This is an automated email from the ASF dual-hosted git repository.

lahirujayathilake pushed a commit to branch auth-endpoints
in repository https://gitbox.apache.org/repos/asf/airavata-custos.git

commit 61183f73ec7abedfb5fbd328932ca06cf14701f4
Author: lahiruj <[email protected]>
AuthorDate: Tue Jun 16 21:49:35 2026 -0400

    Sweep remaining swagger annotations to BearerAuth scheme
---
 api/core.openapi.yaml                              | 214 ++++++++++-----------
 .../ACCESS/AMIE-Processor/api/amie.openapi.yaml    |  26 +--
 .../ACCESS/AMIE-Processor/server/handlers.go       |  22 +--
 internal/server/audit_handlers.go                  |   8 +-
 internal/server/privilege.go                       |   6 +-
 internal/server/server.go                          | 158 +++++++--------
 6 files changed, 217 insertions(+), 217 deletions(-)

diff --git a/api/core.openapi.yaml b/api/core.openapi.yaml
index 1f8d01c18..65d7ed17f 100644
--- a/api/core.openapi.yaml
+++ b/api/core.openapi.yaml
@@ -646,8 +646,8 @@ info:
   contact: {}
   description: 'REST API for Apache Custos: organizations, users, projects, 
compute
     clusters and allocations, audit traces, and the privilege/role 
authorization layer.
-    Authenticate every request with the X-Custos-User-Id header. Connector 
endpoints
-    (/connectors/<name>/...) are documented in separate specs.'
+    Authenticate every request with an OIDC bearer token in the Authorization 
header.
+    Connector endpoints (/connectors/<name>/...) are documented in separate 
specs.'
   title: Apache Custos Core API
   version: 0.2.0
 paths:
@@ -690,7 +690,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List audit events for a trace (optionally one span)
       tags:
       - Audit
@@ -716,7 +716,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List distinct audit-event sources
       tags:
       - Audit
@@ -792,7 +792,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List audit traces with filters
       tags:
       - Audit
@@ -842,7 +842,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Get a trace's nested span tree
       tags:
       - Audit
@@ -872,7 +872,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Create a change request event
       tags:
       - Change Request Events
@@ -895,7 +895,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Delete a change request event
       tags:
       - Change Request Events
@@ -921,7 +921,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Get a change request event
       tags:
       - Change Request Events
@@ -951,7 +951,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Create a compute allocation change request
       tags:
       - Compute Allocation Change Requests
@@ -974,7 +974,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Delete a compute allocation change request
       tags:
       - Compute Allocation Change Requests
@@ -1000,7 +1000,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Get a compute allocation change request
       tags:
       - Compute Allocation Change Requests
@@ -1041,7 +1041,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Update a compute allocation change request
       tags:
       - Compute Allocation Change Requests
@@ -1070,7 +1070,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List events for a change request
       tags:
       - Change Request Events
@@ -1097,7 +1097,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Get the most recent event for a change request
       tags:
       - Change Request Events
@@ -1136,7 +1136,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Create a compute allocation diff
       tags:
       - Compute Allocation Diffs
@@ -1159,7 +1159,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Delete a compute allocation diff
       tags:
       - Compute Allocation Diffs
@@ -1185,7 +1185,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Get a compute allocation diff
       tags:
       - Compute Allocation Diffs
@@ -1215,7 +1215,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Create a membership resource override
       tags:
       - Membership Resource Overrides
@@ -1238,7 +1238,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Delete a membership resource override
       tags:
       - Membership Resource Overrides
@@ -1264,7 +1264,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Get a membership resource override
       tags:
       - Membership Resource Overrides
@@ -1305,7 +1305,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Update a membership resource override
       tags:
       - Membership Resource Overrides
@@ -1335,7 +1335,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Create a compute allocation membership
       tags:
       - Compute Allocation Memberships
@@ -1358,7 +1358,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Delete a compute allocation membership
       tags:
       - Compute Allocation Memberships
@@ -1384,7 +1384,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Get a compute allocation membership
       tags:
       - Compute Allocation Memberships
@@ -1425,7 +1425,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Update a compute allocation membership
       tags:
       - Compute Allocation Memberships
@@ -1454,7 +1454,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List resource overrides for a membership
       tags:
       - Membership Resource Overrides
@@ -1499,7 +1499,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Update a membership's status
       tags:
       - Compute Allocation Memberships
@@ -1538,7 +1538,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Create a compute allocation resource rate
       tags:
       - Compute Allocation Resource Rates
@@ -1565,7 +1565,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Get a compute allocation resource rate
       tags:
       - Compute Allocation Resource Rates
@@ -1588,7 +1588,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List all compute allocation resources
       tags:
       - Compute Allocation Resources
@@ -1626,7 +1626,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Create a compute allocation resource
       tags:
       - Compute Allocation Resources
@@ -1653,7 +1653,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Get a compute allocation resource
       tags:
       - Compute Allocation Resources
@@ -1682,7 +1682,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List compute allocations attached to a resource
       tags:
       - Compute Allocation Resources
@@ -1711,7 +1711,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List membership overrides referencing a resource
       tags:
       - Membership Resource Overrides
@@ -1740,7 +1740,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List rate history for a resource
       tags:
       - Compute Allocation Resource Rates
@@ -1780,7 +1780,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Get the effective rate for a resource at a given time
       tags:
       - Compute Allocation Resource Rates
@@ -1810,7 +1810,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Create a compute allocation usage record
       tags:
       - Compute Allocation Usages
@@ -1833,7 +1833,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Delete a compute allocation usage record
       tags:
       - Compute Allocation Usages
@@ -1859,7 +1859,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Get a compute allocation usage record
       tags:
       - Compute Allocation Usages
@@ -1894,7 +1894,7 @@ paths:
           schema:
             $ref: '#/definitions/ComputeAllocationListResponse'
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List compute allocations (filtered + paginated)
       tags:
       - Compute Allocations
@@ -1923,7 +1923,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Create a compute allocation
       tags:
       - Compute Allocations
@@ -1950,7 +1950,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Get a compute allocation by ID
       tags:
       - Compute Allocations
@@ -1979,7 +1979,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List change requests for a compute allocation
       tags:
       - Compute Allocation Change Requests
@@ -2008,7 +2008,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List diffs for a compute allocation
       tags:
       - Compute Allocation Diffs
@@ -2035,7 +2035,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Get the most recent diff for a compute allocation
       tags:
       - Compute Allocation Diffs
@@ -2064,7 +2064,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List members of a compute allocation
       tags:
       - Compute Allocation Memberships
@@ -2093,7 +2093,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List resources attached to a compute allocation
       tags:
       - Compute Allocation Resources
@@ -2136,7 +2136,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Attach a resource to a compute allocation
       tags:
       - Compute Allocation Resources
@@ -2164,7 +2164,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Detach a resource from a compute allocation
       tags:
       - Compute Allocation Resources
@@ -2210,7 +2210,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Update a compute allocation -> resource mapping
       tags:
       - Compute Allocation Resources
@@ -2239,7 +2239,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List usages for a compute allocation
       tags:
       - Compute Allocation Usages
@@ -2266,7 +2266,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Get total SU usage for a compute allocation
       tags:
       - Compute Allocation Usages
@@ -2298,7 +2298,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Get total SU usage for a user within a compute allocation
       tags:
       - Compute Allocation Usages
@@ -2328,7 +2328,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Create a compute cluster user
       tags:
       - Compute Cluster Users
