> ## Documentation Index
> Fetch the complete documentation index at: https://docs.oleria.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get

> Returns an authenticator by its global id. Requires the `https://devx.{environment}.oleria.io/read` scope.



## OpenAPI

````yaml /developer-docs/api-reference/oleria-public-api-1.0.0.yaml get /v1/authenticators/{id}
openapi: 3.0.3
info:
  title: Oleria Public API
  version: 1.0.0
  description: >-
    REST API for Oleria's identity and access data. Each resource is a
    collection exposing list and get operations; responses return the complete
    object. Where Oleria can change what it reports, the change is a method on
    the same resource: disabling an account is `POST /v1/accounts/{id}/disable`,
    and membership is a sub-resource asserted with `PUT` and removed with
    `DELETE`. Those changes are applied in the source application
    asynchronously: each returns a job under `/v1/action-jobs` that reports the
    outcome for every target it affected, and whether Oleria's own data reflects
    it yet. Authenticate with OAuth 2.0 client credentials and send the access
    token as `Authorization: Bearer <token>`.
servers:
  - url: https://devx.{environment}.oleria.io
    description: Oleria API server.
    variables:
      environment:
        default: prod
        description: >-
          Your Oleria deployment, for example `acme` for
          `https://devx.acme.oleria.io`. Substitute it in the OAuth scope names
          as well, since OpenAPI applies a server variable to the URL only and
          the scopes are published with the placeholder still in them.
security: []
paths:
  /v1/authenticators/{id}:
    get:
      tags:
        - Authenticators
      summary: Get
      description: >-
        Returns an authenticator by its global id. Requires the
        `https://devx.{environment}.oleria.io/read` scope.
      operationId: GetAuthenticator
      parameters:
        - name: id
          in: path
          description: Global id of the authenticator.
          required: true
          schema:
            type: string
      responses:
        '200':
          description: The authenticator.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Oleria_Authenticator'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '429':
          $ref: '#/components/responses/TooManyRequests'
        '500':
          $ref: '#/components/responses/InternalError'
      security:
        - oauth2:
            - https://devx.{environment}.oleria.io/read
components:
  schemas:
    Oleria_Authenticator:
      type: object
      description: >
        An Oleria Authenticator object represents an IDP configured
        authentication mechanism that is available for assignment, enrollment,
        and login
      allOf:
        - $ref: '#/components/schemas/Authenticator'
        - $ref: '#/components/schemas/Oleria_AuthenticatorGlobalIdentifiers'
        - $ref: '#/components/schemas/Oleria_AuthenticatorEnrichedInformation'
        - $ref: '#/components/schemas/Oleria_AuthenticatorAnalyticsInformation'
        - $ref: '#/components/schemas/Oleria_AuthenticatorSystemOfRecordInformation'
        - required:
            - oleriaObjectMetadata
          type: object
          properties:
            oleriaObjectMetadata:
              $ref: '#/components/schemas/Oleria_ObjectMetadata'
    Authenticator:
      required:
        - authenticationKeys
        - authenticationMethods
        - id
        - isActive
        - name
        - objectMetadata
      type: object
      properties:
        id:
          $ref: '#/components/schemas/LocallyUniqueId'
        authenticationKeys:
          type: array
          description: >
            Each array item is a base64 encoded SHA256 hash of authentication
            configuration properties.The authenticationKeys property is used by
            Oleria to match enterprise application IntegratedApplication objects
            with corresponding identity provider configured AssignedApplication
            objects assigned to accounts or groups. When these objects are
            connected and there's a match in authenticationKeys and federated
            identity, the Oleria platform will connect
            [Account](#/components/schemas/Account) objects that have an
            Identity
            [AccountAuthenticationFunction](#/components/schemas/AccountAuthenticationFunction)
            with their corresponding [Account](#/components/schemas/Account)
            objects that have an ApplicationAccount
            [AccountAuthenticationFunction](#/components/schemas/AccountAuthenticationFunction),
            and indicate an SSO-based login flow is available. The following
            protocol configurations are supported:
              1. SAML configurations encode the SAML certificate raw public key info
              2. First party configurations e.g. Microsoft Entra to Microsoft 365 Apps encode the app type + the first party instance specific instance key with a ":" delimiter
              3. OIDC configurations encode the lowercased issuer URL (with trailing slash appended) and the client ID, joined by a "," delimiter, SHA256 hashed and base64 (standard encoding) encoded. Example input: "https://login.example.com/tenant/v2.0/,client-id-abc"
              4. RADIUS configuration encoding is TBD
          example:
            - XD+NWux+oeqdAa1eUPtNC06g/HtrzM6AbNiZU2MhHSM=
          items:
            type: string
        authenticationMethods:
          type: array
          items:
            $ref: '#/components/schemas/AuthenticationMethod'
        description:
          type: string
        isActive:
          type: boolean
        name:
          type: string
        objectMetadata:
          $ref: '#/components/schemas/ObjectMetadata'
      description: >
        An authenticator represents an IDP configured authentication mechanism
        that is available for assignment, enrollment, and login
    Oleria_AuthenticatorGlobalIdentifiers:
      required:
        - globalId
      type: object
      properties:
        globalId:
          type: string
      description: >
        Global identifiers translated from Authenticator local identifiers to be
        composed on Oleria Authenticator
