Single sign-on
Set the organization's identity provider
Org owners only. Creates or replaces the organization’s SAML or OIDC identity provider; send the full settings each time, including the OIDC client secret. People signing in through it join the organization with the default role, only for emails on the organization’s verified domains. Roles are capped below organization owner. IdP-initiated SAML is not supported.
PUT
/
api
/
v1
/
organizations
/
{org_id}
/
sso
/
identity-provider
Set the organization's identity provider
curl --request PUT \
--url https://api.costgraph.ai/api/v1/organizations/{org_id}/sso/identity-provider \
--header 'Authorization: <api-key>' \
--header 'Content-Type: application/json' \
--data '
{
"group_role_mappings": {},
"groups_attribute": "<string>",
"metadata_url": "<string>",
"metadata_xml": "<string>",
"oidc_client_id": "<string>",
"oidc_client_secret": "<string>",
"oidc_issuer": "<string>"
}
'import requests
url = "https://api.costgraph.ai/api/v1/organizations/{org_id}/sso/identity-provider"
payload = {
"group_role_mappings": {},
"groups_attribute": "<string>",
"metadata_url": "<string>",
"metadata_xml": "<string>",
"oidc_client_id": "<string>",
"oidc_client_secret": "<string>",
"oidc_issuer": "<string>"
}
headers = {
"Authorization": "<api-key>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {Authorization: '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
group_role_mappings: {},
groups_attribute: '<string>',
metadata_url: '<string>',
metadata_xml: '<string>',
oidc_client_id: '<string>',
oidc_client_secret: '<string>',
oidc_issuer: '<string>'
})
};
fetch('https://api.costgraph.ai/api/v1/organizations/{org_id}/sso/identity-provider', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.costgraph.ai/api/v1/organizations/{org_id}/sso/identity-provider",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'group_role_mappings' => [
],
'groups_attribute' => '<string>',
'metadata_url' => '<string>',
'metadata_xml' => '<string>',
'oidc_client_id' => '<string>',
'oidc_client_secret' => '<string>',
'oidc_issuer' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: <api-key>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.costgraph.ai/api/v1/organizations/{org_id}/sso/identity-provider"
payload := strings.NewReader("{\n \"group_role_mappings\": {},\n \"groups_attribute\": \"<string>\",\n \"metadata_url\": \"<string>\",\n \"metadata_xml\": \"<string>\",\n \"oidc_client_id\": \"<string>\",\n \"oidc_client_secret\": \"<string>\",\n \"oidc_issuer\": \"<string>\"\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Authorization", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://api.costgraph.ai/api/v1/organizations/{org_id}/sso/identity-provider")
.header("Authorization", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"group_role_mappings\": {},\n \"groups_attribute\": \"<string>\",\n \"metadata_url\": \"<string>\",\n \"metadata_xml\": \"<string>\",\n \"oidc_client_id\": \"<string>\",\n \"oidc_client_secret\": \"<string>\",\n \"oidc_issuer\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.costgraph.ai/api/v1/organizations/{org_id}/sso/identity-provider")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Authorization"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"group_role_mappings\": {},\n \"groups_attribute\": \"<string>\",\n \"metadata_url\": \"<string>\",\n \"metadata_xml\": \"<string>\",\n \"oidc_client_id\": \"<string>\",\n \"oidc_client_secret\": \"<string>\",\n \"oidc_issuer\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"message": "some message",
"status": "success",
"data": {
"created_at": "<string>",
"default_role": "<string>",
"enforce_sso": true,
"group_role_mappings": {},
"has_metadata_xml": true,
"id": "<string>",
"provider_name": "<string>",
"service_provider": {
"acs_url": "<string>",
"entity_id": "<string>",
"oidc_redirect_uri": "<string>",
"sign_in_client_id": "<string>"
},
"type": "saml",
"updated_at": "<string>",
"groups_attribute": "<string>",
"metadata_url": "<string>",
"oidc_client_id": "<string>",
"oidc_issuer": "<string>"
}
}{
"message": "some message",
"status": "error"
}{
"message": "some message",
"status": "error"
}{
"message": "some message",
"status": "error"
}{
"message": "some message",
"status": "error"
}{
"message": "some message",
"status": "error"
}Authorizations
Enter "Bearer {token}"
Path Parameters
Organization ID
Body
application/json
Identity provider settings
Available options:
member, admin, billing_admin Show child attributes
Show child attributes
Available options:
saml, oidc Maximum string length:
256Maximum string length:
2048Maximum string length:
131072Maximum string length:
256Maximum string length:
256Maximum string length:
2048Was this page helpful?
