---
title: "Read tenant authentication settings"
description: "Returns the tenant sign-in and multi-factor policy, identity provider connection metadata, and roles. Provider secrets are write-only; the response reports only whether a secret is configured.\n\n### Quire permissions\n\nRequired capability: `auth/configure`.\n\nCredential scopes: `tenants:read`.\n\nThe acting subject must also be allowed to perform this action in the organisation."
image: "https://docs.quirelms.com/og.png"
---

> Documentation Index
> Fetch the complete documentation index at: https://docs.quirelms.com/llms.txt
> Use this file to discover all available pages before exploring further.

Path: Quire API › tenants

`GET /tenant_auth_settings`

Returns the tenant sign-in and multi-factor policy, identity provider connection metadata, and roles. Provider secrets are write-only; the response reports only whether a secret is configured.

\### Quire permissions

Required capability: `auth/configure`.

Credential scopes: `tenants:read`.

The acting subject must also be allowed to perform this action in the organisation.

## Authentication

Requires one of the following:

- `apiKey`, http, header `Authorization`, scopes: `tenants:read`
- `oauth2`, oauth2, scopes: `tenants:read`

## Header parameters

- `getTenantAuthSettings.header.Quire-Version` (string, optional) — The dated API revision to serve this request at. Omitted, the request is served at the revision the credential was issued against. The response echoes the revision actually applied.
  - format `date`

## Code samples

### cURL

```curl
curl --request GET \
  --url https://your-organisation.quirelms.com/api/v1/tenant_auth_settings \
  --header 'Authorization: Bearer <token>'
```

### TypeScript

```typescript
const url = 'https://your-organisation.quirelms.com/api/v1/tenant_auth_settings';
const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};

fetch(url, options)
  .then(res => res.json())
  .then(json => console.log(json))
  .catch(err => console.error(err));
```

### Python

```python
import requests

url = "https://your-organisation.quirelms.com/api/v1/tenant_auth_settings"

headers = {"Authorization": "Bearer <token>"}

response = requests.get(url, headers=headers)

print(response.text)
```

## Responses

### 200

Success.

#### Example

```json
{
  "policy": {
    "mode": "off",
    "required_roles": [
      "string"
    ],
    "accepted_acr_values": [
      "string"
    ],
    "cookie_cache_seconds": 0,
    "password_min_length": 0,
    "breach_check_enabled": true,
    "magic_link_minutes": 0,
    "self_registration_enabled": true,
    "self_registration_domains": [
      "string"
    ],
    "self_registration_requires_approval": true,
    "enabled_methods": [
      "password"
    ],
    "mfa_methods": [
      "totp"
    ],
    "password_require_mixed_case": true,
    "password_require_digit": true,
    "password_require_symbol": true,
    "session_idle_minutes": 0,
    "session_absolute_hours": 0,
    "max_concurrent_sessions": 0,
    "guest_access_enabled": true
  },
  "connections": [
    {
      "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
      "protocol": "oidc",
      "provider_key": "string",
      "display_name": "string",
      "issuer": "string",
      "client_id": "string",
      "secret_configured": true,
      "domains": [
        "string"
      ],
      "settings": {
        "property1": null,
        "property2": null
      },
      "attribute_mapping": {
        "property1": null,
        "property2": null
      },
      "role_mapping": {
        "property1": "string",
        "property2": "string"
      },
      "accepted_acr_values": [
        "string"
      ],
      "jit_provisioning": true,
      "idp_initiated": true,
      "enabled": true,
      "certificate_expires_at": "2019-08-24T14:15:22Z",
      "last_synced_at": "2019-08-24T14:15:22Z",
      "registration": {
        "property1": "string",
        "property2": "string"
      }
    }
  ],
  "roles": [
    {
      "short_name": "string",
      "name": "string"
    }
  ]
}
```

