Configure the organisation's identity provider
import requests
url = "https://platform.ankra.app/org/organisation/{organisation_id}/sso"
payload = {
"client_id": "<string>",
"issuer": "<string>"
}
headers = {
"cookie": "ankra_session=",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {cookie: 'ankra_session=', 'Content-Type': 'application/json'},
body: JSON.stringify({client_id: '<string>', issuer: '<string>'})
};
fetch('https://platform.ankra.app/org/organisation/{organisation_id}/sso', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));curl --request PUT \
--url https://platform.ankra.app/org/organisation/{organisation_id}/sso \
--header 'Content-Type: application/json' \
--cookie ankra_session= \
--data '
{
"client_id": "<string>",
"issuer": "<string>"
}
'{
"connection": {
"break_glass_user_ids": [
"3c90c3cc-0d44-4b50-8888-8dd25736052a"
],
"client_id": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"enforcement": "optional",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"is_enabled": true,
"issuer": "<string>",
"jit_default_role": "member",
"jit_enabled": true,
"last_login_at": "2023-11-07T05:31:56Z",
"reverify_interval_hours": 360,
"strategy": "oidc",
"updated_at": "2023-11-07T05:31:56Z"
},
"domains": [
{
"domain": "<string>",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"is_verified": true,
"last_checked_at": "2023-11-07T05:31:56Z",
"verification_record_name": "<string>",
"verification_record_value": "<string>",
"verified_at": "2023-11-07T05:31:56Z"
}
],
"group_mappings": [
{
"group": "<string>",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"role": "member"
}
],
"governed_member_count": 123,
"is_available": true,
"redirect_uri": "<string>",
"sign_in_url": "<string>",
"suspended_member_count": 123
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>"
}
]
}Organisation
Configure the organisation's identity provider
Connects the organisation’s own OpenID Connect identity provider, or replaces its issuer and client. The client secret is forwarded to the identity broker and stored nowhere in Ankra, so it is required on the first save and whenever the issuer or client ID changes. The configuring administrator becomes the connection’s first break-glass member.
PUT
/
org
/
organisation
/
{organisation_id}
/
sso
Configure the organisation's identity provider
import requests
url = "https://platform.ankra.app/org/organisation/{organisation_id}/sso"
payload = {
"client_id": "<string>",
"issuer": "<string>"
}
headers = {
"cookie": "ankra_session=",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {cookie: 'ankra_session=', 'Content-Type': 'application/json'},
body: JSON.stringify({client_id: '<string>', issuer: '<string>'})
};
fetch('https://platform.ankra.app/org/organisation/{organisation_id}/sso', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));curl --request PUT \
--url https://platform.ankra.app/org/organisation/{organisation_id}/sso \
--header 'Content-Type: application/json' \
--cookie ankra_session= \
--data '
{
"client_id": "<string>",
"issuer": "<string>"
}
'{
"connection": {
"break_glass_user_ids": [
"3c90c3cc-0d44-4b50-8888-8dd25736052a"
],
"client_id": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"enforcement": "optional",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"is_enabled": true,
"issuer": "<string>",
"jit_default_role": "member",
"jit_enabled": true,
"last_login_at": "2023-11-07T05:31:56Z",
"reverify_interval_hours": 360,
"strategy": "oidc",
"updated_at": "2023-11-07T05:31:56Z"
},
"domains": [
{
"domain": "<string>",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"is_verified": true,
"last_checked_at": "2023-11-07T05:31:56Z",
"verification_record_name": "<string>",
"verification_record_value": "<string>",
"verified_at": "2023-11-07T05:31:56Z"
}
],
"group_mappings": [
{
"group": "<string>",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"role": "member"
}
],
"governed_member_count": 123,
"is_available": true,
"redirect_uri": "<string>",
"sign_in_url": "<string>",
"suspended_member_count": 123
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>"
}
]
}Authorizations
Browser session. Mutations also require X-Ankra-CSRF.
Path Parameters
Body
application/json
Response
Single sign-on settings
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Sends somebody straight to the organisation's identity provider. Served on the portal origin, which proxies /auth/* to the API; null until a domain is verified.