> ## Documentation Index
> Fetch the complete documentation index at: https://docs.opal.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Create app

> Creates an `App` in Opal. Currently supports only Push-only apps (`CUSTOM`)
and Custom Connector apps (`CUSTOM_CONNECTOR`).



## OpenAPI

````yaml https://app.opal.dev/openapi.yaml post /apps
openapi: 3.1.0
info:
  contact:
    email: hello@opal.dev
    name: Opal Team
    url: https://www.opal.dev/
  description: >-
    The Opal API is a RESTful API that allows you to interact with the Opal
    Security platform programmatically.
  title: Opal API
  version: '1.0'
servers:
  - description: Production
    url: https://api.opal.dev/v1
security: []
tags:
  - name: access-rules
    description: Operations related to access rules
  - name: apps
    description: Operations related to apps
  - name: bundles
    description: Operations related to bundles
  - name: campaigns
    description: Operations related to access review campaigns
  - name: configuration-templates
    description: Operations related to configuration templates
  - name: delegations
    description: Operations related to request reviewer delegations
  - name: event-streams
    description: Operations related to event streaming connections
  - name: events
    description: Operations related to events
  - name: groups
    description: Operations related to groups
  - name: group-bindings
    description: Operations related to group bindings
  - name: idp-group-mappings
    description: Operations related to IDP group mappings
  - name: message-channels
    description: Operations related to message channels
  - name: non-human-identities
    description: Operations related to non-human identities
  - name: on-call-schedules
    description: Operations related to on-call schedules
  - name: opal-queries
    description: Operations related to OpalQuery
  - name: owners
    description: Operations related to owners
  - name: requests
    description: Operations related to requests
  - name: resources
    description: Operations related to resources
  - name: paladin
    description: Operations related to Paladin
  - name: sessions
    description: Operations related to sessions
  - name: tags
    description: Operations related to tags
  - name: tokens
    description: Operations related to API tokens
  - name: uars
    description: Operations related to UARs. Deprecated in favor of the `campaigns` API.
  - name: users
    description: Operations related to users
paths:
  /apps:
    post:
      tags:
        - apps
      summary: Create app
      description: >-
        Creates an `App` in Opal. Currently supports only Push-only apps
        (`CUSTOM`)

        and Custom Connector apps (`CUSTOM_CONNECTOR`).
      operationId: createApp
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateAppInfo'
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/App'
          description: The app that was created.
      security:
        - BearerAuth: []
components:
  schemas:
    CreateAppInfo:
      description: |-
        Information needed to create an app. Currently supports only Push-only
        apps (`CUSTOM`) and Custom Connector apps (`CUSTOM_CONNECTOR`).
      properties:
        name:
          description: The name of the app.
          example: My Push-only App
          type: string
        description:
          description: A description of the app.
          example: Bookkeeping app for internal tools.
          type: string
        admin_owner_id:
          description: The ID of the owner of the app.
          example: 7c86c85d-0651-43e2-a748-d69d658418e8
          format: uuid
          type: string
        app_type:
          $ref: '#/components/schemas/AppTypeEnum'
          description: |-
            The type of the app. Must be `CUSTOM` (Push-only App) or
            `CUSTOM_CONNECTOR`.
        visibility:
          $ref: '#/components/schemas/VisibilityTypeEnum'
          description: The visibility of the app. Defaults to `GLOBAL` when omitted.
        visibility_group_ids:
          description: >-
            The IDs of groups that can see this app when visibility is
            `LIMITED`.
          items:
            type: string
            format: uuid
          type: array
        import_visibility:
          $ref: '#/components/schemas/VisibilityTypeEnum'
          description: The visibility of imported items. Defaults to `GLOBAL` when omitted.
        custom_connector:
          $ref: '#/components/schemas/CreateCustomConnectorInfo'
          description: |-
            Required when `app_type` is `CUSTOM_CONNECTOR`. Must not be set when
            `app_type` is `CUSTOM`.
      required:
        - name
        - description
        - admin_owner_id
        - app_type
      type: object
    App:
      description: |-
        # App Object
        ### Description
        The `App` object is used to represent an app to an application.

