> ## Documentation Index
> Fetch the complete documentation index at: https://docs.base44.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Update app SSO settings

> <Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Sets up or changes the app's own SSO provider, and turns SSO sign-in on for the app. The app's other login methods stay as they are. Turn those off with [Update app](/api-reference/update-app).

The credentials and URLs you send take effect on the published app right away, including when you switch providers, so a switch can change or break live sign-ins before you deploy. The provider `name` and SSO being turned on reach the published app once you [deploy the app](/api-reference/deploy-an-app).

Send only the fields you want to change. A field you leave out keeps its stored value, and an empty string clears it. Sending the masked `client_secret` from [Get app SSO settings](/api-reference/get-app-sso-settings) keeps the stored secret.

Changing `name` to a different provider deletes everything stored for the previous one, so send the new provider's settings in the same request.

After the save, the app needs a `client_id`, a `client_secret`, and either a `discovery_url` or both an `auth_endpoint` and a `token_endpoint`. A request that would leave any of these missing is rejected and nothing is saved.

The `discovery_url` is fetched before saving. If it can't serve a sign-in, the request is rejected. If the check fails in a way that may be temporary, the settings are saved and the response carries a `warning`.

Turning SSO on for an app that doesn't use it yet needs a plan that includes SSO for apps. An app that already uses SSO can keep changing its settings.

The settings are stored as the app's secrets whose names start with `sso_`, and the app's backend functions, if it has any, redeploy to pick them up.

This is limited to 20 requests a minute per caller for each app. Some workspaces have a different limit.

<Note>This endpoint accepts a personal API key belonging to a user with editor access to the app. A read-only key is refused, and workspace API keys are not accepted.</Note>



