openapi: 3.0.3 info: title: Stytch B2B Authentication Application SSO API version: 2.0.0 description: Stytch's B2B API for multi-tenant authentication. Supports Organizations, Members, SSO (SAML/OIDC), Magic Links, OTP, OAuth, Discovery, Sessions, B2B RBAC, SCIM, TOTP, Recovery Codes, Passwords, Impersonation, and the B2B IDP. contact: name: Stytch url: https://stytch.com/docs license: name: Proprietary servers: - url: https://api.stytch.com description: Production - url: https://test.stytch.com description: Test tags: - name: SSO paths: /v1/b2b/sso/{organization_id}: get: summary: Getconnections operationId: api_sso_v1_GetConnections tags: - SSO description: Get all SSO Connections owned by the organization. parameters: - name: organization_id in: path required: true schema: type: string description: Globally unique UUID that identifies a specific Organization. The `organization_id` is critical to perform operations on an Organization, so be sure to preserve this value. You may also use the organization_slug or organization_external_id here as a convenience. description: Globally unique UUID that identifies a specific Organization. The `organization_id` is critical to perform operations on an Organization, so be sure to preserve this value. You may also use the organization_slug or organization_external_id here as a convenience. - name: X-Stytch-Member-Session in: header required: false description: A Stytch session that can be used to run the request with the given member's permissions. schema: type: string - name: X-Stytch-Member-SessionJWT in: header required: false description: A Stytch Session JSON Web Token (JWT) that can be used to run the request with the given member's permissions. schema: type: string responses: '200': description: Successful response content: application/json: schema: $ref: '#/components/schemas/api_sso_v1_GetConnectionsResponse' '400': description: Bad request '401': description: Unauthorized content: application/json: example: status_code: 401 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: unauthorized_credentials error_message: Unauthorized credentials. error_url: https://stytch.com/docs/api/errors/401 '429': description: Too Many Requests content: application/json: example: status_code: 429 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: too_many_requests error_message: Too many requests have been made. error_url: https://stytch.com/docs/api/errors/429 '500': description: Internal server error content: application/json: example: status_code: 500 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: internal_server_error error_message: Oops, something seems to have gone wrong, please reach out to support@stytch.com to let us know what went wrong. error_url: https://stytch.com/docs/api/errors/500 x-code-samples: - lang: csharp label: C# source: "// GET /v1/b2b/sso/{organization_id}\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n organization_id: \"${organizationId}\",\n};\n\nconst options = {\n authorization: {\n session_token: '${sessionToken}',\n },\n};\n\nclient.SSO.GetConnections(params, options)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: go label: Go source: "// GET /v1/b2b/sso/{organization_id}\npackage main\n\nimport (\n\t\"context\"\n\t\"log\"\n\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/b2bstytchapi\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/sso\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/methodoptions\"\n)\n\nfunc main() {\n\tclient, err := b2bstytchapi.NewClient(\n\t\t\"${projectId}\",\n\t\t\"${secret}\",\n\t)\n\tif err != nil {\n\t\tlog.Fatalf(\"error instantiating client: %v\", err)\n\t}\n\n\tparams := &sso.GetConnectionsParams{\n\t\tOrganizationID: \"${organizationId}\",\n\t}\n\n\toptions := &sso.GetConnectionsParamsOptions{\n\t\tAuthorization: methodoptions.Authorization{\n\t\t\tSessionToken: \"${sessionToken}\",\n\t\t},\n\t}\n\n\tresp, err := client.SSO.GetConnections(context.Background(), params, options)\n\tif err != nil {\n\t\tlog.Fatalf(\"error in method call: %v\", err)\n\t}\n\n\tlog.Println(resp)\n}\n" - lang: java label: Java source: "// GET /v1/b2b/sso/{organization_id}\npackage com.example;\n\nimport com.stytch.java.b2b.models.sso.GetConnectionsRequest;\nimport com.stytch.java.b2b.models.sso.GetConnectionsRequestOptions;\nimport com.stytch.java.b2b.StytchB2BClient;\nimport com.stytch.java.common.methodoptions.Authorization;\nimport com.stytch.java.common.StytchResult;\n\npublic class Main {\n public static void main(String[] args) {\n StytchB2BClient.configure(\"${projectId}\", \"${secret}\");\n\n GetConnectionsRequest params = new GetConnectionsRequest();\n params.setOrganizationId(\"${organizationId}\");\n\n GetConnectionsRequestOptions options = new GetConnectionsRequestOptions();\n Authorization authorization = new Authorization();\n authorization.setSessionToken(\"${sessionToken}\");\n options.setAuthorization(authorization);\n\n Object result = StytchB2BClient.getSSO().getConnections(params, options);\n if (result instanceof StytchResult.Success) {\n System.out.println(((StytchResult.Success) result).getValue());\n } else {\n System.out.println(((StytchResult.Error) result).getException());\n }\n }\n}" - lang: kotlin label: Kotlin source: "// GET /v1/b2b/sso/{organization_id}\npackage com.example\n\nimport com.stytch.java.b2b.StytchB2BClient\nimport com.stytch.java.b2b.models.sso.GetConnectionsRequest\nimport com.stytch.java.b2b.models.sso.GetConnectionsRequestOptions\nimport com.stytch.java.common.methodoptions.Authorization\n\nfun main() {\n StytchB2BClient.configure(\n projectId = \"${projectId}\",\n secret = \"${secret}\",\n )\n\n when (\n val result =\n StytchB2BClient.sso.getConnections(\n GetConnectionsRequest(\n organizationId = \"${organizationId}\",\n ),\n GetConnectionsRequestOptions(\n Authorization(\n sessionToken = \"${sessionToken}\",\n ),\n ),\n )\n ) {\n is StytchResult.Success -> println(result.value)\n is StytchResult.Error -> println(result.exception)\n }\n}\n" - lang: javascript label: Node.js source: "// GET /v1/b2b/sso/{organization_id}\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n organization_id: \"${organizationId}\",\n};\n\nconst options = {\n authorization: {\n session_token: '${sessionToken}',\n },\n};\n\nclient.sso.getConnections(params, options)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: php label: PHP source: "$response = $client->sso->get_connections([\n 'organization_id' => '${organizationId}',\n], [\n 'authorization' => ['session_token' => '${sessionToken}'],\n\n]);" - lang: python label: Python source: "# GET /v1/b2b/sso/{organization_id}\nfrom stytch import B2BClient\nfrom stytch.b2b.models.sso import GetConnectionsRequestOptions\nfrom stytch.shared.method_options import Authorization\n\nclient = B2BClient(\n project_id=\"${projectId}\",\n secret=\"${secret}\",\n)\n\nresp = client.sso.get_connections(\n organization_id=\"${organizationId}\",\n method_options=GetConnectionsRequestOptions(\n authorization=Authorization(\n session_token=\"${sessionToken}\",\n ),\n ),\n)\n\nprint(resp)\n" - lang: ruby label: Ruby source: "# GET /v1/b2b/sso/{organization_id}\nrequire 'stytch'\n\nclient = StytchB2B::Client.new(\n project_id: \"${projectId}\",\n secret: \"${secret}\"\n)\n\nresp = client.sso.get_connections(\n organization_id: \"${organizationId}\",\n method_options: StytchB2B::SSO::GetConnectionsRequestOptions.new(\n authorization: Stytch::MethodOptions::Authorization.new(session_token: '${sessionToken}')\n )\n)\n\nputs resp" - lang: rust label: Rust source: "// GET /v1/b2b/sso/{organization_id}\nuse stytch::b2b::client::Client;\nuse stytch::b2b::sso::GetConnectionsRequest;\n\nfn main() {\n let client = Client::new(\"${projectId}\", \"${secret}\").unwrap();\n let resp = client.sso.get_connections(\n GetConnectionsRequest{\n organization_id: \"${organizationId}\",\n ..Default::default()\n }\n ).await;\n println!(\"The response is {:?}\", resp);\n}" - lang: bash label: cURL source: "# GET /v1/b2b/sso/{organization_id}\ncurl --request GET \\\n --url https://test.stytch.com/v1/b2b/sso/${organizationId} \\\n -u '${projectId}:${secret}' \\\n -H 'Content-Type: application/json' \\\n -H \"X-Stytch-Member-Session: ${sessionToken}\"" /v1/b2b/sso/{organization_id}/connections/{connection_id}: delete: summary: Deleteconnection operationId: api_sso_v1_DeleteConnection tags: - SSO description: Delete an existing SSO connection. parameters: - name: organization_id in: path required: true schema: type: string description: The organization ID that the SSO connection belongs to. You may also use the organization_slug or organization_external_id here as a convenience. description: The organization ID that the SSO connection belongs to. You may also use the organization_slug or organization_external_id here as a convenience. - name: connection_id in: path required: true schema: type: string description: The ID of the SSO connection. SAML, OIDC, and External connection IDs can be provided. description: The ID of the SSO connection. SAML, OIDC, and External connection IDs can be provided. - name: X-Stytch-Member-Session in: header required: false description: A Stytch session that can be used to run the request with the given member's permissions. schema: type: string - name: X-Stytch-Member-SessionJWT in: header required: false description: A Stytch Session JSON Web Token (JWT) that can be used to run the request with the given member's permissions. schema: type: string responses: '200': description: Successful response content: application/json: schema: $ref: '#/components/schemas/api_sso_v1_DeleteConnectionResponse' '400': description: Bad request '401': description: Unauthorized content: application/json: example: status_code: 401 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: unauthorized_credentials error_message: Unauthorized credentials. error_url: https://stytch.com/docs/api/errors/401 '429': description: Too Many Requests content: application/json: example: status_code: 429 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: too_many_requests error_message: Too many requests have been made. error_url: https://stytch.com/docs/api/errors/429 '500': description: Internal server error content: application/json: example: status_code: 500 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: internal_server_error error_message: Oops, something seems to have gone wrong, please reach out to support@stytch.com to let us know what went wrong. error_url: https://stytch.com/docs/api/errors/500 x-code-samples: - lang: csharp label: C# source: "// DELETE /v1/b2b/sso/{organization_id}/connections/{connection_id}\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n organization_id: \"${organizationId}\",\n connection_id: \"${samlConnectionId}\",\n};\n\nconst options = {\n authorization: {\n session_token: '${sessionToken}',\n },\n};\n\nclient.SSO.DeleteConnection(params, options)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: go label: Go source: "// DELETE /v1/b2b/sso/{organization_id}/connections/{connection_id}\npackage main\n\nimport (\n\t\"context\"\n\t\"log\"\n\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/b2bstytchapi\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/sso\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/methodoptions\"\n)\n\nfunc main() {\n\tclient, err := b2bstytchapi.NewClient(\n\t\t\"${projectId}\",\n\t\t\"${secret}\",\n\t)\n\tif err != nil {\n\t\tlog.Fatalf(\"error instantiating client: %v\", err)\n\t}\n\n\tparams := &sso.DeleteConnectionParams{\n\t\tOrganizationID: \"${organizationId}\",\n\t\tConnectionID: \"${samlConnectionId}\",\n\t}\n\n\toptions := &sso.DeleteConnectionParamsOptions{\n\t\tAuthorization: methodoptions.Authorization{\n\t\t\tSessionToken: \"${sessionToken}\",\n\t\t},\n\t}\n\n\tresp, err := client.SSO.DeleteConnection(context.Background(), params, options)\n\tif err != nil {\n\t\tlog.Fatalf(\"error in method call: %v\", err)\n\t}\n\n\tlog.Println(resp)\n}\n" - lang: java label: Java source: "// DELETE /v1/b2b/sso/{organization_id}/connections/{connection_id}\npackage com.example;\n\nimport com.stytch.java.b2b.models.sso.DeleteConnectionRequest;\nimport com.stytch.java.b2b.models.sso.DeleteConnectionRequestOptions;\nimport com.stytch.java.b2b.StytchB2BClient;\nimport com.stytch.java.common.methodoptions.Authorization;\nimport com.stytch.java.common.StytchResult;\n\npublic class Main {\n public static void main(String[] args) {\n StytchB2BClient.configure(\"${projectId}\", \"${secret}\");\n\n DeleteConnectionRequest params = new DeleteConnectionRequest();\n params.setOrganizationId(\"${organizationId}\");\n params.setConnectionId(\"${samlConnectionId}\");\n\n DeleteConnectionRequestOptions options = new DeleteConnectionRequestOptions();\n Authorization authorization = new Authorization();\n authorization.setSessionToken(\"${sessionToken}\");\n options.setAuthorization(authorization);\n\n Object result = StytchB2BClient.getSSO().deleteConnection(params, options);\n if (result instanceof StytchResult.Success) {\n System.out.println(((StytchResult.Success) result).getValue());\n } else {\n System.out.println(((StytchResult.Error) result).getException());\n }\n }\n}" - lang: kotlin label: Kotlin source: "// DELETE /v1/b2b/sso/{organization_id}/connections/{connection_id}\npackage com.example\n\nimport com.stytch.java.b2b.StytchB2BClient\nimport com.stytch.java.b2b.models.sso.DeleteConnectionRequest\nimport com.stytch.java.b2b.models.sso.DeleteConnectionRequestOptions\nimport com.stytch.java.common.methodoptions.Authorization\n\nfun main() {\n StytchB2BClient.configure(\n projectId = \"${projectId}\",\n secret = \"${secret}\",\n )\n\n when (\n val result =\n StytchB2BClient.sso.deleteConnection(\n DeleteConnectionRequest(\n organizationId = \"${organizationId}\",\n connectionId = \"${samlConnectionId}\",\n ),\n DeleteConnectionRequestOptions(\n Authorization(\n sessionToken = \"${sessionToken}\",\n ),\n ),\n )\n ) {\n is StytchResult.Success -> println(result.value)\n is StytchResult.Error -> println(result.exception)\n }\n}\n" - lang: javascript label: Node.js source: "// DELETE /v1/b2b/sso/{organization_id}/connections/{connection_id}\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n organization_id: \"${organizationId}\",\n connection_id: \"${samlConnectionId}\",\n};\n\nconst options = {\n authorization: {\n session_token: '${sessionToken}',\n },\n};\n\nclient.sso.deleteConnection(params, options)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: php label: PHP source: "$response = $client->sso->delete_connection([\n 'organization_id' => '${organizationId}',\n 'connection_id' => '${samlConnectionId}',\n], [\n 'authorization' => ['session_token' => '${sessionToken}'],\n\n]);" - lang: python label: Python source: "# DELETE /v1/b2b/sso/{organization_id}/connections/{connection_id}\nfrom stytch import B2BClient\nfrom stytch.b2b.models.sso import DeleteConnectionRequestOptions\nfrom stytch.shared.method_options import Authorization\n\nclient = B2BClient(\n project_id=\"${projectId}\",\n secret=\"${secret}\",\n)\n\nresp = client.sso.delete_connection(\n organization_id=\"${organizationId}\",\n connection_id=\"${samlConnectionId}\",\n method_options=DeleteConnectionRequestOptions(\n authorization=Authorization(\n session_token=\"${sessionToken}\",\n ),\n ),\n)\n\nprint(resp)\n" - lang: ruby label: Ruby source: "# DELETE /v1/b2b/sso/{organization_id}/connections/{connection_id}\nrequire 'stytch'\n\nclient = StytchB2B::Client.new(\n project_id: \"${projectId}\",\n secret: \"${secret}\"\n)\n\nresp = client.sso.delete_connection(\n organization_id: \"${organizationId}\",\n connection_id: \"${samlConnectionId}\",\n method_options: StytchB2B::SSO::DeleteConnectionRequestOptions.new(\n authorization: Stytch::MethodOptions::Authorization.new(session_token: '${sessionToken}')\n )\n)\n\nputs resp" - lang: rust label: Rust source: "// DELETE /v1/b2b/sso/{organization_id}/connections/{connection_id}\nuse stytch::b2b::client::Client;\nuse stytch::b2b::sso::DeleteConnectionRequest;\n\nfn main() {\n let client = Client::new(\"${projectId}\", \"${secret}\").unwrap();\n let resp = client.sso.delete_connection(\n DeleteConnectionRequest{\n organization_id: \"${organizationId}\",\n connection_id: \"${samlConnectionId}\",\n ..Default::default()\n }\n ).await;\n println!(\"The response is {:?}\", resp);\n}" - lang: bash label: cURL source: "# DELETE /v1/b2b/sso/{organization_id}/connections/{connection_id}\ncurl --request DELETE \\\n --url https://test.stytch.com/v1/b2b/sso/${organizationId}/connections/${samlConnectionId} \\\n -u '${projectId}:${secret}' \\\n -H 'Content-Type: application/json' \\\n -H \"X-Stytch-Member-Session: ${sessionToken}\"" /v1/b2b/sso/authenticate: post: summary: Authenticate operationId: api_sso_v1_Authenticate tags: - SSO description: "Authenticate a user given a token. \nThis endpoint verifies that the user completed the SSO Authentication flow by verifying that the token is valid and hasn't expired.\nProvide the `session_duration_minutes` parameter to set the lifetime of the session. \nIf the `session_duration_minutes` parameter is not specified, a Stytch session will be created with a 60 minute duration.\nTo link this authentication event to an existing Stytch session, include either the `session_token` or `session_jwt` param.\n\nIf the Member is required to complete MFA to log in to the Organization, the returned value of `member_authenticated` will be `false`, and an `intermediate_session_token` will be returned.\nThe `intermediate_session_token` can be passed into the [OTP SMS Authenticate endpoint](https://stytch.com/docs/b2b/api/authenticate-otp-sms), [TOTP Authenticate endpoint](https://stytch.com/docs/b2b/api/authenticate-totp),\nor [Recovery Codes Recover endpoint](https://stytch.com/docs/b2b/api/recovery-codes-recover) to complete the MFA step and acquire a full member session.\nThe `session_duration_minutes` and `session_custom_claims` parameters will be ignored.\n\nIf a valid `session_token` or `session_jwt` is passed in, the Member will not be required to complete an MFA step." requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/api_sso_v1_AuthenticateRequest' responses: '200': description: Successful response content: application/json: schema: $ref: '#/components/schemas/api_sso_v1_AuthenticateResponse' '400': description: Bad request '401': description: Unauthorized content: application/json: example: status_code: 401 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: unauthorized_credentials error_message: Unauthorized credentials. error_url: https://stytch.com/docs/api/errors/401 '429': description: Too Many Requests content: application/json: example: status_code: 429 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: too_many_requests error_message: Too many requests have been made. error_url: https://stytch.com/docs/api/errors/429 '500': description: Internal server error content: application/json: example: status_code: 500 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: internal_server_error error_message: Oops, something seems to have gone wrong, please reach out to support@stytch.com to let us know what went wrong. error_url: https://stytch.com/docs/api/errors/500 x-code-samples: - lang: csharp label: C# source: "// POST /v1/b2b/sso/authenticate\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n sso_token: \"${token}\",\n};\n\nclient.SSO.Authenticate(params)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: go label: Go source: "// POST /v1/b2b/sso/authenticate\npackage main\n\nimport (\n\t\"context\"\n\t\"log\"\n\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/b2bstytchapi\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/sso\"\n)\n\nfunc main() {\n\tclient, err := b2bstytchapi.NewClient(\n\t\t\"${projectId}\",\n\t\t\"${secret}\",\n\t)\n\tif err != nil {\n\t\tlog.Fatalf(\"error instantiating client: %v\", err)\n\t}\n\n\tparams := &sso.AuthenticateParams{\n\t\tSSOToken: \"${token}\",\n\t}\n\n\tresp, err := client.SSO.Authenticate(context.Background(), params)\n\tif err != nil {\n\t\tlog.Fatalf(\"error in method call: %v\", err)\n\t}\n\n\tlog.Println(resp)\n}\n" - lang: java label: Java source: "// POST /v1/b2b/sso/authenticate\npackage com.example;\n\nimport com.stytch.java.b2b.models.sso.AuthenticateRequest;\nimport com.stytch.java.b2b.StytchB2BClient;\nimport com.stytch.java.common.StytchResult;\n\npublic class Main {\n public static void main(String[] args) {\n StytchB2BClient.configure(\"${projectId}\", \"${secret}\");\n\n AuthenticateRequest params = new AuthenticateRequest();\n params.setSSOToken(\"${token}\");\n\n Object result = StytchB2BClient.getSSO().authenticate(params);\n if (result instanceof StytchResult.Success) {\n System.out.println(((StytchResult.Success) result).getValue());\n } else {\n System.out.println(((StytchResult.Error) result).getException());\n }\n }\n}" - lang: kotlin label: Kotlin source: "// POST /v1/b2b/sso/authenticate\npackage com.example\n\nimport com.stytch.java.b2b.StytchB2BClient\nimport com.stytch.java.b2b.models.sso.AuthenticateRequest\n\nfun main() {\n StytchB2BClient.configure(\n projectId = \"${projectId}\",\n secret = \"${secret}\",\n )\n\n when (\n val result =\n StytchB2BClient.sso.authenticate(\n AuthenticateRequest(\n ssoToken = \"${token}\",\n ),\n )\n ) {\n is StytchResult.Success -> println(result.value)\n is StytchResult.Error -> println(result.exception)\n }\n}\n" - lang: javascript label: Node.js source: "// POST /v1/b2b/sso/authenticate\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n sso_token: \"${token}\",\n};\n\nclient.sso.authenticate(params)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: php label: PHP source: "$response = $client->sso->authenticate([\n 'sso_token' => '${token}',\n]);" - lang: python label: Python source: "# POST /v1/b2b/sso/authenticate\nfrom stytch import B2BClient\n\nclient = B2BClient(\n project_id=\"${projectId}\",\n secret=\"${secret}\",\n)\n\nresp = client.sso.authenticate(\n sso_token=\"${token}\",\n)\n\nprint(resp)\n" - lang: ruby label: Ruby source: "# POST /v1/b2b/sso/authenticate\nrequire 'stytch'\n\nclient = StytchB2B::Client.new(\n project_id: \"${projectId}\",\n secret: \"${secret}\"\n)\n\nresp = client.sso.authenticate(\n sso_token: \"${token}\"\n \n)\n\nputs resp" - lang: rust label: Rust source: "// POST /v1/b2b/sso/authenticate\nuse stytch::b2b::client::Client;\nuse stytch::b2b::sso::AuthenticateRequest;\n\nfn main() {\n let client = Client::new(\"${projectId}\", \"${secret}\").unwrap();\n let resp = client.sso.authenticate(\n AuthenticateRequest{\n sso_token: \"${token}\",\n ..Default::default()\n }\n ).await;\n println!(\"The response is {:?