> ## Documentation Index
> Fetch the complete documentation index at: https://klef.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# List connector catalog

> A connected target's fields include what it reported on its last refresh, such as license SKUs and flexfields. Anything that couldn't be read is in `readErrors`.



## OpenAPI

````yaml /openapi-public.json get /connectors
openapi: 3.1.1
info:
  title: Klef API
  description: Klef's multi-tenant HRIS sync platform API.
  version: v1
servers:
  - url: https://{workspace}.klef.ai/api
    variables:
      workspace:
        default: acme
        description: Your workspace's subdomain.
security: []
tags:
  - name: Users
  - name: Connections
  - name: Adoption
  - name: Policy resources
  - name: Audit
  - name: Catalog
  - name: Sync
  - name: Search
  - name: SyncPlans
  - name: Agent
  - name: Auth
  - name: Workspaces
  - name: Billing
  - name: Invitations
  - name: FirstSignIns
  - name: Connection accounts
  - name: Policies
  - name: Secrets
  - name: Lookup tables
  - name: Scripts
  - name: Segments
  - name: ApiKeys
  - name: Members
  - name: Workers
  - name: Inbox
  - name: Notifications
paths:
  /connectors:
    get:
      tags:
        - Catalog
      summary: List connector catalog
      description: >-
        A connected target's fields include what it reported on its last
        refresh, such as license SKUs and flexfields. Anything that couldn't be
        read is in `readErrors`.
      operationId: ListConnectors
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: >-
                  #/components/schemas/ApiCollectionResponseOfConnectorCatalogResponse
        '401':
          description: Authentication required.
          content:
            application/json:
              schema:
                required:
                  - result
                  - errors
                type: object
                properties:
                  result: {}
                  errors:
                    type: array
                    items:
                      required:
                        - errorCode
                        - errorMessage
                      type: object
                      properties:
                        errorCode:
                          enum:
                            - validation_error
                            - unauthorized
                            - forbidden
                            - not_found
                            - internal_error
                            - error
                            - precondition_required
                            - precondition_failed
                            - invalid_if_match
                            - worker_not_found
                            - worker_version_not_found
                            - connection_not_found
                            - policy_not_found
                            - policy_revision_not_found
                            - lookup_table_not_found
                            - script_not_found
                            - segment_not_found
                            - workspace_secret_not_found
                            - member_not_found
                            - invitation_not_found
                            - user_not_found
                            - workspace_not_found
                            - api_key_not_found
                            - inbox_item_not_found
                            - sync_plan_not_found
                            - connection_account_not_found
                            - managed_account_not_found
                            - adoption_run_not_found
                            - sync_plan_not_ready
                            - sync_plan_stale
                            - sync_plan_already_applying
                            - subdomain_taken
                            - invalid_subdomain
                            - invalid_invite
                            - last_owner_protected
                            - owner_protected
                            - already_member
                            - already_invited
                            - role_not_assignable
                            - invalid_email
                            - email_required
                            - email_mismatch
                            - invitation_gone
                            - invalid_connector_credentials
                            - wrong_connector_type
                            - connection_not_syncable
                            - connector_o_auth_not_configured
                            - connector_authorization_failed
                            - salesforce_manage_users_required
                            - box_admin_required
                            - linear_admin_required
                            - dropbox_admin_required
                            - invalid_match_rule
                            - adoption_run_composed
                            - adoption_run_empty
                            - adoption_selection_refused
                            - invalid_policy
                            - policy_does_not_compile
                            - policy_secret_missing
                            - policy_lookup_table_missing
                            - policy_script_missing
                            - policy_segment_missing
                            - policy_edit_target_missing
                            - policy_secret_disclosure_forbidden
                            - notification_send_failed
                            - invalid_workspace_secret
                            - workspace_secret_referenced
                            - workspace_secret_name_conflict
                            - invalid_lookup_table
                            - lookup_table_referenced
                            - lookup_table_name_conflict
                            - invalid_script
                            - script_name_conflict
                            - script_referenced
                            - invalid_segment
                            - segment_name_conflict
                            - segment_referenced
                            - segment_worker_missing
                            - api_key_scope_not_granted
                            - api_key_limit_reached
                            - subscription_required
                            - already_subscribed
                            - no_billing_customer
                            - workspace_pending_deletion
                            - workspace_deletion_confirmation_mismatch
                            - workspace_deletion_already_scheduled
                            - workspace_deletion_not_scheduled
                            - workspace_export_expired
                            - workspace_export_not_found
                            - agent_conversation_not_found
                            - agent_proposal_not_found
                            - agent_proposal_outdated
                            - agent_proposal_expired
                            - agent_proposal_already_applied
                            - agent_proposal_rejected
                            - notification_kind_unsupported
                            - first_sign_in_not_found
                            - first_sign_in_gone
                            - first_sign_in_not_a_recipient
                            - first_sign_in_recipient_unknown
                            - first_sign_in_locked
                            - first_sign_in_code_refused
                            - first_sign_in_proof_invalid
                            - password_reset_unsupported
                            - invalid_password_rules
                            - avatar_not_owned
                            - unsupported_image_type
                            - image_too_large
                          description: >-
                            The central catalog of every error returned by the
                            API.
