package main
import(
"context"
"github.com/conductorone/conductorone-sdk-go/pkg/models/shared"
conductoronesdkgo "github.com/conductorone/conductorone-sdk-go"
"log"
)
func main() {
ctx := context.Background()
s := conductoronesdkgo.New(
conductoronesdkgo.WithSecurity(shared.Security{
BearerAuth: "<YOUR_BEARER_TOKEN_HERE>",
Oauth: "<YOUR_OAUTH_HERE>",
}),
)
res, err := s.CredentialInventoryPolicy.Create(ctx, nil)
if err != nil {
log.Fatal(err)
}
if res.CredentialInventoryPolicyServiceCreateResponse != nil {
// handle response
}
}curl --request POST \
--url https://{tenantDomain}.conductor.one/api/v1/credential-inventory-policies \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"displayName": "<string>",
"delegated": {
"googleEnabled": true,
"googleHostedDomains": [
"<string>"
],
"microsoftEnabled": true,
"microsoftTenantIds": [
"<string>"
]
},
"emailOtp": {
"codeLength": 123,
"maxAttempts": 123,
"ttlSeconds": 123
},
"enabledTypes": [],
"passkey": {
"allowedAaguids": [
"aSDinaTvuI8gbWludGxpZnk="
],
"requireUserVerification": true
},
"password": {
"checkBreached": true,
"historyDepth": 123,
"minLength": 123,
"requireMixedCase": true,
"requireNumber": true,
"requireSymbol": true
},
"priority": 123,
"totp": {
"codeLength": 123,
"periodSeconds": 123,
"skewTolerance": 123
}
}
'import requests
url = "https://{tenantDomain}.conductor.one/api/v1/credential-inventory-policies"
payload = {
"displayName": "<string>",
"delegated": {
"googleEnabled": True,
"googleHostedDomains": ["<string>"],
"microsoftEnabled": True,
"microsoftTenantIds": ["<string>"]
},
"emailOtp": {
"codeLength": 123,
"maxAttempts": 123,
"ttlSeconds": 123
},
"enabledTypes": [],
"passkey": {
"allowedAaguids": ["aSDinaTvuI8gbWludGxpZnk="],
"requireUserVerification": True
},
"password": {
"checkBreached": True,
"historyDepth": 123,
"minLength": 123,
"requireMixedCase": True,
"requireNumber": True,
"requireSymbol": True
},
"priority": 123,
"totp": {
"codeLength": 123,
"periodSeconds": 123,
"skewTolerance": 123
}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
displayName: '<string>',
delegated: {
googleEnabled: true,
googleHostedDomains: ['<string>'],
microsoftEnabled: true,
microsoftTenantIds: ['<string>']
},
emailOtp: {codeLength: 123, maxAttempts: 123, ttlSeconds: 123},
enabledTypes: [],
passkey: {allowedAaguids: ['aSDinaTvuI8gbWludGxpZnk='], requireUserVerification: true},
password: {
checkBreached: true,
historyDepth: 123,
minLength: 123,
requireMixedCase: true,
requireNumber: true,
requireSymbol: true
},
priority: 123,
totp: {codeLength: 123, periodSeconds: 123, skewTolerance: 123}
})
};
fetch('https://{tenantDomain}.conductor.one/api/v1/credential-inventory-policies', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{tenantDomain}.conductor.one/api/v1/credential-inventory-policies",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'displayName' => '<string>',
'delegated' => [
'googleEnabled' => true,
'googleHostedDomains' => [
'<string>'
],
'microsoftEnabled' => true,
'microsoftTenantIds' => [
'<string>'
]
],
'emailOtp' => [
'codeLength' => 123,
'maxAttempts' => 123,
'ttlSeconds' => 123
],
'enabledTypes' => [