        ### Usage Example
        List from the `GET Apps` endpoint.
      example:
        app_id: f454d283-ca87-4a8a-bdbb-df212eca5353
        name: Okta Org
        description: Okta directory for the engineering team.
        admin_owner_id: 7c86c85d-0651-43e2-a748-d69d658418e8
        app_type: OKTA_DIRECTORY
      properties:
        app_id:
          description: The ID of the app.
          example: f454d283-ca87-4a8a-bdbb-df212eca5353
          format: uuid
          type: string
        name:
          description: The name of the app.
          example: Okta Org
          type: string
        description:
          description: A description of the app.
          example: Okta directory for the engineering team.
          type: string
        admin_owner_id:
          description: The ID of the owner of the app.
          example: 7c86c85d-0651-43e2-a748-d69d658418e8
          format: uuid
          type: string
        app_type:
          $ref: '#/components/schemas/AppTypeEnum'
        visibility:
          $ref: '#/components/schemas/VisibilityTypeEnum'
        validations:
          description: Validation checks of an apps' configuration and permissions.
          items:
            $ref: '#/components/schemas/AppValidation'
          type: array
        custom_connector:
          $ref: '#/components/schemas/CustomConnectorAppConfig'
      required:
        - app_id
        - name
        - description
        - admin_owner_id
        - app_type
      type: object
    AppTypeEnum:
      description: The type of an app.
      enum:
        - ACTIVE_DIRECTORY
        - ANTHROPIC
        - AZURE_AD
        - AWS
        - AWS_SSO
        - CLICKHOUSE
        - COUPA
        - CURSOR
        - CUSTOM
        - CONFLUENCE
        - CUSTOM_CONNECTOR
        - DATABRICKS
        - DATASTAX_ASTRA
        - ALICLOUD
        - DEVIN
        - DOCUSIGN
        - DUO
        - GCP
        - GIT_HUB
        - GIT_LAB
        - GOOGLE_GROUPS
        - GOOGLE_WORKSPACE
        - GRAFANA
        - HUBSPOT
        - ILEVEL
        - INCIDENTIO
        - JIRA
        - LDAP
        - LINEAR
        - MARIADB
        - MONGO
        - MONGO_ATLAS
        - MYSQL
        - NETSUITE
        - DATADOG
        - OKTA_CIAM
        - OKTA_DIRECTORY
        - OPENAI_PLATFORM
        - OPAL
        - ORACLE_FUSION
        - PAGERDUTY
        - POSTGRES
        - ROOTLY
        - SALESFORCE
        - SNOWFLAKE
        - SLACK
        - TABLEAU
        - TAILSCALE
        - TELEPORT
        - TWINGATE
        - VAULT
        - WORKDAY
        - ZENDESK
        - ZOOM
        - RAMP
        - WRIKE
        - VERCEL
        - AXIOM
      example: OKTA_DIRECTORY
      type: string
    VisibilityTypeEnum:
      description: The visibility level of the entity.
      enum:
        - GLOBAL
        - LIMITED
      example: GLOBAL
      type: string
    CreateCustomConnectorInfo:
      description: Information needed to create a Custom Connector app.
      properties:
        identifier:
          description: The identifier of the Custom Connector.
          example: my-connector
          type: string
        base_url:
          description: The base URL of the Custom Connector.
          example: https://my-connector.example.com
          type: string
        signing_secret:
          description: |-
            The signing secret used to authenticate requests to the Custom
            Connector. Write-only; never returned by the API.
          type: string
        tls_mode:
          description: >-
            Whether TLS verification is enabled. Defaults to `true` when
            omitted.