    Oleria_AuthenticatorEnrichedInformation:
      type: object
      description: >
        Enriched information derived from a combination of Authenticator data,
        additional identity signals
    Oleria_AuthenticatorAnalyticsInformation:
      type: object
      description: >
        Analytics information calculated from identity security graph and added
        to the authenticator
    Oleria_AuthenticatorSystemOfRecordInformation:
      type: object
      properties:
        sorPrimaryStewardEmail:
          type: string
      description: >
        System of Record information associated with an authenticator and
        managed in Oleria
    Oleria_ObjectMetadata:
      type: object
      properties:
        enrichmentVersion:
          type: string
        generatedTime:
          type: string
          format: date-time
      description: >
        object metadata supersets object metadata with platform enrichment
        provenance — the enrichment version and the time the record was
        generated
    ErrorResponse:
      type: object
      description: >-
        Error envelope. `code` is a stable machine-readable identifier;
        `message` is human-readable.
      required:
        - code
        - message
      properties:
        code:
          type: string
          description: Stable, machine-readable error code (SCREAMING_SNAKE_CASE).
          example: NOT_FOUND
        details:
          type: object
          description: Optional free-form context for debugging.
          additionalProperties: true
        message:
          type: string
          description: Human-readable description of the error.
          example: No resource with the given id.
    LocallyUniqueId:
      minLength: 1
      type: string
      description: >
        An identifier (unique to the integrated or assigned application) of any
        object or entity represented in the Oleria system as well as any
        relationship or connection among entities when they are represented in
        Oleria. Oleria converts these identifiers to global ids so they can be
        unique in the context of the global system graph. The full list of
        Oleria objects or entities is defined by the object-type enumeration,
        and the full list of relationships or connections is defined by the
        relationship-type enumeration
    AuthenticationMethod:
      type: object
      properties:
        type:
          type: string
        description:
          type: string
      description: >
        Authentication methods describe how an
        [Account](#/components/schemas/Account) is required to authenticate to
        an enterprise application or identity provider.
        [Account](#/components/schemas/Account) include a list of enrolled
        authentication methods for the account, and
        [Activity](#/components/schemas/Activity) will include the
        authentication method used for login and other events. The type
        [AuthenticationMethodType](#/components/schemas/AuthenticationMethodType)
        is a string that can be one of many different authentication methods
        recognized by Oleria
    ObjectMetadata:
      required:
        - ApplicationInstanceId
        - GeneratedTime
      type: object
      properties:
        ApplicationInstanceId:
          type: string
        GeneratedTime:
          type: string
          format: date-time
        Profile:
          $ref: '#/components/schemas/SchemaProfile'
        ObjectOrRelationshipType:
          type: string
      description: >
        The _ObjectMetadata_ structure defines metadata that applies to every
        object and relationship, and is usually managed by the system that
        receives the data
    SchemaProfile:
      type: string
      enum:
        - Account
        - Membership
        - Governance
        - Risk
        - Access
        - Detection
  responses:
    BadRequest:
      description: The request was malformed, for example an invalid cursor or page size.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          example:
            code: BAD_REQUEST
            message: The request was malformed.
    Unauthorized:
      description: Missing or invalid authentication token.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          example:
            code: UNAUTHORIZED
            message: Missing or invalid authentication token.
    Forbidden:
      description: The token lacks the scope required for this resource.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          example:
            code: FORBIDDEN
            message: The token lacks the required scope.
    NotFound:
      description: No resource exists with the given id.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          example:
            code: NOT_FOUND
            message: No resource with the given id.
    TooManyRequests:
      description: Rate limit exceeded. Retry after the interval in the Retry-After header.
      headers:
        Retry-After:
          description: Seconds to wait before retrying.
          schema:
            type: integer
            minimum: 0
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          example:
            code: TOO_MANY_REQUESTS
            message: Rate limit exceeded. Retry after the specified interval.
    InternalError:
      description: An unexpected error occurred.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          example:
            code: INTERNAL_ERROR
            message: An unexpected error occurred.
  securitySchemes:
    oauth2:
      type: oauth2
      description: >-
        OAuth 2.0 client-credentials flow. Request an access token from the
        token endpoint and send it as `Authorization: Bearer <token>`.
      flows:
        clientCredentials:
          tokenUrl: https://auth.prod.oleria.io/oauth/token
          scopes:
            https://devx.{environment}.oleria.io/delete: Irreversibly destroy an object in the source system.
            https://devx.{environment}.oleria.io/read: Read identity and access data, and the jobs that change it.
            https://devx.{environment}.oleria.io/write: >-
              Make reversible changes: grant, enable, assign, revoke and remove
              access.

````