Skip to main content
POST
Create an Identity Provider

Authorizations

Authorization
string
header
required

The access token received from the authorization server in the OAuth 2.0 flow.

FlowClient Credentials
Token URL
/oauth/token
Scopes1
create:my_org:identity_providers
Create identity provider for organization

Body

application/json

Identity provider specific options.

name
string
required

The name of the identity provider

Required string length: 1 - 128
strategy
enum<string>
required

The type of the identity provider

Available options:
adfs,
google-apps,
oidc,
okta,
pingfederate,
samlp,
waad
Allowed value: "adfs"
options
adfs_server · object
required

Identity provider specific options.

domains
string[]

List of domains for Home Realm Discovery (HRD)

display_name
string

Identity provider name used on the login screen.

Required string length: 1 - 128
show_as_button
boolean

Enables showing a button for the connection in the login page (new experience only). If false, it will be usable only by Home Realm Discovery (HRD).

assign_membership_on_login
boolean

If true, the user will be made a member of the organization upon login.

is_enabled
boolean

True if the identity provider is enabled for the organization.

use_for_third_party_client_access
boolean

True if third-party applications can use it. If false, only first-party applications with the connection enabled can use it. Defaults to false.

cross_app_access_resource_app
object
EA

Cross-app access resource application configuration. Only present when the cross-app access resource application feature is enabled for your organization.

Response

Identity provider successfully created.

Identity provider specific options.

strategy
enum<string>
required

The type of the identity provider

Available options:
adfs,
google-apps,
oidc,
okta,
pingfederate,
samlp,
waad
Allowed value: "adfs"
id
string
read-only

Identity provider identifier.

Pattern: ^con_[A-Za-z0-9]{16}$
name
string | null

The name of the identity provider

Maximum string length: 128
domains
string[]

List of domains for Home Realm Discovery (HRD)

display_name
string

Identity provider name used on the login screen.

Required string length: 1 - 128
show_as_button
boolean

Enables showing a button for the connection in the login page (new experience only). If false, it will be usable only by Home Realm Discovery (HRD).

assign_membership_on_login
boolean

If true, the user will be made a member of the organization upon login.

is_enabled
boolean

True if the identity provider is enabled for the organization.

access_level
enum<string>
read-only

The access level allowed for the Organization

Available options:
none,
readonly,
limited,
full
member_access_level
enum<string>
read-only
EA

The Organization Member Access Level for this connection.

Available options:
none,
readonly,
limited,
full
use_for_third_party_client_access
boolean

True if third-party applications can use it. If false, only first-party applications with the connection enabled can use it. Defaults to false.

cross_app_access_resource_app
object
EA

Cross-app access resource application configuration. Only present when the cross-app access resource application feature is enabled for your organization.

options
adfs_server · object

Identity provider specific options.