                        errorMessage:
                          type: string
                        target:
                          type:
                            - 'null'
                            - string
                      description: "One error in an API response: a specific ApiErrorCode, a human-readable message,\r\n    and an optional string? ApiError.Target (the field a validation error applies to)."
                description: "The envelope for a single-resource response: T? ApiResponse&lt;T&gt;.Result on success, otherwise `null`\r\n    with one or more IReadOnlyList&lt;ApiError&gt; ApiResponse&lt;T&gt;.Errors."
        '403':
          description: Permission denied.
          content:
            application/json:
              schema:
                required:
                  - result
                  - errors
                type: object
                properties:
                  result: {}
                  errors:
                    type: array
                    items:
                      required:
                        - errorCode
                        - errorMessage
                      type: object
                      properties:
                        errorCode:
                          enum:
                            - validation_error
                            - unauthorized
                            - forbidden
                            - not_found
                            - internal_error
                            - error
                            - precondition_required
                            - precondition_failed
                            - invalid_if_match
                            - worker_not_found
                            - worker_version_not_found
                            - connection_not_found
                            - policy_not_found
                            - policy_revision_not_found
                            - lookup_table_not_found
                            - script_not_found
                            - segment_not_found
                            - workspace_secret_not_found
                            - member_not_found
                            - invitation_not_found
                            - user_not_found
                            - workspace_not_found
                            - api_key_not_found
                            - inbox_item_not_found
                            - sync_plan_not_found
                            - connection_account_not_found
                            - managed_account_not_found
                            - adoption_run_not_found
                            - sync_plan_not_ready
                            - sync_plan_stale
                            - sync_plan_already_applying
                            - subdomain_taken
                            - invalid_subdomain
                            - invalid_invite
                            - last_owner_protected
                            - owner_protected
                            - already_member
                            - already_invited
                            - role_not_assignable
                            - invalid_email
                            - email_required
                            - email_mismatch
                            - invitation_gone
                            - invalid_connector_credentials
                            - wrong_connector_type
                            - connection_not_syncable
                            - connector_o_auth_not_configured
                            - connector_authorization_failed
                            - salesforce_manage_users_required
                            - box_admin_required
                            - linear_admin_required
                            - dropbox_admin_required
                            - invalid_match_rule
                            - adoption_run_composed
                            - adoption_run_empty
                            - adoption_selection_refused
                            - invalid_policy
                            - policy_does_not_compile
                            - policy_secret_missing
                            - policy_lookup_table_missing
                            - policy_script_missing
                            - policy_segment_missing
                            - policy_edit_target_missing
                            - policy_secret_disclosure_forbidden
                            - notification_send_failed
                            - invalid_workspace_secret
                            - workspace_secret_referenced
                            - workspace_secret_name_conflict
                            - invalid_lookup_table
                            - lookup_table_referenced
                            - lookup_table_name_conflict
                            - invalid_script
                            - script_name_conflict
                            - script_referenced
                            - invalid_segment
                            - segment_name_conflict
                            - segment_referenced
                            - segment_worker_missing
                            - api_key_scope_not_granted
                            - api_key_limit_reached
                            - subscription_required
                            - already_subscribed
                            - no_billing_customer
                            - workspace_pending_deletion
                            - workspace_deletion_confirmation_mismatch
                            - workspace_deletion_already_scheduled
                            - workspace_deletion_not_scheduled
                            - workspace_export_expired
                            - workspace_export_not_found
                            - agent_conversation_not_found
                            - agent_proposal_not_found
                            - agent_proposal_outdated
                            - agent_proposal_expired
                            - agent_proposal_already_applied
                            - agent_proposal_rejected
                            - notification_kind_unsupported
                            - first_sign_in_not_found
                            - first_sign_in_gone
                            - first_sign_in_not_a_recipient
                            - first_sign_in_recipient_unknown
                            - first_sign_in_locked
                            - first_sign_in_code_refused
                            - first_sign_in_proof_invalid
                            - password_reset_unsupported
                            - invalid_password_rules
                            - avatar_not_owned
                            - unsupported_image_type
                            - image_too_large
                          description: >-
                            The central catalog of every error returned by the
                            API.
