> ## Documentation Index
> Fetch the complete documentation index at: https://conductorone-findings-decoys-followup.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Create

> Create an SSO application for an application in your catalog. The
 entitlement that governs sign-in is created alongside it. OIDC creation
 also server-mints the required initial client and returns its secret once
 when the client is confidential. SAML creation has no OAuth-client step.



## OpenAPI

````yaml https://spec.speakeasy.com/conductor-one/conductorone/my-source-with-code-samples post /api/v1/apps/{app_id}/sso/applications
openapi: 3.1.0
info:
  description: The C1 API is a HTTP API for managing C1 resources.
  title: C1 API
  version: 0.1.0-alpha
servers:
  - description: The C1 API server for the current tenant.
    url: https://{tenantDomain}.conductor.one
    variables:
      tenantDomain:
        default: example
        description: The domain of the tenant to use for this request.
security:
  - bearerAuth: []
    oauth: []
paths:
  /api/v1/apps/{app_id}/sso/applications:
    post:
      tags:
        - SSO
      summary: Create
      description: |-
        Create an SSO application for an application in your catalog. The
         entitlement that governs sign-in is created alongside it. OIDC creation
         also server-mints the required initial client and returns its secret once
         when the client is confidential. SAML creation has no OAuth-client step.
      operationId: c1.api.sso.v1.SSOApplicationService.Create
      parameters:
        - in: path
          name: app_id
          required: true
          schema:
            description: >-
              The application in your catalog to attach this sign-in
              configuration to.
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: >-
                #/components/schemas/c1.api.sso.v1.SSOApplicationServiceCreateRequestInput
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: >-
                  #/components/schemas/c1.api.sso.v1.SSOApplicationServiceCreateResponse
          description: >-
            SSOApplicationServiceCreateResponse returns the created SSO
            application.
components:
  schemas:
    c1.api.sso.v1.SSOApplicationServiceCreateRequestInput:
      description: >
        SSOApplicationServiceCreateRequest creates an SSO application.


        This message contains a oneof named protocol. Only a single field of the
        following list may be set at a time:
          - oidc
          - saml
      properties:
        assertionLifetime:
          format: duration
          type:
            - string
            - 'null'
        description:
          description: Description of the SSO application.
          type: string
        displayName:
          description: Display name for the SSO application.
          type: string
        initialClient:
          oneOf:
            - $ref: >-
                #/components/schemas/c1.api.sso.v1.SSOApplicationOIDCClientConfig
            - type: 'null'
        oidc:
          oneOf:
            - $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationOIDCConfig'
            - type: 'null'
        saml:
          oneOf:
            - $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationSAMLConfig'
            - type: 'null'
        sectorId:
          description: |-
            The pairwise sector this application belongs to. Empty means the
             application is its own sector. Immutable after creation.
          type: string
        subjectType:
          description: >-
            How the user's identifier reaches this application. Leave unset to
            use the
             tenant default.
          enum:
            - SSO_SUBJECT_TYPE_UNSPECIFIED
            - SSO_SUBJECT_TYPE_PAIRWISE
            - SSO_SUBJECT_TYPE_PUBLIC
          type: string
          x-speakeasy-unknown-values: allow
      required:
        - displayName
      title: Sso Application Service Create Request
      type: object
      x-speakeasy-name-override: SSOApplicationServiceCreateRequest
    c1.api.sso.v1.SSOApplicationServiceCreateResponse:
      description: SSOApplicationServiceCreateResponse returns the created SSO application.
      properties:
        application:
          oneOf:
            - $ref: '#/components/schemas/c1.api.sso.v1.SSOApplication'
            - type: 'null'
        client:
          oneOf:
            - $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationOIDCClient'
            - type: 'null'
        clientSecret:
          description: >-
            Confidential-client secret returned once. Empty for SAML and public
            OIDC
             clients. C1 stores only its hash.
          type: string
      title: Sso Application Service Create Response
      type: object
      x-speakeasy-name-override: SSOApplicationServiceCreateResponse
    c1.api.sso.v1.SSOApplicationOIDCClientConfig:
      description: >-
        SSOApplicationOIDCClientConfig is the administrator-supplied
        configuration
         from which C1 mints an App-owned OAuth client. The client ID is never input.
      properties:
        authentication:
          oneOf:
            - $ref: >-
                #/components/schemas/c1.api.sso.v1.SSOApplicationOIDCClientAuthentication
            - type: 'null'
        displayName:
          description: Human-readable client name shown to administrators.
          type: string
        pkcePolicy:
          description: >-
            PKCE is required by default on create. On update, UNSPECIFIED
            preserves
             the current policy; set REQUIRED_S256 explicitly to tighten a legacy
             confidential client.
