curl --request POST \
--url https://{tenantDomain}.conductor.one/api/v1/apps/{app_id}/sso/applications \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"displayName": "<string>",
"assertionLifetime": "<string>",
"description": "<string>",
"initialClient": {
"authentication": {
"clientSecretBasic": {},
"clientSecretPost": {},
"none": {},
"privateKeyJwt": {
"publicJwks": "aSDinaTvuI8gbWludGxpZnk="
}
},
"displayName": "<string>",
"redirectUris": [
"<string>"
]
},
"oidc": {
"claimMappings": [
{
"claimName": "<string>",
"userAttributeMappingId": "<string>"
}
]
},
"saml": {
"acsUrls": [
"<string>"
],
"spEntityId": "<string>",
"attributeMappings": [
{
"name": "<string>",
"userAttributeMappingId": "<string>",
"friendlyName": "<string>"
}
],
"encryptAssertions": true,
"requireSignedAuthnRequests": true,
"signAssertions": true,
"signResponses": true,
"spEncryptionCertificate": "aSDinaTvuI8gbWludGxpZnk=",
"spSigningCertificates": [
"aSDinaTvuI8gbWludGxpZnk="
]
},
"sectorId": "<string>"
}
'import requests
url = "https://{tenantDomain}.conductor.one/api/v1/apps/{app_id}/sso/applications"
payload = {
"displayName": "<string>",
"assertionLifetime": "<string>",
"description": "<string>",
"initialClient": {
"authentication": {
"clientSecretBasic": {},
"clientSecretPost": {},
"none": {},
"privateKeyJwt": { "publicJwks": "aSDinaTvuI8gbWludGxpZnk=" }
},
"displayName": "<string>",
"redirectUris": ["<string>"]
},
"oidc": { "claimMappings": [
{
"claimName": "<string>",
"userAttributeMappingId": "<string>"
}
] },
"saml": {
"acsUrls": ["<string>"],
"spEntityId": "<string>",
"attributeMappings": [
{
"name": "<string>",
"userAttributeMappingId": "<string>",
"friendlyName": "<string>"
}
],
"encryptAssertions": True,
"requireSignedAuthnRequests": True,
"signAssertions": True,
"signResponses": True,
"spEncryptionCertificate": "aSDinaTvuI8gbWludGxpZnk=",
"spSigningCertificates": ["aSDinaTvuI8gbWludGxpZnk="]
},
"sectorId": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
displayName: '<string>',
assertionLifetime: '<string>',
description: '<string>',
initialClient: {
authentication: {
clientSecretBasic: {},
clientSecretPost: {},
none: {},
privateKeyJwt: {publicJwks: 'aSDinaTvuI8gbWludGxpZnk='}
},
displayName: '<string>',
redirectUris: ['<string>']
},
oidc: {claimMappings: [{claimName: '<string>', userAttributeMappingId: '<string>'}]},
saml: {
acsUrls: ['<string>'],
spEntityId: '<string>',
attributeMappings: [
{name: '<string>', userAttributeMappingId: '<string>', friendlyName: '<string>'}
],
encryptAssertions: true,
requireSignedAuthnRequests: true,
signAssertions: true,
signResponses: true,
spEncryptionCertificate: 'aSDinaTvuI8gbWludGxpZnk=',
spSigningCertificates: ['aSDinaTvuI8gbWludGxpZnk=']
},
sectorId: '<string>'
})
};
fetch('https://{tenantDomain}.conductor.one/api/v1/apps/{app_id}/sso/applications', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{tenantDomain}.conductor.one/api/v1/apps/{app_id}/sso/applications",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'displayName' => '<string>',
