Skip to main content
PUT
Update app SSO settings

Authorizations

Authorization
string
header
required

Personal access token, sent as Authorization: Bearer <token>.

Path Parameters

app_id
string
required

ID of the app.

Body

application/json

The app's SSO provider and the settings to change, sent together.

name
string | null

Name of the SSO provider. Use google, microsoft, github, or okta for those providers, or a name of your choice for any other OpenID Connect or OAuth provider. Required unless the app already has a provider.

Example:

"okta"

client_id
string | null

OAuth client ID from the identity provider.

Example:

"0oa8f2k1xyzAbCdE5d7"

client_secret
string | null

OAuth client secret from the identity provider. Leave it out to keep the stored one.

Example:

"kq3Vt1-9dPzLr0aYbN2x"

discovery_url
string | null

OpenID Connect discovery URL. It must be an absolute http or https URL on a public address.

Example:

"https://acme.okta.com/.well-known/openid-configuration"

scope
string | null

Scopes to request at sign-in, separated by spaces.

Example:

"openid email profile"

auth_endpoint
string | null

Authorization endpoint, for a provider without a discovery URL.

Example:

"https://github.com/login/oauth/authorize"

token_endpoint
string | null

Token endpoint, for a provider without a discovery URL.

Example:

"https://github.com/login/oauth/access_token"

userinfo_endpoint
string | null

User info endpoint, for a provider without a discovery URL.

Example:

"https://api.github.com/user"

jwks_uri
string | null

URL of the provider's signing keys, for a custom provider.

Example:

"https://idp.acme.com/oauth2/keys"

tenant_id
string | null

Microsoft Entra tenant ID, for the microsoft provider.

Example:

"organizations"

okta_domain
string | null

Okta domain, for the okta provider.

Example:

"acme.okta.com"

Response

The settings were saved.

The result of saving the app's SSO provider settings.

status
string
required

Always success.

Example:

"success"

auth_config
Auth Config · object
required

The app's sign-in settings as saved, with sso_provider_name set to the provider and enable_sso_login set to true.

Example:
warning
string | null

Why the discovery URL couldn't be checked, present only when that happened. The settings are saved, but SSO sign-in fails while the problem lasts.

Example:

"The Discovery URL could not be verified because it did not respond in time. SSO login will fail while that persists."