diff --git a/code/API_definitions/esim-remote-management.yaml b/code/API_definitions/esim-remote-management.yaml index c566a1f..4b5cc3e 100644 --- a/code/API_definitions/esim-remote-management.yaml +++ b/code/API_definitions/esim-remote-management.yaml @@ -21,6 +21,7 @@ info: + # Authorization and authentication The "Camara Security and Interoperability Profile" provides details of how an API consumer requests an access token. Please refer to Identity and Consent Management (https://github.com/camaraproject/IdentityAndConsentManagement/) for the released version of the profile. @@ -30,6 +31,7 @@ info: In cases where personal data is processed by the API and users can exercise their rights through mechanisms such as opt-in and/or opt-out, the use of three-legged access tokens is mandatory. This ensures that the API remains in compliance with privacy regulations, upholding the principles of transparency and user-centric privacy-by-design. + # Identifying the device from the access token This API requires the API consumer to identify a device as the subject of the API as follows: @@ -46,6 +48,7 @@ info: + # Additional CAMARA error responses The list of error codes in this API specification is not exhaustive. Therefore the API specification MAY not document some non-mandatory error statuses as indicated in `CAMARA API Design Guide`. @@ -56,6 +59,7 @@ info: + # Request body strictness This API rejects requests with JSON request bodies that contain properties not declared in this specification, at any nesting level. Unknown properties result in a `400 INVALID_ARGUMENT` response.