⌘I
Set the organization's identity provider
curl --request PUT \
--url https://api.costgraph.ai/api/v1/organizations/{org_id}/sso/identity-provider \
--header 'Authorization: <api-key>' \
--header 'Content-Type: application/json' \
--data '
{
"group_role_mappings": {},
"groups_attribute": "<string>",
"metadata_url": "<string>",
"metadata_xml": "<string>",
"oidc_client_id": "<string>",
"oidc_client_secret": "<string>",
"oidc_issuer": "<string>"
}
'import requests
url = "https://api.costgraph.ai/api/v1/organizations/{org_id}/sso/identity-provider"
payload = {
"group_role_mappings": {},
"groups_attribute": "<string>",
"metadata_url": "<string>",
"metadata_xml": "<string>",
"oidc_client_id": "<string>",
"oidc_client_secret": "<string>",
"oidc_issuer": "<string>"
}
headers = {
"Authorization": "<api-key>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {Authorization: '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
group_role_mappings: {},
groups_attribute: '<string>',
metadata_url: '<string>',
metadata_xml: '<string>',
oidc_client_id: '<string>',
oidc_client_secret: '<string>',
oidc_issuer: '<string>'
})
};
fetch('https://api.costgraph.ai/api/v1/organizations/{org_id}/sso/identity-provider', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.costgraph.ai/api/v1/organizations/{org_id}/sso/identity-provider",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'group_role_mappings' => [
],
'groups_attribute' => '<string>',
'metadata_url' => '<string>',
'metadata_xml' => '<string>',
'oidc_client_id' => '<string>',
'oidc_client_secret' => '<string>',
'oidc_issuer' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: <api-key>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.costgraph.ai/api/v1/organizations/{org_id}/sso/identity-provider"
payload := strings.NewReader("{\n \"group_role_mappings\": {},\n \"groups_attribute\": \"<string>\",\n \"metadata_url\": \"<string>\",\n \"metadata_xml\": \"<string>\",\n \"oidc_client_id\": \"<string>\",\n \"oidc_client_secret\": \"<string>\",\n \"oidc_issuer\": \"<string>\"\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Authorization", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://api.costgraph.ai/api/v1/organizations/{org_id}/sso/identity-provider")
.header("Authorization", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"group_role_mappings\": {},\n \"groups_attribute\": \"<string>\",\n \"metadata_url\": \"<string>\",\n \"metadata_xml\": \"<string>\",\n \"oidc_client_id\": \"<string>\",\n \"oidc_client_secret\": \"<string>\",\n \"oidc_issuer\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.costgraph.ai/api/v1/organizations/{org_id}/sso/identity-provider")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Authorization"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"group_role_mappings\": {},\n \"groups_attribute\": \"<string>\",\n \"metadata_url\": \"<string>\",\n \"metadata_xml\": \"<string>\",\n \"oidc_client_id\": \"<string>\",\n \"oidc_client_secret\": \"<string>\",\n \"oidc_issuer\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"message": "some message",
"status": "success",
"data": {
"created_at": "<string>",
"default_role": "<string>",
"enforce_sso": true,
"group_role_mappings": {},
"has_metadata_xml": true,
"id": "<string>",
"provider_name": "<string>",
"service_provider": {
"acs_url": "<string>",
"entity_id": "<string>",
"oidc_redirect_uri": "<string>",
"sign_in_client_id": "<string>"
},
"type": "saml",
"updated_at": "<string>",
"groups_attribute": "<string>",
"metadata_url": "<string>",
"oidc_client_id": "<string>",
"oidc_issuer": "<string>"
}
}{
"message": "some message",
"status": "error"
}{
"message": "some message",
"status": "error"
}{
"message": "some message",
"status": "error"
}{
"message": "some message",
"status": "error"
}{
"message": "some message",
"status": "error"
}