@@ -2351,7 +2351,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Delete a compute cluster user
       tags:
       - Compute Cluster Users
@@ -2377,7 +2377,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Get a compute cluster user by ID
       tags:
       - Compute Cluster Users
@@ -2418,7 +2418,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Update a compute cluster user
       tags:
       - Compute Cluster Users
@@ -2441,7 +2441,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List compute clusters
       tags:
       - Compute Clusters
@@ -2470,7 +2470,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Create a compute cluster
       tags:
       - Compute Clusters
@@ -2497,7 +2497,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Get a compute cluster by ID
       tags:
       - Compute Clusters
@@ -2526,7 +2526,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List users on a compute cluster
       tags:
       - Compute Cluster Users
@@ -2558,7 +2558,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Get a compute cluster user by (cluster, user) pair
       tags:
       - Compute Cluster Users
@@ -2588,7 +2588,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Create an organization
       tags:
       - Organizations
@@ -2615,7 +2615,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Get an organization by ID
       tags:
       - Organizations
@@ -2654,7 +2654,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List direct holders of a privilege
       tags:
       - Privileges
@@ -2684,7 +2684,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List the declared privilege catalog
       tags:
       - Privileges
@@ -2719,7 +2719,7 @@ paths:
           schema:
             $ref: '#/definitions/ProjectListResponse'
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List projects (filtered + paginated, PI joined)
       tags:
       - Projects
@@ -2748,7 +2748,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Create a project
       tags:
       - Projects
@@ -2775,7 +2775,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Get a project by ID
       tags:
       - Projects
@@ -2804,7 +2804,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List project members (one row per distinct user, with 
allocations)
       tags:
       - Projects
@@ -2849,7 +2849,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Update a project's status
       tags:
       - Projects
@@ -2879,7 +2879,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List all roles
       tags:
       - Roles
@@ -2922,7 +2922,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Create a role
       tags:
       - Roles
@@ -2954,7 +2954,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Delete a role
       tags:
       - Roles
@@ -2994,7 +2994,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Get a role with its privilege bundle
       tags:
       - Roles
@@ -3036,7 +3036,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Update role name / description
       tags:
       - Roles
@@ -3065,7 +3065,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List users holding the role
       tags:
       - Roles
@@ -3111,7 +3111,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Add a privilege to a role
       tags:
       - Roles
@@ -3164,7 +3164,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Remove a privilege from a role
       tags:
       - Roles
@@ -3194,7 +3194,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Create a user identity
       tags:
       - User Identities
@@ -3217,7 +3217,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Delete a user identity
       tags:
       - User Identities
@@ -3243,7 +3243,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Get a user identity
       tags:
       - User Identities
@@ -3284,7 +3284,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Update a user identity
       tags:
       - User Identities
@@ -3311,7 +3311,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Get a user identity by its OIDC subject claim
       tags:
       - User Identities
@@ -3343,7 +3343,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Get a user identity by source and external ID
       tags:
       - User Identities
@@ -3364,7 +3364,7 @@ paths:
                 type: array
             type: object
         "401":
-          description: Missing X-Custos-User-Id header
+          description: Unauthenticated
           schema:
             properties:
               error:
@@ -3378,7 +3378,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Get caller's effective privileges
       tags:
       - Caller
@@ -3408,7 +3408,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Create a user
       tags:
       - Users
@@ -3435,7 +3435,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Get a user by ID
       tags:
       - Users
@@ -3464,7 +3464,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List change requests submitted by a user
       tags:
       - Compute Allocation Change Requests
@@ -3493,7 +3493,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List a user's compute allocation memberships
       tags:
       - Compute Allocation Memberships
@@ -3522,7 +3522,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List usages submitted by a user
       tags:
       - Compute Allocation Usages
@@ -3551,7 +3551,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List compute cluster users for a user
       tags:
       - Compute Cluster Users
@@ -3589,7 +3589,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List a user's direct privilege grants
       tags:
       - Privileges
@@ -3623,7 +3623,7 @@ paths:
                 type: string
             type: object
         "401":
-          description: Missing caller header
+          description: Unauthenticated
           schema:
             properties:
               error:
@@ -3644,7 +3644,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Grant a direct privilege to a user
       tags:
       - Privileges
@@ -3690,7 +3690,7 @@ paths:
                 type: string
             type: object
         "401":
-          description: Missing caller header
+          description: Unauthenticated
           schema:
             properties:
               error:
@@ -3711,7 +3711,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Revoke a direct privilege from a user
       tags:
       - Privileges
@@ -3740,7 +3740,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List roles a user holds
       tags:
       - Role Assignments
@@ -3788,7 +3788,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Grant a role to a user
       tags:
       - Role Assignments
@@ -3839,7 +3839,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Revoke a role from a user
       tags:
       - Role Assignments
@@ -3884,7 +3884,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Update a user's status
       tags:
       - Users
@@ -3913,7 +3913,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List a user's identities
       tags:
       - User Identities
@@ -3952,13 +3952,13 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Merge two users
       tags:
       - Users
 securityDefinitions:
-  CustosUserHeader:
+  BearerAuth:
     in: header
-    name: X-Custos-User-Id
+    name: Authorization
     type: apiKey
 swagger: "2.0"
diff --git a/connectors/ACCESS/AMIE-Processor/api/amie.openapi.yaml 
b/connectors/ACCESS/AMIE-Processor/api/amie.openapi.yaml
index 7f2fe3590..49df48f16 100644
--- a/connectors/ACCESS/AMIE-Processor/api/amie.openapi.yaml
+++ b/connectors/ACCESS/AMIE-Processor/api/amie.openapi.yaml
@@ -149,7 +149,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List AMIE packets
       tags:
       - AMIE Packets
@@ -183,7 +183,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Get an AMIE packet by ID
       tags:
       - AMIE Packets
@@ -212,7 +212,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List processing events for an AMIE packet
       tags:
       - AMIE Packets
@@ -237,7 +237,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Resolve an AMIE packet (not yet implemented)
       tags:
       - AMIE Packets
@@ -262,7 +262,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Retry an AMIE packet (not yet implemented)
       tags:
       - AMIE Packets
@@ -329,7 +329,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List audit events for an AMIE packet
       tags:
       - AMIE Audit
@@ -352,7 +352,7 @@ paths:
           schema:
             $ref: '#/definitions/ReplyListResponse'
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List replies sent to AMIE
       tags:
       - AMIE Replies
@@ -377,7 +377,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Retry an AMIE reply (not yet implemented)
       tags:
       - AMIE Replies
@@ -403,7 +403,7 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Per-day packet stats grouped by status and type
       tags:
       - AMIE Stats
@@ -426,7 +426,7 @@ paths:
           schema:
             $ref: '#/definitions/PacketListResponse'
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: List AMIE packets that could not be mapped to a Custos entity
       tags:
       - AMIE Unmapped
@@ -451,13 +451,13 @@ paths:
                 type: string
             type: object
       security:
-      - CustosUserHeader: []
+      - BearerAuth: []
       summary: Link an unmapped packet to a Custos entity (not yet implemented)
       tags:
       - AMIE Unmapped
 securityDefinitions:
-  CustosUserHeader:
+  BearerAuth:
     in: header
-    name: X-Custos-User-Id
+    name: Authorization
     type: apiKey
 swagger: "2.0"
diff --git a/connectors/ACCESS/AMIE-Processor/server/handlers.go 
b/connectors/ACCESS/AMIE-Processor/server/handlers.go
index bd4dfb36b..4c3557445 100644
--- a/connectors/ACCESS/AMIE-Processor/server/handlers.go
+++ b/connectors/ACCESS/AMIE-Processor/server/handlers.go
@@ -55,7 +55,7 @@ func (h *Handlers) RegisterRoutes(mux *http.ServeMux) {
 