'assertionLifetime' => '<string>',
'description' => '<string>',
'initialClient' => [
'authentication' => [
'clientSecretBasic' => [
],
'clientSecretPost' => [
],
'none' => [
],
'privateKeyJwt' => [
'publicJwks' => 'aSDinaTvuI8gbWludGxpZnk='
]
],
'displayName' => '<string>',
'redirectUris' => [
'<string>'
]
],
'oidc' => [
'claimMappings' => [
[
'claimName' => '<string>',
'userAttributeMappingId' => '<string>'
]
]
],
'saml' => [
'acsUrls' => [
'<string>'
],
'spEntityId' => '<string>',
'attributeMappings' => [
[
'name' => '<string>',
'userAttributeMappingId' => '<string>',
'friendlyName' => '<string>'
]
],
'encryptAssertions' => true,
'requireSignedAuthnRequests' => true,
'signAssertions' => true,
'signResponses' => true,
'spEncryptionCertificate' => 'aSDinaTvuI8gbWludGxpZnk=',
'spSigningCertificates' => [
'aSDinaTvuI8gbWludGxpZnk='
]
],
'sectorId' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://{tenantDomain}.conductor.one/api/v1/apps/{app_id}/sso/applications"
payload := strings.NewReader("{\n \"displayName\": \"<string>\",\n \"assertionLifetime\": \"<string>\",\n \"description\": \"<string>\",\n \"initialClient\": {\n \"authentication\": {\n \"clientSecretBasic\": {},\n \"clientSecretPost\": {},\n \"none\": {},\n \"privateKeyJwt\": {\n \"publicJwks\": \"aSDinaTvuI8gbWludGxpZnk=\"\n }\n },\n \"displayName\": \"<string>\",\n \"redirectUris\": [\n \"<string>\"\n ]\n },\n \"oidc\": {\n \"claimMappings\": [\n {\n \"claimName\": \"<string>\",\n \"userAttributeMappingId\": \"<string>\"\n }\n ]\n },\n \"saml\": {\n \"acsUrls\": [\n \"<string>\"\n ],\n \"spEntityId\": \"<string>\",\n \"attributeMappings\": [\n {\n \"name\": \"<string>\",\n \"userAttributeMappingId\": \"<string>\",\n \"friendlyName\": \"<string>\"\n }\n ],\n \"encryptAssertions\": true,\n \"requireSignedAuthnRequests\": true,\n \"signAssertions\": true,\n \"signResponses\": true,\n \"spEncryptionCertificate\": \"aSDinaTvuI8gbWludGxpZnk=\",\n \"spSigningCertificates\": [\n \"aSDinaTvuI8gbWludGxpZnk=\"\n ]\n },\n \"sectorId\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://{tenantDomain}.conductor.one/api/v1/apps/{app_id}/sso/applications")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"displayName\": \"<string>\",\n \"assertionLifetime\": \"<string>\",\n \"description\": \"<string>\",\n \"initialClient\": {\n \"authentication\": {\n \"clientSecretBasic\": {},\n \"clientSecretPost\": {},\n \"none\": {},\n \"privateKeyJwt\": {\n \"publicJwks\": \"aSDinaTvuI8gbWludGxpZnk=\"\n }\n },\n \"displayName\": \"<string>\",\n \"redirectUris\": [\n \"<string>\"\n ]\n },\n \"oidc\": {\n \"claimMappings\": [\n {\n \"claimName\": \"<string>\",\n \"userAttributeMappingId\": \"<string>\"\n }\n ]\n },\n \"saml\": {\n \"acsUrls\": [\n \"<string>\"\n ],\n \"spEntityId\": \"<string>\",\n \"attributeMappings\": [\n {\n \"name\": \"<string>\",\n \"userAttributeMappingId\": \"<string>\",\n \"friendlyName\": \"<string>\"\n }\n ],\n \"encryptAssertions\": true,\n \"requireSignedAuthnRequests\": true,\n \"signAssertions\": true,\n \"signResponses\": true,\n \"spEncryptionCertificate\": \"aSDinaTvuI8gbWludGxpZnk=\",\n \"spSigningCertificates\": [\n \"aSDinaTvuI8gbWludGxpZnk=\"\n ]\n },\n \"sectorId\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://{tenantDomain}.conductor.one/api/v1/apps/{app_id}/sso/applications")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"displayName\": \"<string>\",\n \"assertionLifetime\": \"<string>\",\n \"description\": \"<string>\",\n \"initialClient\": {\n \"authentication\": {\n \"clientSecretBasic\": {},\n \"clientSecretPost\": {},\n \"none\": {},\n \"privateKeyJwt\": {\n \"publicJwks\": \"aSDinaTvuI8gbWludGxpZnk=\"\n }\n },\n \"displayName\": \"<string>\",\n \"redirectUris\": [\n \"<string>\"\n ]\n },\n \"oidc\": {\n \"claimMappings\": [\n {\n \"claimName\": \"<string>\",\n \"userAttributeMappingId\": \"<string>\"\n }\n ]\n },\n \"saml\": {\n \"acsUrls\": [\n \"<string>\"\n ],\n \"spEntityId\": \"<string>\",\n \"attributeMappings\": [\n {\n \"name\": \"<string>\",\n \"userAttributeMappingId\": \"<string>\",\n \"friendlyName\": \"<string>\"\n }\n ],\n \"encryptAssertions\": true,\n \"requireSignedAuthnRequests\": true,\n \"signAssertions\": true,\n \"signResponses\": true,\n \"spEncryptionCertificate\": \"aSDinaTvuI8gbWludGxpZnk=\",\n \"spSigningCertificates\": [\n \"aSDinaTvuI8gbWludGxpZnk=\"\n ]\n },\n \"sectorId\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"application": {
"appEntitlementId": "<string>",
"appId": "<string>",
"assertionLifetime": "<string>",
"createdAt": "2023-11-07T05:31:56Z",
"description": "<string>",
"disabled": true,
"displayName": "<string>",
"id": "<string>",
"oidc": {
"claimMappings": [
{
"claimName": "<string>",
"userAttributeMappingId": "<string>"
}
]
},
"saml": {
"acsUrls": [
"<string>"
],
"spEntityId": "<string>",
"attributeMappings": [
{
"name": "<string>",
"userAttributeMappingId": "<string>",
"friendlyName": "<string>"
}
],
"encryptAssertions": true,
"requireSignedAuthnRequests": true,
"signAssertions": true,
"signResponses": true,
"spEncryptionCertificate": "aSDinaTvuI8gbWludGxpZnk=",
"spSigningCertificates": [
"aSDinaTvuI8gbWludGxpZnk="
]
},
"sectorId": "<string>",
"updatedAt": "2023-11-07T05:31:56Z"
},
"client": {
"appId": "<string>",
"authentication": {
"clientSecretBasic": {},
"clientSecretPost": {},
"none": {},
"privateKeyJwt": {
"publicJwks": "aSDinaTvuI8gbWludGxpZnk="
}
},
"clientId": "<string>",
"createdAt": "2023-11-07T05:31:56Z",
"displayName": "<string>",
"redirectUris": [
"<string>"
],
"ssoApplicationId": "<string>",
"updatedAt": "2023-11-07T05:31:56Z"
},
"clientSecret": "<string>"
}Create
Create an SSO application for an application in your catalog. The entitlement that governs sign-in is created alongside it. OIDC creation also server-mints the required initial client and returns its secret once when the client is confidential. SAML creation has no OAuth-client step.
