`PUT /v1/orgs/{org}/sso`.
const url = 'https://api.updawg.net/v1/orgs/example/sso';const options = { method: 'PUT', headers: {'Content-Type': 'application/json'}, body: '{"client_id":"example","client_secret":"example","default_role":"example","enabled":true,"enforced":true,"groups_claim":"example","issuer":"example","role_mappings":[{"group":"example","role":"example"}]}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request PUT \ --url https://api.updawg.net/v1/orgs/example/sso \ --header 'Content-Type: application/json' \ --data '{ "client_id": "example", "client_secret": "example", "default_role": "example", "enabled": true, "enforced": true, "groups_claim": "example", "issuer": "example", "role_mappings": [ { "group": "example", "role": "example" } ] }'Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”Organization slug.
Request Bodyrequired
Section titled “Request Bodyrequired”object
Required the first time; absent afterwards keeps the stored one.
Default groups.
The provider’s issuer, exactly as its discovery document names it:
https://acme.okta.com, https://login.microsoftonline.com/<tenant>/v2.0,
https://accounts.google.com.
object
A value of the groups claim, exactly.
admin, operator or viewer.
Examplegenerated
{ "client_id": "example", "client_secret": "example", "default_role": "example", "enabled": true, "enforced": true, "groups_claim": "example", "issuer": "example", "role_mappings": [ { "group": "example", "role": "example" } ]}Responses
Section titled “Responses”Saved. The issuer’s discovery document was read to check it. Audited as sso.connection_saved.
object
Absent until one is saved.
object
For somebody no mapping matches; absent refuses them.
object
A value of the groups claim, exactly.
admin, operator or viewer.
object
The TXT record to publish: its name…
…and its value.
What to register at the provider as the sign-in redirect URI.
Examplegenerated
{ "connection": { "client_id": "example", "default_role": "example", "enabled": true, "enforced": true, "groups_claim": "example", "issuer": "example", "role_mappings": [ { "group": "example", "role": "example" } ], "updated_at": "2026-04-15T12:00:00Z" }, "domains": [ { "domain": "example", "txt_name": "example", "txt_value": "example", "verified": true, "verified_at": "2026-04-15T12:00:00Z" } ], "redirect_uri": "example"}An issuer that is not https:// or whose discovery document cannot be read or names another issuer; no client secret on a first save; a mapping to an unknown role or to owner; enforced without enabled or without a verified domain.
object
Examplegenerated
{ "detail": "example", "status": 1, "title": "example", "type": "example"}No session.
object
Examplegenerated
{ "detail": "example", "status": 1, "title": "example", "type": "example"}Not permitted for this role, or no CSRF token. Or the plan does not include single sign-on (Enterprise): plan-required.
object
Examplegenerated
{ "detail": "example", "status": 1, "title": "example", "type": "example"}No such organization, or not yours.
object
Examplegenerated
{ "detail": "example", "status": 1, "title": "example", "type": "example"}Over the organization’s request limit. Retry-After says when to try again; RateLimit-Limit is the burst.
object
Examplegenerated
{ "detail": "example", "status": 1, "title": "example", "type": "example"}The key secrets are encrypted under is not configured.
object
Examplegenerated
{ "detail": "example", "status": 1, "title": "example", "type": "example"}