> ## Documentation Index
> Fetch the complete documentation index at: https://developers.authlete.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get Service Configuration

> This API gathers configuration information about a service.

This API is supposed to be called from within the implementation of the configuration endpoint of
the service where the service that supports OpenID Connect and [OpenID Connect Discovery 1.0](https://openid.net/specs/openid-connect-discovery-1_0.html)
must expose its configuration information in a JSON format. Details about the format are described
in "[3. OpenID Provider Metadata](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata)"
in OpenID Connect Discovery 1.0.




## OpenAPI

````yaml https://spec.speakeasy.com/authlete/sdk-workspace/authlete-api-explorer-with-code-samples get /api/{serviceId}/service/configuration
openapi: 3.0.3
info:
  title: Authlete API
  description: ''
  version: 3.0.16
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
servers:
  - description: 🇺🇸 US Cluster
    url: https://us.authlete.com
  - description: 🇯🇵 Japan Cluster
    url: https://jp.authlete.com
  - description: 🇪🇺 Europe Cluster
    url: https://eu.authlete.com
  - description: 🇧🇷 Brazil Cluster
    url: https://br.authlete.com
security:
  - bearer: []
tags:
  - name: Service Management
    description: >-
      API endpoints for managing services, including creation, update, and
      deletion of services.
    x-tag-expanded: false
  - name: Client Management
    description: >-
      API endpoints for managing OAuth clients, including creation, update, and
      deletion of clients.
    x-tag-expanded: false
  - name: Authorization Endpoint
    description: API endpoints for implementing OAuth 2.0 Authorization Endpoint.
    x-tag-expanded: false
  - name: Pushed Authorization Endpoint
    description: >-
      API endpoints for implementing OAuth 2.0 Pushed Authorization Requests
      (PAR).
    x-tag-expanded: false
  - name: Token Endpoint
    description: API endpoints for implementing OAuth 2.0 Token Endpoint.
    x-tag-expanded: false
  - name: Token Operations
    description: >-
      API endpoints for various token related operations, including creating,
      revoking and deleting access_tokens with specified scopes.
    x-tag-expanded: false
  - name: Introspection Endpoint
    description: API endpoints for implementing OAuth 2.0 Introspection Endpoint.
    x-tag-expanded: false
  - name: Revocation Endpoint
    description: API endpoint for implementing OAuth 2.0 Revocation Endpoint.
    x-tag-expanded: false
  - name: UserInfo Endpoint
    description: API endpoints for implementing OpenID Connect UserInfo Endpoint.
    x-tag-expanded: false
  - name: JWK Set Endpoint
    description: API endpoints for to generate JSON Web Key Set (JWKS) for a service.
    x-tag-expanded: false
  - name: Discovery Endpoint
    description: API endpoints for implementing OpenID Connect Discovery.
    x-tag-expanded: false
  - name: Configuration Endpoint
    description: API endpoint for accessing configuration settings for a service.
    x-tag-expanded: false
  - name: Dynamic Client Registration
    description: API endpoints for implementing OAuth 2.0 Dynamic Client Registration.
    x-tag-expanded: false
  - name: CIBA
    description: >-
      API endpoints for implementing Client-Initiated Backchannel Authentication
      (CIBA).
    x-tag-expanded: false
  - name: Grant Management Endpoint
    description: >-
      API endpoint for implementing OAuth 2.0 grants, including grant management
      actions like updating and revoking grants.
    x-tag-expanded: false
  - name: Jose Object
    description: API endpoints for JOSE objects.
    x-tag-expanded: false
  - name: Device Flow
    description: API endpoints for implementing OAuth 2.0 Device Flow
    x-tag-expanded: false
  - name: Federation Endpoint
    description: API endpoints for implementing OpenID Federation using Authlete.
    x-tag-expanded: false
  - name: Verifiable Credential Issuer
    description: >-
      API endpoints for implementing and running a Verifiable Credential Issuer
      (VCI).
    x-tag-expanded: false
  - name: Hardware Security Key
    description: API endpoints for managing hardware security keys (HSK).
    x-tag-expanded: false
  - name: Utility Endpoints
    description: API endpoints for various utility operations.
    x-tag-expanded: false
  - name: Native SSO
    description: API endpoints for Native SSO
    x-tag-expanded: false
paths:
  /api/{serviceId}/service/configuration:
    get:
      tags:
        - Service Management
      summary: Get Service Configuration
      description: >
        This API gathers configuration information about a service.


