Skip to content

Set SSO OIDC configuration for specific application in the organization

Request

Set SSO OIDC configuration for specific application in the organization. Creates a new configuration if it does not exist, or updates an existing one.

Required permissions: organizations:edit, orgs:edit.

Security
AdminAccessToken
Path
organization_idstringrequired

ID of the organization

app_idstringrequired

ID of the application

Bodyapplication/jsonrequired
client_idstring, <= 150 charactersrequired

The client ID of the OIDC provider

client_secretstring, <= 150 charactersrequired

The client secret of the OIDC provider

issuer_urlstringrequired

The issuer URL of the OIDC provider

email_attrstring

The email attribute on the decoded token to be used as the user email

redirect_uristring

Redirect URI for backend-driven flows

identifier_typestring

The identifier type used to look up the user during authentication (e.g. email, phone_number, username)

namestringrequired

Name of the SSO configuration

enabledboolean

Indicates whether the SSO configuration is enabled

Default:true
sso_signup_enabledboolean

Indicates whether public signup through SSO is allowed

group_role_mappingobject

Group-to-role mapping configuration

curl -i -X PUT \
  'https://api.sbx.transmitsecurity.io/cis/v1/organizations/{organization_id}/applications/{app_id}/sso/oidc/set' \
  -H 'Authorization: Bearer <YOUR_TOKEN_HERE>' \
  -H 'Content-Type: application/json' \
  -d '{
    "client_id": "string",
    "client_secret": "string",
    "issuer_url": "string",
    "email_attr": "string",
    "redirect_uri": "string",
    "identifier_type": "string",
    "name": "string",
    "enabled": true,
    "sso_signup_enabled": true,
    "group_role_mapping": {
      "enabled": false,
      "group_claim_name": "groups",
      "mappings": [
        {
          "idp_group_name": "string",
          "role_ids": [
            "string"
          ]
        }
      ],
      "default_role_ids": [
        "string"
      ]
    }
  }'

Responses

Bodyapplication/json
resultobjectrequired
Response
{ "result": {} }