],
'passkey' => [
'allowedAaguids' => [
'aSDinaTvuI8gbWludGxpZnk='
],
'requireUserVerification' => true
],
'password' => [
'checkBreached' => true,
'historyDepth' => 123,
'minLength' => 123,
'requireMixedCase' => true,
'requireNumber' => true,
'requireSymbol' => true
],
'priority' => 123,
'totp' => [
'codeLength' => 123,
'periodSeconds' => 123,
'skewTolerance' => 123
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}HttpResponse<String> response = Unirest.post("https://{tenantDomain}.conductor.one/api/v1/credential-inventory-policies")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"displayName\": \"<string>\",\n \"delegated\": {\n \"googleEnabled\": true,\n \"googleHostedDomains\": [\n \"<string>\"\n ],\n \"microsoftEnabled\": true,\n \"microsoftTenantIds\": [\n \"<string>\"\n ]\n },\n \"emailOtp\": {\n \"codeLength\": 123,\n \"maxAttempts\": 123,\n \"ttlSeconds\": 123\n },\n \"enabledTypes\": [],\n \"passkey\": {\n \"allowedAaguids\": [\n \"aSDinaTvuI8gbWludGxpZnk=\"\n ],\n \"requireUserVerification\": true\n },\n \"password\": {\n \"checkBreached\": true,\n \"historyDepth\": 123,\n \"minLength\": 123,\n \"requireMixedCase\": true,\n \"requireNumber\": true,\n \"requireSymbol\": true\n },\n \"priority\": 123,\n \"totp\": {\n \"codeLength\": 123,\n \"periodSeconds\": 123,\n \"skewTolerance\": 123\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://{tenantDomain}.conductor.one/api/v1/credential-inventory-policies")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"displayName\": \"<string>\",\n \"delegated\": {\n \"googleEnabled\": true,\n \"googleHostedDomains\": [\n \"<string>\"\n ],\n \"microsoftEnabled\": true,\n \"microsoftTenantIds\": [\n \"<string>\"\n ]\n },\n \"emailOtp\": {\n \"codeLength\": 123,\n \"maxAttempts\": 123,\n \"ttlSeconds\": 123\n },\n \"enabledTypes\": [],\n \"passkey\": {\n \"allowedAaguids\": [\n \"aSDinaTvuI8gbWludGxpZnk=\"\n ],\n \"requireUserVerification\": true\n },\n \"password\": {\n \"checkBreached\": true,\n \"historyDepth\": 123,\n \"minLength\": 123,\n \"requireMixedCase\": true,\n \"requireNumber\": true,\n \"requireSymbol\": true\n },\n \"priority\": 123,\n \"totp\": {\n \"codeLength\": 123,\n \"periodSeconds\": 123,\n \"skewTolerance\": 123\n }\n}"
response = http.request(request)
puts response.read_body{
"credentialInventoryPolicy": {
"createdAt": "2023-11-07T05:31:56Z",
"delegated": {
"googleEnabled": true,
"googleHostedDomains": [
"<string>"
],
"microsoftEnabled": true,
"microsoftTenantIds": [
"<string>"
]
},
"deletedAt": "2023-11-07T05:31:56Z",
"displayName": "<string>",
"emailOtp": {
"codeLength": 123,
"maxAttempts": 123,
"ttlSeconds": 123
},
"enabledTypes": [],
"id": "<string>",
"isBuiltin": true,
"passkey": {
"allowedAaguids": [
"aSDinaTvuI8gbWludGxpZnk="
],
"requireUserVerification": true
},
"password": {
"checkBreached": true,
"historyDepth": 123,
"minLength": 123,
"requireMixedCase": true,
"requireNumber": true,
"requireSymbol": true
},
"priority": 123,
"totp": {
"codeLength": 123,
"periodSeconds": 123,
"skewTolerance": 123
},
"updatedAt": "2023-11-07T05:31:56Z"
}
}Create
Create a credential inventory policy.
