{ "$schema": "https://json-schema.org/draft/2020-12/schema", "$id": "https://raw.githubusercontent.com/api-evangelist/palo-alto-networks/main/json-schema/palo-alto-networks-identity-saml-settings-schema.json", "title": "identity.SamlSettings", "description": "SamlSettings are the saml connectivity settings", "x-generated": "2026-10-04", "x-method": "derived", "x-generator": "derive-json-schema.py", "x-source": "openapi/palo-alto-networks-settings-api-openapi.yml#/components/schemas/identity.SamlSettings", "properties": { "appId": { "description": "AppID is the Azure application ID.\n", "type": "string" }, "appSecret": { "$ref": "#/$defs/common.Secret" }, "audience": { "description": "Audience specifies the SAML audience used in the verification of the SAML response.\n", "type": "string" }, "cert": { "description": "Cert is idp certificate in PEM format.\n", "type": "string" }, "consoleURL": { "description": "ConsoleURL is the external Console URL that is used by the IDP for routing the browser after login.\n", "type": "string" }, "enabled": { "description": "Enabled indicates whether saml settings are enabled.\n", "type": "boolean" }, "groupAttribute": { "description": "GroupAttribute is the name of the group attribute.\n", "type": "string" }, "issuer": { "description": "Issuer is idp issuer id.\n", "type": "string" }, "providerAlias": { "description": "ProviderAlias is the provider alias used for display.\n", "type": "string" }, "skipAuthnContext": { "description": "SkipAuthnContext indicates whether request authentication contexts should be skipped.\n", "type": "boolean" }, "tenantId": { "description": "TenantID is the Azure Tenant ID.\n", "type": "string" }, "type": { "$ref": "#/$defs/identity.SamlType" }, "url": { "description": "URL is idp sso url.\n", "type": "string" } }, "type": "object", "$defs": { "common.Secret": { "description": "Secret Stores the plain and encrypted version of a value. The plain version is not stored in a database", "properties": { "encrypted": { "description": "Specifies an encrypted value of the secret.\n", "type": "string" }, "plain": { "description": "Specifies the plain text value of the secret.\n", "type": "string" } }, "type": "object" }, "identity.SamlType": { "description": "SamlType represents the type of a SAML configured settings", "enum": [ [ "okta", "gsuite", "ping", "shibboleth", "azure", "adfs" ] ], "type": "string" } } }