コンテンツにスキップ

create_oidc_provider

POST
/api/v1/settings/oidc
curl --request POST \
--url https://example.com/api/v1/settings/oidc \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "client_id": "example", "client_secret": "example", "default_role": "example", "enabled": true, "groups_claim": "example", "issuer": "example", "kind": "entra", "name": "example", "redirect_uri": "example", "role_map": { "additionalProperty": "example" }, "scopes": "example" }'
Media typeapplication/json

Create/update payload from the admin UI. client_secret is write-only: None on update keeps the stored value (so editing other fields doesn’t require re-entering the secret).

object
client_id
required
string
client_secret
string | null
default_role
string | null
enabled
boolean
groups_claim
string
issuer
required
string
kind

Which IdP product this is. Omitted ⇒ generic.

string
Allowed values: entra okta google generic
name
required
string
redirect_uri
required
string
role_map
object
key
additional properties
string
scopes
string

Provider created

Media typeapplication/json

The id of a freshly created resource — the whole body of a 201.

Deliberately one shape for every creator. The json!({"id": …}) literal it replaces was written out per handler, which is how {"id": …} and {"node_id": …} both ended up in this API for the same idea; a client then needs to know which creator it called to read the id back.

object
id
required
string format: uuid
Examplegenerated
{
"id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0"
}

The provider definition is invalid, or the client secret is missing

Media typeapplication/json

The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies undescribed — a client that has to guess the failure shape ends up parsing the success shape and reading undefined.

object
error
required
object
code
required

Stable machine-readable code. Clients branch on this, never on the message.

string
message
required

Operator-facing sentence. Safe to display; never carries an internal error’s own text.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example"
}
}

No valid bearer token

Media typeapplication/json

The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies undescribed — a client that has to guess the failure shape ends up parsing the success shape and reading undefined.

object
error
required
object
code
required

Stable machine-readable code. Clients branch on this, never on the message.

string
message
required

Operator-facing sentence. Safe to display; never carries an internal error’s own text.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example"
}
}

Role lacks the ManageUsers permission

Media typeapplication/json

The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies undescribed — a client that has to guess the failure shape ends up parsing the success shape and reading undefined.

object
error
required
object
code
required

Stable machine-readable code. Clients branch on this, never on the message.

string
message
required

Operator-facing sentence. Safe to display; never carries an internal error’s own text.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example"
}
}

This deployment does not persist SSO configuration

Media typeapplication/json

The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies undescribed — a client that has to guess the failure shape ends up parsing the success shape and reading undefined.

object
error
required
object
code
required

Stable machine-readable code. Clients branch on this, never on the message.

string
message
required

Operator-facing sentence. Safe to display; never carries an internal error’s own text.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example"
}
}