        This API is supposed to be called from within the implementation of the
        configuration endpoint of

        the service where the service that supports OpenID Connect and [OpenID
        Connect Discovery
        1.0](https://openid.net/specs/openid-connect-discovery-1_0.html)

        must expose its configuration information in a JSON format. Details
        about the format are described

        in "[3. OpenID Provider
        Metadata](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata)"

        in OpenID Connect Discovery 1.0.
      operationId: service_configuration_api
      parameters:
        - in: path
          name: serviceId
          description: A service ID.
          schema:
            type: string
          required: true
        - in: query
          name: pretty
          schema:
            type: boolean
          required: false
          description: >-
            This boolean value indicates whether the JSON in the response should
            be formatted or not. If `true`, the JSON in the response is
            pretty-formatted. The default value is `false`.
        - in: query
          name: patch
          schema:
            type: string
          required: false
          description: >-
            Get the JSON Patch [RFC 6902 JavaScript Object Notation (JSON)
            Patch](https://www.rfc-editor.org/rfc/rfc6902) to be applied.
      responses:
        '200':
          description: Service configuration retrieved successfully
          content:
            application/json:
              schema:
                type: object
                additionalProperties: true
                description: >
                  An object representing OpenID Provider configuration
                  information. See [OpenID Provider
                  Metadata](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata)
                  and [OpenID Provider Configuration
                  Response](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderConfigurationResponse)
                  for more details.
              example:
                issuer: https://my-service.example.com
                authorization_endpoint: https://my-service.example.com/authz
                token_endpoint: https://my-service.example.com/token
                scopes_supported:
                  - history.read
                  - timeline.read
                response_types_supported:
                  - code
                response_modes_supported:
                  - query
                  - fragment
                  - form_post
                  - query.jwt
                  - fragment.jwt
                  - form_post.jwt
                  - jwt
                grant_types_supported:
                  - authorization_code
                  - password
                  - refresh_token
                subject_types_supported:
                  - public
                  - pairwise
                id_token_signing_alg_values_supported:
                  - HS256
                  - HS384
                  - HS512
                  - RS256
                  - RS384
                  - RS512
                  - PS256
                  - PS384
                  - PS512
                  - ES256
                  - ES384
                  - ES512
                  - ES256K
                  - EdDSA
                id_token_encryption_alg_values_supported:
                  - RSA1_5
                  - RSA-OAEP
                  - RSA-OEAP-256
                  - ECDH-ES
                  - ECDH-ES+A128KW
                  - ECDH-ES+A192KW
                  - ECDH-ES+A256KW
                  - A128KW
                  - A192KW
                  - A256KW
                  - dir
                  - A128GCMKW
                  - A192GCMKW
                  - A256GCMKW
                  - PBES2-HS256+A128KW
                  - PBES2-HS384+A192KW
                  - PBES2-HS512+A256KW
                id_token_encryption_enc_values_supported:
                  - A128CBC-HS256
                  - A192CBC-HS384
                  - A256CBC-HS512
                  - A128GCM
                  - A192GCM
                  - A256GCM
                userinfo_signing_alg_values_supported:
                  - HS256
                  - HS384
                  - HS512
                  - RS256
                  - RS384
                  - RS512
                  - PS256
                  - PS384
                  - PS512
                  - ES256
                  - ES384
                  - ES512
                  - ES256K
                  - EdDSA
                  - none
                userinfo_encryption_alg_values_supported:
                  - RSA1_5
                  - RSA-OAEP
                  - RSA-OEAP-256
                  - ECDH-ES
                  - ECDH-ES+A128KW
                  - ECDH-ES+A192KW
                  - ECDH-ES+A256KW
                  - A128KW
                  - A192KW
                  - A256KW
                  - dir
                  - A128GCMKW
                  - A192GCMKW
                  - A256GCMKW
