> ## Documentation Index
> Fetch the complete documentation index at: https://docs.base44.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get app SSO settings

> <Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Returns the app's own SSO provider and its settings. This is the provider set up for this app, not the workspace's SSO.

The client secret is never returned. `client_secret` reads as a fixed mask when one is stored. Each provider only returns the settings it uses, so the rest read as empty strings.

Change them with [Update app SSO settings](/api-reference/update-app-sso-settings).

This is limited to 60 requests a minute per caller for each app. Some workspaces have a different limit.

<Note>This endpoint accepts a personal API key belonging to a user with editor access to the app. A read-only key is refused, and workspace API keys are not accepted.</Note>



## OpenAPI

````yaml /developers/references/app-management/app-management-openapi.json get /api/apps/{app_id}/sso/settings
openapi: 3.1.0
info:
  title: Base44 App Management API
  version: 1.0.0
servers:
  - url: https://app.base44.com
security:
  - PersonalAccessTokenAuth: []
paths:
  /api/apps/{app_id}/sso/settings:
    get:
      summary: Get app SSO settings
      description: >-
        <Info>This API is in beta. Endpoints, fields, and behavior may still
        change, so avoid depending on it in production.</Info>


        Returns the app's own SSO provider and its settings. This is the
        provider set up for this app, not the workspace's SSO.


        The client secret is never returned. `client_secret` reads as a fixed
        mask when one is stored. Each provider only returns the settings it
        uses, so the rest read as empty strings.


        Change them with [Update app SSO
        settings](/api-reference/update-app-sso-settings).


        This is limited to 60 requests a minute per caller for each app. Some
        workspaces have a different limit.


        <Note>This endpoint accepts a personal API key belonging to a user with
        editor access to the app. A read-only key is refused, and workspace API
        keys are not accepted.</Note>
      operationId: get_app_sso_settings_api_apps__app_id__sso_settings_get
      parameters:
        - name: app_id
          in: path
          required: true
          schema:
            type: string
            description: ID of the app.
            title: App Id
          description: ID of the app.
          example: 6820f3a4e7b91d003c45a1f2
      responses:
        '200':
          description: The app's SSO provider settings.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AppSSOSettingsResponse'
        '401':
          description: Missing or invalid credentials.
        '403':
          description: >-
            You don't have editor access to this app, your API key is read-only,
            or you used a workspace API key.
        '404':
          description: App not found.
        '429':
          description: >-
            Too many requests for this app's SSO settings from you in the last
            minute.
components:
  schemas:
    AppSSOSettingsResponse:
      properties:
        settings:
          $ref: '#/components/schemas/AppSSOSettings'
          description: The provider and its non-secret settings.
      type: object
      required:
        - settings
      title: AppSSOSettingsResponse
      description: The app's own SSO provider settings, with the client secret masked.
    AppSSOSettings:
      properties:
        name:
          type: string
          title: Name
          description: >-
            Name of the app's SSO provider, or an empty string when none is set.
            The builder uses `google`, `microsoft`, `github`, or `okta` for
            those providers. Any other name is a custom OpenID Connect or OAuth
            provider.
          example: okta
        client_id:
          type: string
          title: Client Id
          description: >-
            OAuth client ID from the identity provider, or an empty string when
            none is stored.
          example: 0oa8f2k1xyzAbCdE5d7
        client_secret:
          type: string
          title: Client Secret
          description: >-
            Reads `XXXXXXXXXXXXXXXXXXXX` when a client secret is stored, and an
            empty string when none is. The secret itself is never returned.
          example: XXXXXXXXXXXXXXXXXXXX
        discovery_url:
          type: string
          title: Discovery Url
          description: >-
            OpenID Connect discovery URL, or an empty string when none is stored
            or the provider doesn't use one.
          example: https://acme.okta.com/.well-known/openid-configuration
        scope:
          type: string
          title: Scope
          description: >-
            Scopes requested at sign-in, separated by spaces. Reads `openid
            email profile` when none is stored or the provider doesn't use one.
          example: openid email profile
        auth_endpoint:
          type: string
          title: Auth Endpoint
          description: >-
            Authorization endpoint for a provider without a discovery URL, or an
            empty string when none is stored or the provider doesn't use one.
          example: ''
        token_endpoint:
          type: string
          title: Token Endpoint
          description: >-
            Token endpoint for a provider without a discovery URL, or an empty
            string when none is stored or the provider doesn't use one.
          example: ''
        userinfo_endpoint:
          type: string
          title: Userinfo Endpoint
          description: >-
            User info endpoint for a provider without a discovery URL, or an
            empty string when none is stored or the provider doesn't use one.
          example: ''
        jwks_uri:
          type: string
          title: Jwks Uri
          description: >-
            URL of the provider's signing keys, for a custom provider. The value
            is an empty string when none is stored or the provider doesn't use
            one.
          example: ''
        tenant_id:
          type: string
          title: Tenant Id
          description: >-
            Microsoft Entra tenant ID, or an empty string when none is stored or
            the provider isn't `microsoft`.
          example: ''
        okta_domain:
          type: string
          title: Okta Domain
          description: >-
            Okta domain, or an empty string when none is stored or the provider
            isn't `okta`.
          example: acme.okta.com
      type: object
      required:
        - name
        - client_id
        - client_secret
        - discovery_url
        - scope
        - auth_endpoint
        - token_endpoint
        - userinfo_endpoint
        - jwks_uri
        - tenant_id
        - okta_domain
      title: AppSSOSettings
  securitySchemes:
    PersonalAccessTokenAuth:
      type: http
      scheme: bearer
      description: 'Personal access token, sent as `Authorization: Bearer <token>`.'

````