}\", resp);\n}" - lang: bash label: cURL source: "# POST /v1/b2b/sso/authenticate\ncurl --request POST \\\n --url https://test.stytch.com/v1/b2b/sso/authenticate \\\n -u '${projectId}:${secret}' \\\n -H 'Content-Type: application/json' \\\n -d '{\n \"sso_token\": \"${token}\"\n }'" /v1/b2b/sso/oidc/{organization_id}: post: summary: Createconnection operationId: api_sso_v1_sso_oidc_CreateConnection tags: - SSO description: Create a new OIDC Connection. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/api_sso_v1_sso_oidc_CreateConnectionRequest' parameters: - name: organization_id in: path required: true schema: type: string description: Globally unique UUID that identifies a specific Organization. The `organization_id` is critical to perform operations on an Organization, so be sure to preserve this value. You may also use the organization_slug or organization_external_id here as a convenience. description: Globally unique UUID that identifies a specific Organization. The `organization_id` is critical to perform operations on an Organization, so be sure to preserve this value. You may also use the organization_slug or organization_external_id here as a convenience. - name: X-Stytch-Member-Session in: header required: false description: A Stytch session that can be used to run the request with the given member's permissions. schema: type: string - name: X-Stytch-Member-SessionJWT in: header required: false description: A Stytch Session JSON Web Token (JWT) that can be used to run the request with the given member's permissions. schema: type: string responses: '200': description: Successful response content: application/json: schema: $ref: '#/components/schemas/api_sso_v1_sso_oidc_CreateConnectionResponse' '400': description: Bad request '401': description: Unauthorized content: application/json: example: status_code: 401 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: unauthorized_credentials error_message: Unauthorized credentials. error_url: https://stytch.com/docs/api/errors/401 '429': description: Too Many Requests content: application/json: example: status_code: 429 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: too_many_requests error_message: Too many requests have been made. error_url: https://stytch.com/docs/api/errors/429 '500': description: Internal server error content: application/json: example: status_code: 500 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: internal_server_error error_message: Oops, something seems to have gone wrong, please reach out to support@stytch.com to let us know what went wrong. error_url: https://stytch.com/docs/api/errors/500 x-code-samples: - lang: csharp label: C# source: "// POST /v1/b2b/sso/oidc/{organization_id}\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n organization_id: \"${organizationId}\",\n display_name: \"Example OIDC connection\",\n};\n\nconst options = {\n authorization: {\n session_token: '${sessionToken}',\n },\n};\n\nclient.SSO.OIDC.CreateConnection(params, options)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: go label: Go source: "// POST /v1/b2b/sso/oidc/{organization_id}\npackage main\n\nimport (\n\t\"context\"\n\t\"log\"\n\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/b2bstytchapi\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/sso/oidc\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/methodoptions\"\n)\n\nfunc main() {\n\tclient, err := b2bstytchapi.NewClient(\n\t\t\"${projectId}\",\n\t\t\"${secret}\",\n\t)\n\tif err != nil {\n\t\tlog.Fatalf(\"error instantiating client: %v\", err)\n\t}\n\n\tparams := &oidc.CreateConnectionParams{\n\t\tOrganizationID: \"${organizationId}\",\n\t\tDisplayName: \"Example OIDC connection\",\n\t}\n\n\toptions := &oidc.CreateConnectionParamsOptions{\n\t\tAuthorization: methodoptions.Authorization{\n\t\t\tSessionToken: \"${sessionToken}\",\n\t\t},\n\t}\n\n\tresp, err := client.SSO.OIDC.CreateConnection(context.Background(), params, options)\n\tif err != nil {\n\t\tlog.Fatalf(\"error in method call: %v\", err)\n\t}\n\n\tlog.Println(resp)\n}\n" - lang: java label: Java source: "// POST /v1/b2b/sso/oidc/{organization_id}\npackage com.example;\n\nimport com.stytch.java.b2b.models.ssooidc.CreateConnectionRequest;\nimport com.stytch.java.b2b.models.ssooidc.CreateConnectionRequestOptions;\nimport com.stytch.java.b2b.StytchB2BClient;\nimport com.stytch.java.common.methodoptions.Authorization;\nimport com.stytch.java.common.StytchResult;\n\npublic class Main {\n public static void main(String[] args) {\n StytchB2BClient.configure(\"${projectId}\", \"${secret}\");\n\n CreateConnectionRequest params = new CreateConnectionRequest();\n params.setOrganizationId(\"${organizationId}\");\n params.setDisplayName(\"Example OIDC connection\");\n\n CreateConnectionRequestOptions options = new CreateConnectionRequestOptions();\n Authorization authorization = new Authorization();\n authorization.setSessionToken(\"${sessionToken}\");\n options.setAuthorization(authorization);\n\n Object result = StytchB2BClient.getSSO().getOIDC().createConnection(params, options);\n if (result instanceof StytchResult.Success) {\n System.out.println(((StytchResult.Success) result).getValue());\n } else {\n System.out.println(((StytchResult.Error) result).getException());\n }\n }\n}" - lang: kotlin label: Kotlin source: "// POST /v1/b2b/sso/oidc/{organization_id}\npackage com.example\n\nimport com.stytch.java.b2b.StytchB2BClient\nimport com.stytch.java.b2b.models.ssooidc.CreateConnectionRequest\nimport com.stytch.java.b2b.models.ssooidc.CreateConnectionRequestOptions\nimport com.stytch.java.common.methodoptions.Authorization\n\nfun main() {\n StytchB2BClient.configure(\n projectId = \"${projectId}\",\n secret = \"${secret}\",\n )\n\n when (\n val result =\n StytchB2BClient.sso.oidc.createConnection(\n CreateConnectionRequest(\n organizationId = \"${organizationId}\",\n displayName = \"Example OIDC connection\",\n ),\n CreateConnectionRequestOptions(\n Authorization(\n sessionToken = \"${sessionToken}\",\n ),\n ),\n )\n ) {\n is StytchResult.Success -> println(result.value)\n is StytchResult.Error -> println(result.exception)\n }\n}\n" - lang: javascript label: Node.js source: "// POST /v1/b2b/sso/oidc/{organization_id}\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n organization_id: \"${organizationId}\",\n display_name: \"Example OIDC connection\",\n};\n\nconst options = {\n authorization: {\n session_token: '${sessionToken}',\n },\n};\n\nclient.sso.oidc.createConnection(params, options)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: php label: PHP source: "$response = $client->sso->oidc->create_connection([\n 'organization_id' => '${organizationId}',\n 'display_name' => 'Example OIDC connection',\n], [\n 'authorization' => ['session_token' => '${sessionToken}'],\n\n]);" - lang: python label: Python source: "# POST /v1/b2b/sso/oidc/{organization_id}\nfrom stytch import B2BClient\nfrom stytch.b2b.models.sso_oidc import CreateConnectionRequestOptions\nfrom stytch.shared.method_options import Authorization\n\nclient = B2BClient(\n project_id=\"${projectId}\",\n secret=\"${secret}\",\n)\n\nresp = client.sso.oidc.create_connection(\n organization_id=\"${organizationId}\",\n display_name=\"Example OIDC connection\",\n method_options=CreateConnectionRequestOptions(\n authorization=Authorization(\n session_token=\"${sessionToken}\",\n ),\n ),\n)\n\nprint(resp)\n" - lang: ruby label: Ruby source: "# POST /v1/b2b/sso/oidc/{organization_id}\nrequire 'stytch'\n\nclient = StytchB2B::Client.new(\n project_id: \"${projectId}\",\n secret: \"${secret}\"\n)\n\nresp = client.sso.oidc.create_connection(\n organization_id: \"${organizationId}\",\n display_name: \"Example OIDC connection\",\n method_options: StytchB2B::SSO::OIDC::CreateConnectionRequestOptions.new(\n authorization: Stytch::MethodOptions::Authorization.new(session_token: '${sessionToken}')\n )\n)\n\nputs resp" - lang: rust label: Rust source: "// POST /v1/b2b/sso/oidc/{organization_id}\nuse stytch::b2b::client::Client;\nuse stytch::b2b::sso_oidc::CreateConnectionRequest;\n\nfn main() {\n let client = Client::new(\"${projectId}\", \"${secret}\").unwrap();\n let resp = client.sso.oidc.create_connection(\n CreateConnectionRequest{\n organization_id: \"${organizationId}\",\n display_name: Some(String::from(\"Example OIDC connection\")),\n ..Default::default()\n }\n ).await;\n println!(\"The response is {:?}\", resp);\n}" - lang: bash label: cURL source: "# POST /v1/b2b/sso/oidc/{organization_id}\ncurl --request POST \\\n --url https://test.stytch.com/v1/b2b/sso/oidc/${organizationId} \\\n -u '${projectId}:${secret}' \\\n -H 'Content-Type: application/json' \\\n -H \"X-Stytch-Member-Session: ${sessionToken}\" \\\n -d '{\n \"display_name\": \"Example OIDC connection\"\n }'" /v1/b2b/sso/oidc/{organization_id}/connections/{connection_id}: put: summary: Updateconnection operationId: api_sso_v1_sso_oidc_UpdateConnection tags: - SSO description: "Updates an existing OIDC connection.\n\nWhen the value of `issuer` changes, Stytch will attempt to retrieve the [OpenID Provider Metadata](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata) document found at `$/.well-known/openid-configuration`.\nIf the metadata document can be retrieved successfully, Stytch will use it to infer the values of `authorization_url`, `token_url`, `jwks_url`, and `userinfo_url`.\nThe `client_id` and `client_secret` values cannot be inferred from the metadata document, and *must* be passed in explicitly.\n\nIf the metadata document cannot be retrieved, Stytch will still update the connection using values from the request body.\n\nIf the metadata document can be retrieved, and values are passed in the request body, the explicit values passed in from the request body will take precedence over the values inferred from the metadata document. \n\nNote that a newly created connection will not become active until all of the following fields are provided:\n* `issuer`\n* `client_id`\n* `client_secret`\n* `authorization_url`\n* `token_url`\n* `userinfo_url`\n* `jwks_url`" requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/api_sso_v1_sso_oidc_UpdateConnectionRequest' parameters: - name: organization_id in: path required: true schema: type: string description: Globally unique UUID that identifies a specific Organization. The `organization_id` is critical to perform operations on an Organization, so be sure to preserve this value. You may also use the organization_slug or organization_external_id here as a convenience. description: Globally unique UUID that identifies a specific Organization. The `organization_id` is critical to perform operations on an Organization, so be sure to preserve this value. You may also use the organization_slug or organization_external_id here as a convenience. - name: connection_id in: path required: true schema: type: string description: Globally unique UUID that identifies a specific SSO `connection_id` for a Member. description: Globally unique UUID that identifies a specific SSO `connection_id` for a Member. - name: X-Stytch-Member-Session in: header required: false description: A Stytch session that can be used to run the request with the given member's permissions. schema: type: string - name: X-Stytch-Member-SessionJWT in: header required: false description: A Stytch Session JSON Web Token (JWT) that can be used to run the request with the given member's permissions. schema: type: string responses: '200': description: Successful response content: application/json: schema: $ref: '#/components/schemas/api_sso_v1_sso_oidc_UpdateConnectionResponse' '400': description: Bad request '401': description: Unauthorized content: application/json: example: status_code: 401 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: unauthorized_credentials error_message: Unauthorized credentials. error_url: https://stytch.com/docs/api/errors/401 '429': description: Too Many Requests content: application/json: example: status_code: 429 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: too_many_requests error_message: Too many requests have been made. error_url: https://stytch.com/docs/api/errors/429 '500': description: Internal server error content: application/json: example: status_code: 500 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: internal_server_error error_message: Oops, something seems to have gone wrong, please reach out to support@stytch.com to let us know what went wrong. error_url: https://stytch.com/docs/api/errors/500 x-code-samples: - lang: csharp label: C# source: "// PUT /v1/b2b/sso/oidc/{organization_id}/connections/{connection_id}\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n organization_id: \"${organizationId}\",\n connection_id: \"${oidcConnectionId}\",\n client_id: \"${exampleClientID}\",\n client_secret: \"${token}\",\n};\n\nconst options = {\n authorization: {\n session_token: '${sessionToken}',\n },\n};\n\nclient.SSO.OIDC.UpdateConnection(params, options)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: go label: Go source: "// PUT /v1/b2b/sso/oidc/{organization_id}/connections/{connection_id}\npackage main\n\nimport (\n\t\"context\"\n\t\"log\"\n\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/b2bstytchapi\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/sso/oidc\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/methodoptions\"\n)\n\nfunc main() {\n\tclient, err := b2bstytchapi.NewClient(\n\t\t\"${projectId}\",\n\t\t\"${secret}\",\n\t)\n\tif err != nil {\n\t\tlog.Fatalf(\"error instantiating client: %v\", err)\n\t}\n\n\tparams := &oidc.UpdateConnectionParams{\n\t\tOrganizationID: \"${organizationId}\",\n\t\tConnectionID: \"${oidcConnectionId}\",\n\t\tClientID: \"${exampleClientID}\",\n\t\tClientSecret: \"${token}\",\n\t}\n\n\toptions := &oidc.UpdateConnectionParamsOptions{\n\t\tAuthorization: methodoptions.Authorization{\n\t\t\tSessionToken: \"${sessionToken}\",\n\t\t},\n\t}\n\n\tresp, err := client.SSO.OIDC.UpdateConnection(context.Background(), params, options)\n\tif err != nil {\n\t\tlog.Fatalf(\"error in method call: %v\", err)\n\t}\n\n\tlog.Println(resp)\n}\n" - lang: java label: Java source: "// PUT /v1/b2b/sso/oidc/{organization_id}/connections/{connection_id}\npackage com.example;\n\nimport com.stytch.java.b2b.models.ssooidc.UpdateConnectionRequest;\nimport com.stytch.java.b2b.models.ssooidc.UpdateConnectionRequestOptions;\nimport com.stytch.java.b2b.StytchB2BClient;\nimport com.stytch.java.common.methodoptions.Authorization;\nimport com.stytch.java.common.StytchResult;\n\npublic class Main {\n public static void main(String[] args) {\n StytchB2BClient.configure(\"${projectId}\", \"${secret}\");\n\n UpdateConnectionRequest params = new UpdateConnectionRequest();\n params.setOrganizationId(\"${organizationId}\");\n params.setConnectionId(\"${oidcConnectionId}\");\n params.setClientId(\"${exampleClientID}\");\n params.setClientSecret(\"${token}\");\n\n UpdateConnectionRequestOptions options = new UpdateConnectionRequestOptions();\n Authorization authorization = new Authorization();\n authorization.setSessionToken(\"${sessionToken}\");\n options.setAuthorization(authorization);\n\n Object result = StytchB2BClient.getSSO().getOIDC().updateConnection(params, options);\n if (result instanceof StytchResult.Success) {\n System.out.println(((StytchResult.Success) result).getValue());\n } else {\n System.out.println(((StytchResult.Error) result).getException());\n }\n }\n}" - lang: kotlin label: Kotlin source: "// PUT /v1/b2b/sso/oidc/{organization_id}/connections/{connection_id}\npackage com.example\n\nimport com.stytch.java.b2b.StytchB2BClient\nimport com.stytch.java.b2b.models.ssooidc.UpdateConnectionRequest\nimport com.stytch.java.b2b.models.ssooidc.UpdateConnectionRequestOptions\nimport com.stytch.java.common.methodoptions.Authorization\n\nfun main() {\n StytchB2BClient.configure(\n projectId = \"${projectId}\",\n secret = \"${secret}\",\n )\n\n when (\n val result =\n StytchB2BClient.sso.oidc.updateConnection(\n UpdateConnectionRequest(\n organizationId = \"${organizationId}\",\n connectionId = \"${oidcConnectionId}\",\n clientId = \"${exampleClientID}\",\n clientSecret = \"${token}\",\n ),\n UpdateConnectionRequestOptions(\n Authorization(\n sessionToken = \"${sessionToken}\",\n ),\n ),\n )\n ) {\n is StytchResult.Success -> println(result.value)\n is StytchResult.Error -> println(result.exception)\n }\n}\n" - lang: javascript label: Node.js source: "// PUT /v1/b2b/sso/oidc/{organization_id}/connections/{connection_id}\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n organization_id: \"${organizationId}\",\n connection_id: \"${oidcConnectionId}\",\n client_id: \"${exampleClientID}\",\n client_secret: \"${token}\",\n};\n\nconst options = {\n authorization: {\n session_token: '${sessionToken}',\n },\n};\n\nclient.sso.oidc.updateConnection(params, options)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: php label: PHP source: "$response = $client->sso->oidc->update_connection([\n 'organization_id' => '${organizationId}',\n 'connection_id' => '${oidcConnectionId}',\n 'client_id' => '${exampleClientID}',\n 'client_secret' => '${token}',\n], [\n 'authorization' => ['session_token' => '${sessionToken}'],\n\n]);" - lang: python label: Python source: "# PUT /v1/b2b/sso/oidc/{organization_id}/connections/{connection_id}\nfrom stytch import B2BClient\nfrom stytch.b2b.models.sso_oidc import UpdateConnectionRequestOptions\nfrom stytch.shared.method_options import Authorization\n\nclient = B2BClient(\n project_id=\"${projectId}\",\n secret=\"${secret}\",\n)\n\nresp = client.sso.oidc.update_connection(\n organization_id=\"${organizationId}\",\n connection_id=\"${oidcConnectionId}\",\n client_id=\"${exampleClientID}\",\n client_secret=\"${token}\",\n method_options=UpdateConnectionRequestOptions(\n authorization=Authorization(\n session_token=\"${sessionToken}\",\n ),\n ),\n)\n\nprint(resp)\n" - lang: ruby label: Ruby source: "# PUT /v1/b2b/sso/oidc/{organization_id}/connections/{connection_id}\nrequire 'stytch'\n\nclient = StytchB2B::Client.new(\n project_id: \"${projectId}\",\n secret: \"${secret}\"\n)\n\nresp = client.sso.oidc.update_connection(\n organization_id: \"${organizationId}\",\n connection_id: \"${oidcConnectionId}\",\n client_id: \"${exampleClientID}\",\n client_secret: \"${token}\",\n method_options: StytchB2B::SSO::OIDC::UpdateConnectionRequestOptions.new(\n authorization: Stytch::MethodOptions::Authorization.new(session_token: '${sessionToken}')\n )\n)\n\nputs resp" - lang: rust label: Rust source: "// PUT /v1/b2b/sso/oidc/{organization_id}/connections/{connection_id}\nuse stytch::b2b::client::Client;\nuse stytch::b2b::sso_oidc::UpdateConnectionRequest;\n\nfn main() {\n let client = Client::new(\"${projectId}\", \"${secret}\").unwrap();\n let resp = client.sso.oidc.update_connection(\n UpdateConnectionRequest{\n organization_id: \"${organizationId}\",\n connection_id: \"${oidcConnectionId}\",\n client_id: Some(String::from(\"${exampleClientID}\")),\n client_secret: Some(String::from(\"${token}\")),\n ..Default::default()\n }\n ).await;\n println!(\"The response is {:?}\", resp);\n}" - lang: bash label: cURL source: "# PUT /v1/b2b/sso/oidc/{organization_id}/connections/{connection_id}\ncurl --request PUT \\\n --url https://test.stytch.com/v1/b2b/sso/oidc/${organizationId}/connections/${oidcConnectionId} \\\n -u '${projectId}:${secret}' \\\n -H 'Content-Type: application/json' \\\n -H \"X-Stytch-Member-Session: ${sessionToken}\" \\\n -d '{\n \"client_id\": \"${exampleClientID}\",\n \"client_secret\": \"${token}\"\n }'" /v1/b2b/sso/saml/{organization_id}: post: summary: Createconnection operationId: api_sso_v1_sso_saml_CreateConnection tags: - SSO description: Create a new SAML Connection. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/api_sso_v1_sso_saml_CreateConnectionRequest' parameters: - name: organization_id in: path required: true schema: type: string description: Globally unique UUID that identifies a specific Organization. The `organization_id` is critical to perform operations on an Organization, so be sure to preserve this value. You may also use the organization_slug or organization_external_id here as a convenience. description: Globally unique UUID that identifies a specific Organization. The `organization_id` is critical to perform operations on an Organization, so be sure to preserve this value. You may also use the organization_slug or organization_external_id here as a convenience. - name: X-Stytch-Member-Session in: header required: false description: A Stytch session that can be used to run the request with the given member's permissions. schema: type: string - name: X-Stytch-Member-SessionJWT in: header required: false description: A Stytch Session JSON Web Token (JWT) that can be used to run the request with the given member's permissions. schema: type: string responses: '200': description: Successful response content: application/json: schema: $ref: '#/components/schemas/api_sso_v1_sso_saml_CreateConnectionResponse' '400': description: Bad request '401': description: Unauthorized content: application/json: example: status_code: 401 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: unauthorized_credentials error_message: Unauthorized credentials. error_url: https://stytch.com/docs/api/errors/401 '429': description: Too Many Requests content: application/json: example: status_code: 429 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: too_many_requests error_message: Too many requests have been made. error_url: https://stytch.com/docs/api/errors/429 '500': description: Internal server error content: application/json: example: status_code: 500 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: internal_server_error error_message: Oops, something seems to have gone wrong, please reach out to support@stytch.com to let us know what went wrong. error_url: https://stytch.com/docs/api/errors/500 x-code-samples: - lang: csharp label: C# source: "// POST /v1/b2b/sso/saml/{organization_id}\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n organization_id: \"${organizationId}\",\n display_name: \"Example SAML connection\",\n};\n\nconst options = {\n authorization: {\n session_token: '${sessionToken}',\n },\n};\n\nclient.SSO.SAML.CreateConnection(params, options)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: go label: Go source: "// POST /v1/b2b/sso/saml/{organization_id}\npackage main\n\nimport (\n\t\"context\"\n\t\"log\"\n\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/b2bstytchapi\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/sso/saml\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/methodoptions\"\n)\n\nfunc main() {\n\tclient, err := b2bstytchapi.NewClient(\n\t\t\"${projectId}\",\n\t\t\"${secret}\",\n\t)\n\tif err != nil {\n\t\tlog.Fatalf(\"error instantiating client: %v\", err)\n\t}\n\n\tparams := &saml.CreateConnectionParams{\n\t\tOrganizationID: \"${organizationId}\",\n\t\tDisplayName: \"Example SAML connection\",\n\t}\n\n\toptions := &saml.CreateConnectionParamsOptions{\n\t\tAuthorization: methodoptions.Authorization{\n\t\t\tSessionToken: \"${sessionToken}\",\n\t\t},\n\t}\n\n\tresp, err := client.SSO.SAML.CreateConnection(context.Background(), params, options)\n\tif err != nil {\n\t\tlog.Fatalf(\"error in method call: %v\", err)\n\t}\n\n\tlog.Println(resp)\n}\n" - lang: java label: Java source: "// POST /v1/b2b/sso/saml/{organization_id}\npackage com.example;\n\nimport com.stytch.java.b2b.models.ssosaml.CreateConnectionRequest;\nimport com.stytch.java.b2b.models.ssosaml.CreateConnectionRequestOptions;\nimport com.stytch.java.b2b.StytchB2BClient;\nimport com.stytch.java.common.methodoptions.Authorization;\nimport com.stytch.java.common.StytchResult;\n\npublic class Main {\n public static void main(String[] args) {\n StytchB2BClient.configure(\"${projectId}\", \"${secret}\");\n\n CreateConnectionRequest params = new CreateConnectionRequest();\n params.setOrganizationId(\"${organizationId}\");\n params.setDisplayName(\"Example SAML connection\");\n\n CreateConnectionRequestOptions options = new CreateConnectionRequestOptions();\n Authorization authorization = new Authorization();\n authorization.setSessionToken(\"${sessionToken}\");\n options.setAuthorization(authorization);\n\n Object result = StytchB2BClient.getSSO().getSAML().createConnection(params, options);\n if (result instanceof StytchResult.Success) {\n System.out.println(((StytchResult.Success) result).getValue());\n } else {\n System.out.println(((StytchResult.Error) result).getException());\n }\n }\n}" - lang: kotlin label: Kotlin source: "// POST /v1/b2b/sso/saml/{organization_id}\npackage com.example\n\nimport com.stytch.java.b2b.StytchB2BClient\nimport com.stytch.java.b2b.models.ssosaml.CreateConnectionRequest\nimport com.stytch.java.b2b.models.ssosaml.CreateConnectionRequestOptions\nimport com.stytch.java.common.methodoptions.Authorization\n\nfun main() {\n StytchB2BClient.configure(\n projectId = \"${projectId}\",\n secret = \"${secret}\",\n )\n\n when (\n val result =\n StytchB2BClient.sso.saml.createConnection(\n CreateConnectionRequest(\n organizationId = \"${organizationId}\",\n displayName = \"Example SAML connection\",\n ),\n CreateConnectionRequestOptions(\n Authorization(\n sessionToken = \"${sessionToken}\",\n ),\n ),\n )\n ) {\n is StytchResult.Success -> println(result.value)\n is StytchResult.Error -> println(result.exception)\n }\n}\n" - lang: javascript label: Node.js source: "// POST /v1/b2b/sso/saml/{organization_id}\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n organization_id: \"${organizationId}\",\n display_name: \"Example SAML connection\",\n};\n\nconst options = {\n authorization: {\n session_token: '${sessionToken}',\n },\n};\n\nclient.sso.saml.createConnection(params, options)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: php label: PHP source: "$response = $client->sso->saml->create_connection([\n 'organization_id' => '${organizationId}',\n 'display_name' => 'Example SAML connection',\n], [\n 'authorization' => ['session_token' => '${sessionToken}'],\n\n]);" - lang: python label: Python source: "# POST /v1/b2b/sso/saml/{organization_id}\nfrom stytch import B2BClient\nfrom stytch.b2b.models.sso_saml import CreateConnectionRequestOptions\nfrom stytch.shared.method_options import Authorization\n\nclient = B2BClient(\n project_id=\"${projectId}\",\n secret=\"${secret}\",\n)\n\nresp = client.sso.saml.create_connection(\n organization_id=\"${organizationId}\",\n display_name=\"Example SAML connection\",\n method_options=CreateConnectionRequestOptions(\n authorization=Authorization(\n session_token=\"${sessionToken}\",\n ),\n ),\n)\n\nprint(resp)\n" - lang: ruby label: Ruby source: "# POST /v1/b2b/sso/saml/{organization_id}\nrequire 'stytch'\n\nclient = StytchB2B::Client.new(\n project_id: \"${projectId}\",\n secret: \"${secret}\"\n)\n\nresp = client.sso.saml.create_connection(\n organization_id: \"${organizationId}\",\n display_name: \"Example SAML connection\",\n method_options: StytchB2B::SSO::SAML::CreateConnectionRequestOptions.new(\n authorization: Stytch::MethodOptions::Authorization.new(session_token: '${sessionToken}')\n )\n)\n\nputs resp" - lang: rust label: Rust source: "// POST /v1/b2b/sso/saml/{organization_id}\nuse stytch::b2b::client::Client;\nuse stytch::b2b::sso_saml::CreateConnectionRequest;\n\nfn main() {\n let client = Client::new(\"${projectId}\", \"${secret}\").unwrap();\n let resp = client.sso.saml.create_connection(\n CreateConnectionRequest{\n organization_id: \"${organizationId}\",\n display_name: Some(String::from(\"Example SAML connection\")),\n ..Default::default()\n }\n ).await;\n println!(\"The response is {:?}\", resp);\n}" - lang: bash label: cURL source: "# POST /v1/b2b/sso/saml/{organization_id}\ncurl --request POST \\\n --url https://test.stytch.com/v1/b2b/sso/saml/${organizationId} \\\n -u '${projectId}:${secret}' \\\n -H 'Content-Type: application/json' \\\n -H \"X-Stytch-Member-Session: ${sessionToken}\" \\\n -d '{\n \"display_name\": \"Example SAML connection\"\n }'" /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}: put: summary: Updateconnection operationId: api_sso_v1_sso_saml_UpdateConnection tags: - SSO description: 'Updates an existing SAML connection. Note that a newly created connection will not become active until all of the following are provided: * `idp_sso_url` * `attribute_mapping` * `idp_entity_id` * `x509_certificate`' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/api_sso_v1_sso_saml_UpdateConnectionRequest' parameters: - name: organization_id in: path required: true schema: type: string description: Globally unique UUID that identifies a specific Organization. The `organization_id` is critical to perform operations on an Organization, so be sure to preserve this value. You may also use the organization_slug or organization_external_id here as a convenience. description: Globally unique UUID that identifies a specific Organization. The `organization_id` is critical to perform operations on an Organization, so be sure to preserve this value. You may also use the organization_slug or organization_external_id here as a convenience. - name: connection_id in: path required: true schema: type: string description: Globally unique UUID that identifies a specific SSO `connection_id` for a Member. description: Globally unique UUID that identifies a specific SSO `connection_id` for a Member. - name: X-Stytch-Member-Session in: header required: false description: A Stytch session that can be used to run the request with the given member's permissions. schema: type: string - name: X-Stytch-Member-SessionJWT in: header required: false description: A Stytch Session JSON Web Token (JWT) that can be used to run the request with the given member's permissions. schema: type: string responses: '200': description: Successful response content: application/json: schema: $ref: '#/components/schemas/api_sso_v1_sso_saml_UpdateConnectionResponse' '400': description: Bad request '401': description: Unauthorized content: application/json: example: status_code: 401 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: unauthorized_credentials error_message: Unauthorized credentials. error_url: https://stytch.com/docs/api/errors/401 '429': description: Too Many Requests content: application/json: example: status_code: 429 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: too_many_requests error_message: Too many requests have been made. error_url: https://stytch.com/docs/api/errors/429 '500': description: Internal server error content: application/json: example: status_code: 500 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: internal_server_error error_message: Oops, something seems to have gone wrong, please reach out to support@stytch.com to let us know what went wrong. error_url: https://stytch.com/docs/api/errors/500 x-code-samples: - lang: csharp label: C# source: "// PUT /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n organization_id: \"${organizationId}\",\n connection_id: \"${samlConnectionId}\",\n x509_certificate: \"${exampleCertificate}\",\n idp_sso_url: \"${exampleIdpSsoUrl}\",\n signing_private_key: \"${examplePrivateKey}\",\n saml_encryption_private_key: \"${examplePrivateKey}\",\n};\n\nconst options = {\n authorization: {\n session_token: '${sessionToken}',\n },\n};\n\nclient.SSO.SAML.UpdateConnection(params, options)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: go label: Go source: "// PUT /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}\npackage main\n\nimport (\n\t\"context\"\n\t\"log\"\n\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/b2bstytchapi\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/sso/saml\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/methodoptions\"\n)\n\nfunc main() {\n\tclient, err := b2bstytchapi.NewClient(\n\t\t\"${projectId}\",\n\t\t\"${secret}\",\n\t)\n\tif err != nil {\n\t\tlog.Fatalf(\"error instantiating client: %v\", err)\n\t}\n\n\tparams := &saml.UpdateConnectionParams{\n\t\tOrganizationID: \"${organizationId}\",\n\t\tConnectionID: \"${samlConnectionId}\",\n\t\tX509Certificate: \"${exampleCertificate}\",\n\t\tIDPSSOURL: \"${exampleIdpSsoUrl}\",\n\t\tSigningPrivateKey: \"${examplePrivateKey}\",\n\t\tSAMLEncryptionPrivateKey: \"${examplePrivateKey}\",\n\t}\n\n\toptions := &saml.UpdateConnectionParamsOptions{\n\t\tAuthorization: methodoptions.Authorization{\n\t\t\tSessionToken: \"${sessionToken}\",\n\t\t},\n\t}\n\n\tresp, err := client.SSO.SAML.UpdateConnection(context.Background(), params, options)\n\tif err != nil {\n\t\tlog.Fatalf(\"error in method call: %v\", err)\n\t}\n\n\tlog.Println(resp)\n}\n" - lang: java label: Java source: "// PUT /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}\npackage com.example;\n\nimport com.stytch.java.b2b.models.ssosaml.UpdateConnectionRequest;\nimport com.stytch.java.b2b.models.ssosaml.UpdateConnectionRequestOptions;\nimport com.stytch.java.b2b.StytchB2BClient;\nimport com.stytch.java.common.methodoptions.Authorization;\nimport com.stytch.java.common.StytchResult;\n\npublic class Main {\n public static void main(String[] args) {\n StytchB2BClient.configure(\"${projectId}\", \"${secret}\");\n\n UpdateConnectionRequest params = new UpdateConnectionRequest();\n params.setOrganizationId(\"${organizationId}\");\n params.setConnectionId(\"${samlConnectionId}\");\n params.setX509Certificate(\"${exampleCertificate}\");\n params.setIDPSSOURL(\"${exampleIdpSsoUrl}\");\n params.setSigningPrivateKey(\"${examplePrivateKey}\");\n params.setSAMLEncryptionPrivateKey(\"${examplePrivateKey}\");\n\n UpdateConnectionRequestOptions options = new UpdateConnectionRequestOptions();\n Authorization authorization = new Authorization();\n authorization.setSessionToken(\"${sessionToken}\");\n options.setAuthorization(authorization);\n\n Object result = StytchB2BClient.getSSO().getSAML().updateConnection(params, options);\n if (result instanceof StytchResult.Success) {\n System.out.println(((StytchResult.Success) result).getValue());\n } else {\n System.out.println(((StytchResult.Error) result).getException());\n }\n }\n}" - lang: kotlin label: Kotlin source: "// PUT /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}\npackage com.example\n\nimport com.stytch.java.b2b.StytchB2BClient\nimport com.stytch.java.b2b.models.ssosaml.UpdateConnectionRequest\nimport com.stytch.java.b2b.models.ssosaml.UpdateConnectionRequestOptions\nimport com.stytch.java.common.methodoptions.Authorization\n\nfun main() {\n StytchB2BClient.configure(\n projectId = \"${projectId}\",\n secret = \"${secret}\",\n )\n\n when (\n val result =\n StytchB2BClient.sso.saml.updateConnection(\n UpdateConnectionRequest(\n organizationId = \"${organizationId}\",\n connectionId = \"${samlConnectionId}\",\n x509Certificate = \"${exampleCertificate}\",\n idpSSOURL = \"${exampleIdpSsoUrl}\",\n signingPrivateKey = \"${examplePrivateKey}\",\n samlEncryptionPrivateKey = \"${examplePrivateKey}\",\n ),\n UpdateConnectionRequestOptions(\n Authorization(\n sessionToken = \"${sessionToken}\",\n ),\n ),\n )\n ) {\n is StytchResult.Success -> println(result.value)\n is StytchResult.Error -> println(result.exception)\n }\n}\n" - lang: javascript label: Node.js source: "// PUT /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n organization_id: \"${organizationId}\",\n connection_id: \"${samlConnectionId}\",\n x509_certificate: \"${exampleCertificate}\",\n idp_sso_url: \"${exampleIdpSsoUrl}\",\n signing_private_key: \"${examplePrivateKey}\",\n saml_encryption_private_key: \"${examplePrivateKey}\",\n};\n\nconst options = {\n authorization: {\n session_token: '${sessionToken}',\n },\n};\n\nclient.sso.saml.updateConnection(params, options)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: php label: PHP source: "$response = $client->sso->saml->update_connection([\n 'organization_id' => '${organizationId}',\n 'connection_id' => '${samlConnectionId}',\n 'x509_certificate' => '${exampleCertificate}',\n 'idp_sso_url' => '${exampleIdpSsoUrl}',\n 'signing_private_key' => '${examplePrivateKey}',\n 'saml_encryption_private_key' => '${examplePrivateKey}',\n], [\n 'authorization' => ['session_token' => '${sessionToken}'],\n\n]);" - lang: python label: Python source: "# PUT /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}\nfrom stytch import B2BClient\nfrom stytch.b2b.models.sso_saml import UpdateConnectionRequestOptions\nfrom stytch.shared.method_options import Authorization\n\nclient = B2BClient(\n project_id=\"${projectId}\",\n secret=\"${secret}\",\n)\n\nresp = client.sso.saml.update_connection(\n organization_id=\"${organizationId}\",\n connection_id=\"${samlConnectionId}\",\n x509_certificate=\"${exampleCertificate}\",\n idp_sso_url=\"${exampleIdpSsoUrl}\",\n signing_private_key=\"${examplePrivateKey}\",\n saml_encryption_private_key=\"${examplePrivateKey}\",\n method_options=UpdateConnectionRequestOptions(\n authorization=Authorization(\n session_token=\"${sessionToken}\",\n ),\n ),\n)\n\nprint(resp)\n" - lang: ruby label: Ruby source: "# PUT /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}\nrequire 'stytch'\n\nclient = StytchB2B::Client.new(\n project_id: \"${projectId}\",\n secret: \"${secret}\"\n)\n\nresp = client.sso.saml.update_connection(\n organization_id: \"${organizationId}\",\n connection_id: \"${samlConnectionId}\",\n x509_certificate: \"${exampleCertificate}\",\n idp_sso_url: \"${exampleIdpSsoUrl}\",\n signing_private_key: \"${examplePrivateKey}\",\n saml_encryption_private_key: \"${examplePrivateKey}\",\n method_options: StytchB2B::SSO::SAML::UpdateConnectionRequestOptions.new(\n authorization: Stytch::MethodOptions::Authorization.new(session_token: '${sessionToken}')\n )\n)\n\nputs resp" - lang: rust label: Rust source: "// PUT /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}\nuse stytch::b2b::client::Client;\nuse stytch::b2b::sso_saml::UpdateConnectionRequest;\n\nfn main() {\n let client = Client::new(\"${projectId}\", \"${secret}\").unwrap();\n let resp = client.sso.saml.update_connection(\n UpdateConnectionRequest{\n organization_id: \"${organizationId}\",\n connection_id: \"${samlConnectionId}\",\n x509_certificate: Some(String::from(\"${exampleCertificate}\")),\n idp_sso_url: Some(String::from(\"${exampleIdpSsoUrl}\")),\n signing_private_key: Some(String::from(\"${examplePrivateKey}\")),\n saml_encryption_private_key: Some(String::from(\"${examplePrivateKey}\")),\n ..Default::default()\n }\n ).await;\n println!(\"The response is {:?}\", resp);\n}" - lang: bash label: cURL source: "# PUT /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}\ncurl --request PUT \\\n --url https://test.stytch.com/v1/b2b/sso/saml/${organizationId}/connections/${samlConnectionId} \\\n -u '${projectId}:${secret}' \\\n -H 'Content-Type: application/json' \\\n -H \"X-Stytch-Member-Session: ${sessionToken}\" \\\n -d '{\n \"x509_certificate\": \"${exampleCertificate}\",\n \"idp_sso_url\": \"${exampleIdpSsoUrl}\",\n \"signing_private_key\": \"${examplePrivateKey}\",\n \"saml_encryption_private_key\": \"${examplePrivateKey}\"\n }'" /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}/url: put: summary: Updatebyurl operationId: api_sso_v1_sso_saml_UpdateByURL tags: - SSO description: 'Used to update an existing SAML connection using an IDP metadata URL. A newly created connection will not become active until all the following are provided: * `idp_sso_url` * `idp_entity_id` * `x509_certificate` * `attribute_mapping` (must be supplied using [Update SAML Connection](update-saml-connection))' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/api_sso_v1_sso_saml_UpdateByURLRequest' parameters: - name: organization_id in: path required: true schema: type: string description: Globally unique UUID that identifies a specific Organization. The `organization_id` is critical to perform operations on an Organization, so be sure to preserve this value. You may also use the organization_slug or organization_external_id here as a convenience. description: Globally unique UUID that identifies a specific Organization. The `organization_id` is critical to perform operations on an Organization, so be sure to preserve this value. You may also use the organization_slug or organization_external_id here as a convenience. - name: connection_id in: path required: true schema: type: string description: Globally unique UUID that identifies a specific SSO `connection_id` for a Member. description: Globally unique UUID that identifies a specific SSO `connection_id` for a Member. - name: X-Stytch-Member-Session in: header required: false description: A Stytch session that can be used to run the request with the given member's permissions. schema: type: string - name: X-Stytch-Member-SessionJWT in: header required: false description: A Stytch Session JSON Web Token (JWT) that can be used to run the request with the given member's permissions. schema: type: string responses: '200': description: Successful response content: application/json: schema: $ref: '#/components/schemas/api_sso_v1_sso_saml_UpdateByURLResponse' '400': description: Bad request '401': description: Unauthorized content: application/json: example: status_code: 401 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: unauthorized_credentials error_message: Unauthorized credentials. error_url: https://stytch.com/docs/api/errors/401 '429': description: Too Many Requests content: application/json: example: status_code: 429 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: too_many_requests error_message: Too many requests have been made. error_url: https://stytch.com/docs/api/errors/429 '500': description: Internal server error content: application/json: example: status_code: 500 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: internal_server_error error_message: Oops, something seems to have gone wrong, please reach out to support@stytch.com to let us know what went wrong. error_url: https://stytch.com/docs/api/errors/500 x-code-samples: - lang: csharp label: C# source: "// PUT /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}/url\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n organization_id: \"${organizationId}\",\n connection_id: \"${samlConnectionId}\",\n metadata_url: \"${exampleIdpMetadataUrl}\",\n};\n\nconst options = {\n authorization: {\n session_token: '${sessionToken}',\n },\n};\n\nclient.SSO.SAML.UpdateByURL(params, options)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: go label: Go source: "// PUT /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}/url\npackage main\n\nimport (\n\t\"context\"\n\t\"log\"\n\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/b2bstytchapi\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/sso/saml\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/methodoptions\"\n)\n\nfunc main() {\n\tclient, err := b2bstytchapi.NewClient(\n\t\t\"${projectId}\",\n\t\t\"${secret}\",\n\t)\n\tif err != nil {\n\t\tlog.Fatalf(\"error instantiating client: %v\", err)\n\t}\n\n\tparams := &saml.UpdateByURLParams{\n\t\tOrganizationID: \"${organizationId}\",\n\t\tConnectionID: \"${samlConnectionId}\",\n\t\tMetadataURL: \"${exampleIdpMetadataUrl}\",\n\t}\n\n\toptions := &saml.UpdateByURLParamsOptions{\n\t\tAuthorization: methodoptions.Authorization{\n\t\t\tSessionToken: \"${sessionToken}\",\n\t\t},\n\t}\n\n\tresp, err := client.SSO.SAML.UpdateByURL(context.Background(), params, options)\n\tif err != nil {\n\t\tlog.Fatalf(\"error in method call: %v\", err)\n\t}\n\n\tlog.Println(resp)\n}\n" - lang: java label: Java source: "// PUT /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}/url\npackage com.example;\n\nimport com.stytch.java.b2b.models.ssosaml.UpdateByURLRequest;\nimport com.stytch.java.b2b.models.ssosaml.UpdateByURLRequestOptions;\nimport com.stytch.java.b2b.StytchB2BClient;\nimport com.stytch.java.common.methodoptions.Authorization;\nimport com.stytch.java.common.StytchResult;\n\npublic class Main {\n public static void main(String[] args) {\n StytchB2BClient.configure(\"${projectId}\", \"${secret}\");\n\n UpdateByURLRequest params = new UpdateByURLRequest();\n params.setOrganizationId(\"${organizationId}\");\n params.setConnectionId(\"${samlConnectionId}\");\n params.setMetadataURL(\"${exampleIdpMetadataUrl}\");\n\n UpdateByURLRequestOptions options = new UpdateByURLRequestOptions();\n Authorization authorization = new Authorization();\n authorization.setSessionToken(\"${sessionToken}\");\n options.setAuthorization(authorization);\n\n Object result = StytchB2BClient.getSSO().getSAML().updateByURL(params, options);\n if (result instanceof StytchResult.Success) {\n System.out.println(((StytchResult.Success) result).getValue());\n } else {\n System.out.println(((StytchResult.Error) result).getException());\n }\n }\n}" - lang: kotlin label: Kotlin source: "// PUT /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}/url\npackage com.example\n\nimport com.stytch.java.b2b.StytchB2BClient\nimport com.stytch.java.b2b.models.ssosaml.UpdateByURLRequest\nimport com.stytch.java.b2b.models.ssosaml.UpdateByURLRequestOptions\nimport com.stytch.java.common.methodoptions.Authorization\n\nfun main() {\n StytchB2BClient.configure(\n projectId = \"${projectId}\",\n secret = \"${secret}\",\n )\n\n when (\n val result =\n StytchB2BClient.sso.saml.updateByURL(\n UpdateByURLRequest(\n organizationId = \"${organizationId}\",\n connectionId = \"${samlConnectionId}\",\n metadataURL = \"${exampleIdpMetadataUrl}\",\n ),\n UpdateByURLRequestOptions(\n Authorization(\n sessionToken = \"${sessionToken}\",\n ),\n ),\n )\n ) {\n is StytchResult.Success -> println(result.value)\n is StytchResult.Error -> println(result.exception)\n }\n}\n" - lang: javascript label: Node.js source: "// PUT /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}/url\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n organization_id: \"${organizationId}\",\n connection_id: \"${samlConnectionId}\",\n metadata_url: \"${exampleIdpMetadataUrl}\",\n};\n\nconst options = {\n authorization: {\n session_token: '${sessionToken}',\n },\n};\n\nclient.sso.saml.updateByURL(params, options)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: php label: PHP source: "$response = $client->sso->saml->update_by_url([\n 'organization_id' => '${organizationId}',\n 'connection_id' => '${samlConnectionId}',\n 'metadata_url' => '${exampleIdpMetadataUrl}',\n], [\n 'authorization' => ['session_token' => '${sessionToken}'],\n\n]);" - lang: python label: Python source: "# PUT /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}/url\nfrom stytch import B2BClient\nfrom stytch.b2b.models.sso_saml import UpdateByURLRequestOptions\nfrom stytch.shared.method_options import Authorization\n\nclient = B2BClient(\n project_id=\"${projectId}\",\n secret=\"${secret}\",\n)\n\nresp = client.sso.saml.update_by_url(\n organization_id=\"${organizationId}\",\n connection_id=\"${samlConnectionId}\",\n metadata_url=\"${exampleIdpMetadataUrl}\",\n method_options=UpdateByURLRequestOptions(\n authorization=Authorization(\n session_token=\"${sessionToken}\",\n ),\n ),\n)\n\nprint(resp)\n" - lang: ruby label: Ruby source: "# PUT /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}/url\nrequire 'stytch'\n\nclient = StytchB2B::Client.new(\n project_id: \"${projectId}\",\n secret: \"${secret}\"\n)\n\nresp = client.sso.saml.update_by_url(\n organization_id: \"${organizationId}\",\n connection_id: \"${samlConnectionId}\",\n metadata_url: \"${exampleIdpMetadataUrl}\",\n method_options: StytchB2B::SSO::SAML::UpdateByURLRequestOptions.new(\n authorization: Stytch::MethodOptions::Authorization.new(session_token: '${sessionToken}')\n )\n)\n\nputs resp" - lang: rust label: Rust source: "// PUT /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}/url\nuse stytch::b2b::client::Client;\nuse stytch::b2b::sso_saml::UpdateByURLRequest;\n\nfn main() {\n let client = Client::new(\"${projectId}\", \"${secret}\").unwrap();\n let resp = client.sso.saml.update_by_url(\n UpdateByURLRequest{\n organization_id: \"${organizationId}\",\n connection_id: \"${samlConnectionId}\",\n metadata_url: \"${exampleIdpMetadataUrl}\",\n ..Default::default()\n }\n ).await;\n println!