                        errorMessage:
                          type: string
                        target:
                          type:
                            - 'null'
                            - string
                      description: "One error in an API response: a specific ApiErrorCode, a human-readable message,\r\n    and an optional string? ApiError.Target (the field a validation error applies to)."
                description: "The envelope for a single-resource response: T? ApiResponse&lt;T&gt;.Result on success, otherwise `null`\r\n    with one or more IReadOnlyList&lt;ApiError&gt; ApiResponse&lt;T&gt;.Errors."
        '500':
          description: Internal server error.
          content:
            application/json:
              schema:
                required:
                  - result
                  - errors
                type: object
                properties:
                  result: {}
                  errors:
                    type: array
                    items:
                      required:
                        - errorCode
                        - errorMessage
                      type: object
                      properties:
                        errorCode:
                          enum:
                            - validation_error
                            - unauthorized
                            - forbidden
                            - not_found
                            - internal_error
                            - error
                            - precondition_required
                            - precondition_failed
                            - invalid_if_match
                            - worker_not_found
                            - worker_version_not_found
                            - connection_not_found
                            - policy_not_found
                            - policy_revision_not_found
                            - lookup_table_not_found
                            - script_not_found
                            - segment_not_found
                            - workspace_secret_not_found
                            - member_not_found
                            - invitation_not_found
                            - user_not_found
                            - workspace_not_found
                            - api_key_not_found
                            - inbox_item_not_found
                            - sync_plan_not_found
                            - connection_account_not_found
                            - managed_account_not_found
                            - adoption_run_not_found
                            - sync_plan_not_ready
                            - sync_plan_stale
                            - sync_plan_already_applying
                            - subdomain_taken
                            - invalid_subdomain
                            - invalid_invite
                            - last_owner_protected
                            - owner_protected
                            - already_member
                            - already_invited
                            - role_not_assignable
                            - invalid_email
                            - email_required
                            - email_mismatch
                            - invitation_gone
                            - invalid_connector_credentials
                            - wrong_connector_type
                            - connection_not_syncable
                            - connector_o_auth_not_configured
                            - connector_authorization_failed
                            - salesforce_manage_users_required
                            - box_admin_required
                            - linear_admin_required
                            - dropbox_admin_required
                            - invalid_match_rule
                            - adoption_run_composed
                            - adoption_run_empty
                            - adoption_selection_refused
                            - invalid_policy
                            - policy_does_not_compile
                            - policy_secret_missing
                            - policy_lookup_table_missing
                            - policy_script_missing
                            - policy_segment_missing
                            - policy_edit_target_missing
                            - policy_secret_disclosure_forbidden
                            - notification_send_failed
                            - invalid_workspace_secret
                            - workspace_secret_referenced
                            - workspace_secret_name_conflict
                            - invalid_lookup_table
                            - lookup_table_referenced
                            - lookup_table_name_conflict
                            - invalid_script
                            - script_name_conflict
                            - script_referenced
                            - invalid_segment
                            - segment_name_conflict
                            - segment_referenced
                            - segment_worker_missing
                            - api_key_scope_not_granted
                            - api_key_limit_reached
                            - subscription_required
                            - already_subscribed
                            - no_billing_customer
                            - workspace_pending_deletion
                            - workspace_deletion_confirmation_mismatch
                            - workspace_deletion_already_scheduled
                            - workspace_deletion_not_scheduled
                            - workspace_export_expired
                            - workspace_export_not_found
                            - agent_conversation_not_found
                            - agent_proposal_not_found
                            - agent_proposal_outdated
                            - agent_proposal_expired
                            - agent_proposal_already_applied
                            - agent_proposal_rejected
                            - notification_kind_unsupported
                            - first_sign_in_not_found
                            - first_sign_in_gone
                            - first_sign_in_not_a_recipient
                            - first_sign_in_recipient_unknown
                            - first_sign_in_locked
                            - first_sign_in_code_refused
                            - first_sign_in_proof_invalid
                            - password_reset_unsupported
                            - invalid_password_rules
                            - avatar_not_owned
                            - unsupported_image_type
                            - image_too_large
                          description: >-
                            The central catalog of every error returned by the
                            API.
