> ## Documentation Index
> Fetch the complete documentation index at: https://developers.authlete.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Process Entity Configuration Request

> This API gathers the federation configuration about a service. The authorization server implementation should retrieve the value of the `action` response parameter from the API response and take the following steps according to the value.

<Accordion title="Full description" defaultOpen={false}>
  ### `OK`

  When the value of the  `action` response
  parameter is `OK`, it means that Authlete
  could prepare an entity configuration successfully.
  In this case, the implementation of the entity configuration endpoint of the
  authorization server should return an HTTP response to the client application
  with the HTTP status code "`200 OK`" and the content type
  "`application/entity-statement+jwt`". The message body (= an entity
  configuration in the JWT format) of the response has been prepared by
  Authlete's `/federation/configuration` API and it is available as the
  `responseContent` response parameter.
  The implementation of the entity configuration endpoint can construct an
  HTTP response by doing like below.

  ```
  200 OK
  Content-Type: application/entity-statement+jwt
  (Other HTTP headers)
  (the value of the responseContent response parameter)
  ```

  ### `NOT_FOUND`

  When the value of the  `action` response
  parameter is `NOT_FOUND`, it means that
  the service configuration has not enabled the feature of [OpenID Connect
  Federation 1.0](https://openid.net/specs/openid-connect-federation-1_0.html) and so the client application should have not access the
  entity configuration endpoint.
  In this case, the implementation of the entity configuration endpoint of the
  authorization server should return an HTTP response to the client application
  with the HTTP status code "`404 Not Found`" and the content type
  "`application/json`". The message body (= error information in the JSON
  format) of the response has been prepared by Authlete's
  `/federation/configuration` API and it is available as the
  `responseContent` response parameter.
  The implementation of the entity configuration endpoint can construct an
  HTTP response by doing like below.

  ```
  404 Not Found
  Content-Type: application/json
  (Other HTTP headers)
  (the value of the responseContent response parameter)
  ```

  ### `INTERNAL_SERVER_ERROR`

  could prepare an entity configuration successfully.
  In this case, the implementation of the entity configuration endpoint of the
  authorization server should return an HTTP response to the client application
  with the HTTP status code "`200 OK`" and the content type
  "`application/entity-statement+jwt`". The message body (= an entity
  configuration in the JWT format) of the response has been prepared by
  Authlete's `/federation/configuration` API and it is available as the
  `responseContent` response parameter.
  The implementation of the entity configuration endpoint can construct an
  HTTP response by doing like below.

  ```
  200 OK
  Content-Type: application/entity-statement+jwt
  (Other HTTP headers)
  (the value of the responseContent response parameter)
  ```
</Accordion>