                  - PBES2-HS256+A128KW
                  - PBES2-HS384+A192KW
                  - PBES2-HS512+A256KW
                userinfo_encryption_enc_values_supported:
                  - A128CBC-HS256
                  - A192CBC-HS384
                  - A256CBC-HS512
                  - A128GCM
                  - A192GCM
                  - A256GCM
                request_object_signing_alg_values_supported:
                  - HS256
                  - HS384
                  - HS512
                  - RS256
                  - RS384
                  - RS512
                  - PS256
                  - PS384
                  - PS512
                  - ES256
                  - ES384
                  - ES512
                  - ES256K
                  - EdDSA
                request_object_encryption_alg_values_supported:
                  - RSA1_5
                  - RSA-OAEP
                  - RSA-OEAP-256
                  - ECDH-ES
                  - ECDH-ES+A128KW
                  - ECDH-ES+A192KW
                  - ECDH-ES+A256KW
                  - A128KW
                  - A192KW
                  - A256KW
                  - dir
                  - A128GCMKW
                  - A192GCMKW
                  - A256GCMKW
                  - PBES2-HS256+A128KW
                  - PBES2-HS384+A192KW
                  - PBES2-HS512+A256KW
                request_object_encryption_enc_values_supported:
                  - A128CBC-HS256
                  - A192CBC-HS384
                  - A256CBC-HS512
                  - A128GCM
                  - A192GCM
                  - A256GCM
                authorization_signing_alg_values_supported:
                  - HS256
                  - HS384
                  - HS512
                  - RS256
                  - RS384
                  - RS512
                  - PS256
                  - PS384
                  - PS512
                  - ES256
                  - ES384
                  - ES512
                  - ES256K
                  - EdDSA
                authorization_encryption_alg_values_supported:
                  - RSA1_5
                  - RSA-OAEP
                  - RSA-OEAP-256
                  - ECDH-ES
                  - ECDH-ES+A128KW
                  - ECDH-ES+A192KW
                  - ECDH-ES+A256KW
                  - A128KW
                  - A192KW
                  - A256KW
                  - dir
                  - A128GCMKW
                  - A192GCMKW
                  - A256GCMKW
                  - PBES2-HS256+A128KW
                  - PBES2-HS384+A192KW
                  - PBES2-HS512+A256KW
                authorization_encryption_enc_values_supported:
                  - A128CBC-HS256
                  - A192CBC-HS384
                  - A256CBC-HS512
                  - A128GCM
                  - A192GCM
                  - A256GCM
                token_endpoint_auth_methods_supported:
                  - client_secret_basic
                token_endpoint_auth_signing_alg_values_supported:
                  - HS256
                  - HS384
                  - HS512
                  - RS256
                  - RS384
                  - RS512
                  - PS256
                  - PS384
                  - PS512
                  - ES256
                  - ES384
                  - ES512
                  - ES256K
                  - EdDSA
                display_values_supported:
                  - page
                claim_types_supported:
                  - normal
                claims_parameter_supported: true
                request_parameter_supported: true
                request_uri_parameter_supported: true
                require_request_uri_registration: true
                revocation_endpoint: https://my-service.example.com/revocation
                revocation_endpoint_auth_methods_supported: []
                revocation_endpoint_auth_signing_alg_values_supported:
                  - HS256
                  - HS384
                  - HS512
                  - RS256
                  - RS384
                  - RS512
                  - PS256
                  - PS384
                  - PS512
                  - ES256
                  - ES384
                  - ES512
                  - ES256K
                  - EdDSA
                introspection_endpoint: https://my-service.example.com/introspection
                introspection_endpoint_auth_methods_supported: []
                introspection_endpoint_auth_signing_alg_values_supported:
                  - HS256
                  - HS384
                  - HS512
                  - RS256
                  - RS384
                  - RS512
                  - PS256
                  - PS384
                  - PS512
                  - ES256
                  - ES384
                  - ES512
                  - ES256K
                  - EdDSA
                code_challenge_methods_supported:
                  - plain
                  - S256
                tls_client_certificate_bound_access_tokens: false
