Skip to content
Browse Gluu Server 4.4

Release

Gluu API References

#Overview

The Gluu Server comes with a variety of APIs to help handle administration and configuration.

Swagger documentation for Gluu Services can be accessed through the following links:

#Additional Information

#SCIM

SCIM requires some additional configuration to get started.

To enable SCIM open the oxTrust administration interface and navigate to Organization Configuration > System Configuration. Find SCIM Support and select Enabled.

enable

Then enable the protection mode you want for your API, see details here.

#SCIM Resource types

The following resources are supported:

ResourceSchema URINotes
Userurn:ietf:params:scim:schemas:core:2.0:UserSee section 4.1 of RFC 7643
Groupurn:ietf:params:scim:schemas:core:2.0:GroupSee section 4.2 of RFC 7643
Fido u2f devicesurn:ietf:params:scim:schemas:core:2.0:FidoDeviceRepresents a fido u2f credential enrolled by a user
Fido 2.0 devicesurn:ietf:params:scim:schemas:core:2.0:Fido2DeviceRepresents a fido 2.0 credential enrolled by a user

Additionally the following resource extensions are defined:

ResourceSchema URIAttributes
Userurn:ietf:params:scim:schemas:extension:gluu:2.0:UserAttributes can be assigned dynamically via oxTrust

In this section we provide a conformance matrix where you can see which features from the spec are supported by Gluu implementation.

To learn about the specific capabilities of the service, inspect your /ServiceProvider, /ResourceTypes, and /Schemas endpoints (see below). These endpoints are not protected so you can use a web browser to check.

#SCIM Conformance matrix

The following table lists characteristics of SCIM protocol (see section 3 of RFC 7644) and correlates the level of support and conformance provided by Gluu Server implementation.

CharacteristicComplianceAvailable via methodsNotes on support
Resource creationFullPOSTCreation of Fido Devices not applicable
Resource retrieval by identifierFullGET
Resource(s) retrieval by queryFullGET and POSTSupports searches from root endpoint too. Complex multi-valued attributes not supported in sortBy param
Resource attributes replacementPartialPUTTo avoid clients to accidentally clear data, only attributes found in payload are modified. No need to pass the whole resource nor required attributes
Resource attributes modificationFullPATCHAll types of operations supported (add/remove/replace) for user and group resources
Resource removalFullDELETE
Bulk operationsFullPOSTCircular reference processing not supported. bulkIds can be used not only in "data" attribute of operations but in "path" too
Returned attributes controlFullGET, POST, PUT, PATCHSupports attributes/excludedAttributes params and attribute notation (sections 3.9/3.10)
"/me" URI alias--Not applicable: operations actually not executed on a user's behalf or other SCIM resource
Resource versioning--Feature may be available upon explicit customer demand