 // @Summary    List audit events for an AMIE packet
 // @Tags       AMIE Audit
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      packet_id       path    string  true    "AMIE packet ID"
 // @Success    200     {object}        
object{packet_id=string,events=[]object{span_id=string,parent_span_id=string,source=string,event_type=string,entity_type=string,entity_id=string,description=string,status=string,created_at=string}}
@@ -86,7 +86,7 @@ func (h *Handlers) listPacketAudits(w http.ResponseWriter, r 
*http.Request) {
 
 // @Summary    List AMIE packets
 // @Tags       AMIE Packets
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      status  query   string  false   "Filter by status (NEW, 
DECODED, PROCESSED, FAILED, all)"
 // @Param      type    query   string  false   "Filter by packet type"
@@ -128,7 +128,7 @@ func (h *Handlers) listPackets(w http.ResponseWriter, r 
*http.Request) {
 
 // @Summary    Get an AMIE packet by ID
 // @Tags       AMIE Packets
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "AMIE packet ID"
 // @Success    200     {object}        PacketResponse
@@ -154,7 +154,7 @@ func (h *Handlers) getPacket(w http.ResponseWriter, r 
*http.Request) {
 
 // @Summary    List processing events for an AMIE packet
 // @Tags       AMIE Packets
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "AMIE packet ID"
 // @Success    200     {array} PacketEventResponse
@@ -179,7 +179,7 @@ func (h *Handlers) listPacketEvents(w http.ResponseWriter, 
r *http.Request) {
 
 // @Summary    Per-day packet stats grouped by status and type
 // @Tags       AMIE Stats
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      window  query   string  false   "Lookback window (e.g. 30d, 
24h); default 30d"
 // @Success    200     {object}        PacketStatsResponse
@@ -209,7 +209,7 @@ type ReplyListResponse struct {
 
 // @Summary    List replies sent to AMIE
 // @Tags       AMIE Replies
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      limit   query   int     false   "Page size (default 50, max 
200)"
 // @Param      offset  query   int     false   "Pagination offset"
@@ -226,7 +226,7 @@ func (h *Handlers) listReplies(w http.ResponseWriter, r 
*http.Request) {
 
 // @Summary    List AMIE packets that could not be mapped to a Custos entity
 // @Tags       AMIE Unmapped
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      limit   query   int     false   "Page size (default 50, max 
200)"
 // @Param      offset  query   int     false   "Pagination offset"
@@ -238,7 +238,7 @@ func (h *Handlers) listUnmapped(w http.ResponseWriter, r 
*http.Request) {
 
 // @Summary    Retry an AMIE packet (not yet implemented)
 // @Tags       AMIE Packets
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "AMIE packet ID"
 // @Failure    501     {object}        object{error=string,message=string}
@@ -249,7 +249,7 @@ func (h *Handlers) retryPacket(w http.ResponseWriter, _ 
*http.Request) {
 
 // @Summary    Resolve an AMIE packet (not yet implemented)
 // @Tags       AMIE Packets
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "AMIE packet ID"
 // @Failure    501     {object}        object{error=string,message=string}
@@ -260,7 +260,7 @@ func (h *Handlers) resolvePacket(w http.ResponseWriter, _ 
*http.Request) {
 
