Skip to content

Add an account

POST
/api/v1/aws/connections/{id}/accounts
curl --request POST \
--url https://api.aletheia-ops.com/api/v1/aws/connections/example/accounts \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "account_id": "example", "name": "example" }'
id
required
string
Media typeapplication/json

Adds a standalone account to a connection

object
account_id
required
string
name
string
Examplegenerated
{
"account_id": "example",
"name": "example"
}

Created

Media typeapplication/json

Public shape of an onboarded account

object
id
string
account_id
string
name
string
email
string
ou_path
string
role_arn
string
included
boolean
status
string
regions
Array<string>
effective_regions
Array<string>
validation

Structured probe summary on an account

object
checks
Array<object>

One validation probe outcome

object
check
string
ok
boolean
message
string
missing_permissions
Array<string>
error
string
last_validated_at
string format: date-time
template

Role template an account actually has deployed, read back from the role’s own critias:template-version tag. An absent version means unknown — a role deployed before the template stamped its version, or one Aletheia currently cannot read — which is never the same as being out of date

object
version
string
behind
boolean
Examplegenerated
{
"id": "example",
"account_id": "example",
"name": "example",
"email": "example",
"ou_path": "example",
"role_arn": "example",
"included": true,
"status": "example",
"regions": [
"example"
],
"effective_regions": [
"example"
],
"validation": {
"checks": [
{
"check": "example",
"ok": true,
"message": "example"
}
],
"missing_permissions": [
"example"
],
"error": "example"
},
"last_validated_at": "2026-04-15T12:00:00Z",
"template": {
"version": "example",
"behind": true
}
}

The request is malformed or fails validation.

Media typeapplication/json
object
code
required

Stable, machine-readable identifier. Branch on this.

string
message
required

Human-readable explanation. Safe to display; do not parse.

string
Examples
{
"code": "validation_failed",
"message": "name: must not be blank"
}

No valid credential was presented, or it has expired.

Media typeapplication/json
object
code
required

Stable, machine-readable identifier. Branch on this.

string
message
required

Human-readable explanation. Safe to display; do not parse.

string
Examples
{
"code": "unauthorized",
"message": "authentication required"
}

Authenticated, but not permitted to perform this action.

Media typeapplication/json
object
code
required

Stable, machine-readable identifier. Branch on this.

string
message
required

Human-readable explanation. Safe to display; do not parse.

string
Examples
{
"code": "forbidden",
"message": "you do not have permission to perform this action"
}

The resource does not exist, or belongs to another organization. The two are deliberately indistinguishable.

Media typeapplication/json
object
code
required

Stable, machine-readable identifier. Branch on this.

string
message
required

Human-readable explanation. Safe to display; do not parse.

string
Examples
Examplenot_found
{
"code": "not_found",
"message": "resource not found"
}

The request conflicts with the current state.

Media typeapplication/json
object
code
required

Stable, machine-readable identifier. Branch on this.

string
message
required

Human-readable explanation. Safe to display; do not parse.

string
Examples
{
"code": "email_taken",
"message": "an account with this email already exists"
}

An unexpected failure. Diagnostic detail is logged server-side and deliberately not returned. Quote the X-Request-Id response header when reporting one.

Media typeapplication/json
object
code
required

Stable, machine-readable identifier. Branch on this.

string
message
required

Human-readable explanation. Safe to display; do not parse.

string
Examples
Exampleinternal_error
{
"code": "internal_error",
"message": "internal server error"
}