          type: boolean
        tls_ca_cert_content:
          description: Optional PEM-encoded CA certificate content for TLS.
          type: string
          nullable: true
        supports_groups:
          description: Whether the Custom Connector supports groups. Defaults to `false`.
          type: boolean
        supports_nested_resources:
          description: |-
            Whether the Custom Connector supports nested resources. Defaults to
            `false`.
          type: boolean
        supports_nested_groups:
          description: |-
            Whether the Custom Connector supports nested groups. Defaults to
            `false`.
          type: boolean
        supports_event_ingestion:
          description: |-
            Whether the Custom Connector supports event ingestion. Defaults to
            `false`.
          type: boolean
      required:
        - identifier
        - base_url
        - signing_secret
      type: object
    AppValidation:
      description: >-
        # App validation object

        ### Description

        The `AppValidation` object is used to represent a validation check of an
        apps' configuration and permissions.


        ### Usage Example

        List from the `GET Apps` endpoint.
      example:
        key: iam:GetRole
        name: Opal's service account is missing the 'iam:GetRole' permission.
        usage_reason: Opal uses the 'iam:GetRole' permissions to view access to resources.
        details: >-
          403 Google API Error. Service account is not authorized to access role
          assignments.
        severity: HIGH
        status: FAILED
        updated_at: '2021-01-06T20:00:00.000Z'
      properties:
        key:
          description: >-
            The key of the app validation. These are not unique IDs between
            runs.
          example: iam:GetUser
          type: string
        name:
          description: >-
            The human-readable description of whether the validation has the
            permissions.
          example: Opal's service account is missing the 'iam:GetUser' description.
        usage_reason:
          description: The reason for needing the validation.
          example: Opal uses the 'iam:GetUser' permission to import users.
          type: string
        details:
          description: >-
            Extra details regarding the validation. Could be an error message or
            restrictions on permissions.
          example: >-
            403 Google API Error. Service account is not authorized to access
            role assignments.
          type: string
        severity:
          $ref: '#/components/schemas/AppValidationSeverityEnum'
        status:
          $ref: '#/components/schemas/AppValidationStatusEnum'
        updated_at:
          description: The date and time the app validation was last run.
          example: '2021-01-06T20:00:00.000Z'
          format: date-time
          type: string
      required:
        - key
        - name
        - status
        - severity
        - updated_at
    CustomConnectorAppConfig:
      description: |-
        Configuration for a Custom Connector app. Does not include the signing
        secret; secrets are write-only and never returned by the API.
      properties:
        identifier:
          description: The identifier of the Custom Connector.
          example: my-connector
          type: string
        base_url:
          description: The base URL of the Custom Connector.
          example: https://my-connector.example.com
          type: string
        tls_mode:
          description: Whether TLS verification is enabled for the Custom Connector.
          type: boolean
        tls_ca_cert_content:
          description: Optional PEM-encoded CA certificate content for TLS.
          type: string
          nullable: true
        supports_groups:
          description: Whether the Custom Connector supports groups.
          type: boolean
        supports_nested_resources:
          description: Whether the Custom Connector supports nested resources.
          type: boolean
        supports_nested_groups:
          description: Whether the Custom Connector supports nested groups.
          type: boolean
        supports_event_ingestion:
          description: Whether the Custom Connector supports event ingestion.
          type: boolean
      required:
        - identifier
        - base_url
        - tls_mode
        - supports_groups
        - supports_nested_resources
        - supports_nested_groups
        - supports_event_ingestion
      type: object
    AppValidationSeverityEnum:
      description: The severity of an app validation.
      enum:
        - CRITICAL
        - HIGH
        - MEDIUM
        - LOW
      example: CRITICAL
      type: string
    AppValidationStatusEnum:
      description: The status of an app validation.
      enum:
        - SUCCESS
        - FAILED
      example: FAILED
      type: string
  securitySchemes:
    BearerAuth:
      scheme: bearer
      type: http

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.