 // @Summary    Retry an AMIE reply (not yet implemented)
 // @Tags       AMIE Replies
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "AMIE reply ID"
 // @Failure    501     {object}        object{error=string,message=string}
@@ -271,7 +271,7 @@ func (h *Handlers) retryReply(w http.ResponseWriter, _ 
*http.Request) {
 
 // @Summary    Link an unmapped packet to a Custos entity (not yet implemented)
 // @Tags       AMIE Unmapped
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "AMIE packet ID"
 // @Failure    501     {object}        object{error=string,message=string}
diff --git a/internal/server/audit_handlers.go 
b/internal/server/audit_handlers.go
index e3ba7a450..f99c43773 100644
--- a/internal/server/audit_handlers.go
+++ b/internal/server/audit_handlers.go
@@ -48,7 +48,7 @@ func (s *Server) requireAuditStore(w http.ResponseWriter) 
(store.AuditTraceStore
 // @Summary    List audit traces with filters
 // @Description        One row per distinct trace_id. `q` matches trace_id hex 
prefix or root-operation substring.
 // @Tags       Audit
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      source  query   []string        false   "Restrict to listed 
sources (repeatable)"       collectionFormat(multi)
 // @Param      status  query   []string        false   "ok | error | 
in_progress (repeatable)" collectionFormat(multi)
@@ -86,7 +86,7 @@ func (s *Server) handleListTraces(w http.ResponseWriter, r 
*http.Request) {
 
 // @Summary    Get a trace's nested span tree
 // @Tags       Audit
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      trace_id        path    string  true    "32-char lowercase hex"
 // @Success    200     {object}        
object{trace_id=string,tree=[]models.TraceNode,truncated=boolean}
@@ -124,7 +124,7 @@ func (s *Server) handleGetTrace(w http.ResponseWriter, r 
*http.Request) {
 
 // @Summary    List audit events for a trace (optionally one span)
 // @Tags       Audit
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      trace_id        query   string  true    "32-char lowercase hex"
 // @Param      span_id query   string  false   "16-char lowercase hex"
@@ -164,7 +164,7 @@ func (s *Server) handleListEvents(w http.ResponseWriter, r 
*http.Request) {
 
 // @Summary    List distinct audit-event sources
 // @Tags       Audit
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Success    200     {object}        object{sources=[]string}
 // @Failure    503     {object}        object{error=string}    "Audit trace 
store not configured"
diff --git a/internal/server/privilege.go b/internal/server/privilege.go
index 1f8839dc6..504ce8baf 100644
--- a/internal/server/privilege.go
+++ b/internal/server/privilege.go
@@ -52,7 +52,7 @@ func (s *Server) getCallerPrivileges(w http.ResponseWriter, r 
*http.Request) {
 
 // @Summary    List the declared privilege catalog
 // @Tags       Privileges
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Success    200     {array} models.PrivilegeKey
 // @Failure    401     {object}        object{error=string}    "Missing caller 
header"
@@ -65,7 +65,7 @@ func (s *Server) getPrivilegeCatalog(w http.ResponseWriter, _ 
*http.Request) {
 // @Summary    List a user's direct privilege grants
 // @Description        Returns DIRECT grants only (not role-derived). Combine 
with `GET /users/{id}/roles` for the full picture.
 // @Tags       Privileges
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "User ID"
 // @Success    200     {array} models.UserPrivilege
@@ -89,7 +89,7 @@ func (s *Server) listUserPrivileges(w http.ResponseWriter, r 
*http.Request) {
 // @Summary    List direct holders of a privilege
 // @Description        Role-derived holders are NOT listed here.
 // @Tags       Privileges
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      key     path    models.PrivilegeKey     true    "Privilege key"
 // @Success    200     {array} models.UserPrivilege
diff --git a/internal/server/server.go b/internal/server/server.go
index 622c2c703..dd833cdaa 100644
--- a/internal/server/server.go
+++ b/internal/server/server.go
@@ -198,7 +198,7 @@ func (s *Server) healthz(w http.ResponseWriter, _ 
*http.Request) {
 
 // @Summary    Create an organization
 // @Tags       Organizations
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Accept     json
 // @Produce    json
 // @Param      request body    models.Organization     true    "Organization 
payload"
@@ -221,7 +221,7 @@ func (s *Server) createOrganization(w http.ResponseWriter, 
r *http.Request) {
 
 // @Summary    Get an organization by ID
 // @Tags       Organizations
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "Organization ID"
 // @Success    200     {object}        models.Organization
@@ -238,7 +238,7 @@ func (s *Server) getOrganization(w http.ResponseWriter, r 
*http.Request) {
 
 // @Summary    Create a user
 // @Tags       Users
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Accept     json
 // @Produce    json
 // @Param      request body    models.User     true    "User payload"
@@ -261,7 +261,7 @@ func (s *Server) createUser(w http.ResponseWriter, r 
*http.Request) {
 
 // @Summary    Get a user by ID
 // @Tags       Users
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "User ID"
 // @Success    200     {object}        models.User
@@ -278,7 +278,7 @@ func (s *Server) getUser(w http.ResponseWriter, r 
*http.Request) {
 
 // @Summary    Create a project
 // @Tags       Projects
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Accept     json
 // @Produce    json
 // @Param      request body    models.Project  true    "Project payload"
@@ -301,7 +301,7 @@ func (s *Server) createProject(w http.ResponseWriter, r 
*http.Request) {
 
 // @Summary    Get a project by ID
 // @Tags       Projects
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "Project ID"
 // @Success    200     {object}        ProjectResponse
@@ -329,7 +329,7 @@ func projectResponseFrom(p *store.ProjectWithPI) 
ProjectResponse {
 
 // @Summary    Create a compute cluster
 // @Tags       Compute Clusters
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Accept     json
 // @Produce    json
 // @Param      request body    models.ComputeCluster   true    "Cluster 
payload"
@@ -352,7 +352,7 @@ func (s *Server) createComputeCluster(w 
http.ResponseWriter, r *http.Request) {
 