(\"The response is {:?}\", resp);\n}" - lang: bash label: cURL source: "# PUT /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}/url\ncurl --request PUT \\\n --url https://test.stytch.com/v1/b2b/sso/saml/${organizationId}/connections/${samlConnectionId}/url \\\n -u '${projectId}:${secret}' \\\n -H 'Content-Type: application/json' \\\n -H \"X-Stytch-Member-Session: ${sessionToken}\" \\\n -d '{\n \"metadata_url\": \"${exampleIdpMetadataUrl}\"\n }'" /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}/verification_certificates/{certificate_id}: delete: summary: Deleteverificationcertificate operationId: api_sso_v1_sso_saml_DeleteVerificationCertificate tags: - SSO description: 'Delete a SAML verification certificate. You may need to do this when rotating certificates from your IdP, since Stytch allows a maximum of 5 certificates per connection. There must always be at least one certificate per active connection.' parameters: - name: organization_id in: path required: true schema: type: string description: The organization ID that the SAML connection belongs to. You may also use the organization_slug or organization_external_id here as a convenience. description: The organization ID that the SAML connection belongs to. You may also use the organization_slug or organization_external_id here as a convenience. - name: connection_id in: path required: true schema: type: string description: The ID of the SAML connection. description: The ID of the SAML connection. - name: certificate_id in: path required: true schema: type: string description: The ID of the certificate to be deleted. description: The ID of the certificate to be deleted. - name: X-Stytch-Member-Session in: header required: false description: A Stytch session that can be used to run the request with the given member's permissions. schema: type: string - name: X-Stytch-Member-SessionJWT in: header required: false description: A Stytch Session JSON Web Token (JWT) that can be used to run the request with the given member's permissions. schema: type: string responses: '200': description: Successful response content: application/json: schema: $ref: '#/components/schemas/api_sso_v1_sso_saml_DeleteVerificationCertificateResponse' '400': description: Bad request '401': description: Unauthorized content: application/json: example: status_code: 401 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: unauthorized_credentials error_message: Unauthorized credentials. error_url: https://stytch.com/docs/api/errors/401 '429': description: Too Many Requests content: application/json: example: status_code: 429 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: too_many_requests error_message: Too many requests have been made. error_url: https://stytch.com/docs/api/errors/429 '500': description: Internal server error content: application/json: example: status_code: 500 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: internal_server_error error_message: Oops, something seems to have gone wrong, please reach out to support@stytch.com to let us know what went wrong. error_url: https://stytch.com/docs/api/errors/500 x-code-samples: - lang: csharp label: C# source: "// DELETE /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}/verification_certificates/{certificate_id}\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n organization_id: \"${organizationId}\",\n connection_id: \"${samlConnectionId}\",\n certificate_id: \"${verificationCertificateId}\",\n};\n\nconst options = {\n authorization: {\n session_token: '${sessionToken}',\n },\n};\n\nclient.SSO.SAML.DeleteVerificationCertificate(params, options)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: go label: Go source: "// DELETE /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}/verification_certificates/{certificate_id}\npackage main\n\nimport (\n\t\"context\"\n\t\"log\"\n\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/b2bstytchapi\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/sso/saml\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/methodoptions\"\n)\n\nfunc main() {\n\tclient, err := b2bstytchapi.NewClient(\n\t\t\"${projectId}\",\n\t\t\"${secret}\",\n\t)\n\tif err != nil {\n\t\tlog.Fatalf(\"error instantiating client: %v\", err)\n\t}\n\n\tparams := &saml.DeleteVerificationCertificateParams{\n\t\tOrganizationID: \"${organizationId}\",\n\t\tConnectionID: \"${samlConnectionId}\",\n\t\tCertificateID: \"${verificationCertificateId}\",\n\t}\n\n\toptions := &saml.DeleteVerificationCertificateParamsOptions{\n\t\tAuthorization: methodoptions.Authorization{\n\t\t\tSessionToken: \"${sessionToken}\",\n\t\t},\n\t}\n\n\tresp, err := client.SSO.SAML.DeleteVerificationCertificate(context.Background(), params, options)\n\tif err != nil {\n\t\tlog.Fatalf(\"error in method call: %v\", err)\n\t}\n\n\tlog.Println(resp)\n}\n" - lang: java label: Java source: "// DELETE /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}/verification_certificates/{certificate_id}\npackage com.example;\n\nimport com.stytch.java.b2b.models.ssosaml.DeleteVerificationCertificateRequest;\nimport com.stytch.java.b2b.models.ssosaml.DeleteVerificationCertificateRequestOptions;\nimport com.stytch.java.b2b.StytchB2BClient;\nimport com.stytch.java.common.methodoptions.Authorization;\nimport com.stytch.java.common.StytchResult;\n\npublic class Main {\n public static void main(String[] args) {\n StytchB2BClient.configure(\"${projectId}\", \"${secret}\");\n\n DeleteVerificationCertificateRequest params = new DeleteVerificationCertificateRequest();\n params.setOrganizationId(\"${organizationId}\");\n params.setConnectionId(\"${samlConnectionId}\");\n params.setCertificateId(\"${verificationCertificateId}\");\n\n DeleteVerificationCertificateRequestOptions options = new DeleteVerificationCertificateRequestOptions();\n Authorization authorization = new Authorization();\n authorization.setSessionToken(\"${sessionToken}\");\n options.setAuthorization(authorization);\n\n Object result = StytchB2BClient.getSSO().getSAML().deleteVerificationCertificate(params, options);\n if (result instanceof StytchResult.Success) {\n System.out.println(((StytchResult.Success) result).getValue());\n } else {\n System.out.println(((StytchResult.Error) result).getException());\n }\n }\n}" - lang: kotlin label: Kotlin source: "// DELETE /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}/verification_certificates/{certificate_id}\npackage com.example\n\nimport com.stytch.java.b2b.StytchB2BClient\nimport com.stytch.java.b2b.models.ssosaml.DeleteVerificationCertificateRequest\nimport com.stytch.java.b2b.models.ssosaml.DeleteVerificationCertificateRequestOptions\nimport com.stytch.java.common.methodoptions.Authorization\n\nfun main() {\n StytchB2BClient.configure(\n projectId = \"${projectId}\",\n secret = \"${secret}\",\n )\n\n when (\n val result =\n StytchB2BClient.sso.saml.deleteVerificationCertificate(\n DeleteVerificationCertificateRequest(\n organizationId = \"${organizationId}\",\n connectionId = \"${samlConnectionId}\",\n certificateId = \"${verificationCertificateId}\",\n ),\n DeleteVerificationCertificateRequestOptions(\n Authorization(\n sessionToken = \"${sessionToken}\",\n ),\n ),\n )\n ) {\n is StytchResult.Success -> println(result.value)\n is StytchResult.Error -> println(result.exception)\n }\n}\n" - lang: javascript label: Node.js source: "// DELETE /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}/verification_certificates/{certificate_id}\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n organization_id: \"${organizationId}\",\n connection_id: \"${samlConnectionId}\",\n certificate_id: \"${verificationCertificateId}\",\n};\n\nconst options = {\n authorization: {\n session_token: '${sessionToken}',\n },\n};\n\nclient.sso.saml.deleteVerificationCertificate(params, options)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: php label: PHP source: "$response = $client->sso->saml->delete_verification_certificate([\n 'organization_id' => '${organizationId}',\n 'connection_id' => '${samlConnectionId}',\n 'certificate_id' => '${verificationCertificateId}',\n], [\n 'authorization' => ['session_token' => '${sessionToken}'],\n\n]);" - lang: python label: Python source: "# DELETE /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}/verification_certificates/{certificate_id}\nfrom stytch import B2BClient\nfrom stytch.b2b.models.sso_saml import DeleteVerificationCertificateRequestOptions\nfrom stytch.shared.method_options import Authorization\n\nclient = B2BClient(\n project_id=\"${projectId}\",\n secret=\"${secret}\",\n)\n\nresp = client.sso.saml.delete_verification_certificate(\n organization_id=\"${organizationId}\",\n connection_id=\"${samlConnectionId}\",\n certificate_id=\"${verificationCertificateId}\",\n method_options=DeleteVerificationCertificateRequestOptions(\n authorization=Authorization(\n session_token=\"${sessionToken}\",\n ),\n ),\n)\n\nprint(resp)\n" - lang: ruby label: Ruby source: "# DELETE /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}/verification_certificates/{certificate_id}\nrequire 'stytch'\n\nclient = StytchB2B::Client.new(\n project_id: \"${projectId}\",\n secret: \"${secret}\"\n)\n\nresp = client.sso.saml.delete_verification_certificate(\n organization_id: \"${organizationId}\",\n connection_id: \"${samlConnectionId}\",\n certificate_id: \"${verificationCertificateId}\",\n method_options: StytchB2B::SSO::SAML::DeleteVerificationCertificateRequestOptions.new(\n authorization: Stytch::MethodOptions::Authorization.new(session_token: '${sessionToken}')\n )\n)\n\nputs resp" - lang: rust label: Rust source: "// DELETE /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}/verification_certificates/{certificate_id}\nuse stytch::b2b::client::Client;\nuse stytch::b2b::sso_saml::DeleteVerificationCertificateRequest;\n\nfn main() {\n let client = Client::new(\"${projectId}\", \"${secret}\").unwrap();\n let resp = client.sso.saml.delete_verification_certificate(\n DeleteVerificationCertificateRequest{\n organization_id: \"${organizationId}\",\n connection_id: \"${samlConnectionId}\",\n certificate_id: \"${verificationCertificateId}\",\n ..Default::default()\n }\n ).await;\n println!(\"The response is {:?}\", resp);\n}" - lang: bash label: cURL source: "# DELETE /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}/verification_certificates/{certificate_id}\ncurl --request DELETE \\\n --url https://test.stytch.com/v1/b2b/sso/saml/${organizationId}/connections/${samlConnectionId}/verification_certificates/${verificationCertificateId} \\\n -u '${projectId}:${secret}' \\\n -H 'Content-Type: application/json' \\\n -H \"X-Stytch-Member-Session: ${sessionToken}\"" /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}/encryption_private_keys/{private_key_id}: delete: summary: Deleteencryptionprivatekey operationId: api_sso_v1_sso_saml_DeleteEncryptionPrivateKey tags: - SSO description: Delete a SAML encryption private key. parameters: - name: organization_id in: path required: true schema: type: string description: Globally unique UUID that identifies a specific Organization. The `organization_id` is critical to perform operations on an Organization, so be sure to preserve this value. You may also use the organization_slug or organization_external_id here as a convenience. description: Globally unique UUID that identifies a specific Organization. The `organization_id` is critical to perform operations on an Organization, so be sure to preserve this value. You may also use the organization_slug or organization_external_id here as a convenience. - name: connection_id in: path required: true schema: type: string description: Globally unique UUID that identifies a specific SSO `connection_id` for a Member. description: Globally unique UUID that identifies a specific SSO `connection_id` for a Member. - name: private_key_id in: path required: true schema: type: string description: The ID of the encryption private key to be deleted. description: The ID of the encryption private key to be deleted. - name: X-Stytch-Member-Session in: header required: false description: A Stytch session that can be used to run the request with the given member's permissions. schema: type: string - name: X-Stytch-Member-SessionJWT in: header required: false description: A Stytch Session JSON Web Token (JWT) that can be used to run the request with the given member's permissions. schema: type: string responses: '200': description: Successful response content: application/json: schema: $ref: '#/components/schemas/api_sso_v1_sso_saml_DeleteEncryptionPrivateKeyResponse' '400': description: Bad request '401': description: Unauthorized content: application/json: example: status_code: 401 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: unauthorized_credentials error_message: Unauthorized credentials. error_url: https://stytch.com/docs/api/errors/401 '429': description: Too Many Requests content: application/json: example: status_code: 429 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: too_many_requests error_message: Too many requests have been made. error_url: https://stytch.com/docs/api/errors/429 '500': description: Internal server error content: application/json: example: status_code: 500 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: internal_server_error error_message: Oops, something seems to have gone wrong, please reach out to support@stytch.com to let us know what went wrong. error_url: https://stytch.com/docs/api/errors/500 x-code-samples: - lang: csharp label: C# source: "// DELETE /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}/encryption_private_keys/{private_key_id}\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n organization_id: \"${organizationId}\",\n connection_id: \"${samlConnectionId}\",\n private_key_id: \"${encryptionPrivateKeyId}\",\n};\n\nconst options = {\n authorization: {\n session_token: '${sessionToken}',\n },\n};\n\nclient.SSO.SAML.DeleteEncryptionPrivateKey(params, options)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: go label: Go source: "// DELETE /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}/encryption_private_keys/{private_key_id}\npackage main\n\nimport (\n\t\"context\"\n\t\"log\"\n\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/b2bstytchapi\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/sso/saml\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/methodoptions\"\n)\n\nfunc main() {\n\tclient, err := b2bstytchapi.NewClient(\n\t\t\"${projectId}\",\n\t\t\"${secret}\",\n\t)\n\tif err != nil {\n\t\tlog.Fatalf(\"error instantiating client: %v\", err)\n\t}\n\n\tparams := &saml.DeleteEncryptionPrivateKeyParams{\n\t\tOrganizationID: \"${organizationId}\",\n\t\tConnectionID: \"${samlConnectionId}\",\n\t\tPrivateKeyID: \"${encryptionPrivateKeyId}\",\n\t}\n\n\toptions := &saml.DeleteEncryptionPrivateKeyParamsOptions{\n\t\tAuthorization: methodoptions.Authorization{\n\t\t\tSessionToken: \"${sessionToken}\",\n\t\t},\n\t}\n\n\tresp, err := client.SSO.SAML.DeleteEncryptionPrivateKey(context.Background(), params, options)\n\tif err != nil {\n\t\tlog.Fatalf(\"error in method call: %v\", err)\n\t}\n\n\tlog.Println(resp)\n}\n" - lang: java label: Java source: "// DELETE /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}/encryption_private_keys/{private_key_id}\npackage com.example;\n\nimport com.stytch.java.b2b.models.ssosaml.DeleteEncryptionPrivateKeyRequest;\nimport com.stytch.java.b2b.models.ssosaml.DeleteEncryptionPrivateKeyRequestOptions;\nimport com.stytch.java.b2b.StytchB2BClient;\nimport com.stytch.java.common.methodoptions.Authorization;\nimport com.stytch.java.common.StytchResult;\n\npublic class Main {\n public static void main(String[] args) {\n StytchB2BClient.configure(\"${projectId}\", \"${secret}\");\n\n DeleteEncryptionPrivateKeyRequest params = new DeleteEncryptionPrivateKeyRequest();\n params.setOrganizationId(\"${organizationId}\");\n params.setConnectionId(\"${samlConnectionId}\");\n params.setPrivateKeyId(\"${encryptionPrivateKeyId}\");\n\n DeleteEncryptionPrivateKeyRequestOptions options = new DeleteEncryptionPrivateKeyRequestOptions();\n Authorization authorization = new Authorization();\n authorization.setSessionToken(\"${sessionToken}\");\n options.setAuthorization(authorization);\n\n Object result = StytchB2BClient.getSSO().getSAML().deleteEncryptionPrivateKey(params, options);\n if (result instanceof StytchResult.Success) {\n System.out.println(((StytchResult.Success) result).getValue());\n } else {\n System.out.println(((StytchResult.Error) result).getException());\n }\n }\n}" - lang: kotlin label: Kotlin source: "// DELETE /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}/encryption_private_keys/{private_key_id}\npackage com.example\n\nimport com.stytch.java.b2b.StytchB2BClient\nimport com.stytch.java.b2b.models.ssosaml.DeleteEncryptionPrivateKeyRequest\nimport com.stytch.java.b2b.models.ssosaml.DeleteEncryptionPrivateKeyRequestOptions\nimport com.stytch.java.common.methodoptions.Authorization\n\nfun main() {\n StytchB2BClient.configure(\n projectId = \"${projectId}\",\n secret = \"${secret}\",\n )\n\n when (\n val result =\n StytchB2BClient.sso.saml.deleteEncryptionPrivateKey(\n DeleteEncryptionPrivateKeyRequest(\n organizationId = \"${organizationId}\",\n connectionId = \"${samlConnectionId}\",\n privateKeyId = \"${encryptionPrivateKeyId}\",\n ),\n DeleteEncryptionPrivateKeyRequestOptions(\n Authorization(\n sessionToken = \"${sessionToken}\",\n ),\n ),\n )\n ) {\n is StytchResult.Success -> println(result.value)\n is StytchResult.Error -> println(result.exception)\n }\n}\n" - lang: javascript label: Node.js source: "// DELETE /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}/encryption_private_keys/{private_key_id}\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n organization_id: \"${organizationId}\",\n connection_id: \"${samlConnectionId}\",\n private_key_id: \"${encryptionPrivateKeyId}\",\n};\n\nconst options = {\n authorization: {\n session_token: '${sessionToken}',\n },\n};\n\nclient.sso.saml.deleteEncryptionPrivateKey(params, options)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: php label: PHP source: "$response = $client->sso->saml->delete_encryption_private_key([\n 'organization_id' => '${organizationId}',\n 'connection_id' => '${samlConnectionId}',\n 'private_key_id' => '${encryptionPrivateKeyId}',\n], [\n 'authorization' => ['session_token' => '${sessionToken}'],\n\n]);" - lang: python label: Python source: "# DELETE /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}/encryption_private_keys/{private_key_id}\nfrom stytch import B2BClient\nfrom stytch.b2b.models.sso_saml import DeleteEncryptionPrivateKeyRequestOptions\nfrom stytch.shared.method_options import Authorization\n\nclient = B2BClient(\n project_id=\"${projectId}\",\n secret=\"${secret}\",\n)\n\nresp = client.sso.saml.delete_encryption_private_key(\n organization_id=\"${organizationId}\",\n connection_id=\"${samlConnectionId}\",\n private_key_id=\"${encryptionPrivateKeyId}\",\n method_options=DeleteEncryptionPrivateKeyRequestOptions(\n authorization=Authorization(\n session_token=\"${sessionToken}\",\n ),\n ),\n)\n\nprint(resp)\n" - lang: ruby label: Ruby source: "# DELETE /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}/encryption_private_keys/{private_key_id}\nrequire 'stytch'\n\nclient = StytchB2B::Client.new(\n project_id: \"${projectId}\",\n secret: \"${secret}\"\n)\n\nresp = client.sso.saml.delete_encryption_private_key(\n organization_id: \"${organizationId}\",\n connection_id: \"${samlConnectionId}\",\n private_key_id: \"${encryptionPrivateKeyId}\",\n method_options: StytchB2B::SSO::SAML::DeleteEncryptionPrivateKeyRequestOptions.new(\n authorization: Stytch::MethodOptions::Authorization.new(session_token: '${sessionToken}')\n )\n)\n\nputs resp" - lang: rust label: Rust source: "// DELETE /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}/encryption_private_keys/{private_key_id}\nuse stytch::b2b::client::Client;\nuse stytch::b2b::sso_saml::DeleteEncryptionPrivateKeyRequest;\n\nfn main() {\n let client = Client::new(\"${projectId}\", \"${secret}\").unwrap();\n let resp = client.sso.saml.delete_encryption_private_key(\n DeleteEncryptionPrivateKeyRequest{\n organization_id: \"${organizationId}\",\n connection_id: \"${samlConnectionId}\",\n private_key_id: \"${encryptionPrivateKeyId}\",\n ..Default::default()\n }\n ).await;\n println!(\"The response is {:?