                        errorMessage:
                          type: string
                        target:
                          type:
                            - 'null'
                            - string
                      description: "One error in an API response: a specific ApiErrorCode, a human-readable message,\r\n    and an optional string? ApiError.Target (the field a validation error applies to)."
                description: "The envelope for a single-resource response: T? ApiResponse&lt;T&gt;.Result on success, otherwise `null`\r\n    with one or more IReadOnlyList&lt;ApiError&gt; ApiResponse&lt;T&gt;.Errors."
      security:
        - cookieAuth: []
        - apiKeyAuth: []
components:
  schemas:
    ApiCollectionResponseOfConnectorCatalogResponse:
      required:
        - results
        - errors
        - pagination
      type: object
      properties:
        results:
          type: array
          items:
            $ref: '#/components/schemas/ConnectorCatalogResponse'
        errors:
          type: array
          items:
            $ref: '#/components/schemas/ApiError'
        pagination:
          oneOf:
            - type: 'null'
            - $ref: '#/components/schemas/PageInfo'
      description: >-
        The envelope for a collection response: IReadOnlyList&lt;T&gt;
        ApiCollectionResponse&lt;T&gt;.Results.
    ConnectorCatalogResponse:
      required:
        - id
        - name
        - role
        - fields
        - object
        - credentials
        - internal
        - readErrors
        - oauth
        - oauthSandbox
        - setsPasswords
      type: object
      properties:
        id:
          $ref: '#/components/schemas/ConnectorExternalSystem'
        name:
          type: string
        role:
          $ref: '#/components/schemas/ConnectorRole'
        fields:
          type:
            - 'null'
            - array
          items:
            $ref: '#/components/schemas/TargetField'
        object:
          oneOf:
            - type: 'null'
            - $ref: '#/components/schemas/TargetObject'
        credentials:
          type: array
          items:
            $ref: '#/components/schemas/CredentialField'
        internal:
          type: boolean
        readErrors:
          type:
            - 'null'
            - array
          items:
            $ref: '#/components/schemas/CatalogReadError'
        oauth:
          type: boolean
        oauthSandbox:
          type: boolean
        setsPasswords:
          type: boolean
    ApiError:
      required:
        - errorCode
        - errorMessage
      type: object
      properties:
        errorCode:
          $ref: '#/components/schemas/ApiErrorCode'
        errorMessage:
          type: string
        target:
          type:
            - 'null'
            - string
      description: "One error in an API response: a specific ApiErrorCode, a human-readable message,\r\n    and an optional string? ApiError.Target (the field a validation error applies to)."
    PageInfo:
      required:
        - nextCursor
        - limit
        - hasMore
      type: object
      properties:
        nextCursor:
          type:
            - 'null'
            - integer
          format: int32
        limit:
          type: integer
          format: int32
        hasMore:
          type: boolean
        total:
          type:
            - 'null'
            - integer
          format: int32
      description: "Cursor-pagination metadata shared across every paged read. int? PageInfo.NextCursor is the\r\noffset of the next page, `null` on the last page."
    ConnectorExternalSystem:
      enum:
        - adp_workforce_now
        - oracle_fusion
        - microsoft_entra
        - gusto
        - microsoft365
        - google_workspace
        - oracle_oci
        - worker_model
        - aws
        - azure
        - aws_identity_center
        - bamboo_hr
        - slack
        - github
        - github_enterprise
        - salesforce
        - hubspot
        - box
        - linear
        - dropbox
        - openai
        - anthropic
        - one_password
        - keeper
        - bitwarden
        - atlassian
        - notion
      description: An external system a workspace can connect to.
    ConnectorRole:
      enum:
        - source
        - target
      description: >-
        Whether Klef reads workers from a connector (source) or provisions into
        it (target).
