external_id": "string", "status": "connected", "last_checked_at": "2019-08-24T14:15:22Z", "config": { "provider": "microsoft_entra", "tenant_id": "string", "client_id": "string", "has_client_secret": true }, "created_at": "2019-08-24T14:15:22Z", "updated_at": "2019-08-24T14:15:22Z"}