> ## Documentation Index
> Fetch the complete documentation index at: https://docs.prisme.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# OpenID Connect Discovery

> Discovery document advertising this instance's OIDC endpoints (authorization, token, userinfo, jwks, end session, introspection, registration, pushed authorization requests) together with the supported scopes, claims, response types and grant types. Preferred entry point: resolve every other /oidc/* URL from here instead of hardcoding paths.



## OpenAPI

````yaml /api-reference/swagger.yml get /oidc/.well-known/openid-configuration
openapi: 3.0.0
info:
  version: 1.0.0
  title: Prisme.ai APIs
  description: Prisme.ai APIs specifications
  termsOfService: https://www.prisme.ai/mentions-legales
  contact:
    name: Prisme.ai Support Team
    email: support@prisme.ai
    url: https://www.prisme.ai
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
servers:
  - url: https://api.studio.prisme.ai
    description: Prisme.ai Cloud
  - url: https://{customDomain}
    description: Self-hosted Prisme.ai instance
    variables:
      customDomain:
        default: api.your-prisme-instance.com
        description: API hostname of your self-hosted Prisme.ai deployment
  - url: http://localhost:3001
    description: Local development
security:
  - BearerAuth: []
  - OrgApiKeyAuth: []
  - BearerAuth: []
    OrgApiKeyAuth: []
tags:
  - name: API Gateway
    description: >-
      Authentication, session management, SSO providers, and user profile
      endpoints.
  - name: Prisme.ai Workspaces
    description: >-
      CRUD operations for workspaces and their resources (pages, apps,
      automations, imports, variables).
  - name: Prisme.ai Runtime
    description: Execute workspace automations and manage their runtime lifecycle.
  - name: Prisme.ai Events
    description: Event ingestion, delivery, and subscription filtering across the platform.
  - name: Organizations
    description: >-
      Manage organizations, members, roles, invites, groups, and org-level
      service accounts.
  - name: Subscriptions
    description: >-
      Manage organization subscription plans and tier assignments (SuperAdmin
      only).
  - name: Secrets
    description: Read and patch encrypted key-value secrets scoped to a workspace.
  - name: ApiKeys
    description: Create, list, rotate, and validate workspace-scoped API keys.
  - name: Permissions
    description: >-
      Share or unshare resources (workspaces, pages, …) with users via roles or
      fine-grained rules.
  - name: Monitoring
    description: Platform readiness checks across services (SuperAdmin only).
  - name: AuthProviders
  - name: OIDC
    description: >-
      Endpoints of the embedded OpenID Connect provider, mounted under /oidc.
      The protocol endpoints follow OpenID Connect Core / OAuth 2.0 and are best
      resolved from GET /oidc/.well-known/openid-configuration; the
      /oidc/interaction/* routes are Prisme.ai-specific and covered by no
      standard.
paths:
  /oidc/.well-known/openid-configuration:
    get:
      tags:
        - OIDC
      summary: OpenID Connect Discovery
      description: >-
        Discovery document advertising this instance's OIDC endpoints
        (authorization, token, userinfo, jwks, end session, introspection,
        registration, pushed authorization requests) together with the supported
        scopes, claims, response types and grant types. Preferred entry point:
        resolve every other /oidc/* URL from here instead of hardcoding paths.
      operationId: discoverOidcConfiguration
      responses:
        '200':
          description: Success Response
          content:
            application/json:
              schema:
                type: object
                additionalProperties: true
                required:
                  - issuer
                  - authorization_endpoint
                  - token_endpoint
                  - jwks_uri
                  - response_types_supported
                  - subject_types_supported
                  - id_token_signing_alg_values_supported
                properties:
                  issuer:
                    type: string
                  authorization_endpoint:
                    type: string
                  token_endpoint:
                    type: string
                  userinfo_endpoint:
                    type: string
                  jwks_uri:
                    type: string
                  end_session_endpoint:
                    type: string
                  introspection_endpoint:
                    type: string
                  registration_endpoint:
                    type: string
                  pushed_authorization_request_endpoint:
                    type: string
                  scopes_supported:
                    type: array
                    items:
                      type: string
                  claims_supported:
                    type: array
                    items:
                      type: string
                  response_types_supported:
                    type: array
                    items:
                      type: string
                  subject_types_supported:
                    type: array
                    items:
                      type: string
                  id_token_signing_alg_values_supported:
                    type: array
                    items:
                      type: string
                  grant_types_supported:
                    type: array
                    items:
                      type: string
                  code_challenge_methods_supported:
                    type: array
                    items:
                      type: string
      security: []
components:
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
    OrgApiKeyAuth:
      type: apiKey
      in: header
      name: x-prismeai-api-key

````