}\", resp);\n}" - lang: bash label: cURL source: "# DELETE /v1/b2b/sso/saml/{organization_id}/connections/{connection_id}/encryption_private_keys/{private_key_id}\ncurl --request DELETE \\\n --url https://test.stytch.com/v1/b2b/sso/saml/${organizationId}/connections/${samlConnectionId}/encryption_private_keys/${encryptionPrivateKeyId} \\\n -u '${projectId}:${secret}' \\\n -H 'Content-Type: application/json' \\\n -H \"X-Stytch-Member-Session: ${sessionToken}\"" /v1/b2b/sso/external/{organization_id}: post: summary: Createconnection operationId: api_sso_v1_sso_external_CreateConnection tags: - SSO description: Create a new External SSO Connection. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/api_sso_v1_sso_external_CreateConnectionRequest' parameters: - name: organization_id in: path required: true schema: type: string description: Globally unique UUID that identifies a specific Organization. The `organization_id` is critical to perform operations on an Organization, so be sure to preserve this value. You may also use the organization_slug or organization_external_id here as a convenience. description: Globally unique UUID that identifies a specific Organization. The `organization_id` is critical to perform operations on an Organization, so be sure to preserve this value. You may also use the organization_slug or organization_external_id here as a convenience. - name: X-Stytch-Member-Session in: header required: false description: A Stytch session that can be used to run the request with the given member's permissions. schema: type: string - name: X-Stytch-Member-SessionJWT in: header required: false description: A Stytch Session JSON Web Token (JWT) that can be used to run the request with the given member's permissions. schema: type: string responses: '200': description: Successful response content: application/json: schema: $ref: '#/components/schemas/api_sso_v1_sso_external_CreateConnectionResponse' '400': description: Bad request '401': description: Unauthorized content: application/json: example: status_code: 401 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: unauthorized_credentials error_message: Unauthorized credentials. error_url: https://stytch.com/docs/api/errors/401 '429': description: Too Many Requests content: application/json: example: status_code: 429 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: too_many_requests error_message: Too many requests have been made. error_url: https://stytch.com/docs/api/errors/429 '500': description: Internal server error content: application/json: example: status_code: 500 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: internal_server_error error_message: Oops, something seems to have gone wrong, please reach out to support@stytch.com to let us know what went wrong. error_url: https://stytch.com/docs/api/errors/500 x-code-samples: - lang: csharp label: C# source: "// POST /v1/b2b/sso/external/{organization_id}\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n organization_id: \"${organizationId}\",\n external_organization_id: \"${organizationId}\",\n external_connection_id: \"${samlConnectionId}\",\n display_name: \"Example External connection\",\n};\n\nconst options = {\n authorization: {\n session_token: '${sessionToken}',\n },\n};\n\nclient.SSO.External.CreateConnection(params, options)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: go label: Go source: "// POST /v1/b2b/sso/external/{organization_id}\npackage main\n\nimport (\n\t\"context\"\n\t\"log\"\n\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/b2bstytchapi\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/sso/external\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/methodoptions\"\n)\n\nfunc main() {\n\tclient, err := b2bstytchapi.NewClient(\n\t\t\"${projectId}\",\n\t\t\"${secret}\",\n\t)\n\tif err != nil {\n\t\tlog.Fatalf(\"error instantiating client: %v\", err)\n\t}\n\n\tparams := &external.CreateConnectionParams{\n\t\tOrganizationID: \"${organizationId}\",\n\t\tExternalOrganizationID: \"${organizationId}\",\n\t\tExternalConnectionID: \"${samlConnectionId}\",\n\t\tDisplayName: \"Example External connection\",\n\t}\n\n\toptions := &external.CreateConnectionParamsOptions{\n\t\tAuthorization: methodoptions.Authorization{\n\t\t\tSessionToken: \"${sessionToken}\",\n\t\t},\n\t}\n\n\tresp, err := client.SSO.External.CreateConnection(context.Background(), params, options)\n\tif err != nil {\n\t\tlog.Fatalf(\"error in method call: %v\", err)\n\t}\n\n\tlog.Println(resp)\n}\n" - lang: java label: Java source: "// POST /v1/b2b/sso/external/{organization_id}\npackage com.example;\n\nimport com.stytch.java.b2b.models.ssoexternal.CreateConnectionRequest;\nimport com.stytch.java.b2b.models.ssoexternal.CreateConnectionRequestOptions;\nimport com.stytch.java.b2b.StytchB2BClient;\nimport com.stytch.java.common.methodoptions.Authorization;\nimport com.stytch.java.common.StytchResult;\n\npublic class Main {\n public static void main(String[] args) {\n StytchB2BClient.configure(\"${projectId}\", \"${secret}\");\n\n CreateConnectionRequest params = new CreateConnectionRequest();\n params.setOrganizationId(\"${organizationId}\");\n params.setExternalOrganizationId(\"${organizationId}\");\n params.setExternalConnectionId(\"${samlConnectionId}\");\n params.setDisplayName(\"Example External connection\");\n\n CreateConnectionRequestOptions options = new CreateConnectionRequestOptions();\n Authorization authorization = new Authorization();\n authorization.setSessionToken(\"${sessionToken}\");\n options.setAuthorization(authorization);\n\n Object result = StytchB2BClient.getSSO().getExternal().createConnection(params, options);\n if (result instanceof StytchResult.Success) {\n System.out.println(((StytchResult.Success) result).getValue());\n } else {\n System.out.println(((StytchResult.Error) result).getException());\n }\n }\n}" - lang: kotlin label: Kotlin source: "// POST /v1/b2b/sso/external/{organization_id}\npackage com.example\n\nimport com.stytch.java.b2b.StytchB2BClient\nimport com.stytch.java.b2b.models.ssoexternal.CreateConnectionRequest\nimport com.stytch.java.b2b.models.ssoexternal.CreateConnectionRequestOptions\nimport com.stytch.java.common.methodoptions.Authorization\n\nfun main() {\n StytchB2BClient.configure(\n projectId = \"${projectId}\",\n secret = \"${secret}\",\n )\n\n when (\n val result =\n StytchB2BClient.sso.external.createConnection(\n CreateConnectionRequest(\n organizationId = \"${organizationId}\",\n externalOrganizationId = \"${organizationId}\",\n externalConnectionId = \"${samlConnectionId}\",\n displayName = \"Example External connection\",\n ),\n CreateConnectionRequestOptions(\n Authorization(\n sessionToken = \"${sessionToken}\",\n ),\n ),\n )\n ) {\n is StytchResult.Success -> println(result.value)\n is StytchResult.Error -> println(result.exception)\n }\n}\n" - lang: javascript label: Node.js source: "// POST /v1/b2b/sso/external/{organization_id}\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n organization_id: \"${organizationId}\",\n external_organization_id: \"${organizationId}\",\n external_connection_id: \"${samlConnectionId}\",\n display_name: \"Example External connection\",\n};\n\nconst options = {\n authorization: {\n session_token: '${sessionToken}',\n },\n};\n\nclient.sso.external.createConnection(params, options)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: php label: PHP source: "$response = $client->sso->external->create_connection([\n 'organization_id' => '${organizationId}',\n 'external_organization_id' => '${organizationId}',\n 'external_connection_id' => '${samlConnectionId}',\n 'display_name' => 'Example External connection',\n], [\n 'authorization' => ['session_token' => '${sessionToken}'],\n\n]);" - lang: python label: Python source: "# POST /v1/b2b/sso/external/{organization_id}\nfrom stytch import B2BClient\nfrom stytch.b2b.models.sso_external import CreateConnectionRequestOptions\nfrom stytch.shared.method_options import Authorization\n\nclient = B2BClient(\n project_id=\"${projectId}\",\n secret=\"${secret}\",\n)\n\nresp = client.sso.external.create_connection(\n organization_id=\"${organizationId}\",\n external_organization_id=\"${organizationId}\",\n external_connection_id=\"${samlConnectionId}\",\n display_name=\"Example External connection\",\n method_options=CreateConnectionRequestOptions(\n authorization=Authorization(\n session_token=\"${sessionToken}\",\n ),\n ),\n)\n\nprint(resp)\n" - lang: ruby label: Ruby source: "# POST /v1/b2b/sso/external/{organization_id}\nrequire 'stytch'\n\nclient = StytchB2B::Client.new(\n project_id: \"${projectId}\",\n secret: \"${secret}\"\n)\n\nresp = client.sso.external.create_connection(\n organization_id: \"${organizationId}\",\n external_organization_id: \"${organizationId}\",\n external_connection_id: \"${samlConnectionId}\",\n display_name: \"Example External connection\",\n method_options: StytchB2B::SSO::External::CreateConnectionRequestOptions.new(\n authorization: Stytch::MethodOptions::Authorization.new(session_token: '${sessionToken}')\n )\n)\n\nputs resp" - lang: rust label: Rust source: "// POST /v1/b2b/sso/external/{organization_id}\nuse stytch::b2b::client::Client;\nuse stytch::b2b::sso_external::CreateConnectionRequest;\n\nfn main() {\n let client = Client::new(\"${projectId}\", \"${secret}\").unwrap();\n let resp = client.sso.external.create_connection(\n CreateConnectionRequest{\n organization_id: \"${organizationId}\",\n external_organization_id: \"${organizationId}\",\n external_connection_id: \"${samlConnectionId}\",\n display_name: Some(String::from(\"Example External connection\")),\n ..Default::default()\n }\n ).await;\n println!(\"The response is {:?}\", resp);\n}" - lang: bash label: cURL source: "# POST /v1/b2b/sso/external/{organization_id}\ncurl --request POST \\\n --url https://test.stytch.com/v1/b2b/sso/external/${organizationId} \\\n -u '${projectId}:${secret}' \\\n -H 'Content-Type: application/json' \\\n -H \"X-Stytch-Member-Session: ${sessionToken}\" \\\n -d '{\n \"external_organization_id\": \"${organizationId}\",\n \"external_connection_id\": \"${samlConnectionId}\",\n \"display_name\": \"Example External connection\"\n }'" /v1/b2b/sso/external/{organization_id}/connections/{connection_id}: put: summary: Updateconnection operationId: api_sso_v1_sso_external_UpdateConnection tags: - SSO description: Updates an existing External SSO connection. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/api_sso_v1_sso_external_UpdateConnectionRequest' parameters: - name: organization_id in: path required: true schema: type: string description: Globally unique UUID that identifies a specific Organization. The `organization_id` is critical to perform operations on an Organization, so be sure to preserve this value. You may also use the organization_slug or organization_external_id here as a convenience. description: Globally unique UUID that identifies a specific Organization. The `organization_id` is critical to perform operations on an Organization, so be sure to preserve this value. You may also use the organization_slug or organization_external_id here as a convenience. - name: connection_id in: path required: true schema: type: string description: Globally unique UUID that identifies a specific External SSO Connection. description: Globally unique UUID that identifies a specific External SSO Connection. - name: X-Stytch-Member-Session in: header required: false description: A Stytch session that can be used to run the request with the given member's permissions. schema: type: string - name: X-Stytch-Member-SessionJWT in: header required: false description: A Stytch Session JSON Web Token (JWT) that can be used to run the request with the given member's permissions. schema: type: string responses: '200': description: Successful response content: application/json: schema: $ref: '#/components/schemas/api_sso_v1_sso_external_UpdateConnectionResponse' '400': description: Bad request '401': description: Unauthorized content: application/json: example: status_code: 401 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: unauthorized_credentials error_message: Unauthorized credentials. error_url: https://stytch.com/docs/api/errors/401 '429': description: Too Many Requests content: application/json: example: status_code: 429 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: too_many_requests error_message: Too many requests have been made. error_url: https://stytch.com/docs/api/errors/429 '500': description: Internal server error content: application/json: example: status_code: 500 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: internal_server_error error_message: Oops, something seems to have gone wrong, please reach out to support@stytch.com to let us know what went wrong. error_url: https://stytch.com/docs/api/errors/500 x-code-samples: - lang: csharp label: C# source: "// PUT /v1/b2b/sso/external/{organization_id}/connections/{connection_id}\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n organization_id: \"${organizationId}\",\n connection_id: \"${externalConnectionId}\",\n};\n\nconst options = {\n authorization: {\n session_token: '${sessionToken}',\n },\n};\n\nclient.SSO.External.UpdateConnection(params, options)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: go label: Go source: "// PUT /v1/b2b/sso/external/{organization_id}/connections/{connection_id}\npackage main\n\nimport (\n\t\"context\"\n\t\"log\"\n\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/b2bstytchapi\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/sso/external\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/methodoptions\"\n)\n\nfunc main() {\n\tclient, err := b2bstytchapi.NewClient(\n\t\t\"${projectId}\",\n\t\t\"${secret}\",\n\t)\n\tif err != nil {\n\t\tlog.Fatalf(\"error instantiating client: %v\", err)\n\t}\n\n\tparams := &external.UpdateConnectionParams{\n\t\tOrganizationID: \"${organizationId}\",\n\t\tConnectionID: \"${externalConnectionId}\",\n\t}\n\n\toptions := &external.UpdateConnectionParamsOptions{\n\t\tAuthorization: methodoptions.Authorization{\n\t\t\tSessionToken: \"${sessionToken}\",\n\t\t},\n\t}\n\n\tresp, err := client.SSO.External.UpdateConnection(context.Background(), params, options)\n\tif err != nil {\n\t\tlog.Fatalf(\"error in method call: %v\", err)\n\t}\n\n\tlog.Println(resp)\n}\n" - lang: java label: Java source: "// PUT /v1/b2b/sso/external/{organization_id}/connections/{connection_id}\npackage com.example;\n\nimport com.stytch.java.b2b.models.ssoexternal.UpdateConnectionRequest;\nimport com.stytch.java.b2b.models.ssoexternal.UpdateConnectionRequestOptions;\nimport com.stytch.java.b2b.StytchB2BClient;\nimport com.stytch.java.common.methodoptions.Authorization;\nimport com.stytch.java.common.StytchResult;\n\npublic class Main {\n public static void main(String[] args) {\n StytchB2BClient.configure(\"${projectId}\", \"${secret}\");\n\n UpdateConnectionRequest params = new UpdateConnectionRequest();\n params.setOrganizationId(\"${organizationId}\");\n params.setConnectionId(\"${externalConnectionId}\");\n\n UpdateConnectionRequestOptions options = new UpdateConnectionRequestOptions();\n Authorization authorization = new Authorization();\n authorization.setSessionToken(\"${sessionToken}\");\n options.setAuthorization(authorization);\n\n Object result = StytchB2BClient.getSSO().getExternal().updateConnection(params, options);\n if (result instanceof StytchResult.Success) {\n System.out.println(((StytchResult.Success) result).getValue());\n } else {\n System.out.println(((StytchResult.Error) result).getException());\n }\n }\n}" - lang: kotlin label: Kotlin source: "// PUT /v1/b2b/sso/external/{organization_id}/connections/{connection_id}\npackage com.example\n\nimport com.stytch.java.b2b.StytchB2BClient\nimport com.stytch.java.b2b.models.ssoexternal.UpdateConnectionRequest\nimport com.stytch.java.b2b.models.ssoexternal.UpdateConnectionRequestOptions\nimport com.stytch.java.common.methodoptions.Authorization\n\nfun main() {\n StytchB2BClient.configure(\n projectId = \"${projectId}\",\n secret = \"${secret}\",\n )\n\n when (\n val result =\n StytchB2BClient.sso.external.updateConnection(\n UpdateConnectionRequest(\n organizationId = \"${organizationId}\",\n connectionId = \"${externalConnectionId}\",\n ),\n UpdateConnectionRequestOptions(\n Authorization(\n sessionToken = \"${sessionToken}\",\n ),\n ),\n )\n ) {\n is StytchResult.Success -> println(result.value)\n is StytchResult.Error -> println(result.exception)\n }\n}\n" - lang: javascript label: Node.js source: "// PUT /v1/b2b/sso/external/{organization_id}/connections/{connection_id}\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n organization_id: \"${organizationId}\",\n connection_id: \"${externalConnectionId}\",\n};\n\nconst options = {\n authorization: {\n session_token: '${sessionToken}',\n },\n};\n\nclient.sso.external.updateConnection(params, options)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: php label: PHP source: "$response = $client->sso->external->update_connection([\n 'organization_id' => '${organizationId}',\n 'connection_id' => '${externalConnectionId}',\n], [\n 'authorization' => ['session_token' => '${sessionToken}'],\n\n]);" - lang: python label: Python source: "# PUT /v1/b2b/sso/external/{organization_id}/connections/{connection_id}\nfrom stytch import B2BClient\nfrom stytch.b2b.models.sso_external import UpdateConnectionRequestOptions\nfrom stytch.shared.method_options import Authorization\n\nclient = B2BClient(\n project_id=\"${projectId}\",\n secret=\"${secret}\",\n)\n\nresp = client.sso.external.update_connection(\n organization_id=\"${organizationId}\",\n connection_id=\"${externalConnectionId}\",\n method_options=UpdateConnectionRequestOptions(\n authorization=Authorization(\n session_token=\"${sessionToken}\",\n ),\n ),\n)\n\nprint(resp)\n" - lang: ruby label: Ruby source: "# PUT /v1/b2b/sso/external/{organization_id}/connections/{connection_id}\nrequire 'stytch'\n\nclient = StytchB2B::Client.new(\n project_id: \"${projectId}\",\n secret: \"${secret}\"\n)\n\nresp = client.sso.external.update_connection(\n organization_id: \"${organizationId}\",\n connection_id: \"${externalConnectionId}\",\n method_options: StytchB2B::SSO::External::UpdateConnectionRequestOptions.new(\n authorization: Stytch::MethodOptions::Authorization.new(session_token: '${sessionToken}')\n )\n)\n\nputs resp" - lang: rust label: Rust source: "// PUT /v1/b2b/sso/external/{organization_id}/connections/{connection_id}\nuse stytch::b2b::client::Client;\nuse stytch::b2b::sso_external::UpdateConnectionRequest;\n\nfn main() {\n let client = Client::new(\"${projectId}\", \"${secret}\").unwrap();\n let resp = client.sso.external.update_connection(\n UpdateConnectionRequest{\n organization_id: \"${organizationId}\",\n connection_id: \"${externalConnectionId}\",\n ..Default::default()\n }\n ).await;\n println!(\"The response is {:?}\", resp);\n}" - lang: bash label: cURL source: "# PUT /v1/b2b/sso/external/{organization_id}/connections/{connection_id}\ncurl --request PUT \\\n --url https://test.stytch.com/v1/b2b/sso/external/${organizationId}/connections/${externalConnectionId} \\\n -u '${projectId}:${secret}' \\\n -H 'Content-Type: application/json' \\\n -H \"X-Stytch-Member-Session: ${sessionToken}\"" components: schemas: api_session_v1_SlackOAuthFactor: type: object properties: id: type: string description: The unique ID of an OAuth registration. provider_subject: type: string description: The unique identifier for the User within a given OAuth provider. Also commonly called the `sub` or "Subject field" in OAuth protocols. email_id: type: string description: The globally unique UUID of the Member's email. required: - id - provider_subject api_session_v1_HubspotOAuthFactor: type: object properties: id: type: string description: The unique ID of an OAuth registration. provider_subject: type: string description: The unique identifier for the User within a given OAuth provider. Also commonly called the `sub` or "Subject field" in OAuth protocols. email_id: type: string description: The globally unique UUID of the Member's email. required: - id - provider_subject api_sso_v1_sso_oidc_UpdateConnectionResponse: type: object properties: request_id: type: string description: Globally unique UUID that is returned with every API call. This value is important to log for debugging purposes; we may ask for this value to help identify a specific API call when helping you debug an issue. status_code: type: integer format: int32 description: The HTTP status code of the response. Stytch follows standard HTTP response status code patterns, e.g. 2XX values equate to success, 3XX values are redirects, 4XX are client errors, and 5XX are server errors. connection: $ref: '#/components/schemas/api_sso_v1_OIDCConnection' description: The [OIDC Connection Object](https://stytch.com/docs/b2b/api/oidc-connection-object). warning: type: string description: If it is not possible to resolve the well-known metadata document from the OIDC issuer, this field will explain what went wrong if the request is successful otherwise. In other words, even if the overall request succeeds, there could be relevant warnings related to the connection update. required: - request_id - status_code api_sso_v1_X509Certificate: type: object properties: certificate_id: type: string description: The ID of the certificate. certificate: type: string description: The certificate, in [PEM](https://en.wikipedia.org/wiki/Privacy-Enhanced_Mail) format. issuer: type: string description: The issuer of the certificate. For signing certificates, this value will be "Stytch". created_at: type: string description: A timestamp that indicates when the certificate was created. expires_at: type: string description: A timestamp that indicates when the certificate will expire. updated_at: type: string description: A timestamp that indicates when the certificate was updated. required: - certificate_id - certificate - issuer api_session_v1_DiscordOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_session_v1_SalesforceOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_b2b_session_v1_PrimaryRequired: type: object properties: allowed_auth_methods: type: array items: type: string description: Details the auth method that the member must also complete to fulfill the primary authentication requirements of the Organization. For example, a value of `[magic_link]` indicates that the Member must also complete a magic link authentication step. If you have an intermediate session token, you must pass it into that primary authentication step. required: - allowed_auth_methods api_b2b_mfa_v1_MemberOptions: type: object properties: mfa_phone_number: type: string description: The Member's MFA phone number. totp_registration_id: type: string description: The Member's MFA TOTP registration ID. required: - mfa_phone_number - totp_registration_id api_sso_v1_sso_saml_UpdateByURLRequest: type: object properties: metadata_url: type: string description: A URL that points to the IdP metadata. This will be provided by the IdP. description: Request type required: - metadata_url api_session_v1_SAMLSSOFactor: type: object properties: id: type: string description: The unique ID of an SSO Registration. provider_id: type: string description: Globally unique UUID that identifies a specific SAML Connection. external_id: type: string description: The ID of the member given by the identity provider. required: - id - provider_id - external_id api_organization_v1_CustomRole: type: object properties: role_id: type: string description: type: string permissions: type: array items: $ref: '#/components/schemas/api_organization_v1_CustomRolePermission' required: - role_id - description - permissions api_sso_v1_sso_saml_DeleteVerificationCertificateResponse: type: object properties: request_id: type: string description: Globally unique UUID that is returned with every API call. This value is important to log for debugging purposes; we may ask for this value to help identify a specific API call when helping you debug an issue. certificate_id: type: string description: The ID of the certificate that was deleted. status_code: type: integer format: int32 description: The HTTP status code of the response. Stytch follows standard HTTP response status code patterns, e.g. 2XX values equate to success, 3XX values are redirects, 4XX are client errors, and 5XX are server errors. required: - request_id - certificate_id - status_code api_session_v1_ImpersonatedFactor: type: object properties: impersonator_id: type: string description: For impersonated sessions initiated via the Stytch Dashboard, the `impersonator_id` will be the impersonator's Stytch Dashboard `member_id`. impersonator_email_address: type: string description: The email address of the impersonator. required: - impersonator_id - impersonator_email_address api_session_v1_TikTokOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_sso_v1_AuthenticateRequestLocale: type: string enum: - en - es - pt-br - fr - it - de-DE - zh-Hans - ca-ES api_sso_v1_sso_external_CreateConnectionRequest: type: object properties: external_organization_id: type: string description: Globally unique UUID that identifies a different Organization within your Project. external_connection_id: type: string description: Globally unique UUID that identifies a specific SSO connection configured for a different Organization in your Project. display_name: type: string description: A human-readable display name for the connection. connection_implicit_role_assignments: type: array items: $ref: '#/components/schemas/api_sso_v1_SAMLConnectionImplicitRoleAssignment' group_implicit_role_assignments: type: array items: $ref: '#/components/schemas/api_sso_v1_SAMLGroupImplicitRoleAssignment' description: Request type required: - external_organization_id - external_connection_id api_session_v1_CoinbaseOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_b2b_mfa_v1_MfaRequired: type: object properties: member_options: $ref: '#/components/schemas/api_b2b_mfa_v1_MemberOptions' description: Information about the Member's options for completing MFA. secondary_auth_initiated: type: string description: If null, indicates that no secondary authentication has been initiated. If equal to "sms_otp", indicates that the Member has a phone number, and a one time passcode has been sent to the Member's phone number. No secondary authentication will be initiated during calls to the discovery authenticate or list organizations endpoints, even if the Member has a phone number. api_organization_v1_SSORegistration: type: object properties: connection_id: type: string description: Globally unique UUID that identifies a specific SSO `connection_id` for a Member. external_id: type: string description: The ID of the member given by the identity provider. registration_id: type: string description: The unique ID of an SSO Registration. sso_attributes: type: object additionalProperties: true description: An object for storing SSO attributes brought over from the identity provider. required: - connection_id - external_id - registration_id api_sso_v1_sso_saml_CreateConnectionResponse: type: object properties: request_id: type: string description: Globally unique UUID that is returned with every API call. This value is important to log for debugging purposes; we may ask for this value to help identify a specific API call when helping you debug an issue. status_code: type: integer format: int32 description: The HTTP status code of the response. Stytch follows standard HTTP response status code patterns, e.g. 2XX values equate to success, 3XX values are redirects, 4XX are client errors, and 5XX are server errors. connection: $ref: '#/components/schemas/api_sso_v1_SAMLConnection' description: The [SAML Connection Object](https://stytch.com/docs/b2b/api/saml-connection-object) required: - request_id - status_code api_organization_v1_RetiredEmail: type: object properties: email_id: type: string description: The globally unique UUID of a Member's email. email_address: type: string description: The email address of the Member. required: - email_id - email_address api_organization_v1_MemberRole: type: object properties: role_id: type: string description: "The unique identifier of the RBAC Role, provided by the developer and intended to be human-readable.\n\n Reserved `role_id`s that are predefined by Stytch include:\n\n * `stytch_member`\n * `stytch_admin`\n\n Check out the [guide on Stytch default Roles](https://stytch.com/docs/b2b/guides/rbac/stytch-default) for a more detailed explanation.\n\n " sources: type: array items: $ref: '#/components/schemas/api_organization_v1_MemberRoleSource' description: A list of sources for this role assignment. A role assignment can come from multiple sources - for example, the Role could be both explicitly assigned and implicitly granted from the Member's email domain. required: - role_id - sources api_sso_v1_CreateConnectionRequestIdentityProvider: type: string enum: - classlink - cyberark - duo - generic - google-workspace - jumpcloud - keycloak - miniorange - microsoft-entra - okta - onelogin - pingfederate - rippling - salesforce - shibboleth api_session_v1_EmbeddableMagicLinkFactor: type: object properties: embedded_id: type: string required: - embedded_id api_b2b_scim_v1_SCIMAttributes: type: object properties: user_name: type: string id: type: string external_id: type: string active: type: boolean groups: type: array items: $ref: '#/components/schemas/api_b2b_scim_v1_Group' display_name: type: string nick_name: type: string profile_url: type: string user_type: type: string title: type: string preferred_language: type: string locale: type: string timezone: type: string emails: type: array items: $ref: '#/components/schemas/api_b2b_scim_v1_Email' phone_numbers: type: array items: $ref: '#/components/schemas/api_b2b_scim_v1_PhoneNumber' addresses: type: array items: $ref: '#/components/schemas/api_b2b_scim_v1_Address' ims: type: array items: $ref: '#/components/schemas/api_b2b_scim_v1_IMs' photos: type: array items: $ref: '#/components/schemas/api_b2b_scim_v1_Photo' entitlements: type: array items: $ref: '#/components/schemas/api_b2b_scim_v1_Entitlement' roles: type: array items: $ref: '#/components/schemas/api_b2b_scim_v1_Role' x509certificates: type: array items: $ref: '#/components/schemas/api_b2b_scim_v1_X509Certificate' name: $ref: '#/components/schemas/api_b2b_scim_v1_Name' enterprise_extension: $ref: '#/components/schemas/api_b2b_scim_v1_EnterpriseExtension' required: - user_name - id - external_id - active - groups - display_name - nick_name - profile_url - user_type - title - preferred_language - locale - timezone - emails - phone_numbers - addresses - ims - photos - entitlements - roles - x509certificates api_b2b_session_v1_MemberSession: type: object properties: member_session_id: type: string description: Globally unique UUID that identifies a specific Session. member_id: type: string description: Globally unique UUID that identifies a specific Member. started_at: type: string description: The timestamp when the Session was created. Values conform to the RFC 3339 standard and are expressed in UTC, e.g. `2021-12-29T12:33:09Z`. last_accessed_at: type: string description: The timestamp when the Session was last accessed. Values conform to the RFC 3339 standard and are expressed in UTC, e.g. `2021-12-29T12:33:09Z`. expires_at: type: string description: The timestamp when the Session expires. Values conform to the RFC 3339 standard and are expressed in UTC, e.g. `2021-12-29T12:33:09Z`. authentication_factors: type: array items: $ref: '#/components/schemas/api_session_v1_AuthenticationFactor' description: An array of different authentication factors that comprise a Session. organization_id: type: string description: Globally unique UUID that identifies a specific Organization. The `organization_id` is critical to perform operations on an Organization, so be sure to preserve this value. roles: type: array items: type: string organization_slug: type: string description: 'The unique URL slug of the Organization. The slug only accepts alphanumeric characters and the following reserved characters: `-` `.` `_` `~`. Must be between 2 and 128 characters in length. Wherever an organization_id is expected in a path or request parameter, you may also use the organization_slug as a convenience.' custom_claims: type: object additionalProperties: true description: The custom claims map for a Session. Claims can be added to a session during a Sessions authenticate call. required: - member_session_id - member_id - started_at - last_accessed_at - expires_at - authentication_factors - organization_id - roles - organization_slug api_device_history_v1_DeviceInfo: type: object properties: visitor_id: type: string description: The `visitor_id` (a unique identifier) of the user's device. See the [Device Fingerprinting documentation](https://stytch.com/docs/fraud/guides/device-fingerprinting/fingerprints) for more details on the `visitor_id`. visitor_id_details: $ref: '#/components/schemas/api_device_history_v1_DeviceAttributeDetails' description: Information about the `visitor_id`. ip_address: type: string description: The IP address of the user's device. ip_address_details: $ref: '#/components/schemas/api_device_history_v1_DeviceAttributeDetails' description: Information about the `ip_address`. ip_geo_city: type: string description: The city where the IP address is located. ip_geo_region: type: string description: The region where the IP address is located. ip_geo_country: type: string description: The country code where the IP address is located. ip_geo_country_details: $ref: '#/components/schemas/api_device_history_v1_DeviceAttributeDetails' description: Information about the `ip_geo_country`. required: - visitor_id api_b2b_scim_v1_Entitlement: type: object properties: value: type: string type: type: string primary: type: boolean required: - value - type - primary api_session_v1_BitbucketOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_sso_v1_AuthenticateResponse: type: object properties: request_id: type: string description: Globally unique UUID that is returned with every API call. This value is important to log for debugging purposes; we may ask for this value to help identify a specific API call when helping you debug an issue. member_id: type: string description: Globally unique UUID that identifies a specific Member. organization_id: type: string description: Globally unique UUID that identifies a specific Organization. The `organization_id` is critical to perform operations on an Organization, so be sure to preserve this value. member: $ref: '#/components/schemas/api_organization_v1_Member' description: The [Member object](https://stytch.com/docs/b2b/api/member-object) session_token: type: string description: A secret token for a given Stytch Session. session_jwt: type: string description: The JSON Web Token (JWT) for a given Stytch Session. reset_session: type: boolean description: This field is deprecated. organization: $ref: '#/components/schemas/api_organization_v1_Organization' description: The [Organization object](https://stytch.com/docs/b2b/api/organization-object). intermediate_session_token: type: string description: The returned Intermediate Session Token contains an SSO factor associated with the Member. If this value is non-empty, the member must complete an MFA step to finish logging in to the Organization. The token can be used with the [OTP SMS Authenticate endpoint](https://stytch.com/docs/b2b/api/authenticate-otp-sms), [TOTP Authenticate endpoint](https://stytch.com/docs/b2b/api/authenticate-totp), or [Recovery Codes Recover endpoint](https://stytch.com/docs/b2b/api/recovery-codes-recover) to complete an MFA flow and log in to the Organization. The token has a default expiry of 10 minutes. SSO factors are not transferable between Organizations, so the intermediate session token is not valid for use with discovery endpoints. member_authenticated: type: boolean description: Indicates whether the Member is fully authenticated. If false, the Member needs to complete an MFA step to log in to the Organization. status_code: type: integer format: int32 description: The HTTP status code of the response. Stytch follows standard HTTP response status code patterns, e.g. 2XX values equate to success, 3XX values are redirects, 4XX are client errors, and 5XX are server errors. member_session: $ref: '#/components/schemas/api_b2b_session_v1_MemberSession' description: The [Session object](https://stytch.com/docs/b2b/api/session-object). mfa_required: $ref: '#/components/schemas/api_b2b_mfa_v1_MfaRequired' description: Information about the MFA requirements of the Organization and the Member's options for fulfilling MFA. primary_required: $ref: '#/components/schemas/api_b2b_session_v1_PrimaryRequired' member_device: $ref: '#/components/schemas/api_device_history_v1_DeviceInfo' description: If a valid `telemetry_id` was passed in the request and the [Fingerprint Lookup API](https://stytch.com/docs/fraud/api/fingerprint-lookup) returned results, the `member_device` response field will contain information about the member's device attributes. required: - request_id - member_id - organization_id - member - session_token - session_jwt - reset_session - organization - intermediate_session_token - member_authenticated - status_code api_sso_v1_EncryptionPrivateKey: type: object properties: private_key_id: type: string private_key: type: string created_at: type: string required: - private_key_id - private_key api_organization_v1_SCIMRegistration: type: object properties: connection_id: type: string description: The ID of the SCIM connection. registration_id: type: string description: The unique ID of a SCIM Registration. external_id: type: string description: The ID of the member given by the identity provider. scim_attributes: $ref: '#/components/schemas/api_b2b_scim_v1_SCIMAttributes' description: An object for storing SCIM attributes brought over from the identity provider. required: - connection_id - registration_id api_sso_v1_sso_oidc_CreateConnectionResponse: type: object properties: request_id: type: string description: Globally unique UUID that is returned with every API call. This value is important to log for debugging purposes; we may ask for this value to help identify a specific API call when helping you debug an issue. status_code: type: integer format: int32 description: The HTTP status code of the response. Stytch follows standard HTTP response status code patterns, e.g. 2XX values equate to success, 3XX values are redirects, 4XX are client errors, and 5XX are server errors. connection: $ref: '#/components/schemas/api_sso_v1_OIDCConnection' description: The [OIDC Connection Object](https://stytch.com/docs/b2b/api/oidc-connection-object). required: - request_id - status_code api_session_v1_TwitterOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_session_v1_YahooOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_b2b_scim_v1_Email: type: object properties: value: type: string type: type: string primary: type: boolean required: - value - type - primary api_sso_v1_DeleteConnectionResponse: type: object properties: request_id: type: string description: Globally unique UUID that is returned with every API call. This value is important to log for debugging purposes; we may ask for this value to help identify a specific API call when helping you debug an issue. connection_id: type: string description: The `connection_id` that was deleted as part of the delete request. status_code: type: integer format: int32 description: The HTTP status code of the response. Stytch follows standard HTTP response status code patterns, e.g. 2XX values equate to success, 3XX values are redirects, 4XX are client errors, and 5XX are server errors. required: - request_id - connection_id - status_code api_organization_v1_Organization: type: object properties: organization_id: type: string description: Globally unique UUID that identifies a specific Organization. The `organization_id` is critical to perform operations on an Organization, so be sure to preserve this value. You may also use the organization_slug or organization_external_id here as a convenience. organization_name: type: string description: The name of the Organization. Must be between 1 and 128 characters in length. organization_logo_url: type: string description: The image URL of the Organization logo. organization_slug: type: string description: 'The unique URL slug of the Organization. The slug only accepts alphanumeric characters and the following reserved characters: `-` `.` `_` `~`. Must be between 2 and 128 characters in length. Wherever an organization_id is expected in a path or request parameter, you may also use the organization_slug as a convenience.' sso_jit_provisioning: type: string description: "The authentication setting that controls the JIT provisioning of Members when authenticating via SSO. The accepted values are:\n \n `ALL_ALLOWED` – the default setting, new Members will be automatically provisioned upon successful authentication via any of the Organization's `sso_active_connections`.\n \n `RESTRICTED` – only new Members with SSO logins that comply with `sso_jit_provisioning_allowed_connections` can be provisioned upon authentication.\n \n `NOT_ALLOWED` – disable JIT provisioning via SSO.\n " sso_jit_provisioning_allowed_connections: type: array items: type: string description: "An array of `connection_id`s that reference [SAML Connection objects](https://stytch.com/docs/b2b/api/saml-connection-object).\n Only these connections will be allowed to JIT provision Members via SSO when `sso_jit_provisioning` is set to `RESTRICTED`." sso_active_connections: type: array items: $ref: '#/components/schemas/api_organization_v1_ActiveSSOConnection' description: An array of active [SAML Connection references](https://stytch.com/docs/b2b/api/saml-connection-object) or [OIDC Connection references](https://stytch.com/docs/b2b/api/oidc-connection-object). email_allowed_domains: type: array items: type: string description: "An array of email domains that allow invites or JIT provisioning for new Members. This list is enforced when either `email_invites` or `email_jit_provisioning` is set to `RESTRICTED`.\n \n \n Common domains such as `gmail.com` are not allowed. See the [common email domains resource](https://stytch.com/docs/b2b/api/common-email-domains) for the full list." email_jit_provisioning: type: string description: "The authentication setting that controls how a new Member can be provisioned by authenticating via Email Magic Link or OAuth. The accepted values are:\n \n `RESTRICTED` – only new Members with verified emails that comply with `email_allowed_domains` can be provisioned upon authentication via Email Magic Link or OAuth.\n \n `NOT_ALLOWED` – the default setting, disables JIT provisioning via Email Magic Link and OAuth.\n " email_invites: type: string description: "The authentication setting that controls how a new Member can be invited to an organization by email. The accepted values are:\n \n `ALL_ALLOWED` – any new Member can be invited to join via email.\n \n `RESTRICTED` – only new Members with verified emails that comply with `email_allowed_domains` can be invited via email.\n \n `NOT_ALLOWED` – disable email invites.\n " auth_methods: type: string description: "The setting that controls which authentication methods can be used by Members of an Organization. The accepted values are:\n \n `ALL_ALLOWED` – the default setting which allows all authentication methods to be used.\n \n `RESTRICTED` – only methods that comply with `allowed_auth_methods` can be used for authentication. This setting does not apply to Members with `is_breakglass` set to `true`.\n " allowed_auth_methods: type: array items: type: string description: "An array of allowed authentication methods. This list is enforced when `auth_methods` is set to `RESTRICTED`.\n The list's accepted values are: `sso`, `magic_link`, `email_otp`, `password`, `google_oauth`, `microsoft_oauth`, `slack_oauth`, `github_oauth`, and `hubspot_oauth`.\n " mfa_policy: type: string description: "The setting that controls the MFA policy for all Members in the Organization. The accepted values are:\n \n `REQUIRED_FOR_ALL` – All Members within the Organization will be required to complete MFA every time they wish to log in. However, any active Session that existed prior to this setting change will remain valid.\n \n `OPTIONAL` – The default value. The Organization does not require MFA by default for all Members. Members will be required to complete MFA only if their `mfa_enrolled` status is set to true.\n " rbac_email_implicit_role_assignments: type: array items: $ref: '#/components/schemas/api_organization_v1_EmailImplicitRoleAssignment' description: "Implicit role assignments based off of email domains.\n For each domain-Role pair, all Members whose email addresses have the specified email domain will be granted the\n associated Role, regardless of their login method. See the [RBAC guide](https://stytch.com/docs/b2b/guides/rbac/role-assignment)\n for more information about role assignment." mfa_methods: type: string description: "The setting that controls which MFA methods can be used by Members of an Organization. The accepted values are:\n \n `ALL_ALLOWED` – the default setting which allows all authentication methods to be used.\n \n `RESTRICTED` – only methods that comply with `allowed_mfa_methods` can be used for authentication. This setting does not apply to Members with `is_breakglass` set to `true`.\n " allowed_mfa_methods: type: array items: type: string description: "An array of allowed MFA authentication methods. This list is enforced when `mfa_methods` is set to `RESTRICTED`.\n The list's accepted values are: `sms_otp` and `totp`.\n " oauth_tenant_jit_provisioning: type: string description: "The authentication setting that controls how a new Member can JIT provision into an organization by tenant. The accepted values are:\n \n `RESTRICTED` – only new Members with tenants in `allowed_oauth_tenants` can JIT provision via tenant.