## OpenAPI

````yaml /developers/references/app-management/app-management-openapi.json put /api/apps/{app_id}/sso/settings
openapi: 3.1.0
info:
  title: Base44 App Management API
  version: 1.0.0
servers:
  - url: https://app.base44.com
security:
  - PersonalAccessTokenAuth: []
paths:
  /api/apps/{app_id}/sso/settings:
    put:
      summary: Update app SSO settings
      description: >-
        <Info>This API is in beta. Endpoints, fields, and behavior may still
        change, so avoid depending on it in production.</Info>


        Sets up or changes the app's own SSO provider, and turns SSO sign-in on
        for the app. The app's other login methods stay as they are. Turn those
        off with [Update app](/api-reference/update-app).


        The credentials and URLs you send take effect on the published app right
        away, including when you switch providers, so a switch can change or
        break live sign-ins before you deploy. The provider `name` and SSO being
        turned on reach the published app once you [deploy the
        app](/api-reference/deploy-an-app).


        Send only the fields you want to change. A field you leave out keeps its
        stored value, and an empty string clears it. Sending the masked
        `client_secret` from [Get app SSO
        settings](/api-reference/get-app-sso-settings) keeps the stored secret.


        Changing `name` to a different provider deletes everything stored for
        the previous one, so send the new provider's settings in the same
        request.


        After the save, the app needs a `client_id`, a `client_secret`, and
        either a `discovery_url` or both an `auth_endpoint` and a
        `token_endpoint`. A request that would leave any of these missing is
        rejected and nothing is saved.


        The `discovery_url` is fetched before saving. If it can't serve a
        sign-in, the request is rejected. If the check fails in a way that may
        be temporary, the settings are saved and the response carries a
        `warning`.


        Turning SSO on for an app that doesn't use it yet needs a plan that
        includes SSO for apps. An app that already uses SSO can keep changing
        its settings.


        The settings are stored as the app's secrets whose names start with
        `sso_`, and the app's backend functions, if it has any, redeploy to pick
        them up.


        This is limited to 20 requests a minute per caller for each app. Some
        workspaces have a different limit.


        <Note>This endpoint accepts a personal API key belonging to a user with
        editor access to the app. A read-only key is refused, and workspace API
        keys are not accepted.</Note>
      operationId: update_app_sso_settings_api_apps__app_id__sso_settings_put
      parameters:
        - name: app_id
          in: path
          required: true
          schema:
            type: string
            description: ID of the app.
            title: App Id
          description: ID of the app.
          example: 6820f3a4e7b91d003c45a1f2
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AppSSOUpdateRequest'
            example:
              name: okta
              client_id: 0oa8f2k1xyzAbCdE5d7
              client_secret: kq3Vt1-9dPzLr0aYbN2x
              okta_domain: acme.okta.com
              discovery_url: https://acme.okta.com/.well-known/openid-configuration
      responses:
        '200':
          description: The settings were saved.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AppSSOUpdateResponse'
        '400':
          description: >-
            No provider `name` was sent and the app has none, the settings would
            be incomplete, a URL isn't an absolute public `http` or `https` URL,
            or the `discovery_url` can't serve a sign-in.
        '401':
          description: Missing or invalid credentials.
        '402':
          description: >-
            You're turning SSO on, and the app's workspace plan doesn't include
            SSO for apps.
        '403':
          description: >-
            You don't have editor access to this app, your API key is read-only,
            or you used a workspace API key.
        '404':
          description: App not found.
        '422':
          description: The body isn't a JSON object, or a field isn't a string.
        '429':
          description: >-
            Too many SSO settings updates for this app from you in the last
            minute.
components:
  schemas:
    AppSSOUpdateRequest:
      properties:
        name:
          anyOf:
            - type: string
            - type: 'null'
          title: Name
          description: >-
            Name of the SSO provider. Use `google`, `microsoft`, `github`, or
            `okta` for those providers, or a name of your choice for any other
            OpenID Connect or OAuth provider. Required unless the app already
            has a provider.
          example: okta
        client_id:
          anyOf:
            - type: string
            - type: 'null'
          title: Client Id
          description: OAuth client ID from the identity provider.
          example: 0oa8f2k1xyzAbCdE5d7
        client_secret:
          anyOf:
            - type: string
            - type: 'null'
          title: Client Secret
          description: >-
            OAuth client secret from the identity provider. Leave it out to keep
            the stored one.
          example: kq3Vt1-9dPzLr0aYbN2x
        discovery_url:
          anyOf:
            - type: string
            - type: 'null'
          title: Discovery Url
          description: >-
            OpenID Connect discovery URL. It must be an absolute `http` or
            `https` URL on a public address.
          example: https://acme.okta.com/.well-known/openid-configuration
        scope:
          anyOf:
            - type: string
            - type: 'null'
          title: Scope
          description: Scopes to request at sign-in, separated by spaces.
          example: openid email profile
        auth_endpoint:
          anyOf:
            - type: string
            - type: 'null'
          title: Auth Endpoint
          description: Authorization endpoint, for a provider without a discovery URL.
          example: https://github.com/login/oauth/authorize
        token_endpoint:
          anyOf:
            - type: string
            - type: 'null'
          title: Token Endpoint
          description: Token endpoint, for a provider without a discovery URL.
          example: https://github.com/login/oauth/access_token
        userinfo_endpoint:
          anyOf:
            - type: string
            - type: 'null'
          title: Userinfo Endpoint
          description: User info endpoint, for a provider without a discovery URL.
          example: https://api.github.com/user
        jwks_uri:
          anyOf:
            - type: string
            - type: 'null'
          title: Jwks Uri
          description: URL of the provider's signing keys, for a custom provider.
          example: https://idp.acme.com/oauth2/keys
        tenant_id:
          anyOf:
            - type: string
            - type: 'null'
          title: Tenant Id
          description: Microsoft Entra tenant ID, for the `microsoft` provider.
          example: organizations
        okta_domain:
          anyOf:
            - type: string
            - type: 'null'
          title: Okta Domain
          description: Okta domain, for the `okta` provider.
          example: acme.okta.com
      type: object
      title: AppSSOUpdateRequest
      description: The app's SSO provider and the settings to change, sent together.
    AppSSOUpdateResponse:
      properties:
        status:
          type: string
          title: Status
          description: Always `success`.
          example: success
        auth_config:
          additionalProperties: true
          type: object
          title: Auth Config
          description: >-
            The app's sign-in settings as saved, with `sso_provider_name` set to
            the provider and `enable_sso_login` set to `true`.
          example:
            enable_apple_login: false
            enable_facebook_login: false
            enable_google_login: true
            enable_microsoft_login: false
            enable_sso_login: true
            enable_username_password: false
            sso_provider_name: okta
        warning:
          anyOf:
            - type: string
            - type: 'null'
          title: Warning
          description: >-
            Why the discovery URL couldn't be checked, present only when that
            happened. The settings are saved, but SSO sign-in fails while the
            problem lasts.
          example: >-
            The Discovery URL could not be verified because it did not respond
            in time. SSO login will fail while that persists.
      type: object
      required:
        - status
        - auth_config
      title: AppSSOUpdateResponse
      description: The result of saving the app's SSO provider settings.
  securitySchemes:
    PersonalAccessTokenAuth:
      type: http
      scheme: bearer
      description: 'Personal access token, sent as `Authorization: Bearer <token>`.'

````