Skip to content

Create tenant authentication connection

Creates an OIDC, SAML, LDAP, or social sign-in connection through the existing audited identity service. The submitted secret is write-only and is sealed by the identity service. Requires an idempotency key.

Quire permissions

Required capability: auth/configure.

Credential scopes: tenants:write.

The acting subject must also be allowed to perform this action in the organisation.

POST
https://your-organisation.quirelms.com/api/v1/tenant_auth_connections

Authorisation

  • apiKeyoptionalHTTP
  • oauth2optionalOAuth 2.0

Header parameters

  • Idempotency-Keystringrequired

    A caller-chosen key making this request safe to retry. A replay of a completed request returns the recorded response with Idempotency-Replayed: true. Reusing a key for a different request is refused.

    maxLength: 255
  • Quire-Versionoptionalstring

    The dated API revision to serve this request at. Omitted, the request is served at the revision the credential was issued against. The response echoes the revision actually applied.

    format: date

Request bodyJSONrequired

  • protocoloidcorsamlorldaporsocialrequired
  • provider_keystringrequired
    maxLength: 63, minLength: 1
  • display_namestringrequired
    maxLength: 200, minLength: 1
  • issuerstringrequired
    maxLength: 2000
  • client_idoptionalstring
    maxLength: 500
  • secretoptionalstring

    Write-only provider secret. An empty or omitted value keeps the stored secret on update.

    maxLength: 4000
  • domainsoptionalarray ofstring
    maxLength: 253
  • settingsoptionalmap ofunknown
  • attribute_mappingoptionalmap ofunknown
  • role_mappingoptionalmap ofstring
  • accepted_acr_valuesoptionalarray ofstring
    maxLength: 300, minLength: 1
  • jit_provisioningoptionalboolean
  • idp_initiatedoptionalboolean
  • enabledoptionalboolean

Returns

201

Success.

JSON
  • idstringrequired
    format: uuid, pattern: ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
  • protocoloidcorsamlorldaporsocialrequired
  • provider_keystringrequired
  • display_namestringrequired
  • issuerstringrequired
  • client_idstring | nullrequired
  • secret_configuredbooleanrequired
  • domainsarray ofstringrequired
  • settingsmap ofunknownrequired
  • attribute_mappingmap ofunknownrequired
  • role_mappingmap ofstringrequired
  • accepted_acr_valuesarray ofstringrequired
  • jit_provisioningbooleanrequired
  • idp_initiatedbooleanrequired
  • enabledbooleanrequired
  • certificate_expires_atstringornullrequired
    2 variants

    One of the following:

    • string
    • null
  • last_synced_atstringornullrequired
    2 variants

    One of the following:

    • string
    • null
  • registrationmap ofstringrequired

401

The credential is missing, malformed, expired or revoked.

JSON
  • typestringrequired
    format: uri
  • titlestringrequired
  • statusintegerrequired
  • codestringrequired
  • categoryvalidationorauthenticationorauthorizationornot_foundorconflictorprecondition+4 morerequired
  • detailstringrequired
  • request_idstringrequired
  • docs_urlstringrequired
    format: uri
  • errorsoptionalarray ofobject
    3 properties
    • pathstringrequired

      RFC 6901 JSON Pointer into the request body.

    • codestringrequired
    • detailstringrequired
  • retry_afteroptionalinteger | null

403

The credential lacks the scope this operation requires, or the acting subject lacks the capability.

JSON
  • typestringrequired
    format: uri
  • titlestringrequired
  • statusintegerrequired
  • codestringrequired
  • categoryvalidationorauthenticationorauthorizationornot_foundorconflictorprecondition+4 morerequired
  • detailstringrequired
  • request_idstringrequired
  • docs_urlstringrequired
    format: uri
  • errorsoptionalarray ofobject
    3 properties
    • pathstringrequired

      RFC 6901 JSON Pointer into the request body.

    • codestringrequired
    • detailstringrequired
  • retry_afteroptionalinteger | null

409

The request conflicts with the current state, with a previous use of the same idempotency key, or with a concurrent write.

JSON
  • typestringrequired
    format: uri
  • titlestringrequired
  • statusintegerrequired
  • codestringrequired
  • categoryvalidationorauthenticationorauthorizationornot_foundorconflictorprecondition+4 morerequired
  • detailstringrequired
  • request_idstringrequired
  • docs_urlstringrequired
    format: uri
  • errorsoptionalarray ofobject
    3 properties
    • pathstringrequired

      RFC 6901 JSON Pointer into the request body.

    • codestringrequired
    • detailstringrequired
  • retry_afteroptionalinteger | null

422

The request was understood and its content is not valid. errors names each field.

JSON
  • typestringrequired
    format: uri
  • titlestringrequired
  • statusintegerrequired
  • codestringrequired
  • categoryvalidationorauthenticationorauthorizationornot_foundorconflictorprecondition+4 morerequired
  • detailstringrequired
  • request_idstringrequired
  • docs_urlstringrequired
    format: uri
  • errorsoptionalarray ofobject
    3 properties
    • pathstringrequired

      RFC 6901 JSON Pointer into the request body.

    • codestringrequired
    • detailstringrequired
  • retry_afteroptionalinteger | null

429

A rate limit or a concurrency cap was reached. Retry-After says when to try again.

JSON
  • typestringrequired
    format: uri
  • titlestringrequired
  • statusintegerrequired
  • codestringrequired
  • categoryvalidationorauthenticationorauthorizationornot_foundorconflictorprecondition+4 morerequired
  • detailstringrequired
  • request_idstringrequired
  • docs_urlstringrequired
    format: uri
  • errorsoptionalarray ofobject
    3 properties
    • pathstringrequired

      RFC 6901 JSON Pointer into the request body.

    • codestringrequired
    • detailstringrequired
  • retry_afteroptionalinteger | null

500

Something failed at our end. Quote request_id when reporting it.

JSON
  • typestringrequired
    format: uri
  • titlestringrequired
  • statusintegerrequired
  • codestringrequired
  • categoryvalidationorauthenticationorauthorizationornot_foundorconflictorprecondition+4 morerequired
  • detailstringrequired
  • request_idstringrequired
  • docs_urlstringrequired
    format: uri
  • errorsoptionalarray ofobject
    3 properties
    • pathstringrequired

      RFC 6901 JSON Pointer into the request body.

    • codestringrequired
    • detailstringrequired
  • retry_afteroptionalinteger | null
Navigation

Type to search…

↑↓ navigate↵ selectEsc close