- `getTenantAuthSettings.response.200.policy` (object, required)
  - `getTenantAuthSettings.response.200.policy.mode` (string, required)
    - one of `"off"`, `"optional"`, `"required"`, `"required_for_roles"`
  - `getTenantAuthSettings.response.200.policy.required_roles` (array<string>, required)
  - `getTenantAuthSettings.response.200.policy.accepted_acr_values` (array<string>, required)
  - `getTenantAuthSettings.response.200.policy.cookie_cache_seconds` (number, required)
  - `getTenantAuthSettings.response.200.policy.password_min_length` (number, required)
  - `getTenantAuthSettings.response.200.policy.breach_check_enabled` (boolean, required)
  - `getTenantAuthSettings.response.200.policy.magic_link_minutes` (number, required)
  - `getTenantAuthSettings.response.200.policy.self_registration_enabled` (boolean, required)
  - `getTenantAuthSettings.response.200.policy.self_registration_domains` (array<string>, required)
  - `getTenantAuthSettings.response.200.policy.self_registration_requires_approval` (boolean, required)
  - `getTenantAuthSettings.response.200.policy.enabled_methods` (array<string>, required)
    - one of `"password"`, `"magic_link"`, `"passkey"`, `"social"`, `"sso"`, `"ldap"`
  - `getTenantAuthSettings.response.200.policy.mfa_methods` (array<string>, required)
    - one of `"totp"`, `"email_otp"`, `"backup_code"`
  - `getTenantAuthSettings.response.200.policy.password_require_mixed_case` (boolean, required)
  - `getTenantAuthSettings.response.200.policy.password_require_digit` (boolean, required)
  - `getTenantAuthSettings.response.200.policy.password_require_symbol` (boolean, required)
  - `getTenantAuthSettings.response.200.policy.session_idle_minutes` (number | null, required)
  - `getTenantAuthSettings.response.200.policy.session_absolute_hours` (number | null, required)
  - `getTenantAuthSettings.response.200.policy.max_concurrent_sessions` (number | null, required)
  - `getTenantAuthSettings.response.200.policy.guest_access_enabled` (boolean, required)
- `getTenantAuthSettings.response.200.connections` (array<object>, required)
  - `getTenantAuthSettings.response.200.connections.id` (string, required)
    - format `uuid`; pattern `^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$`
  - `getTenantAuthSettings.response.200.connections.protocol` (string, required)
    - one of `"oidc"`, `"saml"`, `"ldap"`, `"social"`
  - `getTenantAuthSettings.response.200.connections.provider_key` (string, required)
  - `getTenantAuthSettings.response.200.connections.display_name` (string, required)
  - `getTenantAuthSettings.response.200.connections.issuer` (string, required)
  - `getTenantAuthSettings.response.200.connections.client_id` (string | null, required)
  - `getTenantAuthSettings.response.200.connections.secret_configured` (boolean, required)
  - `getTenantAuthSettings.response.200.connections.domains` (array<string>, required)
  - `getTenantAuthSettings.response.200.connections.settings` (map<unknown>, required)
  - `getTenantAuthSettings.response.200.connections.attribute_mapping` (map<unknown>, required)
  - `getTenantAuthSettings.response.200.connections.role_mapping` (map<string>, required)
  - `getTenantAuthSettings.response.200.connections.accepted_acr_values` (array<string>, required)
  - `getTenantAuthSettings.response.200.connections.jit_provisioning` (boolean, required)
  - `getTenantAuthSettings.response.200.connections.idp_initiated` (boolean, required)
  - `getTenantAuthSettings.response.200.connections.enabled` (boolean, required)
  - `getTenantAuthSettings.response.200.connections.certificate_expires_at` (any of, required)
    - any of: `string`, `null`
  - `getTenantAuthSettings.response.200.connections.last_synced_at` (any of, required)
    - any of: `string`, `null`
  - `getTenantAuthSettings.response.200.connections.registration` (map<string>, required)
- `getTenantAuthSettings.response.200.roles` (array<object>, required)
  - `getTenantAuthSettings.response.200.roles.short_name` (string, required)
  - `getTenantAuthSettings.response.200.roles.name` (string, required)

### 401

The credential is missing, malformed, expired or revoked.