    TargetField:
      required:
        - type
      type: object
      anyOf:
        - $ref: '#/components/schemas/TargetFieldStringField'
        - $ref: '#/components/schemas/TargetFieldBoolField'
        - $ref: '#/components/schemas/TargetFieldIntField'
        - $ref: '#/components/schemas/TargetFieldDateField'
        - $ref: '#/components/schemas/TargetFieldEnumField'
        - $ref: '#/components/schemas/TargetFieldReferenceField'
        - $ref: '#/components/schemas/TargetFieldLinkField'
        - $ref: '#/components/schemas/TargetFieldArrayField'
        - $ref: '#/components/schemas/TargetFieldGrantField'
        - $ref: '#/components/schemas/TargetFieldMapField'
        - $ref: '#/components/schemas/TargetFieldObjectField'
      description: One field a target connector accepts in a desired user payload.
      discriminator:
        propertyName: type
        mapping:
          string:
            $ref: '#/components/schemas/TargetFieldStringField'
          bool:
            $ref: '#/components/schemas/TargetFieldBoolField'
          int:
            $ref: '#/components/schemas/TargetFieldIntField'
          date:
            $ref: '#/components/schemas/TargetFieldDateField'
          enum:
            $ref: '#/components/schemas/TargetFieldEnumField'
          reference:
            $ref: '#/components/schemas/TargetFieldReferenceField'
          link:
            $ref: '#/components/schemas/TargetFieldLinkField'
          array:
            $ref: '#/components/schemas/TargetFieldArrayField'
          grant:
            $ref: '#/components/schemas/TargetFieldGrantField'
          map:
            $ref: '#/components/schemas/TargetFieldMapField'
          object:
            $ref: '#/components/schemas/TargetFieldObjectField'
    TargetObject:
      required:
        - key
        - label
        - operations
      type: object
      properties:
        key:
          type: string
        label:
          type: string
        operations:
          type: array
          items:
            $ref: '#/components/schemas/TargetOperation'
      description: The object a target connector writes, and what it can do to it.
    CredentialField:
      required:
        - key
        - label
        - kind
        - required
        - secret
      type: object
      properties:
        key:
          type: string
        label:
          type: string
        kind:
          $ref: '#/components/schemas/CredentialFieldKind'
        required:
          type: boolean
        secret:
          type: boolean
        description:
          type:
            - 'null'
            - string
          description: What to enter, and where to find it.
        options:
          type: array
          items:
            $ref: '#/components/schemas/CredentialOption'
      description: "One field a connector needs to authenticate. A Secret field is encrypted at\r\nrest and never read back, so it is entered masked and left blank to keep the stored value."
    CatalogReadError:
      required:
        - part
        - message
      type: object
      properties:
        part:
          type: string
          description: Which part could not be read, named for a person.
        message:
          type: string
          description: What the target answered.
      description: "A read the catalog needed and did not get, so it is built without whatever that call would have\r\nreturned."
    ApiErrorCode:
      enum:
        - validation_error
        - unauthorized
        - forbidden
        - not_found
        - internal_error
        - error
        - precondition_required
        - precondition_failed
        - invalid_if_match
        - worker_not_found
        - worker_version_not_found
        - connection_not_found
        - policy_not_found
        - policy_revision_not_found
        - lookup_table_not_found
        - script_not_found
        - segment_not_found
        - workspace_secret_not_found
        - member_not_found
        - invitation_not_found
        - user_not_found
        - workspace_not_found
        - api_key_not_found
        - inbox_item_not_found
        - sync_plan_not_found
        - connection_account_not_found
        - managed_account_not_found
        - adoption_run_not_found
        - sync_plan_not_ready
        - sync_plan_stale
        - sync_plan_already_applying
        - subdomain_taken
        - invalid_subdomain
        - invalid_invite
        - last_owner_protected
        - owner_protected
        - already_member
        - already_invited
        - role_not_assignable
        - invalid_email
        - email_required
        - email_mismatch
        - invitation_gone
        - invalid_connector_credentials
        - wrong_connector_type
        - connection_not_syncable
        - connector_o_auth_not_configured
        - connector_authorization_failed
        - salesforce_manage_users_required
        - box_admin_required
        - linear_admin_required
        - dropbox_admin_required
        - invalid_match_rule
        - adoption_run_composed
        - adoption_run_empty
        - adoption_selection_refused
