Replace the M2M workloads of an onboarding case
PUT/v1/onboarding-cases/:case_id/m2m-clients
Declares the bank's machine-to-machine (M2M) workloads: back-end systems that call
the Lyriq Connector without a human user. A workload authenticates with a short-lived
assertion issued by the bank's FIS identity provider; the platform IAM verifies it
against workload_identity_provider and exchanges it for a Lyriq Connector access
token. Workloads are secretless: no client secret or private key is sent to or held
by the platform.
Required scope: connector:onboarding:artifacts:write.
Allowed states: AWAITING_BANK_ADMIN, BANK_CONFIGURING, NEEDS_CHANGES
(otherwise 409). The first edit moves AWAITING_BANK_ADMIN to BANK_CONFIGURING.
Full replacement. The request replaces the complete list. Send every workload you
want to keep; send m2m_clients: [] (and workload_identity_provider: null) to remove
them all. No Idempotency-Key is used; repeating the same request is safe and has the
same effect (the case version still increases).
workload_identity_provider (required key; may be null only when m2m_clients
is empty, otherwise 422):
jwks_url(required): the JWKS endpoint the platform IAM uses to verify your workload assertions. AbsolutehttpsURL, at most 2048 characters (plainhttpis accepted only forlocalhostin a sandbox case).issuer(optional): the exactissvalue of your workload assertions. Omitted or blank means the case'sfis_idp_entity_id. At most 2048 characters.
When m2m_clients is empty the provider is not stored.
Each m2m_clients[] entry (at most 20 entries; surrounding whitespace is trimmed
from all strings):
display_name(required, 1 to 128 characters): a name for the workload.business_purpose(required, 1 to 512 characters): what the workload does.fis_client_id(required, 1 to 256 characters): the workload's client identifier at FIS. Thesubclaim of the workload's assertion must equal this value exactly (case-sensitive). Must be unique within the request and within your bank.roles(required, at least one, unique): preset labelsmaker,checker,readonly. Labels describe the workload; they do not grant permissions. Administrative roles (bank-admin) cannot be given to a workload.scopes(required, at least one, unique): the permissions the workload's access tokens carry. This is the only thing that authorises its API calls. Any assignable scope may be combined with any role. Assignable scopes:connector:accounts:create,connector:accounts:list,connector:accounts:read,connector:accounts:holding-registrations:create,connector:accounts:holding-registrations:list,connector:accounts:holding-registrations:read,connector:assets:list,connector:assets:read,connector:auth-profiles:bind,connector:auth-profiles:create,connector:auth-profiles:list,connector:auth-profiles:read,connector:auth-profiles:update,connector:balances:list,connector:banks:list,connector:banks:read,connector:exposures:list,connector:liabilities:list,connector:limits:list,connector:limits:read,connector:limits:update,connector:operations:cancel,connector:operations:list,connector:operations:read,connector:redemptions:create,connector:redemptions:list,connector:redemptions:read,connector:redemption-policies:list,connector:redemption-policies:read,connector:reviews:decide,connector:reviews:list,connector:reviews:read,connector:settlement_cycle:list,connector:settlement_cycle:read,connector:transfers:create,connector:transfers:list,connector:transfers:read,connector:transfers:screening-decide,connector:webhook_deliveries:list,connector:webhook_deliveries:read,connector:webhooks:create,connector:webhooks:list,connector:webhooks:read,connector:webhooks:rotate-secret,connector:webhooks:test,connector:webhooks:update. Any other scope (operator, onboarding, staff,connector:m2m-clients:read, unknown) returns422.
Do not send a platform client id. The platform generates one per workload
(keycloak_client_id in the response, shown as Platform client ID in the Bank
Portal) of the form bank-m2m-{uuid}. It keeps the same value for a workload across
later replacements as long as its fis_client_id is unchanged.
Provisioning outcome. Saving workloads provisions nothing. When the case is
accepted and its activation operation succeeds, the platform IAM creates one client
per workload with the generated platform client id. Each client is created disabled,
receives its approved scopes and bank membership, and is then enabled. The case
reaches ACTIVE only after every workload (and every staff member) has been
provisioned; from then on the workload can obtain access tokens (valid 300 seconds)
and appears in GET /v1/m2m-clients.
The response is the updated case; the saved workloads are in
data.attributes.configuration.m2m_clients.
Request
Responses
- 200
- 400
- 401
- 403
- 404
- 409
- 422
- 503
The workload list was replaced. Returns the updated onboarding case, including
readiness.
The request is malformed: invalid JSON syntax, an invalid path or query parameter, a
missing required header such as Idempotency-Key, or a single field that fails its own
format rule. Fix the request before retrying; retrying it unchanged fails again.
The bearer token is missing, malformed, expired, signed by an unknown key, or was not issued by the platform IAM for the Lyriq Connector. Obtain a new token and retry. See the Authentication section.
The token is valid but may not perform this request: it lacks the required scope, has
no bank membership, needs an x-dan-bank-id header to choose between several
memberships, names a bank in x-dan-bank-id it has no membership for, or the caller's
bank is suspended or terminated. A new token with the same configuration fails the same
way. See the Authentication section.
The resource does not exist, or it belongs to another bank. The Lyriq Connector does not distinguish the two cases, so resources of other banks are never disclosed.
The request conflicts with an earlier request or with the current state of the target:
an Idempotency-Key reused with a different body (IDEMPOTENCY_CONFLICT), a request with
the same key still in progress (IDEMPOTENCY_PENDING), or a target resource in a state
that does not allow the request (STATE_CONFLICT).
The body does not match the schema (for example an unknown field such as
keycloak_client_id, or a role outside maker, checker, readonly), or a
workload violates the rules above.
The request could not be served right now. Either the network is not fully operational
(OUTBOUND_HALTED or READ_ONLY: mutations are refused while read endpoints keep
working; OPERATIONAL_STATE_UNKNOWN: the state could not be determined), or a platform
dependency is temporarily unavailable. No Retry-After header is sent; retry later with
backoff. When retrying a mutation, reuse the same Idempotency-Key and body.