# ==============================================================================
# JACK HENRY AUTHENTICATION FRAMEWORK: SECURITY SCHEMES
#
# This file serves as the centralized source of truth for security definitions. It is intended to be referenced ($ref) by individual 
# API specification files across the developer portal.
# ==============================================================================

openapi: 3.0.0
info:
  version: '0.0'
  title: Standard Security Schemes

components:
  securitySchemes:

    # --------------------------------------------------------------------------
    # 1. ENTERPRISE AUTHENTICATION
    # Centralized Auth for FI Employees, JH Employees & Service-to-Service
    # --------------------------------------------------------------------------
    OpenIDEnterprise:
      type: openIdConnect
      openIdConnectUrl: https://login.jackhenry.com/.well-known/openid-configuration
      description: |
        Jack Henry Enterprise Authentication. 
        
        ### Supported Flows
        
        #### 1. Authorization Code Flow
        * **Use Case:** Person-at-keyboard logins (FI or JH Employees).
        * **Security:** Supports/recommends PKCE (S256). Supports Pushed Authorization Requests (PAR), and DPoP token binding.
        * **Client Auth:** Supports/recommends `client_assertion` (Private Key JWT), also supports `client_secret`.
        
        #### 2. Client Credentials Flow
        * **Use Case:** System services and machine-to-machine integrations.
        * **Security:** Supports DPoP token binding.
        * **Client Auth:** **Requires** `client_assertion` (Private Key JWT).

    # --------------------------------------------------------------------------
    # 2. CONSUMER AUTHENTICATION
    # Centralized Auth for FI Customers or Members
    # --------------------------------------------------------------------------
    OpenIDConsumer:
      type: openIdConnect
      openIdConnectUrl: https://digital.garden-fi.com/.well-known/openid-configuration
      description: |
        Jack Henry Consumer Authentication. 
        
        > **WARNING: FI-SPECIFIC ROUTING**
        > The authorization server is currently pointing to our **Sandbox Environment** (`digital.garden-fi.com`) so you can test this documentation. In production code, this domain **must** be replaced with the specific Financial Institution's domain.
        > Example: Replace `{API-ENVIRONMENT}` in `https://{API-ENVIRONMENT}/.well-known/openid-configuration` with `digital.garden-fi.com` for the Garden financial institution.
       
        ### Supported Flows
        
        #### 1. Authorization Code Flow
        * **Use Case:** Person-at-keyboard logins (customer or member of FI).
        * **Security:** Supports/recommends PKCE (S256). Supports Pushed Authorization Requests (PAR), and DPoP token binding.
        * **Client Auth:** Supports `client_secret`.