        - invalid_policy
        - policy_does_not_compile
        - policy_secret_missing
        - policy_lookup_table_missing
        - policy_script_missing
        - policy_segment_missing
        - policy_edit_target_missing
        - policy_secret_disclosure_forbidden
        - notification_send_failed
        - invalid_workspace_secret
        - workspace_secret_referenced
        - workspace_secret_name_conflict
        - invalid_lookup_table
        - lookup_table_referenced
        - lookup_table_name_conflict
        - invalid_script
        - script_name_conflict
        - script_referenced
        - invalid_segment
        - segment_name_conflict
        - segment_referenced
        - segment_worker_missing
        - api_key_scope_not_granted
        - api_key_limit_reached
        - subscription_required
        - already_subscribed
        - no_billing_customer
        - workspace_pending_deletion
        - workspace_deletion_confirmation_mismatch
        - workspace_deletion_already_scheduled
        - workspace_deletion_not_scheduled
        - workspace_export_expired
        - workspace_export_not_found
        - agent_conversation_not_found
        - agent_proposal_not_found
        - agent_proposal_outdated
        - agent_proposal_expired
        - agent_proposal_already_applied
        - agent_proposal_rejected
        - notification_kind_unsupported
        - first_sign_in_not_found
        - first_sign_in_gone
        - first_sign_in_not_a_recipient
        - first_sign_in_recipient_unknown
        - first_sign_in_locked
        - first_sign_in_code_refused
        - first_sign_in_proof_invalid
        - password_reset_unsupported
        - invalid_password_rules
        - avatar_not_owned
        - unsupported_image_type
        - image_too_large
      description: The central catalog of every error returned by the API.
    TargetFieldStringField:
      required:
        - key
        - label
        - required
      properties:
        type:
          enum:
            - string
          type: string
        maxLength:
          type:
            - 'null'
            - integer
          format: int32
        key:
          type: string
        label:
          type: string
        required:
          type: boolean
        hidden:
          type: boolean
          description: Whether this field is hidden from the frontend mapping editor.
        description:
          type:
            - 'null'
            - string
          description: What the field holds in the target.
        values:
          type:
            - 'null'
            - array
          items:
            $ref: '#/components/schemas/CatalogValue'
          description: "The values a client offers for this field, or `null` when it takes any value.\r\nAn array field's values are its items'. Only an EnumField is held to them; for\r\nevery other field they are the connection's suggestions, since a target grows options between\r\nthe moment the catalog is read and the moment a plan runs."
    TargetFieldBoolField:
      required:
        - key
        - label
        - required
      properties:
        type:
          enum:
            - bool
          type: string
        key:
          type: string
        label:
          type: string
        required:
          type: boolean
        hidden:
          type: boolean
          description: Whether this field is hidden from the frontend mapping editor.
        description:
          type:
            - 'null'
            - string
          description: What the field holds in the target.
        values:
          type:
            - 'null'
            - array
          items:
            $ref: '#/components/schemas/CatalogValue'
          description: "The values a client offers for this field, or `null` when it takes any value.\r\nAn array field's values are its items'. Only an EnumField is held to them; for\r\nevery other field they are the connection's suggestions, since a target grows options between\r\nthe moment the catalog is read and the moment a plan runs."
    TargetFieldIntField:
      required:
        - key
        - label
        - required
      properties:
        type:
          enum:
            - int
          type: string
        key:
          type: string
        label:
          type: string
        required:
          type: boolean
        hidden:
          type: boolean
          description: Whether this field is hidden from the frontend mapping editor.
        description:
          type:
            - 'null'
            - string
          description: What the field holds in the target.
        values:
          type:
            - 'null'
            - array
          items:
            $ref: '#/components/schemas/CatalogValue'
          description: "The values a client offers for this field, or `null` when it takes any value.\r\nAn array field's values are its items'. Only an EnumField is held to them; for\r\nevery other field they are the connection's suggestions, since a target grows options between\r\nthe moment the catalog is read and the moment a plan runs."