 // @Summary    Get a compute cluster by ID
 // @Tags       Compute Clusters
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "Compute cluster ID"
 // @Success    200     {object}        models.ComputeCluster
@@ -369,7 +369,7 @@ func (s *Server) getComputeCluster(w http.ResponseWriter, r 
*http.Request) {
 
 // @Summary    List compute clusters
 // @Tags       Compute Clusters
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Success    200     {array} models.ComputeCluster
 // @Failure    500     {object}        object{error=string}
@@ -385,7 +385,7 @@ func (s *Server) listComputeClusters(w http.ResponseWriter, 
r *http.Request) {
 
 // @Summary    Create a compute cluster user
 // @Tags       Compute Cluster Users
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Accept     json
 // @Produce    json
 // @Param      request body    models.ComputeClusterUser       true    
"Cluster user payload"
@@ -408,7 +408,7 @@ func (s *Server) createComputeClusterUser(w 
http.ResponseWriter, r *http.Request
 
 // @Summary    Get a compute cluster user by ID
 // @Tags       Compute Cluster Users
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "Compute cluster user ID"
 // @Success    200     {object}        models.ComputeClusterUser
@@ -425,7 +425,7 @@ func (s *Server) getComputeClusterUser(w 
http.ResponseWriter, r *http.Request) {
 
 // @Summary    Update a compute cluster user
 // @Tags       Compute Cluster Users
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Accept     json
 // @Produce    json
 // @Param      id      path    string  true    "Compute cluster user ID"
@@ -450,7 +450,7 @@ func (s *Server) updateComputeClusterUser(w 
http.ResponseWriter, r *http.Request
 
 // @Summary    Delete a compute cluster user
 // @Tags       Compute Cluster Users
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Param      id      path    string  true    "Compute cluster user ID"
 // @Success    204     "No Content"
 // @Failure    404     {object}        object{error=string}
@@ -465,7 +465,7 @@ func (s *Server) deleteComputeClusterUser(w 
http.ResponseWriter, r *http.Request
 
 // @Summary    List users on a compute cluster
 // @Tags       Compute Cluster Users
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "Compute cluster ID"
 // @Success    200     {array} models.ComputeClusterUser
@@ -482,7 +482,7 @@ func (s *Server) listComputeClusterUsersByCluster(w 
http.ResponseWriter, r *http
 
 // @Summary    Get a compute cluster user by (cluster, user) pair
 // @Tags       Compute Cluster Users
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "Compute cluster ID"
 // @Param      userId  path    string  true    "User ID"
@@ -500,7 +500,7 @@ func (s *Server) getComputeClusterUserByPair(w 
http.ResponseWriter, r *http.Requ
 
 // @Summary    List compute cluster users for a user
 // @Tags       Compute Cluster Users
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "User ID"
 // @Success    200     {array} models.ComputeClusterUser
@@ -517,7 +517,7 @@ func (s *Server) listComputeClusterUsersByUser(w 
http.ResponseWriter, r *http.Re
 
 // @Summary    Create a compute allocation
 // @Tags       Compute Allocations
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Accept     json
 // @Produce    json
 // @Param      request body    models.ComputeAllocation        true    
"Compute allocation payload"
@@ -540,7 +540,7 @@ func (s *Server) createComputeAllocation(w 
http.ResponseWriter, r *http.Request)
 
 // @Summary    Get a compute allocation by ID
 // @Tags       Compute Allocations
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "Compute allocation ID"
 // @Success    200     {object}        models.ComputeAllocation
@@ -558,7 +558,7 @@ func (s *Server) getComputeAllocation(w 
http.ResponseWriter, r *http.Request) {
 // @Summary    Create a compute allocation resource
 // @Description        Defines a resource (partition) — e.g. a CPU or GPU 
partition that allocations can be attached to.
 // @Tags       Compute Allocation Resources
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Accept     json
 // @Produce    json
 // @Param      request body    models.ComputeAllocationResource        true    
"Resource payload"
@@ -582,7 +582,7 @@ func (s *Server) createComputeAllocationResource(w 
http.ResponseWriter, r *http.
 
 // @Summary    Get a compute allocation resource
 // @Tags       Compute Allocation Resources
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "Resource ID"
 // @Success    200     {object}        models.ComputeAllocationResource
@@ -599,7 +599,7 @@ func (s *Server) getComputeAllocationResource(w 
http.ResponseWriter, r *http.Req
 
 // @Summary    List all compute allocation resources
 // @Tags       Compute Allocation Resources
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Success    200     {array} models.ComputeAllocationResource
 // @Failure    401     {object}        object{error=string}
@@ -622,7 +622,7 @@ type attachResourceRequest struct {
 // @Summary    Attach a resource to a compute allocation
 // @Description        Creates a mapping between a compute allocation and a 
resource (partition) with a specific amount and wall-clock time grant.
 // @Tags       Compute Allocation Resources
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Accept     json
 // @Produce    json
 // @Param      id      path    string  true    "Compute allocation ID"
@@ -652,7 +652,7 @@ type updateAllocationResourceMappingRequest struct {
 
 // @Summary    Update a compute allocation -> resource mapping
 // @Tags       Compute Allocation Resources
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Accept     json
 // @Produce    json
 // @Param      id      path    string  true    "Compute allocation ID"
@@ -678,7 +678,7 @@ func (s *Server) updateAllocationResourceMapping(w 
http.ResponseWriter, r *http.
 