## OpenAPI

````yaml https://spec.speakeasy.com/authlete/sdk-workspace/authlete-api-explorer-with-code-samples post /api/{serviceId}/federation/configuration
openapi: 3.0.3
info:
  title: Authlete API
  description: ''
  version: 3.0.16
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
servers:
  - description: 🇺🇸 US Cluster
    url: https://us.authlete.com
  - description: 🇯🇵 Japan Cluster
    url: https://jp.authlete.com
  - description: 🇪🇺 Europe Cluster
    url: https://eu.authlete.com
  - description: 🇧🇷 Brazil Cluster
    url: https://br.authlete.com
security:
  - bearer: []
tags:
  - name: Service Management
    description: >-
      API endpoints for managing services, including creation, update, and
      deletion of services.
    x-tag-expanded: false
  - name: Client Management
    description: >-
      API endpoints for managing OAuth clients, including creation, update, and
      deletion of clients.
    x-tag-expanded: false
  - name: Authorization Endpoint
    description: API endpoints for implementing OAuth 2.0 Authorization Endpoint.
    x-tag-expanded: false
  - name: Pushed Authorization Endpoint
    description: >-
      API endpoints for implementing OAuth 2.0 Pushed Authorization Requests
      (PAR).
    x-tag-expanded: false
  - name: Token Endpoint
    description: API endpoints for implementing OAuth 2.0 Token Endpoint.
    x-tag-expanded: false
  - name: Token Operations
    description: >-
      API endpoints for various token related operations, including creating,
      revoking and deleting access_tokens with specified scopes.
    x-tag-expanded: false
  - name: Introspection Endpoint
    description: API endpoints for implementing OAuth 2.0 Introspection Endpoint.
    x-tag-expanded: false
  - name: Revocation Endpoint
    description: API endpoint for implementing OAuth 2.0 Revocation Endpoint.
    x-tag-expanded: false
  - name: UserInfo Endpoint
    description: API endpoints for implementing OpenID Connect UserInfo Endpoint.
    x-tag-expanded: false
  - name: JWK Set Endpoint
    description: API endpoints for to generate JSON Web Key Set (JWKS) for a service.
    x-tag-expanded: false
  - name: Discovery Endpoint
    description: API endpoints for implementing OpenID Connect Discovery.
    x-tag-expanded: false
  - name: Configuration Endpoint
    description: API endpoint for accessing configuration settings for a service.
    x-tag-expanded: false
  - name: Dynamic Client Registration
    description: API endpoints for implementing OAuth 2.0 Dynamic Client Registration.
    x-tag-expanded: false
  - name: CIBA
    description: >-
      API endpoints for implementing Client-Initiated Backchannel Authentication
      (CIBA).
    x-tag-expanded: false
  - name: Grant Management Endpoint
    description: >-
      API endpoint for implementing OAuth 2.0 grants, including grant management
      actions like updating and revoking grants.
    x-tag-expanded: false
  - name: Jose Object
    description: API endpoints for JOSE objects.
    x-tag-expanded: false
  - name: Device Flow
    description: API endpoints for implementing OAuth 2.0 Device Flow
    x-tag-expanded: false
  - name: Federation Endpoint
    description: API endpoints for implementing OpenID Federation using Authlete.
    x-tag-expanded: false
  - name: Verifiable Credential Issuer
    description: >-
      API endpoints for implementing and running a Verifiable Credential Issuer
      (VCI).
    x-tag-expanded: false
  - name: Hardware Security Key
    description: API endpoints for managing hardware security keys (HSK).
    x-tag-expanded: false
  - name: Utility Endpoints
    description: API endpoints for various utility operations.
    x-tag-expanded: false
  - name: Native SSO
    description: API endpoints for Native SSO
    x-tag-expanded: false
paths:
  /api/{serviceId}/federation/configuration:
    post:
      tags:
        - Federation Endpoint
      summary: Process Entity Configuration Request
      description: |
        This API gathers the federation configuration about a service.
        The authorization server implementation should
        retrieve the value of the `action`
        response parameter from the API response and take the following steps
        according to the value.
      operationId: federation_configuration_api
      parameters:
        - in: path
          name: serviceId
          description: A service ID.
          schema:
            type: string
          required: true
      requestBody:
        content:
          application/json:
            schema:
              type: object
      responses:
        '200':
          description: Federation configuration retrieved successfully
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/federation_configuration_response'
        '400':
          $ref: '#/components/responses/400'
        '401':
          $ref: '#/components/responses/401'
        '403':
          $ref: '#/components/responses/403'
        '500':
          $ref: '#/components/responses/500'
      x-codeSamples:
        - lang: typescript
          label: Typescript (SDK)
          source: |-
            import { Authlete } from "@authlete/typescript-sdk";

            const authlete = new Authlete({
              bearer: process.env["AUTHLETE_BEARER"] ?? "",
            });

            async function run() {
              const result = await authlete.federation.configuration({
                serviceId: "<id>",
              });

              console.log(result);
            }

            run();
        - lang: ruby
          label: Ruby (SDK)
          source: |-
            require 'authlete_ruby_sdk'

            Models = ::Authlete::Models
            s = ::Authlete::Client.new(
              bearer: '<YOUR_BEARER_TOKEN_HERE>'
            )
            res = s.federation.configuration(service_id: '<id>')

            unless res.federation_configuration_response.nil?
              # handle response
            end
        - lang: go
          label: Go (SDK)
          source: "package main\n\nimport(\n\t\"context\"\n\t\"os\"\n\tauthlete \"github.com/authlete/authlete-go-sdk\"\n\t\"log\"\n)\n\nfunc main() {\n    ctx := context.Background()\n\n    s := authlete.New(\n        authlete.WithSecurity(os.Getenv(\"AUTHLETE_BEARER\")),\n    )\n\n    res, err := s.Federation.Configuration(ctx, \"<id>\", nil)\n    if err != nil {\n        log.Fatal(err)\n    }\n    if res.FederationConfigurationResponse != nil {\n        // handle response\n    }\n}"
      x-code-samples:
        - lang: shell
          label: curl
          source: >
            curl -v
            https://us.authlete.com/api/21653835348762/federation/configuration
            \

            -H 'Authorization: Bearer
            V5a40R6dWvw2gMkCOBFdZcM95q4HC0Z-T0YKD9-nR6F'
        - lang: java
          label: java
          source: |
            AuthleteConfiguration conf = ...;
            AuthleteApi api = AuthleteApiFactory.create(conf);

            api.getFederationConfiguration();
        - lang: python
          source: |
            conf = ...
            api = AuthleteApiImpl(conf)

            api.getFederationConfiguration(True)
components:
  schemas:
    federation_configuration_response:
      type: object
      properties:
        resultCode:
          type: string
          description: The code which represents the result of the API call.
        resultMessage:
          type: string
          description: A short message which explains the result of the API call.
        action:
          type: string
          enum:
            - OK
            - NOT_FOUND
            - INTERNAL_SERVER_ERROR
          description: >-
            The next action that the authorization server implementation should
            take.
        responseContent:
          type: string
          description: >
            The content that the authorization server implementation is to
            return to the client application.

            Its format varies depending on the value of `action` parameter.
    result:
      type: object
      properties:
        resultCode:
          type: string
          description: The code which represents the result of the API call.
        resultMessage:
          type: string
          description: A short message which explains the result of the API call.
  responses:
    '400':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001201
            resultMessage: '[A001201] /auth/authorization, TLS must be used.'
    '401':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001202
            resultMessage: '[A001202] /auth/authorization, Authorization header is missing.'
    '403':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001215
            resultMessage: >-
              [A001215] /auth/authorization, The client (ID = 26837717140341) is
              locked.
    '500':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001101
            resultMessage: '[A001101] /auth/authorization, Authlete Server error.'
  securitySchemes:
    bearer:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >
        Authenticate every request with a **Service Access Token** or
        **Organization Token**.

        Set the token value in the `Authorization: Bearer <token>` header.


        **Service Access Token**: Scoped to a single service. Use when
        automating service-level configuration or runtime flows.


        **Organization Token**: Scoped to the organization; inherits permissions
        across services. Use for org-wide automation or when managing multiple
        services programmatically.


        Both token types are issued by the Authlete console or provisioning
        APIs.

````