    TargetFieldDateField:
      required:
        - key
        - label
        - required
      properties:
        type:
          enum:
            - date
          type: string
        key:
          type: string
        label:
          type: string
        required:
          type: boolean
        hidden:
          type: boolean
          description: Whether this field is hidden from the frontend mapping editor.
        description:
          type:
            - 'null'
            - string
          description: What the field holds in the target.
        values:
          type:
            - 'null'
            - array
          items:
            $ref: '#/components/schemas/CatalogValue'
          description: "The values a client offers for this field, or `null` when it takes any value.\r\nAn array field's values are its items'. Only an EnumField is held to them; for\r\nevery other field they are the connection's suggestions, since a target grows options between\r\nthe moment the catalog is read and the moment a plan runs."
    TargetFieldEnumField:
      required:
        - key
        - label
        - required
      properties:
        type:
          enum:
            - enum
          type: string
        key:
          type: string
        label:
          type: string
        required:
          type: boolean
        hidden:
          type: boolean
          description: Whether this field is hidden from the frontend mapping editor.
        description:
          type:
            - 'null'
            - string
          description: What the field holds in the target.
        values:
          type:
            - 'null'
            - array
          items:
            $ref: '#/components/schemas/CatalogValue'
          description: "The values a client offers for this field, or `null` when it takes any value.\r\nAn array field's values are its items'. Only an EnumField is held to them; for\r\nevery other field they are the connection's suggestions, since a target grows options between\r\nthe moment the catalog is read and the moment a plan runs."
    TargetFieldReferenceField:
      required:
        - kind
        - key
        - label
        - required
      properties:
        type:
          enum:
            - reference
          type: string
        kind:
          $ref: '#/components/schemas/TargetReferenceKind'
        key:
          type: string
        label:
          type: string
        required:
          type: boolean
        hidden:
          type: boolean
          description: Whether this field is hidden from the frontend mapping editor.
        description:
          type:
            - 'null'
            - string
          description: What the field holds in the target.
        values:
          type:
            - 'null'
            - array
          items:
            $ref: '#/components/schemas/CatalogValue'
          description: "The values a client offers for this field, or `null` when it takes any value.\r\nAn array field's values are its items'. Only an EnumField is held to them; for\r\nevery other field they are the connection's suggestions, since a target grows options between\r\nthe moment the catalog is read and the moment a plan runs."
      description: "A field holding the id of something that already exists in the target. The connector resolves it,\r\nso a policy may map whatever identifies the subject there — an id, a user name, or an address."
    TargetFieldLinkField:
      required:
        - key
        - label
        - required
      properties:
        type:
          enum:
            - link
          type: string
        key:
          type: string
        label:
          type: string
        required:
          type: boolean
        hidden:
          type: boolean
          description: Whether this field is hidden from the frontend mapping editor.
        description:
          type:
            - 'null'
            - string
          description: What the field holds in the target.
        values:
          type:
            - 'null'
            - array
          items:
            $ref: '#/components/schemas/CatalogValue'
          description: "The values a client offers for this field, or `null` when it takes any value.\r\nAn array field's values are its items'. Only an EnumField is held to them; for\r\nevery other field they are the connection's suggestions, since a target grows options between\r\nthe moment the catalog is read and the moment a plan runs."
      description: "A field pointing at another user of the same target, mapped from a worker reference. The engine\r\nresolves the referenced worker's account on the connection when the plan applies, after any\r\ncreate in the same plan."
    TargetFieldArrayField:
      required:
        - item
        - key
        - label
      properties:
        type:
          enum:
            - array
          type: string
        item:
          $ref: '#/components/schemas/TargetField'
        exclusiveField:
          type:
            - 'null'
            - string
          description: "The boolean property of Item that at most one element may set, or\r\n`null` when no property is exclusive."
        endField:
          type:
            - 'null'
            - string
          description: "The date property of Item that ends an element the policy has stopped\r\nnaming, written into the payload with the rest of the account."
        keyFields:
          type: array
          items:
            type: string
          description: "The properties of `Item` that together identify one element across runs, or empty\r\nwhen the target does not identify them."
        endAction:
          type:
            - 'null'
            - string
          description: "The connector-defined action that ends an element the policy has stopped naming, for a target\r\nthat ends one through a call of its own rather than a property."
        key:
          type: string
        label:
          type: string
        required:
          type: boolean
        hidden:
          type: boolean
          description: Whether this field is hidden from the frontend mapping editor.
        description:
          type:
            - 'null'
            - string
          description: What the field holds in the target.
        values:
          description: "The values a client offers for this field, or `null` when it takes any value.\r\nAn array field's values are its items'. Only an EnumField is held to them; for\r\nevery other field they are the connection's suggestions, since a target grows options between\r\nthe moment the catalog is read and the moment a plan runs."