curl --request POST \
--url https://{tenantDomain}.conductor.one/api/v1/apps/{app_id}/sso/applications \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"displayName": "<string>",
"assertionLifetime": "<string>",
"description": "<string>",
"initialClient": {
"authentication": {
"clientSecretBasic": {},
"clientSecretPost": {},
"none": {},
"privateKeyJwt": {
"publicJwks": "aSDinaTvuI8gbWludGxpZnk="
}
},
"displayName": "<string>",
"redirectUris": [
"<string>"
]
},
"oidc": {
"claimMappings": [
{
"claimName": "<string>",
"userAttributeMappingId": "<string>"
}
]
},
"saml": {
"acsUrls": [
"<string>"
],
"spEntityId": "<string>",
"attributeMappings": [
{
"name": "<string>",
"userAttributeMappingId": "<string>",
"friendlyName": "<string>"
}
],
"encryptAssertions": true,
"requireSignedAuthnRequests": true,
"signAssertions": true,
"signResponses": true,
"spEncryptionCertificate": "aSDinaTvuI8gbWludGxpZnk=",
"spSigningCertificates": [
"aSDinaTvuI8gbWludGxpZnk="
]
},
"sectorId": "<string>"
}
'import requests
url = "https://{tenantDomain}.conductor.one/api/v1/apps/{app_id}/sso/applications"
payload = {
"displayName": "<string>",
"assertionLifetime": "<string>",
"description": "<string>",
"initialClient": {
"authentication": {
"clientSecretBasic": {},
"clientSecretPost": {},
"none": {},
"privateKeyJwt": { "publicJwks": "aSDinaTvuI8gbWludGxpZnk=" }
},
"displayName": "<string>",
"redirectUris": ["<string>"]
},
"oidc": { "claimMappings": [
{
"claimName": "<string>",
"userAttributeMappingId": "<string>"
}
] },
"saml": {
"acsUrls": ["<string>"],
"spEntityId": "<string>",
"attributeMappings": [
{
"name": "<string>",
"userAttributeMappingId": "<string>",
"friendlyName": "<string>"
}
],
"encryptAssertions": True,
"requireSignedAuthnRequests": True,
"signAssertions": True,
"signResponses": True,
"spEncryptionCertificate": "aSDinaTvuI8gbWludGxpZnk=",
"spSigningCertificates": ["aSDinaTvuI8gbWludGxpZnk="]
},
"sectorId": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
displayName: '<string>',
assertionLifetime: '<string>',
description: '<string>',
initialClient: {
authentication: {
clientSecretBasic: {},
clientSecretPost: {},
none: {},
privateKeyJwt: {publicJwks: 'aSDinaTvuI8gbWludGxpZnk='}
},
displayName: '<string>',
redirectUris: ['<string>']
},
oidc: {claimMappings: [{claimName: '<string>', userAttributeMappingId: '<string>'}]},
saml: {
acsUrls: ['<string>'],
spEntityId: '<string>',
attributeMappings: [
{name: '<string>', userAttributeMappingId: '<string>', friendlyName: '<string>'}
],
encryptAssertions: true,
requireSignedAuthnRequests: true,
signAssertions: true,
signResponses: true,
spEncryptionCertificate: 'aSDinaTvuI8gbWludGxpZnk=',
spSigningCertificates: ['aSDinaTvuI8gbWludGxpZnk=']
},
sectorId: '<string>'
})
};
fetch('https://{tenantDomain}.conductor.one/api/v1/apps/{app_id}/sso/applications', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{tenantDomain}.conductor.one/api/v1/apps/{app_id}/sso/applications",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'displayName' => '<string>',
'assertionLifetime' => '<string>',
'description' => '<string>',
'initialClient' => [
'authentication' => [
'clientSecretBasic' => [
],
'clientSecretPost' => [
],
'none' => [
],
'privateKeyJwt' => [
'publicJwks' => 'aSDinaTvuI8gbWludGxpZnk='
]
],
'displayName' => '<string>',
'redirectUris' => [
'<string>'
]
],
'oidc' => [
'claimMappings' => [
[
'claimName' => '<string>',
'userAttributeMappingId' => '<string>'
]
]
],
'saml' => [
'acsUrls' => [
'<string>'
],
'spEntityId' => '<string>',
'attributeMappings' => [
