> ## Documentation Index
> Fetch the complete documentation index at: https://docs.costgraph.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Set the organization's identity provider

> Org owners only. Creates or replaces the organization's SAML or OIDC identity provider; send the full settings each time, including the OIDC client secret. People signing in through it join the organization with the default role, only for emails on the organization's verified domains. Roles are capped below organization owner. IdP-initiated SAML is not supported.



## OpenAPI

````yaml /api-reference/costgraph/openapi.json put /api/v1/organizations/{org_id}/sso/identity-provider
openapi: 3.0.0
info:
  description: Read and manage your CostGraph organization, spend, alerts, and settings.
  title: CostGraph API
  contact: {}
  version: '1.0'
servers:
  - url: https://api.costgraph.ai
security: []
tags:
  - name: ai
    x-group: AI
  - name: ai-serving
    x-group: AI serving
  - name: anomalies
    x-group: Anomalies
  - name: auth
    x-group: Auth
  - name: billing
    x-group: Billing
  - name: billing-export
    x-group: Billing export
  - name: budgets
    x-group: Budgets
  - name: ci
    x-group: CI
  - name: compute-recommendations
    x-group: Compute recommendations
  - name: config
    x-group: Config
  - name: cost
    x-group: Cost
  - name: gpus
    x-group: GPUs
  - name: graphai
    x-group: Graph AI
  - name: infracost
    x-group: Infracost
  - name: integrations
    x-group: Integrations
  - name: invitations
    x-group: Invitations
  - name: kubernetes-clusters
    x-group: Kubernetes clusters
  - name: marketplace
    x-group: Marketplace
  - name: network-requests
    x-group: Network requests
  - name: notifications
    x-group: Notifications
  - name: oauth
    x-group: OAuth
  - name: oauth-clients
    x-group: OAuth clients
  - name: opencost
    x-group: OpenCost
  - name: organization
    x-group: Audit log
  - name: organizations
    x-group: Organizations
  - name: placement-alternatives
    x-group: Placement alternatives
  - name: reports
    x-group: Reports
  - name: service-map
    x-group: Service map
  - name: settings
    x-group: Settings
  - name: sso
    x-group: Single sign-on
  - name: tenants
    x-group: Tenants
  - name: user
    x-group: Users
  - name: virtual-machines
    x-group: Virtual machines
  - name: virtual-tags
    x-group: Virtual tags
  - name: workflows
    x-group: Workflows
paths:
  /api/v1/organizations/{org_id}/sso/identity-provider:
    put:
      tags:
        - sso
      summary: Set the organization's identity provider
      description: >-
        Org owners only. Creates or replaces the organization's SAML or OIDC
        identity provider; send the full settings each time, including the OIDC
        client secret. People signing in through it join the organization with
        the default role, only for emails on the organization's verified
        domains. Roles are capped below organization owner. IdP-initiated SAML
        is not supported.
      parameters:
        - description: Organization ID
          name: org_id
          in: path
          required: true
          schema:
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/sso.IdentityProviderInput'
        description: Identity provider settings
        required: true
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/responses.SuccessResponse'
                  - type: object
                    properties:
                      data:
                        $ref: '#/components/schemas/sso.IdentityProvider'
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/responses.ErrorResponse'
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/responses.ErrorResponse'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/responses.ErrorResponse'
        '409':
          description: Conflict
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/responses.ErrorResponse'
        '503':
          description: Service Unavailable
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/responses.ErrorResponse'
      security:
        - BearerAuth: []
components:
  schemas:
    sso.IdentityProviderInput:
      type: object
      required:
        - default_role
        - group_role_mappings
        - type
      properties:
        default_role:
          type: string
          enum:
            - member
            - admin
            - billing_admin
        group_role_mappings:
          type: object
          additionalProperties:
            type: string
        groups_attribute:
          type: string
          maxLength: 256
        metadata_url:
          type: string
          maxLength: 2048
        metadata_xml:
          type: string
          maxLength: 131072
        oidc_client_id:
          type: string
          maxLength: 256
        oidc_client_secret:
          type: string
          maxLength: 256
        oidc_issuer:
          type: string
          maxLength: 2048
        type:
          type: string
          enum:
            - saml
            - oidc
    responses.SuccessResponse:
      type: object
      required:
        - message
        - status
      properties:
        data: {}
        message:
          type: string
          example: some message
        status:
          type: string
          example: success
    sso.IdentityProvider:
      type: object
      required:
        - created_at
        - default_role
        - enforce_sso
        - group_role_mappings
        - has_metadata_xml
        - id
        - provider_name
        - service_provider
        - type
        - updated_at
      properties:
        created_at:
          type: string
        default_role:
          type: string
        enforce_sso:
          type: boolean
        group_role_mappings:
          type: object
          additionalProperties:
            type: string
        groups_attribute:
          type: string
        has_metadata_xml:
          type: boolean
        id:
          type: string
        metadata_url:
          type: string
        oidc_client_id:
          type: string
        oidc_issuer:
          type: string
        provider_name:
          type: string
        service_provider:
          $ref: '#/components/schemas/sso.ServiceProvider'
        type:
          type: string
          enum:
            - saml
            - oidc
        updated_at:
          type: string
    responses.ErrorResponse:
      type: object
      required:
        - message
        - status
      properties:
        message:
          type: string
          example: some message
        status:
          type: string
          example: error
    sso.ServiceProvider:
      type: object
      required:
        - acs_url
        - entity_id
        - oidc_redirect_uri
      properties:
        acs_url:
          type: string
        entity_id:
          type: string
        oidc_redirect_uri:
          type: string
        sign_in_client_id:
          type: string
  securitySchemes:
    BearerAuth:
      description: Enter "Bearer {token}"
      type: apiKey
      name: Authorization
      in: header

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.