\n \n `NOT_ALLOWED` – the default setting, disables JIT provisioning by OAuth Tenant.\n " claimed_email_domains: type: array items: type: string description: A list of email domains that are claimed by the Organization. first_party_connected_apps_allowed_type: type: string description: "The authentication setting that sets the Organization's policy towards first party Connected Apps. The accepted values are:\n \n `ALL_ALLOWED` – the default setting, any first party Connected App in the Project is permitted for use by Members.\n \n `RESTRICTED` – only first party Connected Apps with IDs in `allowed_first_party_connected_apps` can be used by Members.\n \n `NOT_ALLOWED` – no first party Connected Apps are permitted.\n " allowed_first_party_connected_apps: type: array items: type: string description: An array of first party Connected App IDs that are allowed for the Organization. Only used when the Organization's `first_party_connected_apps_allowed_type` is `RESTRICTED`. third_party_connected_apps_allowed_type: type: string description: "The authentication setting that sets the Organization's policy towards third party Connected Apps. The accepted values are:\n \n `ALL_ALLOWED` – the default setting, any third party Connected App in the Project is permitted for use by Members.\n \n `RESTRICTED` – only third party Connected Apps with IDs in `allowed_first_party_connected_apps` can be used by Members.\n \n `NOT_ALLOWED` – no third party Connected Apps are permitted.\n " allowed_third_party_connected_apps: type: array items: type: string description: An array of third party Connected App IDs that are allowed for the Organization. Only used when the Organization's `third_party_connected_apps_allowed_type` is `RESTRICTED`. custom_roles: type: array items: $ref: '#/components/schemas/api_organization_v1_CustomRole' trusted_metadata: type: object additionalProperties: true description: An arbitrary JSON object for storing application-specific data or identity-provider-specific data. created_at: type: string description: The timestamp of the Organization's creation. Values conform to the RFC 3339 standard and are expressed in UTC, e.g. `2021-12-29T12:33:09Z`. updated_at: type: string description: The timestamp of when the Organization was last updated. Values conform to the RFC 3339 standard and are expressed in UTC, e.g. `2021-12-29T12:33:09Z`. organization_external_id: type: string description: A unique identifier for the organization. sso_default_connection_id: type: string description: The default connection used for SSO when there are multiple active connections. scim_active_connection: $ref: '#/components/schemas/api_organization_v1_ActiveSCIMConnection' description: An active [SCIM Connection references](https://stytch.com/docs/b2b/api/scim-connection-object). allowed_oauth_tenants: type: object additionalProperties: true description: A map of allowed OAuth tenants. If this field is not passed in, the Organization will not allow JIT provisioning by OAuth Tenant. Allowed keys are "slack", "hubspot", and "github". required: - organization_id - organization_name - organization_logo_url - organization_slug - sso_jit_provisioning - sso_jit_provisioning_allowed_connections - sso_active_connections - email_allowed_domains - email_jit_provisioning - email_invites - auth_methods - allowed_auth_methods - mfa_policy - rbac_email_implicit_role_assignments - mfa_methods - allowed_mfa_methods - oauth_tenant_jit_provisioning - claimed_email_domains - first_party_connected_apps_allowed_type - allowed_first_party_connected_apps - third_party_connected_apps_allowed_type - allowed_third_party_connected_apps - custom_roles api_session_v1_SpotifyOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_sso_v1_AuthenticateRequest: type: object properties: sso_token: type: string description: The token to authenticate. pkce_code_verifier: type: string description: A base64url encoded one time secret used to validate that the request starts and ends on the same device. session_token: type: string description: The `session_token` belonging to the member that you wish to associate the email with. session_jwt: type: string description: The `session_jwt` belonging to the member that you wish to associate the email with. session_duration_minutes: type: integer format: int32 description: "Set the session lifetime to be this many minutes from now. This will start a new session if one doesn't already exist,\n returning both an opaque `session_token` and `session_jwt` for this session. Remember that the `session_jwt` will have a fixed lifetime of\n five minutes regardless of the underlying session duration, and will need to be refreshed over time.\n\n This value must be a minimum of 5 and a maximum of 527040 minutes (366 days).\n\n If a `session_token` or `session_jwt` is provided then a successful authentication will continue to extend the session this many minutes.\n\n If the `session_duration_minutes` parameter is not specified, a Stytch session will be created with a 60 minute duration. If you don't want\n to use the Stytch session product, you can ignore the session fields in the response." session_custom_claims: type: object additionalProperties: true description: "Add a custom claims map to the Session being authenticated. Claims are only created if a Session is initialized by providing a value in\n `session_duration_minutes`. Claims will be included on the Session object and in the JWT. To update a key in an existing Session, supply a new value. To\n delete a key, supply a null value. Custom claims made with reserved claims (`iss`, `sub`, `aud`, `exp`, `nbf`, `iat`, `jti`) will be ignored.\n Total custom claims size cannot exceed four kilobytes." locale: $ref: '#/components/schemas/api_sso_v1_AuthenticateRequestLocale' description: 'If the Member needs to complete an MFA step, and the Member has a phone number, this endpoint will pre-emptively send a one-time passcode (OTP) to the Member''s phone number. The locale argument will be used to determine which language to use when sending the passcode. Parameter is an [IETF BCP 47 language tag](https://www.w3.org/International/articles/language-tags/), e.g. `"en"`. Currently supported languages are English (`"en"`), Spanish (`"es"`), and Brazilian Portuguese (`"pt-br"`); if no value is provided, the copy defaults to English. Request support for additional languages [here](https://docs.google.com/forms/d/e/1FAIpQLScZSpAu_m2AmLXRT3F3kap-s_mcV6UTBitYn6CdyWP0-o7YjQ/viewform?usp=sf_link")! ' intermediate_session_token: type: string description: Adds this primary authentication factor to the intermediate session token. If the resulting set of factors satisfies the organization's primary authentication requirements and MFA requirements, the intermediate session token will be consumed and converted to a member session. If not, the same intermediate session token will be returned. telemetry_id: type: string description: If the `telemetry_id` is passed, as part of this request, Stytch will call the [Fingerprint Lookup API](https://stytch.com/docs/fraud/api/fingerprint-lookup) and store the associated fingerprints and IPGEO information for the Member. Your workspace must be enabled for Device Fingerprinting to use this feature. description: Request type required: - sso_token api_session_v1_GitLabOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_sso_v1_SAMLGroupImplicitRoleAssignment: type: object properties: role_id: type: string group: type: string required: - role_id - group api_organization_v1_ActiveSSOConnection: type: object properties: connection_id: type: string description: Globally unique UUID that identifies a specific SSO `connection_id` for a Member. display_name: type: string description: A human-readable display name for the connection. identity_provider: type: string required: - connection_id - display_name - identity_provider api_session_v1_AuthenticationFactor: type: object properties: type: $ref: '#/components/schemas/api_session_v1_AuthenticationFactorType' description: "The type of authentication factor. The possible values are: `email_otp`, `impersonated`, `imported`,\n `magic_link`, `oauth`, `otp`, `password`, `recovery_codes`, `sso`, `trusted_auth_token`, or `totp`." delivery_method: $ref: '#/components/schemas/api_session_v1_AuthenticationFactorDeliveryMethod' description: "The method that was used to deliver the authentication factor. The possible values depend on the `type`:\n \n `email_otp` – Only `email`.\n \n `impersonated` – Only `impersonation`.\n \n `imported` – Only `imported_auth0`.\n \n `magic_link` – Only `email`.\n \n `oauth` – The delivery method is determined by the specific OAuth provider used. The possible values are `oauth_google`, `oauth_microsoft`, `oauth_hubspot`, `oauth_slack`, or `oauth_github`.\n \n In addition, you may see an 'exchange' delivery method when a non-email-verifying OAuth factor originally authenticated in one organization is exchanged for a factor in another organization.\n This can happen during authentication flows such as [session exchange](https://stytch.com/docs/b2b/api/exchange-session).\n The non-email-verifying OAuth providers are Hubspot, Slack, and Github.\n Google is also considered non-email-verifying when the HD claim is empty.\n The possible exchange values are `oauth_exchange_google`, `oauth_exchange_hubspot`, `oauth_exchange_slack`, or `oauth_exchange_github`.\n \n The final possible value is `oauth_access_token_exchange`, if this factor came from an [access token exchange flow](https://stytch.com/docs/b2b/api/connected-app-access-token-exchange).\n \n `otp` – Only `sms`.\n \n `password` – Only `knowledge`.\n \n `recovery_codes` – Only `recovery_code`.\n \n `sso` – Either `sso_saml` or `sso_oidc`.\n \n `trusted_auth_token` – Only `trusted_token_exchange`.\n \n `totp` – Only `authenticator_app`.\n " last_authenticated_at: type: string description: The timestamp when the factor was last authenticated. created_at: type: string description: The timestamp when the factor was initially authenticated. updated_at: type: string description: The timestamp when the factor was last updated. email_factor: $ref: '#/components/schemas/api_session_v1_EmailFactor' description: Information about the email factor, if one is present. phone_number_factor: $ref: '#/components/schemas/api_session_v1_PhoneNumberFactor' description: Information about the phone number factor, if one is present. google_oauth_factor: $ref: '#/components/schemas/api_session_v1_GoogleOAuthFactor' description: Information about the Google OAuth factor, if one is present. microsoft_oauth_factor: $ref: '#/components/schemas/api_session_v1_MicrosoftOAuthFactor' description: Information about the Microsoft OAuth factor, if one is present. apple_oauth_factor: $ref: '#/components/schemas/api_session_v1_AppleOAuthFactor' webauthn_factor: $ref: '#/components/schemas/api_session_v1_WebAuthnFactor' authenticator_app_factor: $ref: '#/components/schemas/api_session_v1_AuthenticatorAppFactor' description: Information about the TOTP-backed Authenticator App factor, if one is present. github_oauth_factor: $ref: '#/components/schemas/api_session_v1_GithubOAuthFactor' description: Information about the Github OAuth factor, if one is present. recovery_code_factor: $ref: '#/components/schemas/api_session_v1_RecoveryCodeFactor' facebook_oauth_factor: $ref: '#/components/schemas/api_session_v1_FacebookOAuthFactor' crypto_wallet_factor: $ref: '#/components/schemas/api_session_v1_CryptoWalletFactor' amazon_oauth_factor: $ref: '#/components/schemas/api_session_v1_AmazonOAuthFactor' bitbucket_oauth_factor: $ref: '#/components/schemas/api_session_v1_BitbucketOAuthFactor' coinbase_oauth_factor: $ref: '#/components/schemas/api_session_v1_CoinbaseOAuthFactor' discord_oauth_factor: $ref: '#/components/schemas/api_session_v1_DiscordOAuthFactor' figma_oauth_factor: $ref: '#/components/schemas/api_session_v1_FigmaOAuthFactor' git_lab_oauth_factor: $ref: '#/components/schemas/api_session_v1_GitLabOAuthFactor' instagram_oauth_factor: $ref: '#/components/schemas/api_session_v1_InstagramOAuthFactor' linked_in_oauth_factor: $ref: '#/components/schemas/api_session_v1_LinkedInOAuthFactor' shopify_oauth_factor: $ref: '#/components/schemas/api_session_v1_ShopifyOAuthFactor' slack_oauth_factor: $ref: '#/components/schemas/api_session_v1_SlackOAuthFactor' description: Information about the Slack OAuth factor, if one is present. snapchat_oauth_factor: $ref: '#/components/schemas/api_session_v1_SnapchatOAuthFactor' spotify_oauth_factor: $ref: '#/components/schemas/api_session_v1_SpotifyOAuthFactor' steam_oauth_factor: $ref: '#/components/schemas/api_session_v1_SteamOAuthFactor' tik_tok_oauth_factor: $ref: '#/components/schemas/api_session_v1_TikTokOAuthFactor' twitch_oauth_factor: $ref: '#/components/schemas/api_session_v1_TwitchOAuthFactor' twitter_oauth_factor: $ref: '#/components/schemas/api_session_v1_TwitterOAuthFactor' embeddable_magic_link_factor: $ref: '#/components/schemas/api_session_v1_EmbeddableMagicLinkFactor' biometric_factor: $ref: '#/components/schemas/api_session_v1_BiometricFactor' saml_sso_factor: $ref: '#/components/schemas/api_session_v1_SAMLSSOFactor' description: Information about the SAML SSO factor, if one is present. oidc_sso_factor: $ref: '#/components/schemas/api_session_v1_OIDCSSOFactor' description: Information about the OIDC SSO factor, if one is present. salesforce_oauth_factor: $ref: '#/components/schemas/api_session_v1_SalesforceOAuthFactor' yahoo_oauth_factor: $ref: '#/components/schemas/api_session_v1_YahooOAuthFactor' hubspot_oauth_factor: $ref: '#/components/schemas/api_session_v1_HubspotOAuthFactor' description: Information about the Hubspot OAuth factor, if one is present. slack_oauth_exchange_factor: $ref: '#/components/schemas/api_session_v1_SlackOAuthExchangeFactor' description: Information about the Slack OAuth Exchange factor, if one is present. hubspot_oauth_exchange_factor: $ref: '#/components/schemas/api_session_v1_HubspotOAuthExchangeFactor' description: Information about the Hubspot OAuth Exchange factor, if one is present. github_oauth_exchange_factor: $ref: '#/components/schemas/api_session_v1_GithubOAuthExchangeFactor' description: Information about the Github OAuth Exchange factor, if one is present. google_oauth_exchange_factor: $ref: '#/components/schemas/api_session_v1_GoogleOAuthExchangeFactor' description: Information about the Google OAuth Exchange factor, if one is present. impersonated_factor: $ref: '#/components/schemas/api_session_v1_ImpersonatedFactor' description: Information about the impersonated factor, if one is present. oauth_access_token_exchange_factor: $ref: '#/components/schemas/api_session_v1_OAuthAccessTokenExchangeFactor' description: Information about the access token exchange factor, if one is present. trusted_auth_token_factor: $ref: '#/components/schemas/api_session_v1_TrustedAuthTokenFactor' description: Information about the trusted auth token factor, if one is present. required: - type - delivery_method api_session_v1_PhoneNumberFactor: type: object properties: phone_id: type: string description: The globally unique UUID of the Member's phone number. phone_number: type: string description: The phone number of the Member. required: - phone_id - phone_number api_b2b_scim_v1_Manager: type: object properties: value: type: string ref: type: string display_name: type: string required: - value - ref - display_name api_session_v1_RecoveryCodeFactor: type: object properties: totp_recovery_code_id: type: string required: - totp_recovery_code_id api_session_v1_HubspotOAuthExchangeFactor: type: object properties: email_id: type: string description: The globally unique UUID of the Member's email. required: - email_id api_organization_v1_Member: type: object properties: organization_id: type: string description: Globally unique UUID that identifies a specific Organization. The `organization_id` is critical to perform operations on an Organization, so be sure to preserve this value. You may also use the organization_slug or organization_external_id here as a convenience. member_id: type: string description: Globally unique UUID that identifies a specific Member. The `member_id` is critical to perform operations on a Member, so be sure to preserve this value. You may use an external_id here if one is set for the member. email_address: type: string description: The email address of the Member. status: type: string description: 'The status of the Member. The possible values are: `pending`, `invited`, `active`, or `deleted`.' name: type: string description: The name of the Member. sso_registrations: type: array items: $ref: '#/components/schemas/api_organization_v1_SSORegistration' description: An array of registered [SAML Connection](https://stytch.com/docs/b2b/api/saml-connection-object) or [OIDC Connection](https://stytch.com/docs/b2b/api/oidc-connection-object) objects the Member has authenticated with. is_breakglass: type: boolean description: Identifies the Member as a break glass user - someone who has permissions to authenticate into an Organization by bypassing the Organization's settings. A break glass account is typically used for emergency purposes to gain access outside of normal authentication procedures. Refer to the [Organization object](https://stytch.com/docs/b2b/api/organization-object) and its `auth_methods` and `allowed_auth_methods` fields for more details. member_password_id: type: string description: Globally unique UUID that identifies a Member's password. oauth_registrations: type: array items: $ref: '#/components/schemas/api_organization_v1_OAuthRegistration' description: A list of OAuth registrations for this member. email_address_verified: type: boolean description: Whether or not the Member's email address is verified. mfa_phone_number_verified: type: boolean description: Whether or not the Member's phone number is verified. is_admin: type: boolean description: "Whether or not the Member has the `stytch_admin` Role. This Role is automatically granted to Members\n who create an Organization through the [discovery flow](https://stytch.com/docs/b2b/api/create-organization-via-discovery). See the\n [RBAC guide](https://stytch.com/docs/b2b/guides/rbac/stytch-default) for more details on this Role." totp_registration_id: type: string description: Globally unique UUID that identifies a TOTP instance. retired_email_addresses: type: array items: $ref: '#/components/schemas/api_organization_v1_RetiredEmail' description: "\n A list of retired email addresses for this member.\n A previously active email address can be marked as retired in one of two ways:\n - It's replaced with a new primary email address during an explicit Member update.\n - A new email address is surfaced by an OAuth, SAML or OIDC provider. In this case the new email address becomes the\n Member's primary email address and the old primary email address is retired.\n \n A retired email address cannot be used by other Members in the same Organization. However, unlinking retired email\n addresses allows them to be subsequently re-used by other Organization Members. Retired email addresses can be unlinked\n using the [Unlink Retired Email endpoint](https://stytch.com/docs/b2b/api/unlink-retired-member-email).\n " is_locked: type: boolean description: Whether the Member is temporarily locked due to too many failed authentication attempts. See the [User Locking Guide](https://stytch.com/docs/resources/platform/user-locks) for more information. mfa_enrolled: type: boolean description: Sets whether the Member is enrolled in MFA. If true, the Member must complete an MFA step whenever they wish to log in to their Organization. If false, the Member only needs to complete an MFA step if the Organization's MFA policy is set to `REQUIRED_FOR_ALL`. mfa_phone_number: type: string description: The Member's phone number. A Member may only have one phone number. The phone number should be in E.164 format (i.e. +1XXXXXXXXXX). default_mfa_method: type: string description: The Member's default MFA method. This value is used to determine which secondary MFA method to use in the case of multiple methods registered for a Member. The current possible values are `sms_otp` and `totp`. roles: type: array items: $ref: '#/components/schemas/api_organization_v1_MemberRole' description: "Explicit or implicit Roles assigned to this Member, along with details about the role assignment source.