package main
import(
"context"
"github.com/conductorone/conductorone-sdk-go/pkg/models/shared"
conductoronesdkgo "github.com/conductorone/conductorone-sdk-go"
"log"
)
func main() {
ctx := context.Background()
s := conductoronesdkgo.New(
conductoronesdkgo.WithSecurity(shared.Security{
BearerAuth: "<YOUR_BEARER_TOKEN_HERE>",
Oauth: "<YOUR_OAUTH_HERE>",
}),
)
res, err := s.CredentialInventoryPolicy.Create(ctx, nil)
if err != nil {
log.Fatal(err)
}
if res.CredentialInventoryPolicyServiceCreateResponse != nil {
// handle response
}
}curl --request POST \
--url https://{tenantDomain}.conductor.one/api/v1/credential-inventory-policies \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"displayName": "<string>",
"delegated": {
"googleEnabled": true,
"googleHostedDomains": [
"<string>"
],
"microsoftEnabled": true,
"microsoftTenantIds": [
"<string>"
]
},
"emailOtp": {
"codeLength": 123,
"maxAttempts": 123,
"ttlSeconds": 123
},
"enabledTypes": [],
"passkey": {
"allowedAaguids": [
"aSDinaTvuI8gbWludGxpZnk="
],
"requireUserVerification": true
},
"password": {
"checkBreached": true,
"historyDepth": 123,
"minLength": 123,
"requireMixedCase": true,
"requireNumber": true,
"requireSymbol": true
},
"priority": 123,
"totp": {
"codeLength": 123,
"periodSeconds": 123,
"skewTolerance": 123
}
}
'import requests
url = "https://{tenantDomain}.conductor.one/api/v1/credential-inventory-policies"
payload = {
"displayName": "<string>",
"delegated": {
"googleEnabled": True,
"googleHostedDomains": ["<string>"],
"microsoftEnabled": True,
"microsoftTenantIds": ["<string>"]
},
"emailOtp": {
"codeLength": 123,
"maxAttempts": 123,
"ttlSeconds": 123
},
"enabledTypes": [],
"passkey": {
"allowedAaguids": ["aSDinaTvuI8gbWludGxpZnk="],
"requireUserVerification": True
},
"password": {
"checkBreached": True,
"historyDepth": 123,
"minLength": 123,
"requireMixedCase": True,
"requireNumber": True,
"requireSymbol": True
},
"priority": 123,
"totp": {
"codeLength": 123,
"periodSeconds": 123,
"skewTolerance": 123
}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
displayName: '<string>',
delegated: {
googleEnabled: true,
googleHostedDomains: ['<string>'],
microsoftEnabled: true,
microsoftTenantIds: ['<string>']
},
emailOtp: {codeLength: 123, maxAttempts: 123, ttlSeconds: 123},
enabledTypes: [],
passkey: {allowedAaguids: ['aSDinaTvuI8gbWludGxpZnk='], requireUserVerification: true},
password: {
checkBreached: true,
historyDepth: 123,
minLength: 123,
requireMixedCase: true,
requireNumber: true,
requireSymbol: true
},
priority: 123,
totp: {codeLength: 123, periodSeconds: 123, skewTolerance: 123}
})
};
fetch('https://{tenantDomain}.conductor.one/api/v1/credential-inventory-policies', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{tenantDomain}.conductor.one/api/v1/credential-inventory-policies",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'displayName' => '<string>',
'delegated' => [
'googleEnabled' => true,
'googleHostedDomains' => [
'<string>'
],
'microsoftEnabled' => true,
'microsoftTenantIds' => [
'<string>'
]
],
'emailOtp' => [
'codeLength' => 123,
'maxAttempts' => 123,
'ttlSeconds' => 123
],
'enabledTypes' => [
],
'passkey' => [
'allowedAaguids' => [
'aSDinaTvuI8gbWludGxpZnk='
],
'requireUserVerification' => true
],
'password' => [
'checkBreached' => true,
'historyDepth' => 123,
'minLength' => 123,
'requireMixedCase' => true,
'requireNumber' => true,
'requireSymbol' => true
],
'priority' => 123,
'totp' => [
'codeLength' => 123,
'periodSeconds' => 123,
'skewTolerance' => 123