 // @Summary    Detach a resource from a compute allocation
 // @Tags       Compute Allocation Resources
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Param      id      path    string  true    "Compute allocation ID"
 // @Param      resourceId      path    string  true    "Compute allocation 
resource ID"
 // @Success    204     "No Content"
@@ -694,7 +694,7 @@ func (s *Server) detachResourceFromAllocation(w 
http.ResponseWriter, r *http.Req
 
 // @Summary    List resources attached to a compute allocation
 // @Tags       Compute Allocation Resources
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "Compute allocation ID"
 // @Success    200     {array} models.ComputeAllocationResourceMapping
@@ -711,7 +711,7 @@ func (s *Server) listResourcesForAllocation(w 
http.ResponseWriter, r *http.Reque
 
 // @Summary    List compute allocations attached to a resource
 // @Tags       Compute Allocation Resources
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "Compute allocation resource ID"
 // @Success    200     {array} models.ComputeAllocationResourceMapping
@@ -729,7 +729,7 @@ func (s *Server) listAllocationsForResource(w 
http.ResponseWriter, r *http.Reque
 // @Summary    Create a compute allocation resource rate
 // @Description        Records the SU rate (e.g. SU per CPU-hour) for a 
resource over a time window.
 // @Tags       Compute Allocation Resource Rates
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Accept     json
 // @Produce    json
 // @Param      request body    models.ComputeAllocationResourceRate    true    
"Rate payload"
@@ -753,7 +753,7 @@ func (s *Server) createComputeAllocationResourceRate(w 
http.ResponseWriter, r *h
 
 // @Summary    Get a compute allocation resource rate
 // @Tags       Compute Allocation Resource Rates
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "Rate ID"
 // @Success    200     {object}        models.ComputeAllocationResourceRate
@@ -770,7 +770,7 @@ func (s *Server) getComputeAllocationResourceRate(w 
http.ResponseWriter, r *http
 
 // @Summary    List rate history for a resource
 // @Tags       Compute Allocation Resource Rates
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "Compute allocation resource ID"
 // @Success    200     {array} models.ComputeAllocationResourceRate
@@ -788,7 +788,7 @@ func (s *Server) listRatesForResource(w 
http.ResponseWriter, r *http.Request) {
 // @Summary    Get the effective rate for a resource at a given time
 // @Description        Returns the rate whose `[start_time, end_time)` window 
contains the `at` timestamp. Defaults to now when `at` is omitted.
 // @Tags       Compute Allocation Resource Rates
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "Compute allocation resource ID"
 // @Param      at      query   string  false   "RFC3339 time; defaults to now"
@@ -817,7 +817,7 @@ func (s *Server) getEffectiveRateForResource(w 
http.ResponseWriter, r *http.Requ
 // @Summary    Create a compute allocation diff
 // @Description        Records a discrete change against a compute allocation 
(e.g. USAGE_UPDATE or ALLOCATION_STATUS_CHANGE).
 // @Tags       Compute Allocation Diffs
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Accept     json
 // @Produce    json
 // @Param      request body    models.ComputeAllocationDiff    true    "Diff 
payload"
@@ -841,7 +841,7 @@ func (s *Server) createComputeAllocationDiff(w 
http.ResponseWriter, r *http.Requ
 
 // @Summary    Get a compute allocation diff
 // @Tags       Compute Allocation Diffs
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "Diff ID"
 // @Success    200     {object}        models.ComputeAllocationDiff
@@ -858,7 +858,7 @@ func (s *Server) getComputeAllocationDiff(w 
http.ResponseWriter, r *http.Request
 
 // @Summary    Delete a compute allocation diff
 // @Tags       Compute Allocation Diffs
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Param      id      path    string  true    "Diff ID"
 // @Success    204     "No Content"
 // @Failure    404     {object}        object{error=string}
@@ -873,7 +873,7 @@ func (s *Server) deleteComputeAllocationDiff(w 
http.ResponseWriter, r *http.Requ
 
 // @Summary    List diffs for a compute allocation
 // @Tags       Compute Allocation Diffs
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "Compute allocation ID"
 // @Success    200     {array} models.ComputeAllocationDiff
@@ -890,7 +890,7 @@ func (s *Server) listDiffsForAllocation(w 
http.ResponseWriter, r *http.Request)
 
 // @Summary    Get the most recent diff for a compute allocation
 // @Tags       Compute Allocation Diffs
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "Compute allocation ID"
 // @Success    200     {object}        models.ComputeAllocationDiff
@@ -907,7 +907,7 @@ func (s *Server) getLatestDiffForAllocation(w 
http.ResponseWriter, r *http.Reque
 
 // @Summary    Create a compute allocation change request
 // @Tags       Compute Allocation Change Requests
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Accept     json
 // @Produce    json
 // @Param      request body    models.ComputeAllocationChangeRequest   true    
"Change request payload"
@@ -930,7 +930,7 @@ func (s *Server) createComputeAllocationChangeRequest(w 
http.ResponseWriter, r *
 
 // @Summary    Get a compute allocation change request
 // @Tags       Compute Allocation Change Requests
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "Change request ID"
 // @Success    200     {object}        models.ComputeAllocationChangeRequest
@@ -947,7 +947,7 @@ func (s *Server) getComputeAllocationChangeRequest(w 
http.ResponseWriter, r *htt
 
 // @Summary    Update a compute allocation change request
 // @Tags       Compute Allocation Change Requests
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Accept     json
 // @Produce    json
 // @Param      id      path    string  true    "Change request ID"
@@ -973,7 +973,7 @@ func (s *Server) updateComputeAllocationChangeRequest(w 
http.ResponseWriter, r *
 
 // @Summary    Delete a compute allocation change request
 // @Tags       Compute Allocation Change Requests
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Param      id      path    string  true    "Change request ID"
 // @Success    204     "No Content"
 // @Failure    404     {object}        object{error=string}
@@ -988,7 +988,7 @@ func (s *Server) deleteComputeAllocationChangeRequest(w 
http.ResponseWriter, r *
 
 // @Summary    List change requests for a compute allocation
 // @Tags       Compute Allocation Change Requests
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "Compute allocation ID"
 // @Success    200     {array} models.ComputeAllocationChangeRequest
@@ -1005,7 +1005,7 @@ func (s *Server) listChangeRequestsForAllocation(w 
http.ResponseWriter, r *http.
 