#### Example

```json
{
  "type": "http://example.com",
  "title": "string",
  "status": 0,
  "code": "string",
  "category": "validation",
  "detail": "string",
  "request_id": "string",
  "errors": [
    {
      "path": "string",
      "code": "string",
      "detail": "string"
    }
  ],
  "retry_after": 0,
  "docs_url": "http://example.com"
}
```

- `getTenantAuthSettings.response.401.type` (string, required)
  - format `uri`
- `getTenantAuthSettings.response.401.title` (string, required)
- `getTenantAuthSettings.response.401.status` (integer, required)
- `getTenantAuthSettings.response.401.code` (string, required)
- `getTenantAuthSettings.response.401.category` (string, required)
  - one of `"validation"`, `"authentication"`, `"authorization"`, `"not_found"`, `"conflict"`, `"precondition"`, `"quota"`, `"rate_limit"`, `"upstream"`, `"internal"`
- `getTenantAuthSettings.response.401.detail` (string, required)
- `getTenantAuthSettings.response.401.request_id` (string, required)
- `getTenantAuthSettings.response.401.docs_url` (string, required)
  - format `uri`
- `getTenantAuthSettings.response.401.errors` (array<object>, optional)
  - `getTenantAuthSettings.response.401.errors.path` (string, required) — RFC 6901 JSON Pointer into the request body.
  - `getTenantAuthSettings.response.401.errors.code` (string, required)
  - `getTenantAuthSettings.response.401.errors.detail` (string, required)
- `getTenantAuthSettings.response.401.retry_after` (integer | null, optional)

### 403

The credential lacks the scope this operation requires, or the acting subject lacks the capability.

#### Example

```json
{
  "type": "http://example.com",
  "title": "string",
  "status": 0,
  "code": "string",
  "category": "validation",
  "detail": "string",
  "request_id": "string",
  "errors": [
    {
      "path": "string",
      "code": "string",
      "detail": "string"
    }
  ],
  "retry_after": 0,
  "docs_url": "http://example.com"
}
```

- `getTenantAuthSettings.response.403.type` (string, required)
  - format `uri`
- `getTenantAuthSettings.response.403.title` (string, required)
- `getTenantAuthSettings.response.403.status` (integer, required)
- `getTenantAuthSettings.response.403.code` (string, required)
- `getTenantAuthSettings.response.403.category` (string, required)
  - one of `"validation"`, `"authentication"`, `"authorization"`, `"not_found"`, `"conflict"`, `"precondition"`, `"quota"`, `"rate_limit"`, `"upstream"`, `"internal"`
- `getTenantAuthSettings.response.403.detail` (string, required)
- `getTenantAuthSettings.response.403.request_id` (string, required)
- `getTenantAuthSettings.response.403.docs_url` (string, required)
  - format `uri`
- `getTenantAuthSettings.response.403.errors` (array<object>, optional)
  - `getTenantAuthSettings.response.403.errors.path` (string, required) — RFC 6901 JSON Pointer into the request body.
  - `getTenantAuthSettings.response.403.errors.code` (string, required)
  - `getTenantAuthSettings.response.403.errors.detail` (string, required)
- `getTenantAuthSettings.response.403.retry_after` (integer | null, optional)

### 422

The request was understood and its content is not valid. `errors` names each field.

#### Example

```json
{
  "type": "http://example.com",
  "title": "string",
  "status": 0,
  "code": "string",
  "category": "validation",
  "detail": "string",
  "request_id": "string",
  "errors": [
    {
      "path": "string",
      "code": "string",
      "detail": "string"
    }
  ],
  "retry_after": 0,
  "docs_url": "http://example.com"
}
```

