{ "$schema": "https://json-schema.org/draft/2020-12/schema", "$id": "https://raw.githubusercontent.com/api-evangelist/delinea/main/json-schema/delinea-configuration-saml-identity-provider-model-schema.json", "title": "ConfigurationSamlIdentityProviderModel", "description": "SAML Identity Provider configuration", "x-generated": "2026-10-03", "x-method": "derived", "x-generator": "derive-json-schema.py", "x-source": "openapi/delinea-configuration-api-openapi.yml#/components/schemas/ConfigurationSamlIdentityProviderModel", "properties": { "active": { "description": "Active status of the Identity Provider. Users can only log-in via an active Identity Provider.", "type": "boolean" }, "authnContext": { "description": "When specified, instructs the IDP on how to authenticate the user(optional).", "type": "string" }, "clockSkew": { "description": "The allowed number of minutes of difference between Secret Server's clock and the IDP's clock. The default is 3 minutes.", "type": "integer", "format": "int32" }, "description": { "description": "Description of the Identity Provider.", "type": "string" }, "disableAssertionReplayCheck": { "description": "When true, SAML messages that were already received from this IDP will be allowed by Secret Server. Otherwise, resending messages from the IDP will trigger an error.", "type": "boolean" }, "disableAudienceRestrictionCheck": { "description": "A SAML assertion may include an audience restriction URI. This identifies the intended recipient of the SAML assertion. If included it should match the service provider's name. When this setting is true, this check is skipped.", "type": "boolean" }, "disableAuthnContextCheck": { "description": "Disables the authentication context check, which validates that the real authentication method matches the ExpectedAuthnContext method.", "type": "boolean" }, "disableDestinationCheck": { "description": "When true, the destination URI in the SAML response will not be validated.", "type": "boolean" }, "disableInboundLogout": { "description": "When true, logout requests coming from this IDP are ignored.", "type": "boolean" }, "disableInResponseToCheck": { "description": "When true, the InResponseTo attribute in SAML messages is not checked.", "type": "boolean" }, "disablePendingLogoutCheck": { "description": "When true, a SAML logout response will be considered legitimate even if there was no corresponding logout request.", "type": "boolean" }, "disableRecipientCheck": { "description": "When true, the built-in check against the AssertionConsumerService URL will be skipped.", "type": "boolean" }, "disableTimePeriodCheck": { "description": "When true, a SAML response is valid regardless of when it was sent.", "type": "boolean" }, "displayName": { "description": "The Display Name for the Identity Provider.", "type": "string" }, "domainAttribute": { "description": "Optional AttributeName to use for matching a Secret Server user's domain.", "type": "string" }, "enableDetailedLog": { "description": "When true, a more detailed log will be generated for SAML logins and logouts.", "type": "boolean" }, "enableSLO": { "description": "When true, logging out of Secret Server will log the user out of this Identity Provider.", "type": "boolean" }, "forceAuthentication": { "description": "When true, the Identity Provider will be instructed to re-authenticate the user, even if they are already authenticated.", "type": "boolean" }, "identityProviderId": { "description": "SAML Identity Provider Id", "type": "integer", "format": "int32" }, "logoutRequestLifeTime": { "description": "The logout request life time.", "type": "integer", "format": "int32" }, "name": { "description": "Name of the Identity Provider.", "type": "string" }, "overridePendingAuthnRequest": { "description": "When true, an in-progress SP-initiated login may be interrupted by an IDP-initiated login.", "type": "boolean" }, "publicCertificate": { "description": "The public certificate for the Identity Provider. Base64 encoded", "type": "string" }, "publicCertificateThumbprint": { "description": "The public certificate thumbprint", "type": "string" }, "signAuthnRequest": { "description": "When true, the authentication requests sent to this IDP will be signed.", "type": "boolean" }, "signLogoutRequest": { "description": "When true, logout requests sent to this IDP will be signed.<", "type": "boolean" }, "signLogoutResponse": { "description": "When true, logout responses sent to this IDP will be signed.", "type": "boolean" }, "singleLogoutServiceResponseUrl": { "description": "The URL where Secret Server will send responses to single logout messages.", "type": "string" }, "singleLogoutServiceUrl": { "description": "The URL to send the single logout message to.", "type": "string" }, "ssoServiceBinding": { "description": "Method for communicating with the Identity Provider. HTTPRedirect is recommended in most cases.", "type": "integer", "format": "int32" }, "ssoServiceUrl": { "description": "The URL of the Identity Provider where the user will be sent to authenticate.", "type": "string" }, "usernameAttribute": { "description": "Optional AttributeName to use for matching a Secret Server user.", "type": "string" }, "wantAssertionEncrypted": { "description": "When true, Secret Server will expect SAML assertions from this IDP to be encrypted. Unencrypted assertions or assertions that cannot be decrypted will cause an error.", "type": "boolean" }, "wantAssertionOrResponseSigned": { "description": "When true, Secret Server will expect either SAML assertions or SAML responses from this IDP to be signed. Unsigned assertions/responses and assertions/responses whose signatures cannot be verified will cause an error.", "type": "boolean" }, "wantAssertionSigned": { "description": "When true, Secret Server will expect SAML assertions from this IDP to be signed. Unsigned assertions or assertions whose signatures cannot be verified will cause an error.", "type": "boolean" }, "wantLogoutRequestSigned": { "description": "When true, Secret Server will expect logout requests from this IDP to be signed. Unsigned responses or responses whose signatures cannot be verified will cause an error.", "type": "boolean" }, "wantLogoutResponseSigned": { "description": "When true, Secret Server will expect logout responses from this IDP to be signed. Unsigned responses or responses whose signatures cannot be verified will cause an error.", "type": "boolean" }, "wantSAMLResponseSigned": { "description": "When true, Secret Server will expect SAML responses from this IDP to be signed. Unsigned responses or responses whose signatures cannot be verified will cause an error.", "type": "boolean" } }, "type": "object" }