[
'name' => '<string>',
'userAttributeMappingId' => '<string>',
'friendlyName' => '<string>'
]
],
'encryptAssertions' => true,
'requireSignedAuthnRequests' => true,
'signAssertions' => true,
'signResponses' => true,
'spEncryptionCertificate' => 'aSDinaTvuI8gbWludGxpZnk=',
'spSigningCertificates' => [
'aSDinaTvuI8gbWludGxpZnk='
]
],
'sectorId' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://{tenantDomain}.conductor.one/api/v1/apps/{app_id}/sso/applications"
payload := strings.NewReader("{\n \"displayName\": \"<string>\",\n \"assertionLifetime\": \"<string>\",\n \"description\": \"<string>\",\n \"initialClient\": {\n \"authentication\": {\n \"clientSecretBasic\": {},\n \"clientSecretPost\": {},\n \"none\": {},\n \"privateKeyJwt\": {\n \"publicJwks\": \"aSDinaTvuI8gbWludGxpZnk=\"\n }\n },\n \"displayName\": \"<string>\",\n \"redirectUris\": [\n \"<string>\"\n ]\n },\n \"oidc\": {\n \"claimMappings\": [\n {\n \"claimName\": \"<string>\",\n \"userAttributeMappingId\": \"<string>\"\n }\n ]\n },\n \"saml\": {\n \"acsUrls\": [\n \"<string>\"\n ],\n \"spEntityId\": \"<string>\",\n \"attributeMappings\": [\n {\n \"name\": \"<string>\",\n \"userAttributeMappingId\": \"<string>\",\n \"friendlyName\": \"<string>\"\n }\n ],\n \"encryptAssertions\": true,\n \"requireSignedAuthnRequests\": true,\n \"signAssertions\": true,\n \"signResponses\": true,\n \"spEncryptionCertificate\": \"aSDinaTvuI8gbWludGxpZnk=\",\n \"spSigningCertificates\": [\n \"aSDinaTvuI8gbWludGxpZnk=\"\n ]\n },\n \"sectorId\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://{tenantDomain}.conductor.one/api/v1/apps/{app_id}/sso/applications")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"displayName\": \"<string>\",\n \"assertionLifetime\": \"<string>\",\n \"description\": \"<string>\",\n \"initialClient\": {\n \"authentication\": {\n \"clientSecretBasic\": {},\n \"clientSecretPost\": {},\n \"none\": {},\n \"privateKeyJwt\": {\n \"publicJwks\": \"aSDinaTvuI8gbWludGxpZnk=\"\n }\n },\n \"displayName\": \"<string>\",\n \"redirectUris\": [\n \"<string>\"\n ]\n },\n \"oidc\": {\n \"claimMappings\": [\n {\n \"claimName\": \"<string>\",\n \"userAttributeMappingId\": \"<string>\"\n }\n ]\n },\n \"saml\": {\n \"acsUrls\": [\n \"<string>\"\n ],\n \"spEntityId\": \"<string>\",\n \"attributeMappings\": [\n {\n \"name\": \"<string>\",\n \"userAttributeMappingId\": \"<string>\",\n \"friendlyName\": \"<string>\"\n }\n ],\n \"encryptAssertions\": true,\n \"requireSignedAuthnRequests\": true,\n \"signAssertions\": true,\n \"signResponses\": true,\n \"spEncryptionCertificate\": \"aSDinaTvuI8gbWludGxpZnk=\",\n \"spSigningCertificates\": [\n \"aSDinaTvuI8gbWludGxpZnk=\"\n ]\n },\n \"sectorId\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://{tenantDomain}.conductor.one/api/v1/apps/{app_id}/sso/applications")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"displayName\": \"<string>\",\n \"assertionLifetime\": \"<string>\",\n \"description\": \"<string>\",\n \"initialClient\": {\n \"authentication\": {\n \"clientSecretBasic\": {},\n \"clientSecretPost\": {},\n \"none\": {},\n \"privateKeyJwt\": {\n \"publicJwks\": \"aSDinaTvuI8gbWludGxpZnk=\"\n }\n },\n \"displayName\": \"<string>\",\n \"redirectUris\": [\n \"<string>\"\n ]\n },\n \"oidc\": {\n \"claimMappings\": [\n {\n \"claimName\": \"<string>\",\n \"userAttributeMappingId\": \"<string>\"\n }\n ]\n },\n \"saml\": {\n \"acsUrls\": [\n \"<string>\"\n ],\n \"spEntityId\": \"<string>\",\n \"attributeMappings\": [\n {\n \"name\": \"<string>\",\n \"userAttributeMappingId\": \"<string>\",\n \"friendlyName\": \"<string>\"\n }\n ],\n \"encryptAssertions\": true,\n \"requireSignedAuthnRequests\": true,\n \"signAssertions\": true,\n \"signResponses\": true,\n \"spEncryptionCertificate\": \"aSDinaTvuI8gbWludGxpZnk=\",\n \"spSigningCertificates\": [\n \"aSDinaTvuI8gbWludGxpZnk=\"\n ]\n },\n \"sectorId\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"application": {