          enum:
            - SSO_APPLICATION_OIDC_PKCE_POLICY_UNSPECIFIED
            - SSO_APPLICATION_OIDC_PKCE_POLICY_REQUIRED_S256
            - SSO_APPLICATION_OIDC_PKCE_POLICY_ALLOW_MISSING_FOR_LEGACY
          type: string
          x-speakeasy-unknown-values: allow
        redirectUris:
          description: >-
            Exact redirect URIs the client may use after authorization. HTTPS
            and
             loopback HTTP are accepted; public clients may also use a reversed-DNS
             private-use scheme for native-app redirects.
          items:
            type: string
          type:
            - array
            - 'null'
      required:
        - displayName
        - authentication
      title: Sso Application Oidc Client Config
      type: object
      x-speakeasy-name-override: SSOApplicationOIDCClientConfig
    c1.api.sso.v1.SSOApplicationOIDCConfig:
      description: SSOApplicationOIDCConfig is the OIDC-specific sign-in configuration.
      properties:
        claimMappings:
          description: >-
            Custom claims released to this application, in addition to the
            standard
             claims its granted scopes already release.
          items:
            $ref: '#/components/schemas/c1.api.sso.v1.OIDCClaimMapping'
          type:
            - array
            - 'null'
        idTokenSignedResponseAlg:
          description: The algorithm used to sign this application's id_token.
          enum:
            - OIDC_SIGNING_ALGORITHM_UNSPECIFIED
            - OIDC_SIGNING_ALGORITHM_EDDSA
            - OIDC_SIGNING_ALGORITHM_ES256
            - OIDC_SIGNING_ALGORITHM_RS256
          type: string
          x-speakeasy-unknown-values: allow
      title: Sso Application Oidc Config
      type: object
      x-speakeasy-name-override: SSOApplicationOIDCConfig
    c1.api.sso.v1.SSOApplicationSAMLConfig:
      description: SSOApplicationSAMLConfig is the SAML-specific sign-in configuration.
      properties:
        acsUrls:
          description: |-
            The Assertion Consumer Service URLs the assertion may be posted to.
             Matched exactly; a URL that is not in this list is refused.
          items:
            type: string
          type:
            - array
            - 'null'
        attributeMappings:
          description: >-
            The attributes released in the assertion's AttributeStatement. SAML
            has no
             scopes, so this list is the whole release: the NameID carries the
             identifier and these carry everything else.
          items:
            $ref: '#/components/schemas/c1.api.sso.v1.SAMLAttributeMapping'
          type:
            - array
            - 'null'
        encryptAssertions:
          description: Encrypt the assertion.
          type: boolean
        encryptionAlgorithm:
          description: The algorithm used when encrypt_assertions is set.
          enum:
            - SAML_ENCRYPTION_ALGORITHM_UNSPECIFIED
            - SAML_ENCRYPTION_ALGORITHM_AES256_GCM
            - SAML_ENCRYPTION_ALGORITHM_AES128_GCM
            - SAML_ENCRYPTION_ALGORITHM_AES256_CBC
          type: string
          x-speakeasy-unknown-values: allow
        nameIdFormat:
          description: >-
            Set this when the service provider requires a specific NameID
            format. This
             also selects the NameID value semantics: EMAIL_ADDRESS uses the user's
             primary email, TRANSIENT creates a new value for each sign-in, and
             PERSISTENT uses the application's pairwise subject. Immutable once set.
          enum:
            - SAML_NAME_ID_FORMAT_UNSPECIFIED
            - SAML_NAME_ID_FORMAT_PERSISTENT
            - SAML_NAME_ID_FORMAT_EMAIL_ADDRESS
            - SAML_NAME_ID_FORMAT_UNSPECIFIED_URN
            - SAML_NAME_ID_FORMAT_TRANSIENT
          type: string
          x-speakeasy-unknown-values: allow
        requireSignedAuthnRequests:
          description: |-
            Reject any AuthnRequest that is not signed by one of
             sp_signing_certificates. At least one signing certificate is required when
             this is set.
          type: boolean
        signAssertions:
          description: >-
            Sign the assertion. At least one of sign_assertions or
            sign_responses must
             be set.
          type: boolean
        signResponses:
          description: |-
            Sign the response envelope. At least one of sign_assertions or
             sign_responses must be set.
          type: boolean
        spEncryptionCertificate:
          description: >-
            The service provider's DER-encoded encryption certificate, taken
            from the
             encryption KeyDescriptor in its metadata. Required when encrypt_assertions
             is set.
          format: base64
          type: string
        spEntityId:
          description: |-
            The service provider's entity ID, taken from its metadata. It is the
             audience every assertion this application issues is restricted to, and it
             is what the service provider presents at sign-in. Set it at creation: it is
             fixed for the life of the application, because changing it re-points every
             assertion already issued. An entity ID already in use by another SSO
             application in the tenant is rejected.
          type: string
        spSigningCertificates:
          description: >-
            The service provider's DER-encoded signing certificates, taken from
            the
             signing KeyDescriptors in its metadata.
          items:
            format: base64
            type: string
          type:
            - array
            - 'null'
      required:
        - spEntityId
        - acsUrls
      title: Sso Application Saml Config
      type: object
      x-speakeasy-name-override: SSOApplicationSAMLConfig
    c1.api.sso.v1.SSOApplication:
      description: >
        SSOApplication is one application your users sign in to through
        ConductorOne.


