curl --request PUT \
--url https://app.base44.com/api/apps/{app_id}/sso/settings \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"name": "okta",
"client_id": "0oa8f2k1xyzAbCdE5d7",
"client_secret": "kq3Vt1-9dPzLr0aYbN2x",
"okta_domain": "acme.okta.com",
"discovery_url": "https://acme.okta.com/.well-known/openid-configuration"
}
'import requests
url = "https://app.base44.com/api/apps/{app_id}/sso/settings"
payload = {
"name": "okta",
"client_id": "0oa8f2k1xyzAbCdE5d7",
"client_secret": "kq3Vt1-9dPzLr0aYbN2x",
"okta_domain": "acme.okta.com",
"discovery_url": "https://acme.okta.com/.well-known/openid-configuration"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: 'okta',
client_id: '0oa8f2k1xyzAbCdE5d7',
client_secret: 'kq3Vt1-9dPzLr0aYbN2x',
okta_domain: 'acme.okta.com',
discovery_url: 'https://acme.okta.com/.well-known/openid-configuration'
})
};
fetch('https://app.base44.com/api/apps/{app_id}/sso/settings', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.base44.com/api/apps/{app_id}/sso/settings",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'name' => 'okta',
'client_id' => '0oa8f2k1xyzAbCdE5d7',
'client_secret' => 'kq3Vt1-9dPzLr0aYbN2x',
'okta_domain' => 'acme.okta.com',
'discovery_url' => 'https://acme.okta.com/.well-known/openid-configuration'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.base44.com/api/apps/{app_id}/sso/settings"
payload := strings.NewReader("{\n \"name\": \"okta\",\n \"client_id\": \"0oa8f2k1xyzAbCdE5d7\",\n \"client_secret\": \"kq3Vt1-9dPzLr0aYbN2x\",\n \"okta_domain\": \"acme.okta.com\",\n \"discovery_url\": \"https://acme.okta.com/.well-known/openid-configuration\"\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://app.base44.com/api/apps/{app_id}/sso/settings")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"okta\",\n \"client_id\": \"0oa8f2k1xyzAbCdE5d7\",\n \"client_secret\": \"kq3Vt1-9dPzLr0aYbN2x\",\n \"okta_domain\": \"acme.okta.com\",\n \"discovery_url\": \"https://acme.okta.com/.well-known/openid-configuration\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.base44.com/api/apps/{app_id}/sso/settings")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"okta\",\n \"client_id\": \"0oa8f2k1xyzAbCdE5d7\",\n \"client_secret\": \"kq3Vt1-9dPzLr0aYbN2x\",\n \"okta_domain\": \"acme.okta.com\",\n \"discovery_url\": \"https://acme.okta.com/.well-known/openid-configuration\"\n}"
response = http.request(request)
puts response.read_body{
"status": "success",
"auth_config": {
"enable_apple_login": false,
"enable_facebook_login": false,
"enable_google_login": true,
"enable_microsoft_login": false,
"enable_sso_login": true,
"enable_username_password": false,
"sso_provider_name": "okta"
},
"warning": "The Discovery URL could not be verified because it did not respond in time. SSO login will fail while that persists."
}Update app SSO settings
Sets up or changes the app’s own SSO provider, and turns SSO sign-in on for the app. The app’s other login methods stay as they are. Turn those off with Update app.
The credentials and URLs you send take effect on the published app right away, including when you switch providers, so a switch can change or break live sign-ins before you deploy. The provider name and SSO being turned on reach the published app once you deploy the app.
Send only the fields you want to change. A field you leave out keeps its stored value, and an empty string clears it. Sending the masked client_secret from Get app SSO settings keeps the stored secret.
Changing name to a different provider deletes everything stored for the previous one, so send the new provider’s settings in the same request.
After the save, the app needs a client_id, a client_secret, and either a discovery_url or both an auth_endpoint and a token_endpoint. A request that would leave any of these missing is rejected and nothing is saved.
The discovery_url is fetched before saving. If it can’t serve a sign-in, the request is rejected. If the check fails in a way that may be temporary, the settings are saved and the response carries a warning.
Turning SSO on for an app that doesn’t use it yet needs a plan that includes SSO for apps. An app that already uses SSO can keep changing its settings.
The settings are stored as the app’s secrets whose names start with sso_, and the app’s backend functions, if it has any, redeploy to pick them up.