 // @Summary    List change requests submitted by a user
 // @Tags       Compute Allocation Change Requests
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "User ID"
 // @Success    200     {array} models.ComputeAllocationChangeRequest
@@ -1022,7 +1022,7 @@ func (s *Server) listChangeRequestsByRequester(w 
http.ResponseWriter, r *http.Re
 
 // @Summary    Create a change request event
 // @Tags       Change Request Events
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Accept     json
 // @Produce    json
 // @Param      request body    models.ComputeAllocationChangeRequestEvent      
true    "Event payload"
@@ -1045,7 +1045,7 @@ func (s *Server) 
createComputeAllocationChangeRequestEvent(w http.ResponseWriter
 
 // @Summary    Get a change request event
 // @Tags       Change Request Events
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "Event ID"
 // @Success    200     {object}        
models.ComputeAllocationChangeRequestEvent
@@ -1062,7 +1062,7 @@ func (s *Server) getComputeAllocationChangeRequestEvent(w 
http.ResponseWriter, r
 
 // @Summary    Delete a change request event
 // @Tags       Change Request Events
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Param      id      path    string  true    "Event ID"
 // @Success    204     "No Content"
 // @Failure    404     {object}        object{error=string}
@@ -1077,7 +1077,7 @@ func (s *Server) 
deleteComputeAllocationChangeRequestEvent(w http.ResponseWriter
 
 // @Summary    List events for a change request
 // @Tags       Change Request Events
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "Change request ID"
 // @Success    200     {array} models.ComputeAllocationChangeRequestEvent
@@ -1094,7 +1094,7 @@ func (s *Server) listEventsForChangeRequest(w 
http.ResponseWriter, r *http.Reque
 
 // @Summary    Get the most recent event for a change request
 // @Tags       Change Request Events
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "Change request ID"
 // @Success    200     {object}        
models.ComputeAllocationChangeRequestEvent
@@ -1111,7 +1111,7 @@ func (s *Server) getLatestEventForChangeRequest(w 
http.ResponseWriter, r *http.R
 
 // @Summary    Create a compute allocation membership
 // @Tags       Compute Allocation Memberships
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Accept     json
 // @Produce    json
 // @Param      request body    models.ComputeAllocationMembership      true    
"Membership payload"
@@ -1134,7 +1134,7 @@ func (s *Server) createComputeAllocationMembership(w 
http.ResponseWriter, r *htt
 
 // @Summary    Get a compute allocation membership
 // @Tags       Compute Allocation Memberships
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "Membership ID"
 // @Success    200     {object}        models.ComputeAllocationMembership
@@ -1151,7 +1151,7 @@ func (s *Server) getComputeAllocationMembership(w 
http.ResponseWriter, r *http.R
 
 // @Summary    Update a compute allocation membership
 // @Tags       Compute Allocation Memberships
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Accept     json
 // @Produce    json
 // @Param      id      path    string  true    "Membership ID"
@@ -1177,7 +1177,7 @@ func (s *Server) updateComputeAllocationMembership(w 
http.ResponseWriter, r *htt
 
 // @Summary    Update a membership's status
 // @Tags       Compute Allocation Memberships
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Accept     json
 // @Produce    json
 // @Param      id      path    string  true    "Membership ID"
@@ -1204,7 +1204,7 @@ func (s *Server) updateMembershipStatus(w 
http.ResponseWriter, r *http.Request)
 
 // @Summary    Delete a compute allocation membership
 // @Tags       Compute Allocation Memberships
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Param      id      path    string  true    "Membership ID"
 // @Success    204     "No Content"
 // @Failure    404     {object}        object{error=string}
@@ -1219,7 +1219,7 @@ func (s *Server) deleteComputeAllocationMembership(w 
http.ResponseWriter, r *htt
 
 // @Summary    List members of a compute allocation
 // @Tags       Compute Allocation Memberships
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "Compute allocation ID"
 // @Success    200     {array} AllocationMembershipResponse
@@ -1245,7 +1245,7 @@ func (s *Server) listMembersForAllocation(w 
http.ResponseWriter, r *http.Request
 
 // @Summary    List a user's compute allocation memberships
 // @Tags       Compute Allocation Memberships
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "User ID"
 // @Success    200     {array} models.ComputeAllocationMembership
@@ -1262,7 +1262,7 @@ func (s *Server) listAllocationsForUser(w 
http.ResponseWriter, r *http.Request)
 
 // @Summary    Create a compute allocation usage record
 // @Tags       Compute Allocation Usages
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Accept     json
 // @Produce    json
 // @Param      request body    models.ComputeAllocationUsage   true    "Usage 
payload"
@@ -1285,7 +1285,7 @@ func (s *Server) createComputeAllocationUsage(w 
http.ResponseWriter, r *http.Req
 
 // @Summary    Get a compute allocation usage record
 // @Tags       Compute Allocation Usages
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "Usage ID"
 // @Success    200     {object}        models.ComputeAllocationUsage
@@ -1302,7 +1302,7 @@ func (s *Server) getComputeAllocationUsage(w 
http.ResponseWriter, r *http.Reques
 
 // @Summary    Delete a compute allocation usage record
 // @Tags       Compute Allocation Usages
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Param      id      path    string  true    "Usage ID"
 // @Success    204     "No Content"
 // @Failure    404     {object}        object{error=string}
@@ -1317,7 +1317,7 @@ func (s *Server) deleteComputeAllocationUsage(w 
http.ResponseWriter, r *http.Req
 
 // @Summary    List usages for a compute allocation
 // @Tags       Compute Allocation Usages
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "Compute allocation ID"
 // @Success    200     {array} models.ComputeAllocationUsage
@@ -1334,7 +1334,7 @@ func (s *Server) listUsagesForAllocation(w 
http.ResponseWriter, r *http.Request)
 
 // @Summary    List usages submitted by a user
 // @Tags       Compute Allocation Usages
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "User ID"
 // @Success    200     {array} models.ComputeAllocationUsage
@@ -1351,7 +1351,7 @@ func (s *Server) listUsagesByUser(w http.ResponseWriter, 
r *http.Request) {
 
 // @Summary    Create a membership resource override
 // @Tags       Membership Resource Overrides
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Accept     json
 // @Produce    json
 // @Param      request body    
models.ComputeAllocationMembershipResourceOverride      true    "Override 
payload"
@@ -1374,7 +1374,7 @@ func (s *Server) 
createComputeAllocationMembershipResourceOverride(w http.Respon
 
 // @Summary    Get a membership resource override
 // @Tags       Membership Resource Overrides
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "Override ID"
 // @Success    200     {object}        
models.ComputeAllocationMembershipResourceOverride
@@ -1391,7 +1391,7 @@ func (s *Server) 
getComputeAllocationMembershipResourceOverride(w http.ResponseW
 
