Models: I
IdentityProviderCollectionPage
Section titled “IdentityProviderCollectionPage”data: list[kindgi.client.IdentityProviderConfig]
IdentityProviderConfig
Section titled “IdentityProviderConfig”OAuth 2.0 / OIDC provider configuration registered on a tenant. clientSecretRef is a REFERENCE resolved server-side (env-var key, secrets-manager path, KMS handle) — the plaintext client secret never crosses the wire.
provider_id: str(providerIdon the wire)kind: Literal['oauth2', 'oidc']client_id: str(clientIdon the wire)client_secret_ref: str(clientSecretRefon the wire)authorization_endpoint: AnyUrl(authorizationEndpointon the wire)token_endpoint: AnyUrl(tokenEndpointon the wire)userinfo_endpoint: AnyUrl | None(userinfoEndpointon the wire) (optional)scopes: list[str]allowed_redirect_uris: list[kindgi.client.AllowedRedirectUri] | None(allowedRedirectUrison the wire) (optional)claim_mapping: kindgi.client.ClaimMappingSpec | None(claimMappingon the wire) (optional)metadata: dict[str, Any] | None(optional)
IdentityProviderKind
Section titled “IdentityProviderKind”root: Literal['oauth2', 'oidc']
IdentitySessionCollectionPage
Section titled “IdentitySessionCollectionPage”data: list[kindgi.client.IdentitySessionSummary]has_more: bool(hasMoreon the wire)next_cursor: str | None(nextCursoron the wire) (optional)
IdentitySessionSummary
Section titled “IdentitySessionSummary”Wire-safe subset of a session. Excludes provider access-token / refresh-token — those never cross the wire, even to admins.
session_id: str(sessionIdon the wire)user_id: str(userIdon the wire)provider_id: str(providerIdon the wire)created_at: AwareDatetime(createdAton the wire)expires_at: AwareDatetime(expiresAton the wire)scopes: list[str]revoked_at: AwareDatetime | None(revokedAton the wire) (optional)