Skip to content

`PUT /v1/orgs/{org}/sso`.

PUT
/v1/orgs/{org}/sso
curl --request PUT \
--url https://api.updawg.net/v1/orgs/example/sso \
--header 'Content-Type: application/json' \
--data '{ "client_id": "example", "client_secret": "example", "default_role": "example", "enabled": true, "enforced": true, "groups_claim": "example", "issuer": "example", "role_mappings": [ { "group": "example", "role": "example" } ] }'
org
required
string

Organization slug.

Media typeapplication/json
object
client_id
required
string
client_secret

Required the first time; absent afterwards keeps the stored one.

string | null
default_role
string | null
enabled
boolean
enforced
boolean
groups_claim

Default groups.

string | null
issuer
required

The provider’s issuer, exactly as its discovery document names it: https://acme.okta.com, https://login.microsoftonline.com/<tenant>/v2.0, https://accounts.google.com.

string
role_mappings
Array<object>
object
group
required

A value of the groups claim, exactly.

string
role
required

admin, operator or viewer.

string
Examplegenerated
{
"client_id": "example",
"client_secret": "example",
"default_role": "example",
"enabled": true,
"enforced": true,
"groups_claim": "example",
"issuer": "example",
"role_mappings": [
{
"group": "example",
"role": "example"
}
]
}

Saved. The issuer’s discovery document was read to check it. Audited as sso.connection_saved.

Media typeapplication/json
object
connection
One of:

Absent until one is saved.

object
client_id
required
string
default_role

For somebody no mapping matches; absent refuses them.

string | null
enabled
required
boolean
enforced
required
boolean
groups_claim
required
string
issuer
required
string
role_mappings
required
Array<object>
object
group
required

A value of the groups claim, exactly.

string
role
required

admin, operator or viewer.

string
updated_at
required
string format: date-time
domains
required
Array<object>
object
domain
required
string
txt_name
required

The TXT record to publish: its name…

string
txt_value
required

…and its value.

string
verified
required
boolean
verified_at
string | null format: date-time
redirect_uri
required

What to register at the provider as the sign-in redirect URI.

string
Examplegenerated
{
"connection": {
"client_id": "example",
"default_role": "example",
"enabled": true,
"enforced": true,
"groups_claim": "example",
"issuer": "example",
"role_mappings": [
{
"group": "example",
"role": "example"
}
],
"updated_at": "2026-04-15T12:00:00Z"
},
"domains": [
{
"domain": "example",
"txt_name": "example",
"txt_value": "example",
"verified": true,
"verified_at": "2026-04-15T12:00:00Z"
}
],
"redirect_uri": "example"
}

An issuer that is not https:// or whose discovery document cannot be read or names another issuer; no client secret on a first save; a mapping to an unknown role or to owner; enforced without enabled or without a verified domain.

Media typeapplication/json
object
detail
string | null
status
required
integer format: int32
title
required
string
type
required
string
Examplegenerated
{
"detail": "example",
"status": 1,
"title": "example",
"type": "example"
}

No session.

Media typeapplication/json
object
detail
string | null
status
required
integer format: int32
title
required
string
type
required
string
Examplegenerated
{
"detail": "example",
"status": 1,
"title": "example",
"type": "example"
}

Not permitted for this role, or no CSRF token. Or the plan does not include single sign-on (Enterprise): plan-required.

Media typeapplication/json
object
detail
string | null
status
required
integer format: int32
title
required
string
type
required
string
Examplegenerated
{
"detail": "example",
"status": 1,
"title": "example",
"type": "example"
}

No such organization, or not yours.

Media typeapplication/json
object
detail
string | null
status
required
integer format: int32
title
required
string
type
required
string
Examplegenerated
{
"detail": "example",
"status": 1,
"title": "example",
"type": "example"
}

Over the organization’s request limit. Retry-After says when to try again; RateLimit-Limit is the burst.

Media typeapplication/json
object
detail
string | null
status
required
integer format: int32
title
required
string
type
required
string
Examplegenerated
{
"detail": "example",
"status": 1,
"title": "example",
"type": "example"
}

The key secrets are encrypted under is not configured.

Media typeapplication/json
object
detail
string | null
status
required
integer format: int32
title
required
string
type
required
string
Examplegenerated
{
"detail": "example",
"status": 1,
"title": "example",
"type": "example"
}