        This message contains a oneof named protocol. Only a single field of the
        following list may be set at a time:
          - oidc
          - saml
      properties:
        appEntitlementId:
          description: |-
            The entitlement a user must hold to sign in. Created with the SSO
             application and not settable by the caller.
          type: string
        appId:
          description: >-
            The application in your catalog that owns this sign-in
            configuration. Its
             owners, entitlements, and access reviews govern who may sign in.
          type: string
        assertionLifetime:
          format: duration
          type:
            - string
            - 'null'
        createdAt:
          format: date-time
          type:
            - string
            - 'null'
        description:
          description: Description of the SSO application.
          type: string
        disabled:
          description: >-
            When true, sign-in through this application is refused. The
            application
             and its entitlement are left in place.
          type: boolean
        displayName:
          description: Display name for the SSO application.
          type: string
        id:
          description: Unique identifier for this SSO application.
          type: string
        oidc:
          oneOf:
            - $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationOIDCConfig'
            - type: 'null'
        saml:
          oneOf:
            - $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationSAMLConfig'
            - type: 'null'
        sectorId:
          description: |-
            The pairwise sector this application belongs to. Empty means the
             application is its own sector and shares linkability with nothing; set a
             shared value to issue one identifier across applications a user should
             appear the same to. Ignored when the subject type resolves to PUBLIC.
             Immutable once set.
          type: string
        subjectType:
          description: How the user's identifier reaches this application.
          enum:
            - SSO_SUBJECT_TYPE_UNSPECIFIED
            - SSO_SUBJECT_TYPE_PAIRWISE
            - SSO_SUBJECT_TYPE_PUBLIC
          type: string
          x-speakeasy-unknown-values: allow
        updatedAt:
          format: date-time
          type:
            - string
            - 'null'
      title: Sso Application
      type: object
      x-speakeasy-name-override: SSOApplication
    c1.api.sso.v1.SSOApplicationOIDCClient:
      description: SSOApplicationOIDCClient is an App-owned OAuth client minted by C1.
      properties:
        appId:
          description: Application that owns this client.
          type: string
        authentication:
          oneOf:
            - $ref: >-
                #/components/schemas/c1.api.sso.v1.SSOApplicationOIDCClientAuthentication
            - type: 'null'
        clientId:
          description: Client ID generated by ConductorOne.
          type: string
        createdAt:
          format: date-time
          type:
            - string
            - 'null'
        displayName:
          description: Human-readable client name.
          type: string
        pkcePolicy:
          description: Effective PKCE policy.
          enum:
            - SSO_APPLICATION_OIDC_PKCE_POLICY_UNSPECIFIED
            - SSO_APPLICATION_OIDC_PKCE_POLICY_REQUIRED_S256
            - SSO_APPLICATION_OIDC_PKCE_POLICY_ALLOW_MISSING_FOR_LEGACY
          type: string
          x-speakeasy-unknown-values: allow
        redirectUris:
          description: Exact callback URLs registered for this client.
          items:
            type: string
          type:
            - array
            - 'null'
        ssoApplicationId:
          description: SSO application whose identity policy applies to this client.
          type: string
        updatedAt:
          format: date-time
          type:
            - string
            - 'null'
      title: Sso Application Oidc Client
      type: object
      x-speakeasy-name-override: SSOApplicationOIDCClient
    c1.api.sso.v1.SSOApplicationOIDCClientAuthentication:
      description: >
        SSOApplicationOIDCClientAuthentication is the exact token-endpoint
        client
         authentication method assigned to an OIDC client.

