[Experimental] Get AuthZEN PDP configuration and capabilities
[Experimental] The GetConfiguration API returns metadata about the Policy Decision Point (PDP) including its name, version, supported endpoints, and capabilities. This endpoint follows the AuthZEN specification for PDP discovery.
Following the AuthZEN spec’s multi-tenant pattern, OpenFGA provides a per-store discovery endpoint at /.well-known/authzen-configuration/{store_id}. This returns absolute endpoint URLs specific to that store.
Example Response
{
"policy_decision_point": "https://example.com/stores/01ARZ3NDEKTSV4RRFFQ69G5FAV",
"access_evaluation_endpoint": "https://example.com/stores/01ARZ3NDEKTSV4RRFFQ69G5FAV/access/v1/evaluation",
"access_evaluations_endpoint": "https://example.com/stores/01ARZ3NDEKTSV4RRFFQ69G5FAV/access/v1/evaluations",
"search_subject_endpoint": "https://example.com/stores/01ARZ3NDEKTSV4RRFFQ69G5FAV/access/v1/search/subject",
"search_resource_endpoint": "https://example.com/stores/01ARZ3NDEKTSV4RRFFQ69G5FAV/access/v1/search/resource",
"search_action_endpoint": "https://example.com/stores/01ARZ3NDEKTSV4RRFFQ69G5FAV/access/v1/search/action"
}
Path Parameters
The store ID for which to retrieve configuration. Following the AuthZEN spec's multi-tenant pattern, each store has its own discovery endpoint.
Response
A successful response.
REQUIRED. The access evaluation endpoint URL.
REQUIRED. The PDP identifier URL (HTTPS, no query or fragment).
OPTIONAL. The batch evaluations endpoint URL.
OPTIONAL. Supported capabilities as URN strings.
OPTIONAL. The action search endpoint URL.
OPTIONAL. The resource search endpoint URL.
OPTIONAL. The subject search endpoint URL.
OPTIONAL. Signed metadata JWT per AuthZEN metadata specification.