"appEntitlementId": "<string>",
"appId": "<string>",
"assertionLifetime": "<string>",
"createdAt": "2023-11-07T05:31:56Z",
"description": "<string>",
"disabled": true,
"displayName": "<string>",
"id": "<string>",
"oidc": {
"claimMappings": [
{
"claimName": "<string>",
"userAttributeMappingId": "<string>"
}
]
},
"saml": {
"acsUrls": [
"<string>"
],
"spEntityId": "<string>",
"attributeMappings": [
{
"name": "<string>",
"userAttributeMappingId": "<string>",
"friendlyName": "<string>"
}
],
"encryptAssertions": true,
"requireSignedAuthnRequests": true,
"signAssertions": true,
"signResponses": true,
"spEncryptionCertificate": "aSDinaTvuI8gbWludGxpZnk=",
"spSigningCertificates": [
"aSDinaTvuI8gbWludGxpZnk="
]
},
"sectorId": "<string>",
"updatedAt": "2023-11-07T05:31:56Z"
},
"client": {
"appId": "<string>",
"authentication": {
"clientSecretBasic": {},
"clientSecretPost": {},
"none": {},
"privateKeyJwt": {
"publicJwks": "aSDinaTvuI8gbWludGxpZnk="
}
},
"clientId": "<string>",
"createdAt": "2023-11-07T05:31:56Z",
"displayName": "<string>",
"redirectUris": [
"<string>"
],
"ssoApplicationId": "<string>",
"updatedAt": "2023-11-07T05:31:56Z"
},
"clientSecret": "<string>"
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
This API uses OAuth2 with the Client Credential flow. Client Credentials must be sent in the BODY, not the headers. For an example of how to implement this, refer to the c1TokenSource.Token() function.
Path Parameters
The application in your catalog to attach this sign-in configuration to.
Body
SSOApplicationServiceCreateRequest creates an SSO application.
This message contains a oneof named protocol. Only a single field of the following list may be set at a time:
- oidc
- saml
Display name for the SSO application.
Description of the SSO application.
SSOApplicationOIDCClientConfig is the administrator-supplied configuration from which C1 mints an App-owned OAuth client. The client ID is never input.
Show child attributes
Show child attributes
SSOApplicationOIDCConfig is the OIDC-specific sign-in configuration.
Show child attributes
Show child attributes
SSOApplicationSAMLConfig is the SAML-specific sign-in configuration.
Show child attributes
Show child attributes
The pairwise sector this application belongs to. Empty means the application is its own sector. Immutable after creation.
How the user's identifier reaches this application. Leave unset to use the tenant default.
SSO_SUBJECT_TYPE_UNSPECIFIED, SSO_SUBJECT_TYPE_PAIRWISE, SSO_SUBJECT_TYPE_PUBLIC Response
SSOApplicationServiceCreateResponse returns the created SSO application.
SSOApplicationServiceCreateResponse returns the created SSO application.
SSOApplication is one application your users sign in to through ConductorOne.
This message contains a oneof named protocol. Only a single field of the following list may be set at a time:
- oidc
- saml
Show child attributes
Show child attributes
SSOApplicationOIDCClient is an App-owned OAuth client minted by C1.
Show child attributes
Show child attributes
Confidential-client secret returned once. Empty for SAML and public OIDC clients. C1 stores only its hash.
Was this page helpful?