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}HttpResponse<String> response = Unirest.post("https://{tenantDomain}.conductor.one/api/v1/credential-inventory-policies")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"displayName\": \"<string>\",\n \"delegated\": {\n \"googleEnabled\": true,\n \"googleHostedDomains\": [\n \"<string>\"\n ],\n \"microsoftEnabled\": true,\n \"microsoftTenantIds\": [\n \"<string>\"\n ]\n },\n \"emailOtp\": {\n \"codeLength\": 123,\n \"maxAttempts\": 123,\n \"ttlSeconds\": 123\n },\n \"enabledTypes\": [],\n \"passkey\": {\n \"allowedAaguids\": [\n \"aSDinaTvuI8gbWludGxpZnk=\"\n ],\n \"requireUserVerification\": true\n },\n \"password\": {\n \"checkBreached\": true,\n \"historyDepth\": 123,\n \"minLength\": 123,\n \"requireMixedCase\": true,\n \"requireNumber\": true,\n \"requireSymbol\": true\n },\n \"priority\": 123,\n \"totp\": {\n \"codeLength\": 123,\n \"periodSeconds\": 123,\n \"skewTolerance\": 123\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://{tenantDomain}.conductor.one/api/v1/credential-inventory-policies")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"displayName\": \"<string>\",\n \"delegated\": {\n \"googleEnabled\": true,\n \"googleHostedDomains\": [\n \"<string>\"\n ],\n \"microsoftEnabled\": true,\n \"microsoftTenantIds\": [\n \"<string>\"\n ]\n },\n \"emailOtp\": {\n \"codeLength\": 123,\n \"maxAttempts\": 123,\n \"ttlSeconds\": 123\n },\n \"enabledTypes\": [],\n \"passkey\": {\n \"allowedAaguids\": [\n \"aSDinaTvuI8gbWludGxpZnk=\"\n ],\n \"requireUserVerification\": true\n },\n \"password\": {\n \"checkBreached\": true,\n \"historyDepth\": 123,\n \"minLength\": 123,\n \"requireMixedCase\": true,\n \"requireNumber\": true,\n \"requireSymbol\": true\n },\n \"priority\": 123,\n \"totp\": {\n \"codeLength\": 123,\n \"periodSeconds\": 123,\n \"skewTolerance\": 123\n }\n}"
response = http.request(request)
puts response.read_body{
"credentialInventoryPolicy": {
"createdAt": "2023-11-07T05:31:56Z",
"delegated": {
"googleEnabled": true,
"googleHostedDomains": [
"<string>"
],
"microsoftEnabled": true,
"microsoftTenantIds": [
"<string>"
]
},
"deletedAt": "2023-11-07T05:31:56Z",
"displayName": "<string>",
"emailOtp": {
"codeLength": 123,
"maxAttempts": 123,
"ttlSeconds": 123
},
"enabledTypes": [],
"id": "<string>",
"isBuiltin": true,
"passkey": {
"allowedAaguids": [
"aSDinaTvuI8gbWludGxpZnk="
],
"requireUserVerification": true
},
"password": {
"checkBreached": true,
"historyDepth": 123,
"minLength": 123,
"requireMixedCase": true,
"requireNumber": true,
"requireSymbol": true
},
"priority": 123,
"totp": {
"codeLength": 123,
"periodSeconds": 123,
"skewTolerance": 123
},
"updatedAt": "2023-11-07T05:31:56Z"
}
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
This API uses OAuth2 with the Client Credential flow. Client Credentials must be sent in the BODY, not the headers. For an example of how to implement this, refer to the c1TokenSource.Token() function.
Body
The CredentialInventoryPolicyServiceCreateRequest message.
A human-readable name for the policy.
DelegatedConstraints controls which third-party sign-in providers are accepted as proof of email ownership, and how they are scoped.
Show child attributes
Show child attributes
EmailOTPConstraints configures one-time codes delivered by email.
Show child attributes
Show child attributes
The credential types users are permitted to enroll under this policy.
CREDENTIAL_TYPE_UNSPECIFIED, CREDENTIAL_TYPE_PASSKEY, CREDENTIAL_TYPE_PASSWORD, CREDENTIAL_TYPE_TOTP, CREDENTIAL_TYPE_EMAIL_OTP, CREDENTIAL_TYPE_RECOVERY_CODE, CREDENTIAL_TYPE_DELEGATED_GOOGLE, CREDENTIAL_TYPE_DELEGATED_MICROSOFT, CREDENTIAL_TYPE_UPSTREAM_IDP PasskeyConstraints controls how users may enroll passkeys (FIDO2 / WebAuthn).
Show child attributes
Show child attributes
PasswordConstraints sets the complexity rules a user's password must satisfy.
Show child attributes
Show child attributes
When a user matches more than one policy, the policy with the highest priority applies.
TOTPConstraints configures authenticator-app one-time codes (RFC 6238).
Show child attributes
Show child attributes
Response
Successful response
The CredentialInventoryPolicyServiceCreateResponse message.
CredentialInventoryPolicy defines which credential types your users may enroll and the rules for each type.
Show child attributes
Show child attributes
Was this page helpful?