Ga naar inhoud

Link an identity provider

PUT
/api/v1/settings/idp
curl --request PUT \
--url https://example.com/api/v1/settings/idp \
--header 'Content-Type: application/json' \
--cookie bl_%3Cslug%3E_session=%3Cbl_%3Cslug%3E_session%3E \
--data '{ "issuer": "example", "internal_url": "example", "client_id": "example", "client_secret": "example", "role_claim": "example", "role_mapping": { "additionalProperty": [ "example" ] }, "offline_access": true }'

Links the participant’s own OpenID Connect provider for the login of the UI and of bl. The link is tested first, as POST /api/v1/settings/idp/test does, and refused when a check fails. Without a client secret the current one is kept; without a role mapping the default applies. Another issuer or client ends every session, the caller’s own too; if the new provider then does not let anyone in, an operator with shell access resets the link with connector reset-idp (decisions #80).

Media typeapplication/json

The link with the participant’s OpenID Connect provider.

object
issuer
required

Issuer as seen by browsers (and as it appears in iss).

string
internal_url

Optional base URL used for back-channel calls (discovery, token) when the IdP is reachable under a different name from the server.

string | null
client_id
required
string
client_secret

Write only: never returned.

string | null
role_claim

Dotted path to the roles claim, e.g. realm_access.roles or groups.

string
role_mapping

App role → IdP role names that grant it.

object
key
additional properties
Array<string>
offline_access

Ask for offline_access: an IdP such as Entra ID only gives a refresh token with it. Keycloak gives one without, bound to its session; with it, an offline token that outlives a logout.

boolean

Example generated

{
"issuer": "example",
"internal_url": "example",
"client_id": "example",
"client_secret": "example",
"role_claim": "example",
"role_mapping": {
"additionalProperty": [
"example"
]
},
"offline_access": true
}

OK.

Media typeapplication/json

GET /api/v1/settings/idp: documents the JSON built in [idp_view].

object
One of:
null
configured
required

Whether an identity provider is linked; the other fields only then.

boolean
client_secret_set

A client secret is stored; it is never shown.

boolean | null

Example generated

{
"issuer": "example",
"internal_url": "example",
"client_id": "example",
"client_secret": "example",
"role_claim": "example",
"role_mapping": {
"additionalProperty": [
"example"
]
},
"offline_access": true,
"configured": true,
"client_secret_set": true
}

Issuer or client id missing, or the link fails a check.

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}

No valid session, DPoP-bound token or API key.

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}

The caller lacks the role this operation needs; or a change with the session cookie came from a page of another site (cross_site_request, decisions #83).

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}