 // @Summary    Update a membership resource override
 // @Tags       Membership Resource Overrides
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Accept     json
 // @Produce    json
 // @Param      id      path    string  true    "Override ID"
@@ -1417,7 +1417,7 @@ func (s *Server) 
updateComputeAllocationMembershipResourceOverride(w http.Respon
 
 // @Summary    Delete a membership resource override
 // @Tags       Membership Resource Overrides
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Param      id      path    string  true    "Override ID"
 // @Success    204     "No Content"
 // @Failure    404     {object}        object{error=string}
@@ -1432,7 +1432,7 @@ func (s *Server) 
deleteComputeAllocationMembershipResourceOverride(w http.Respon
 
 // @Summary    List resource overrides for a membership
 // @Tags       Membership Resource Overrides
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "Membership ID"
 // @Success    200     {array} 
models.ComputeAllocationMembershipResourceOverride
@@ -1449,7 +1449,7 @@ func (s *Server) listOverridesForMembership(w 
http.ResponseWriter, r *http.Reque
 
 // @Summary    List membership overrides referencing a resource
 // @Tags       Membership Resource Overrides
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "Compute allocation resource ID"
 // @Success    200     {array} 
models.ComputeAllocationMembershipResourceOverride
@@ -1466,7 +1466,7 @@ func (s *Server) listOverridesForResource(w 
http.ResponseWriter, r *http.Request
 
 // @Summary    Get total SU usage for a compute allocation
 // @Tags       Compute Allocation Usages
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "Compute allocation ID"
 // @Success    200     {object}        AllocationSUTotalResponse
@@ -1486,7 +1486,7 @@ func (s *Server) getTotalSUUsageForAllocation(w 
http.ResponseWriter, r *http.Req
 
 // @Summary    Get total SU usage for a user within a compute allocation
 // @Tags       Compute Allocation Usages
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "Compute allocation ID"
 // @Param      userId  path    string  true    "User ID"
@@ -1514,7 +1514,7 @@ type statusUpdateRequest struct {
 
 // @Summary    Update a user's status
 // @Tags       Users
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Accept     json
 // @Produce    json
 // @Param      id      path    string  true    "User ID"
@@ -1539,7 +1539,7 @@ func (s *Server) updateUserStatus(w http.ResponseWriter, 
r *http.Request) {
 
 // @Summary    Update a project's status
 // @Tags       Projects
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Accept     json
 // @Produce    json
 // @Param      id      path    string  true    "Project ID"
@@ -1564,7 +1564,7 @@ func (s *Server) updateProjectStatus(w 
http.ResponseWriter, r *http.Request) {
 
 // @Summary    Create a user identity
 // @Tags       User Identities
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Accept     json
 // @Produce    json
 // @Param      request body    models.UserIdentity     true    "Identity 
payload"
@@ -1587,7 +1587,7 @@ func (s *Server) createUserIdentity(w 
http.ResponseWriter, r *http.Request) {
 
 // @Summary    Get a user identity
 // @Tags       User Identities
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "Identity ID"
 // @Success    200     {object}        models.UserIdentity
@@ -1604,7 +1604,7 @@ func (s *Server) getUserIdentity(w http.ResponseWriter, r 
*http.Request) {
 
 // @Summary    Get a user identity by source and external ID
 // @Tags       User Identities
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      source  path    string  true    "Identity source"
 // @Param      externalId      path    string  true    "Identity's external ID 
at that source"
@@ -1622,7 +1622,7 @@ func (s *Server) getUserIdentityBySourceAndExternalID(w 
http.ResponseWriter, r *
 
 // @Summary    Get a user identity by its OIDC subject claim
 // @Tags       User Identities
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      oidcSub path    string  true    "OIDC subject claim"
 // @Success    200     {object}        models.UserIdentity
@@ -1639,7 +1639,7 @@ func (s *Server) getUserIdentityByOIDCSub(w 
http.ResponseWriter, r *http.Request
 
 // @Summary    List a user's identities
 // @Tags       User Identities
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "User ID"
 // @Success    200     {array} models.UserIdentity
@@ -1656,7 +1656,7 @@ func (s *Server) listUserIdentitiesForUser(w 
http.ResponseWriter, r *http.Reques
 
 // @Summary    Update a user identity
 // @Tags       User Identities
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Accept     json
 // @Produce    json
 // @Param      id      path    string  true    "Identity ID"
@@ -1681,7 +1681,7 @@ func (s *Server) updateUserIdentity(w 
http.ResponseWriter, r *http.Request) {
 
 // @Summary    Delete a user identity
 // @Tags       User Identities
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Param      id      path    string  true    "Identity ID"
 // @Success    204     "No Content"
 // @Failure    404     {object}        object{error=string}
@@ -1702,7 +1702,7 @@ type mergeUsersRequest struct {
 // @Summary    Merge two users
 // @Description        Merges the retiring user into the surviving user; the 
surviving record is returned.
 // @Tags       Users
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Accept     json
 // @Produce    json
 // @Param      request body    mergeUsersRequest       true    "Merge payload"
@@ -1782,7 +1782,7 @@ func writeServiceError(w http.ResponseWriter, err error) {
 
 // @Summary    List projects (filtered + paginated, PI joined)
 // @Tags       Projects
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      pi_id   query   string  false   "Filter by PI user ID"
 // @Param      status  query   string  false   "Filter by status"
@@ -1814,7 +1814,7 @@ func (s *Server) listProjects(w http.ResponseWriter, r 
*http.Request) {
 
 // @Summary    List project members (one row per distinct user, with 
allocations)
 // @Tags       Projects
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      id      path    string  true    "Project ID"
 // @Success    200     {array} ProjectMemberResponse
@@ -1870,7 +1870,7 @@ func (s *Server) listProjectMembers(w 
http.ResponseWriter, r *http.Request) {
 
 // @Summary    List compute allocations (filtered + paginated)
 // @Tags       Compute Allocations
-// @Security   CustosUserHeader
+// @Security   BearerAuth
 // @Produce    json
 // @Param      project_id      query   string  false   "Filter by project ID"
 // @Param      status  query   string  false   "Filter by status"

Reply via email to