                backchannel_token_delivery_modes_supported: []
                backchannel_authentication_request_signing_alg_values_supported:
                  - RS256
                  - RS384
                  - RS512
                  - PS256
                  - PS384
                  - PS512
                  - ES256
                  - ES384
                  - ES512
                  - ES256K
                  - EdDSA
                backchannel_user_code_parameter_supported: false
                require_pushed_authorization_requests: false
                authorization_details_supported: true
                verified_claims_supported: false
                dpop_signing_alg_values_supported:
                  - RS256
                  - RS384
                  - RS512
                  - PS256
                  - PS384
                  - PS512
                  - ES256
                  - ES384
                  - ES512
                  - ES256K
                  - EdDSA
                require_signed_request_object: false
                authorization_response_iss_parameter_supported: true
        '400':
          $ref: '#/components/responses/400'
        '401':
          $ref: '#/components/responses/401'
        '403':
          $ref: '#/components/responses/403'
        '500':
          $ref: '#/components/responses/500'
      x-codeSamples:
        - lang: typescript
          label: Typescript (SDK)
          source: |-
            import { Authlete } from "@authlete/typescript-sdk";

            const authlete = new Authlete({
              bearer: process.env["AUTHLETE_BEARER"] ?? "",
            });

            async function run() {
              const result = await authlete.service.getConfiguration({
                serviceId: "<id>",
              });

              console.log(result);
            }

            run();
        - lang: ruby
          label: Ruby (SDK)
          source: |-
            require 'authlete_ruby_sdk'

            Models = ::Authlete::Models
            s = ::Authlete::Client.new(
              bearer: '<YOUR_BEARER_TOKEN_HERE>'
            )
            res = s.services.configuration(service_id: '<id>')

            unless res.object.nil?
              # handle response
            end
        - lang: go
          label: Go (SDK)
          source: "package main\n\nimport(\n\t\"context\"\n\t\"os\"\n\tauthlete \"github.com/authlete/authlete-go-sdk\"\n\t\"log\"\n)\n\nfunc main() {\n    ctx := context.Background()\n\n    s := authlete.New(\n        authlete.WithSecurity(os.Getenv(\"AUTHLETE_BEARER\")),\n    )\n\n    res, err := s.Service.GetConfiguration(ctx, \"<id>\", nil, nil)\n    if err != nil {\n        log.Fatal(err)\n    }\n    if res.Object != nil {\n        // handle response\n    }\n}"
      x-code-samples:
        - lang: shell
          label: curl
          source: >
            curl -v
            https://us.authlete.com/api/21653835348762/service/configuration?pretty=true
            \

            -H 'Authorization: Bearer
            V5a40R6dWvw2gMkCOBFdZcM95q4HC0Z-T0YKD9-nR6F'
        - lang: java
          label: java
          source: |
            AuthleteConfiguration conf = ...;
            AuthleteApi api = AuthleteApiFactory.create(conf);

            api.getServiceConfiguration(true);
        - lang: python
          source: |
            conf = ...
            api = AuthleteApiImpl(conf)

            api.getServiceConfiguration(True)
components:
  responses:
    '400':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001201
            resultMessage: '[A001201] /auth/authorization, TLS must be used.'
    '401':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001202
            resultMessage: '[A001202] /auth/authorization, Authorization header is missing.'
    '403':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001215
            resultMessage: >-
              [A001215] /auth/authorization, The client (ID = 26837717140341) is
              locked.
    '500':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001101
            resultMessage: '[A001101] /auth/authorization, Authlete Server error.'
  schemas:
    result:
      type: object
      properties:
        resultCode:
          type: string
          description: The code which represents the result of the API call.
        resultMessage:
          type: string
          description: A short message which explains the result of the API call.
  securitySchemes:
    bearer:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >
        Authenticate every request with a **Service Access Token** or
        **Organization Token**.

        Set the token value in the `Authorization: Bearer <token>` header.


        **Service Access Token**: Scoped to a single service. Use when
        automating service-level configuration or runtime flows.


        **Organization Token**: Scoped to the organization; inherits permissions
        across services. Use for org-wide automation or when managing multiple
        services programmatically.


        Both token types are issued by the Authlete console or provisioning
        APIs.

````