- `getTenantAuthSettings.response.422.type` (string, required)
  - format `uri`
- `getTenantAuthSettings.response.422.title` (string, required)
- `getTenantAuthSettings.response.422.status` (integer, required)
- `getTenantAuthSettings.response.422.code` (string, required)
- `getTenantAuthSettings.response.422.category` (string, required)
  - one of `"validation"`, `"authentication"`, `"authorization"`, `"not_found"`, `"conflict"`, `"precondition"`, `"quota"`, `"rate_limit"`, `"upstream"`, `"internal"`
- `getTenantAuthSettings.response.422.detail` (string, required)
- `getTenantAuthSettings.response.422.request_id` (string, required)
- `getTenantAuthSettings.response.422.docs_url` (string, required)
  - format `uri`
- `getTenantAuthSettings.response.422.errors` (array<object>, optional)
  - `getTenantAuthSettings.response.422.errors.path` (string, required) — RFC 6901 JSON Pointer into the request body.
  - `getTenantAuthSettings.response.422.errors.code` (string, required)
  - `getTenantAuthSettings.response.422.errors.detail` (string, required)
- `getTenantAuthSettings.response.422.retry_after` (integer | null, optional)

### 429

A rate limit or a concurrency cap was reached. `Retry-After` says when to try again.

#### Example

```json
{
  "type": "http://example.com",
  "title": "string",
  "status": 0,
  "code": "string",
  "category": "validation",
  "detail": "string",
  "request_id": "string",
  "errors": [
    {
      "path": "string",
      "code": "string",
      "detail": "string"
    }
  ],
  "retry_after": 0,
  "docs_url": "http://example.com"
}
```

- `getTenantAuthSettings.response.429.type` (string, required)
  - format `uri`
- `getTenantAuthSettings.response.429.title` (string, required)
- `getTenantAuthSettings.response.429.status` (integer, required)
- `getTenantAuthSettings.response.429.code` (string, required)
- `getTenantAuthSettings.response.429.category` (string, required)
  - one of `"validation"`, `"authentication"`, `"authorization"`, `"not_found"`, `"conflict"`, `"precondition"`, `"quota"`, `"rate_limit"`, `"upstream"`, `"internal"`
- `getTenantAuthSettings.response.429.detail` (string, required)
- `getTenantAuthSettings.response.429.request_id` (string, required)
- `getTenantAuthSettings.response.429.docs_url` (string, required)
  - format `uri`
- `getTenantAuthSettings.response.429.errors` (array<object>, optional)
  - `getTenantAuthSettings.response.429.errors.path` (string, required) — RFC 6901 JSON Pointer into the request body.
  - `getTenantAuthSettings.response.429.errors.code` (string, required)
  - `getTenantAuthSettings.response.429.errors.detail` (string, required)
- `getTenantAuthSettings.response.429.retry_after` (integer | null, optional)

### 500

Something failed at our end. Quote `request_id` when reporting it.

#### Example

```json
{
  "type": "http://example.com",
  "title": "string",
  "status": 0,
  "code": "string",
  "category": "validation",
  "detail": "string",
  "request_id": "string",
  "errors": [
    {
      "path": "string",
      "code": "string",
      "detail": "string"
    }
  ],
  "retry_after": 0,
  "docs_url": "http://example.com"
}
```

- `getTenantAuthSettings.response.500.type` (string, required)
  - format `uri`
- `getTenantAuthSettings.response.500.title` (string, required)
- `getTenantAuthSettings.response.500.status` (integer, required)
- `getTenantAuthSettings.response.500.code` (string, required)
- `getTenantAuthSettings.response.500.category` (string, required)
  - one of `"validation"`, `"authentication"`, `"authorization"`, `"not_found"`, `"conflict"`, `"precondition"`, `"quota"`, `"rate_limit"`, `"upstream"`, `"internal"`
- `getTenantAuthSettings.response.500.detail` (string, required)
- `getTenantAuthSettings.response.500.request_id` (string, required)
- `getTenantAuthSettings.response.500.docs_url` (string, required)
  - format `uri`
- `getTenantAuthSettings.response.500.errors` (array<object>, optional)
  - `getTenantAuthSettings.response.500.errors.path` (string, required) — RFC 6901 JSON Pointer into the request body.
  - `getTenantAuthSettings.response.500.errors.code` (string, required)
  - `getTenantAuthSettings.response.500.errors.detail` (string, required)
- `getTenantAuthSettings.response.500.retry_after` (integer | null, optional)


Source: https://docs.quirelms.com/api/tenants/getTenantAuthSettings/index.md