    TargetFieldGrantField:
      required:
        - itemLabel
        - item
        - key
        - label
      properties:
        type:
          enum:
            - grant
          type: string
        itemLabel:
          type: string
        item:
          $ref: '#/components/schemas/TargetField'
        key:
          type: string
        label:
          type: string
        required:
          type: boolean
        hidden:
          type: boolean
          description: Whether this field is hidden from the frontend mapping editor.
        description:
          type:
            - 'null'
            - string
          description: What the field holds in the target.
        values:
          description: "The values a client offers for this field, or `null` when it takes any value.\r\nAn array field's values are its items'. Only an EnumField is held to them; for\r\nevery other field they are the connection's suggestions, since a target grows options between\r\nthe moment the catalog is read and the moment a plan runs."
      description: "A set of things a user is granted in the target — roles, groups, licenses — that the connector\r\nreconciles as a set rather than writing as a field value. ItemLabel names one\r\nof them."
    TargetFieldMapField:
      required:
        - name
        - entry
        - key
        - label
      properties:
        type:
          enum:
            - map
          type: string
        name:
          $ref: '#/components/schemas/StringField'
        entry:
          $ref: '#/components/schemas/TargetField'
        key:
          type: string
        label:
          type: string
        required:
          type: boolean
        hidden:
          type: boolean
          description: Whether this field is hidden from the frontend mapping editor.
        description:
          type:
            - 'null'
            - string
          description: What the field holds in the target.
        values:
          description: "The values a client offers for this field, or `null` when it takes any value.\r\nAn array field's values are its items'. Only an EnumField is held to them; for\r\nevery other field they are the connection's suggestions, since a target grows options between\r\nthe moment the catalog is read and the moment a plan runs."
      description: "An object whose property names the policy writes rather than the catalog — a tag set, a set of\r\nnamed policy documents. Name declares what a property is called and\r\nEntry the value held under it."
    TargetFieldObjectField:
      required:
        - properties
        - key
        - label
        - required
      properties:
        type:
          enum:
            - object
          type: string
        properties: {}
        key:
          type: string
        label:
          type: string
        required:
          type: boolean
        hidden:
          type: boolean
          description: Whether this field is hidden from the frontend mapping editor.
        description:
          type:
            - 'null'
            - string
          description: What the field holds in the target.
        values:
          description: "The values a client offers for this field, or `null` when it takes any value.\r\nAn array field's values are its items'. Only an EnumField is held to them; for\r\nevery other field they are the connection's suggestions, since a target grows options between\r\nthe moment the catalog is read and the moment a plan runs."
    TargetOperation:
      enum:
        - sync
        - delete
      description: What a connector can do to the object it writes.
    CredentialFieldKind:
      enum:
        - text
        - password
        - text_area
        - select
        - switch
      description: How a credential field is entered.
    CredentialOption:
      required:
        - value
        - label
      type: object
      properties:
        value:
          type: string
        label:
          type: string
    CatalogValue:
      required:
        - value
        - label
      type: object
      properties:
        value:
          type: string
        label:
          type: string
        available:
          type:
            - 'null'
            - integer
          format: int32
        total:
          type:
            - 'null'
            - integer
          format: int32
      description: "A pickable option for a field: the Value stored in the payload and a human\r\nLabel for display."
    TargetReferenceKind:
      enum:
        - user
        - group
      description: What a ReferenceField points at in the target system.
    StringField: {}
  securitySchemes:
    cookieAuth:
      type: apiKey
      description: >-
        Cookie-based session. Obtain by completing the `/auth/login/{provider}`
        OAuth flow; the `/auth/callback` response sets the `klef.session` cookie
        that subsequent requests send automatically.
      name: klef.session
      in: cookie
    apiKeyAuth:
      type: http
      description: >-
        An API key from **Settings > API keys**, sent as `Authorization: Bearer
        klef_sk_…`. A key works only on its own workspace's subdomain, and only
        with the permissions its scopes grant.
      scheme: bearer
      bearerFormat: klef_sk_…

````