        This message contains a oneof named method. Only a single field of the
        following list may be set at a time:
          - none
          - clientSecretBasic
          - clientSecretPost
          - privateKeyJwt
      properties:
        clientSecretBasic:
          oneOf:
            - $ref: >-
                #/components/schemas/c1.api.sso.v1.SSOApplicationOIDCClientAuthClientSecretBasic
            - type: 'null'
        clientSecretPost:
          oneOf:
            - $ref: >-
                #/components/schemas/c1.api.sso.v1.SSOApplicationOIDCClientAuthClientSecretPost
            - type: 'null'
        none:
          oneOf:
            - $ref: >-
                #/components/schemas/c1.api.sso.v1.SSOApplicationOIDCClientAuthNone
            - type: 'null'
        privateKeyJwt:
          oneOf:
            - $ref: >-
                #/components/schemas/c1.api.sso.v1.SSOApplicationOIDCClientAuthPrivateKeyJWT
            - type: 'null'
      title: Sso Application Oidc Client Authentication
      type: object
      x-speakeasy-name-override: SSOApplicationOIDCClientAuthentication
    c1.api.sso.v1.OIDCClaimMapping:
      description: |-
        OIDCClaimMapping releases one user attribute to the application as one
         OIDC claim.
      properties:
        claimName:
          description: >-
            The name of the claim as the application sees it. Namespace custom
            claims
             so they cannot collide with the registered OIDC claim set.
          type: string
        destination:
          description: Where the claim is released.
          enum:
            - OIDC_CLAIM_DESTINATION_UNSPECIFIED
            - OIDC_CLAIM_DESTINATION_ID_TOKEN_ONLY
            - OIDC_CLAIM_DESTINATION_USERINFO_ONLY
          type: string
          x-speakeasy-unknown-values: allow
        userAttributeMappingId:
          description: >-
            The user attribute mapping that resolves the value, including its
            fallback
             chain.
          type: string
      required:
        - userAttributeMappingId
        - claimName
      title: Oidc Claim Mapping
      type: object
      x-speakeasy-name-override: OIDCClaimMapping
    c1.api.sso.v1.SAMLAttributeMapping:
      description: |-
        SAMLAttributeMapping releases one user attribute to the service provider
         as one Attribute in the assertion's AttributeStatement.
      properties:
        friendlyName:
          description: Optional FriendlyName, for service providers that display it.
          type: string
        name:
          description: The Name attribute, dictated by the service provider.
          type: string
        nameFormat:
          description: The NameFormat attribute.
          enum:
            - SAML_ATTRIBUTE_NAME_FORMAT_UNSPECIFIED
            - SAML_ATTRIBUTE_NAME_FORMAT_URI
            - SAML_ATTRIBUTE_NAME_FORMAT_BASIC
            - SAML_ATTRIBUTE_NAME_FORMAT_UNSPECIFIED_URN
          type: string
          x-speakeasy-unknown-values: allow
        userAttributeMappingId:
          description: >-
            The user attribute mapping that resolves the value, including its
            fallback
             chain.
          type: string
      required:
        - userAttributeMappingId
        - name
      title: Saml Attribute Mapping
      type: object
      x-speakeasy-name-override: SAMLAttributeMapping
    c1.api.sso.v1.SSOApplicationOIDCClientAuthClientSecretBasic:
      description: RFC 6749 client_secret_basic. C1 generates and returns the secret once.
      title: Sso Application Oidc Client Auth Client Secret Basic
      type: object
      x-speakeasy-name-override: SSOApplicationOIDCClientAuthClientSecretBasic
    c1.api.sso.v1.SSOApplicationOIDCClientAuthClientSecretPost:
      description: RFC 6749 client_secret_post. C1 generates and returns the secret once.
      title: Sso Application Oidc Client Auth Client Secret Post
      type: object
      x-speakeasy-name-override: SSOApplicationOIDCClientAuthClientSecretPost
    c1.api.sso.v1.SSOApplicationOIDCClientAuthNone:
      description: Public client authentication. No client credential is issued.
      title: Sso Application Oidc Client Auth None
      type: object
      x-speakeasy-name-override: SSOApplicationOIDCClientAuthNone
    c1.api.sso.v1.SSOApplicationOIDCClientAuthPrivateKeyJWT:
      description: >-
        RFC 7523 private_key_jwt using an inline RFC 7517 JWK Set. Multiple
        public
         signing keys allow overlap during relying-party key rotation; C1 selects by
         the assertion's `kid`. The relying party retains every private key.
      properties:
        publicJwks:
          description: The publicJwks field.
          format: base64
          type: string
      required:
        - publicJwks
      title: Sso Application Oidc Client Auth Private Key Jwt
      type: object
      x-speakeasy-name-override: SSOApplicationOIDCClientAuthPrivateKeyJWT
  securitySchemes:
    bearerAuth:
      scheme: bearer
      type: http
    oauth:
      description: >-
        This API uses OAuth2 with the Client Credential flow.

        Client Credentials must be sent in the BODY, not the headers.

        For an example of how to implement this, refer to the
        [c1TokenSource.Token()](https://github.com/ConductorOne/conductorone-sdk-go/blob/3375fe7c0126d17e7ec4e711693dee7b791023aa/token_source.go#L101-L187)
        function.
      flows:
        clientCredentials:
          scopes: {}
          tokenUrl: /auth/v1/token
      type: oauth2

````