This is limited to 20 requests a minute per caller for each app. Some workspaces have a different limit.
curl --request PUT \
--url https://app.base44.com/api/apps/{app_id}/sso/settings \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"name": "okta",
"client_id": "0oa8f2k1xyzAbCdE5d7",
"client_secret": "kq3Vt1-9dPzLr0aYbN2x",
"okta_domain": "acme.okta.com",
"discovery_url": "https://acme.okta.com/.well-known/openid-configuration"
}
'import requests
url = "https://app.base44.com/api/apps/{app_id}/sso/settings"
payload = {
"name": "okta",
"client_id": "0oa8f2k1xyzAbCdE5d7",
"client_secret": "kq3Vt1-9dPzLr0aYbN2x",
"okta_domain": "acme.okta.com",
"discovery_url": "https://acme.okta.com/.well-known/openid-configuration"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: 'okta',
client_id: '0oa8f2k1xyzAbCdE5d7',
client_secret: 'kq3Vt1-9dPzLr0aYbN2x',
okta_domain: 'acme.okta.com',
discovery_url: 'https://acme.okta.com/.well-known/openid-configuration'
})
};
fetch('https://app.base44.com/api/apps/{app_id}/sso/settings', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.base44.com/api/apps/{app_id}/sso/settings",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'name' => 'okta',
'client_id' => '0oa8f2k1xyzAbCdE5d7',
'client_secret' => 'kq3Vt1-9dPzLr0aYbN2x',
'okta_domain' => 'acme.okta.com',
'discovery_url' => 'https://acme.okta.com/.well-known/openid-configuration'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.base44.com/api/apps/{app_id}/sso/settings"
payload := strings.NewReader("{\n \"name\": \"okta\",\n \"client_id\": \"0oa8f2k1xyzAbCdE5d7\",\n \"client_secret\": \"kq3Vt1-9dPzLr0aYbN2x\",\n \"okta_domain\": \"acme.okta.com\",\n \"discovery_url\": \"https://acme.okta.com/.well-known/openid-configuration\"\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://app.base44.com/api/apps/{app_id}/sso/settings")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"okta\",\n \"client_id\": \"0oa8f2k1xyzAbCdE5d7\",\n \"client_secret\": \"kq3Vt1-9dPzLr0aYbN2x\",\n \"okta_domain\": \"acme.okta.com\",\n \"discovery_url\": \"https://acme.okta.com/.well-known/openid-configuration\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.base44.com/api/apps/{app_id}/sso/settings")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"okta\",\n \"client_id\": \"0oa8f2k1xyzAbCdE5d7\",\n \"client_secret\": \"kq3Vt1-9dPzLr0aYbN2x\",\n \"okta_domain\": \"acme.okta.com\",\n \"discovery_url\": \"https://acme.okta.com/.well-known/openid-configuration\"\n}"
response = http.request(request)
puts response.read_body{
"status": "success",
"auth_config": {
"enable_apple_login": false,
"enable_facebook_login": false,
"enable_google_login": true,
"enable_microsoft_login": false,
"enable_sso_login": true,
"enable_username_password": false,
"sso_provider_name": "okta"
},
"warning": "The Discovery URL could not be verified because it did not respond in time. SSO login will fail while that persists."
}Authorizations
Personal access token, sent as Authorization: Bearer <token>.
Path Parameters
ID of the app.
Body
The app's SSO provider and the settings to change, sent together.
Name of the SSO provider. Use google, microsoft, github, or okta for those providers, or a name of your choice for any other OpenID Connect or OAuth provider. Required unless the app already has a provider.
"okta"
OAuth client ID from the identity provider.
"0oa8f2k1xyzAbCdE5d7"
OAuth client secret from the identity provider. Leave it out to keep the stored one.
"kq3Vt1-9dPzLr0aYbN2x"
OpenID Connect discovery URL. It must be an absolute http or https URL on a public address.
"https://acme.okta.com/.well-known/openid-configuration"
Scopes to request at sign-in, separated by spaces.
"openid email profile"
Authorization endpoint, for a provider without a discovery URL.
"https://github.com/login/oauth/authorize"
Token endpoint, for a provider without a discovery URL.
"https://github.com/login/oauth/access_token"
User info endpoint, for a provider without a discovery URL.
"https://api.github.com/user"
URL of the provider's signing keys, for a custom provider.
"https://idp.acme.com/oauth2/keys"
Microsoft Entra tenant ID, for the microsoft provider.
"organizations"
Okta domain, for the okta provider.
"acme.okta.com"
Response
The settings were saved.
The result of saving the app's SSO provider settings.
Always success.
"success"
The app's sign-in settings as saved, with sso_provider_name set to the provider and enable_sso_login set to true.
{
"enable_apple_login": false,
"enable_facebook_login": false,
"enable_google_login": true,
"enable_microsoft_login": false,
"enable_sso_login": true,
"enable_username_password": false,
"sso_provider_name": "okta"
}
Why the discovery URL couldn't be checked, present only when that happened. The settings are saved, but SSO sign-in fails while the problem lasts.
"The Discovery URL could not be verified because it did not respond in time. SSO login will fail while that persists."
Was this page helpful?