1. Docs
  2. API Reference
  3. Set up an organization's SSO connection

Set up an organization's SSO connection

POST/api/v1/organizations/{id}/sso-connection

Creates an end_user SSO connection at the Account, links it to the organization's Environment, and binds it to the organization with default_role_id as the membership role, in one call. The connection starts configuring and belongs to this organization: no other organization may bind it. Returns 409 (organization.sso_connection_already_configured) when the organization already has one. Requires hierarchy.manage or canopy:organization.manage at the organization.

Authentication

Bearer TokenAuthorization Option A

JWT access token. Never send alongside X-API-Key: a request carrying both is refused.

API KeyX-API-Key Option B

API key for management-tier access. Never send alongside an Authorization header: a request carrying both is refused.

Path Parameters

idstring Required

Request body

application/json

typeenum Required

one of "saml" · "oidc"

namestring Required

Human label, e.g. "Acme Corp Okta".

saml_entity_idstring Optional
saml_sso_urlstring Optional
saml_slo_urlstring Optional
saml_signing_certstring Optional

IdP X.509 signing certificate (PEM).

saml_signature_algorithmstring Optional
saml_want_assertions_signedboolean Optional
saml_name_id_formatstring Optional
force_authnboolean Optional

Force the IdP to re-authenticate the user on every login (SAML ForceAuthn / OIDC max_age=0). Prevents silent reuse of a stale IdP session on shared devices.

oidc_discovery_urlstring Optional
oidc_client_idstring Optional
oidc_client_secretstring Optional

OIDC client secret (plaintext in; encrypted at rest).

oidc_scopesstring[] Optional
attribute_mappingobject Optional
jit_provisioning_enabledboolean Optional
default_role_idstring Required

The Environment role a person joins the organization with when they first sign in through this connection.

Responses

application/json

  • dataOrganizationSsoConnectionDetailResponseDto*

application/json

  • errorApiErrorBodyDto*

application/json

  • errorApiErrorBodyDto*

application/json

  • errorApiErrorBodyDto*

application/json

  • errorApiErrorBodyDto*

application/json

  • errorApiErrorBodyDto*

Returned object

Request
curl -X POST "https://auth.canopy-io.com/api/v1/organizations/value/sso-connection" \
  -H "X-API-Key: $CANOPY_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "type": "saml",
    "name": "string",
    "saml_entity_id": "string",
    "saml_sso_url": "string",
    "saml_slo_url": "string",
    "saml_signing_cert": "string",
    "saml_signature_algorithm": "string",
    "saml_want_assertions_signed": false,
    "saml_name_id_format": "string",
    "force_authn": false,
    "oidc_discovery_url": "string",
    "oidc_client_id": "string",
    "oidc_client_secret": "string",
    "oidc_scopes": [
      "string"
    ],
    "attribute_mapping": {},
    "jit_provisioning_enabled": false,
    "default_role_id": "string"
  }'
Response
{
  "data": {
    "connection": {
      "id": "string",
      "account_id": "string",
      "scope": "admin",
      "type": "saml",
      "name": "string",
      "status": "configuring",
      "saml_entity_id": "string",
      "saml_sso_url": "string",
      "saml_slo_url": "string",
      "saml_signing_cert": "string",
      "saml_signature_algorithm": "string",
      "saml_want_assertions_signed": false,
      "saml_name_id_format": "string",
      "force_authn": false,
      "oidc_discovery_url": "string",
      "oidc_client_id": "string",
      "oidc_scopes": [
        "string"
      ],
      "has_oidc_client_secret": false,
      "jit_provisioning_enabled": false,
      "attribute_mapping": {},
      "last_login_at": "2026-04-20T12:00:00.000Z",
      "last_login_failure_at": "2026-04-20T12:00:00.000Z",
      "consecutive_failures": 0,
      "auto_disabled_at": "2026-04-20T12:00:00.000Z",
      "created_at": "2026-04-20T12:00:00.000Z",
      "updated_at": "2026-04-20T12:00:00.000Z"
    },
    "default_role": {
      "id": "string",
      "name": "string"
    },
    "owned_by_organization": false,
    "service_provider": {
      "protocol": "saml",
      "acs_url": "string",
      "entity_id": "string",
      "metadata_url": "string",
      "redirect_uri": "string"
    }
  }
}
Related endpoints
GETList organizations
POSTCreate an organization
DELETEDelete every organization
GETGet an organization
PATCHUpdate an organization
DELETEDelete an organization
GETGet an organization's authentication policy
PATCHUpdate an organization's authentication policy
POSTRegenerate the organization's SSO recovery codes
POSTStart a test sign-in on the organization's connection
GETRead the organization's test sign-in
GETList the organization's domain claims
POSTClaim a domain for the organization
POSTVerify one of the organization's domains
DELETERemove one of the organization's domain claims
GETList an organization's SSO connections
POSTBind an SSO connection to an organization
DELETEUnbind an SSO connection from an organization
GETList an organization's members
POSTAdd a member to an organization
PATCHChange a member's role
DELETERemove a member from an organization
GETList an organization's invitations
POSTInvite a member into an organization
GETList the roles an organization may assign
DELETERevoke an organization invitation
GETGet an organization's SSO connection
PATCHChange an organization's SSO connection
DELETERemove an organization's SSO connection
POSTActivate an organization's SSO connection
POSTDisable an organization's SSO connection
POSTImport the identity provider's SAML metadata
GETGet the service-provider values for an organization's SSO connection
Was this page helpful?

Tell us how we can improve this guide.