\n See the [RBAC guide](https://stytch.com/docs/b2b/guides/rbac/role-assignment) for more information about role assignment." trusted_metadata: type: object additionalProperties: true description: An arbitrary JSON object for storing application-specific data or identity-provider-specific data. untrusted_metadata: type: object additionalProperties: true description: "An arbitrary JSON object of application-specific data. These fields can be edited directly by the\n frontend SDK, and should not be used to store critical information. See the [Metadata resource](https://stytch.com/docs/b2b/api/metadata)\n for complete field behavior details." created_at: type: string description: The timestamp of the Member's creation. Values conform to the RFC 3339 standard and are expressed in UTC, e.g. `2021-12-29T12:33:09Z`. updated_at: type: string description: The timestamp of when the Member was last updated. Values conform to the RFC 3339 standard and are expressed in UTC, e.g. `2021-12-29T12:33:09Z`. scim_registration: $ref: '#/components/schemas/api_organization_v1_SCIMRegistration' description: A scim member registration, referencing a [SCIM Connection](https://stytch.com/docs/b2b/api/scim-connection-object) object in use for the Member creation. external_id: type: string description: The ID of the member given by the identity provider. lock_created_at: type: string description: When the member lock was created, if there is one. Values conform to the RFC 3339 standard and are expressed in UTC, e.g. `2021-12-29T12:33:09Z`. lock_expires_at: type: string description: When the member lock expires, if there is one. Values conform to the RFC 3339 standard and are expressed in UTC, e.g. `2021-12-29T12:33:09Z`. required: - organization_id - member_id - email_address - status - name - sso_registrations - is_breakglass - member_password_id - oauth_registrations - email_address_verified - mfa_phone_number_verified - is_admin - totp_registration_id - retired_email_addresses - is_locked - mfa_enrolled - mfa_phone_number - default_mfa_method - roles api_sso_v1_sso_saml_UpdateConnectionRequest: type: object properties: idp_entity_id: type: string description: A globally unique name for the IdP. This will be provided by the IdP. display_name: type: string description: A human-readable display name for the connection. attribute_mapping: type: object additionalProperties: true description: 'An object that represents the attributes used to identify a Member. This object will map the IdP-defined User attributes to Stytch-specific values. Required attributes: `email` and one of `full_name` or `first_name` and `last_name`.' x509_certificate: type: string description: A certificate that Stytch will use to verify the sign-in assertion sent by the IdP, in [PEM](https://en.wikipedia.org/wiki/Privacy-Enhanced_Mail) format. See our [X509 guide](https://stytch.com/docs/b2b/api/saml-certificates) for more info. idp_sso_url: type: string description: The URL for which assertions for login requests will be sent. This will be provided by the IdP. saml_connection_implicit_role_assignments: type: array items: $ref: '#/components/schemas/api_sso_v1_SAMLConnectionImplicitRoleAssignment' description: All Members who log in with this SAML connection will implicitly receive the specified Roles. See the [RBAC guide](https://stytch.com/docs/b2b/guides/rbac/role-assignment) for more information about role assignment. saml_group_implicit_role_assignments: type: array items: $ref: '#/components/schemas/api_sso_v1_SAMLGroupImplicitRoleAssignment' description: "Defines the names of the SAML groups\n that grant specific role assignments. For each group-Role pair, if a Member logs in with this SAML connection and\n belongs to the specified SAML group, they will be granted the associated Role. See the\n [RBAC guide](https://stytch.com/docs/b2b/guides/rbac/role-assignment) for more information about role assignment. Before adding any group implicit role assignments, you must add a \"groups\" key to your SAML connection's\n `attribute_mapping`. Make sure that your IdP is configured to correctly send the group information." alternative_audience_uri: type: string description: An alternative URL to use for the Audience Restriction. This value can be used when you wish to migrate an existing SAML integration to Stytch with zero downtime. Read our [SSO migration guide](https://stytch.com/docs/b2b/guides/migrations/additional-migration-considerations) for more info. identity_provider: $ref: '#/components/schemas/api_sso_v1_UpdateConnectionRequestIdentityProvider' description: 'Name of the IdP. Enum with possible values: `classlink`, `cyberark`, `duo`, `google-workspace`, `jumpcloud`, `keycloak`, `miniorange`, `microsoft-entra`, `okta`, `onelogin`, `pingfederate`, `rippling`, `salesforce`, `shibboleth`, or `generic`. Specifying a known provider allows Stytch to handle any provider-specific logic.' signing_private_key: type: string description: A PKCS1 format RSA private key used for signing SAML requests. Only PKCS1 format (starting with "-----BEGIN RSA PRIVATE KEY-----") is supported. When provided, Stytch will generate a new x509 certificate from this key and return it in the signing_certificates array. nameid_format: type: string description: The NameID format the SAML Connection expects to use. Defaults to `urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress`. alternative_acs_url: type: string description: An alternative URL to use for the `AssertionConsumerServiceURL` in SP initiated SAML AuthNRequests. This value can be used when you wish to migrate an existing SAML integration to Stytch with zero downtime. Note that you will be responsible for proxying requests sent to the Alternative ACS URL to Stytch. Read our [SSO migration guide](https://stytch.com/docs/b2b/guides/migrations/additional-migration-considerations) for more info. idp_initiated_auth_disabled: type: boolean description: Determines whether IDP initiated auth is allowed for a given SAML connection. Defaults to false (IDP Initiated Auth is enabled). saml_encryption_private_key: type: string description: A PKCS1 format RSA private key used to decrypt encrypted SAML assertions. Only PKCS1 format (starting with "-----BEGIN RSA PRIVATE KEY-----") is supported. allow_gateway_callback: type: boolean description: Request type api_b2b_scim_v1_Address: type: object properties: formatted: type: string street_address: type: string locality: type: string region: type: string postal_code: type: string country: type: string type: type: string primary: type: boolean required: - formatted - street_address - locality - region - postal_code - country - type - primary api_session_v1_BiometricFactor: type: object properties: biometric_registration_id: type: string required: - biometric_registration_id api_b2b_scim_v1_Group: type: object properties: value: type: string display: type: string required: - value - display api_sso_v1_sso_external_UpdateConnectionResponse: type: object properties: request_id: type: string description: Globally unique UUID that is returned with every API call. This value is important to log for debugging purposes; we may ask for this value to help identify a specific API call when helping you debug an issue. status_code: type: integer format: int32 description: The HTTP status code of the response. Stytch follows standard HTTP response status code patterns, e.g. 2XX values equate to success, 3XX values are redirects, 4XX are client errors, and 5XX are server errors. connection: $ref: '#/components/schemas/api_sso_v1_Connection' description: The [External Connection Object](https://stytch.com/docs/b2b/api/external-connection-object). required: - request_id - status_code api_sso_v1_sso_saml_CreateConnectionRequest: type: object properties: display_name: type: string description: A human-readable display name for the connection. identity_provider: $ref: '#/components/schemas/api_sso_v1_CreateConnectionRequestIdentityProvider' description: 'Name of the IdP. Enum with possible values: `classlink`, `cyberark`, `duo`, `google-workspace`, `jumpcloud`, `keycloak`, `miniorange`, `microsoft-entra`, `okta`, `onelogin`, `pingfederate`, `rippling`, `salesforce`, `shibboleth`, or `generic`. Specifying a known provider allows Stytch to handle any provider-specific logic.' description: Request type api_b2b_scim_v1_Photo: type: object properties: value: type: string type: type: string primary: type: boolean required: - value - type - primary api_sso_v1_GetConnectionsResponse: type: object properties: request_id: type: string description: Globally unique UUID that is returned with every API call. This value is important to log for debugging purposes; we may ask for this value to help identify a specific API call when helping you debug an issue. saml_connections: type: array items: $ref: '#/components/schemas/api_sso_v1_SAMLConnection' description: The list of [SAML Connections](https://stytch.com/docs/b2b/api/saml-connection-object) owned by this organization. oidc_connections: type: array items: $ref: '#/components/schemas/api_sso_v1_OIDCConnection' description: The list of [OIDC Connections](https://stytch.com/docs/b2b/api/oidc-connection-object) owned by this organization. external_connections: type: array items: $ref: '#/components/schemas/api_sso_v1_Connection' description: The list of [External Connections](https://stytch.com/docs/b2b/api/external-connection-object) owned by this organization. status_code: type: integer format: int32 description: The HTTP status code of the response. Stytch follows standard HTTP response status code patterns, e.g. 2XX values equate to success, 3XX values are redirects, 4XX are client errors, and 5XX are server errors. required: - request_id - saml_connections - oidc_connections - external_connections - status_code api_sso_v1_sso_saml_UpdateConnectionResponse: type: object properties: request_id: type: string description: Globally unique UUID that is returned with every API call. This value is important to log for debugging purposes; we may ask for this value to help identify a specific API call when helping you debug an issue. status_code: type: integer format: int32 description: The HTTP status code of the response. Stytch follows standard HTTP response status code patterns, e.g. 2XX values equate to success, 3XX values are redirects, 4XX are client errors, and 5XX are server errors. connection: $ref: '#/components/schemas/api_sso_v1_SAMLConnection' description: The [SAML Connection Object](https://stytch.com/docs/b2b/api/saml-connection-object) required: - request_id - status_code api_session_v1_TwitchOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_b2b_scim_v1_IMs: type: object properties: value: type: string type: type: string primary: type: boolean required: - value - type - primary api_organization_v1_MemberRoleSource: type: object properties: type: type: string description: "The type of role assignment. The possible values are:\n \n `direct_assignment` – an explicitly assigned Role.\n\n Directly assigned roles can be updated by passing in the `roles` argument to the\n [Update Member](https://stytch.com/docs/b2b/api/update-member) endpoint.\n \n `email_assignment` – an implicit Role granted by the Member's email domain, regardless of their login method.\n\n Email implicit role assignments can be updated by passing in the `rbac_email_implicit_role_assignments` argument to\n the [Update Organization](https://stytch.com/docs/b2b/api/update-organization) endpoint.\n \n `sso_connection` – an implicit Role granted by the Member's SSO connection. This is currently only available\n for SAML connections and not for OIDC. If the Member has a SAML Member registration with the given connection, this\n role assignment will appear in the list. However, for authorization check purposes (in\n [sessions authenticate](https://stytch.com/docs/b2b/api/authenticate-session) or in any endpoint that enforces RBAC with session\n headers), the Member will only be granted the Role if their session contains an authentication factor with the\n specified SAML connection.\n\n SAML connection implicit role assignments can be updated by passing in the\n `saml_connection_implicit_role_assignments` argument to the\n [Update SAML connection](https://stytch.com/docs/b2b/api/update-saml-connection) endpoint.\n \n `sso_connection_group` – an implicit Role granted by the Member's SSO connection and group. This is currently only\n available for SAML connections and not for OIDC. If the Member has a SAML Member registration with the given\n connection, and belongs to a specific group within the IdP, this role assignment will appear in the list. However,\n for authorization check purposes (in [sessions authenticate](https://stytch.com/docs/b2b/api/authenticate-session) or in any endpoint\n that enforces RBAC with session headers), the Member will only be granted the role if their session contains an\n authentication factor with the specified SAML connection.\n\n SAML group implicit role assignments can be updated by passing in the `saml_group_implicit_role_assignments`\n argument to the [Update SAML connection](https://stytch.com/docs/b2b/api/update-saml-connection) endpoint.\n\n `scim_connection_group` – an implicit Role granted by the Member's SCIM connection and group. If the Member has\n a SCIM Member registration with the given connection, and belongs to a specific group within the IdP, this role assignment will appear in the list.\n\n SCIM group implicit role assignments can be updated by passing in the `scim_group_implicit_role_assignments`\n argument to the [Update SCIM connection](https://stytch.com/docs/b2b/api/update-scim-connection) endpoint.\n " details: type: object additionalProperties: true description: "An object containing additional metadata about the source assignment. The fields will vary depending\n on the role assignment type as follows:\n \n `direct_assignment` – no additional details.\n \n `email_assignment` – will contain the email domain that granted the assignment.\n \n `sso_connection` – will contain the `connection_id` of the SAML connection that granted the assignment.\n \n `sso_connection_group` – will contain the `connection_id` of the SAML connection and the name of the `group`\n that granted the assignment.\n \n `scim_connection_group` – will contain the `connection_id` of the SAML connection and the `group_id`\n that granted the assignment.\n " required: - type api_sso_v1_UpdateConnectionRequestIdentityProvider: type: string enum: - classlink - cyberark - duo - generic - google-workspace - jumpcloud - keycloak - miniorange - microsoft-entra - okta - onelogin - pingfederate - rippling - salesforce - shibboleth api_session_v1_AmazonOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_sso_v1_SAMLConnection: type: object properties: organization_id: type: string description: Globally unique UUID that identifies a specific Organization. The `organization_id` is critical to perform operations on an Organization, so be sure to preserve this value. You may also use the organization_slug or organization_external_id here as a convenience. connection_id: type: string description: Globally unique UUID that identifies a specific SAML Connection. status: type: string description: The status of the connection. The possible values are pending or active. See the [Update SAML Connection endpoint](https://stytch.com/docs/b2b/api/update-saml-connection) for more details. idp_entity_id: type: string description: A globally unique name for the IdP. This will be provided by the IdP. display_name: type: string description: A human-readable display name for the connection. idp_sso_url: type: string description: The URL for which assertions for login requests will be sent. This will be provided by the IdP. acs_url: type: string description: The URL of the Assertion Consumer Service. This value will be passed to the IdP to redirect the Member back to Stytch after a sign-in attempt. Read our [SAML Overview](https://stytch.com/docs/b2b/api/saml-overview) for more info. audience_uri: type: string description: The URL of the Audience Restriction. This value will indicate that Stytch is the intended audience of an assertion. Read our [SAML Overview](https://stytch.com/docs/b2b/api/saml-overview) for more info. signing_certificates: type: array items: $ref: '#/components/schemas/api_sso_v1_X509Certificate' description: A list of X.509 certificates Stytch will use to sign its assertion requests. Certificates should be uploaded to the IdP. verification_certificates: type: array items: $ref: '#/components/schemas/api_sso_v1_X509Certificate' description: A list of X.509 certificates Stytch will use to validate an assertion callback. Certificates should be populated from the IdP. encryption_private_keys: type: array items: $ref: '#/components/schemas/api_sso_v1_EncryptionPrivateKey' saml_connection_implicit_role_assignments: type: array items: $ref: '#/components/schemas/api_sso_v1_SAMLConnectionImplicitRoleAssignment' description: All Members who log in with this SAML connection will implicitly receive the specified Roles. See the [RBAC guide](https://stytch.com/docs/b2b/guides/rbac/role-assignment) for more information about role assignment. saml_group_implicit_role_assignments: type: array items: $ref: '#/components/schemas/api_sso_v1_SAMLGroupImplicitRoleAssignment' description: "Defines the names of the SAML groups\n that grant specific role assignments. For each group-Role pair, if a Member logs in with this SAML connection and\n belongs to the specified SAML group, they will be granted the associated Role. See the\n [RBAC guide](https://stytch.com/docs/b2b/guides/rbac/role-assignment) for more information about role assignment." alternative_audience_uri: type: string description: An alternative URL to use for the Audience Restriction. This value can be used when you wish to migrate an existing SAML integration to Stytch with zero downtime. Read our [SSO migration guide](https://stytch.com/docs/b2b/guides/migrations/additional-migration-considerations) for more info. identity_provider: type: string description: 'Name of the IdP. Enum with possible values: `classlink`, `cyberark`, `duo`, `google-workspace`, `jumpcloud`, `keycloak`, `miniorange`, `microsoft-entra`, `okta`, `onelogin`, `pingfederate`, `rippling`, `salesforce`, `shibboleth`, or `generic`. Specifying a known provider allows Stytch to handle any provider-specific logic.' nameid_format: type: string description: The NameID format the SAML Connection expects to use. Defaults to `urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress`. alternative_acs_url: type: string description: An alternative URL to use for the `AssertionConsumerServiceURL` in SP initiated SAML AuthNRequests. This value can be used when you wish to migrate an existing SAML integration to Stytch with zero downtime. Note that you will be responsible for proxying requests sent to the Alternative ACS URL to Stytch. Read our [SSO migration guide](https://stytch.com/docs/b2b/guides/migrations/additional-migration-considerations) for more info. idp_initiated_auth_disabled: type: boolean description: Determines whether IDP initiated auth is allowed for a given SAML connection. Defaults to false (IDP Initiated Auth is enabled). allow_gateway_callback: type: boolean attribute_mapping: type: object additionalProperties: true description: 'An object that represents the attributes used to identify a Member. This object will map the IdP-defined User attributes to Stytch-specific values. Required attributes: `email` and one of `full_name` or `first_name` and `last_name`.' required: - organization_id - connection_id - status - idp_entity_id - display_name - idp_sso_url - acs_url - audience_uri - signing_certificates - verification_certificates - encryption_private_keys - saml_connection_implicit_role_assignments - saml_group_implicit_role_assignments - alternative_audience_uri - identity_provider - nameid_format - alternative_acs_url - idp_initiated_auth_disabled - allow_gateway_callback api_session_v1_CryptoWalletFactor: type: object properties: crypto_wallet_id: type: string crypto_wallet_address: type: string crypto_wallet_type: type: string required: - crypto_wallet_id - crypto_wallet_address - crypto_wallet_type api_session_v1_OIDCSSOFactor: type: object properties: id: type: string description: The unique ID of an SSO Registration. provider_id: type: string description: Globally unique UUID that identifies a specific OIDC Connection. external_id: type: string description: The ID of the member given by the identity provider. required: - id - provider_id - external_id api_session_v1_GithubOAuthExchangeFactor: type: object properties: email_id: type: string description: The globally unique UUID of the Member's email. required: - email_id api_session_v1_LinkedInOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_organization_v1_OAuthRegistration: type: object properties: provider_type: type: string description: Denotes the OAuth identity provider that the user has authenticated with, e.g. Google, Microsoft, GitHub etc. provider_subject: type: string description: The unique identifier for the User within a given OAuth provider. Also commonly called the `sub` or "Subject field" in OAuth protocols. member_oauth_registration_id: type: string description: The unique ID of an OAuth registration. profile_picture_url: type: string description: If available, the `profile_picture_url` is a URL of the User's profile picture set in OAuth identity the provider that the User has authenticated with, e.g. Google profile picture. locale: type: string description: If available, the `locale` is the Member's locale set in the OAuth identity provider that the user has authenticated with. required: - provider_type - provider_subject - member_oauth_registration_id api_sso_v1_sso_saml_UpdateByURLResponse: type: object properties: request_id: type: string description: Globally unique UUID that is returned with every API call. This value is important to log for debugging purposes; we may ask for this value to help identify a specific API call when helping you debug an issue. status_code: type: integer format: int32 description: The HTTP status code of the response. Stytch follows standard HTTP response status code patterns, e.g. 2XX values equate to success, 3XX values are redirects, 4XX are client errors, and 5XX are server errors. connection: $ref: '#/components/schemas/api_sso_v1_SAMLConnection' description: The [SAML Connection Object](https://stytch.com/docs/b2b/api/saml-connection-object) required: - request_id - status_code api_organization_v1_ActiveSCIMConnection: type: object properties: connection_id: type: string description: The ID of the SCIM connection. display_name: type: string description: A human-readable display name for the connection. bearer_token_last_four: type: string bearer_token_expires_at: type: string required: - connection_id - display_name - bearer_token_last_four api_session_v1_GithubOAuthFactor: type: object properties: id: type: string description: The unique ID of an OAuth registration. provider_subject: type: string description: The unique identifier for the User within a given OAuth provider. Also commonly called the `sub` or "Subject field" in OAuth protocols. email_id: type: string description: The globally unique UUID of the Member's email. required: - id - provider_subject api_session_v1_FacebookOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_session_v1_AuthenticatorAppFactor: type: object properties: totp_id: type: string description: Globally unique UUID that identifies a TOTP instance. required: - totp_id api_sso_v1_OIDCConnection: type: object properties: organization_id: type: string description: Globally unique UUID that identifies a specific Organization. The `organization_id` is critical to perform operations on an Organization, so be sure to preserve this value. You may also use the organization_slug or organization_external_id here as a convenience. connection_id: type: string description: Globally unique UUID that identifies a specific OIDC Connection. status: type: string description: The status of the connection. The possible values are pending or active. See the [Update OIDC Connection endpoint](https://stytch.com/docs/b2b/api/update-oidc-connection) for more details. display_name: type: string description: A human-readable display name for the connection. redirect_url: type: string description: The callback URL for this OIDC connection. This value will be passed to the IdP to redirect the Member back to Stytch after a sign-in attempt. client_id: type: string description: The OAuth2.0 client ID used to authenticate login attempts. This will be provided by the IdP. client_secret: type: string description: The secret belonging to the OAuth2.0 client used to authenticate login attempts. This will be provided by the IdP. issuer: type: string description: A case-sensitive `https://` URL that uniquely identifies the IdP. This will be provided by the IdP. authorization_url: type: string description: The location of the URL that starts an OAuth login at the IdP. This will be provided by the IdP. token_url: type: string description: The location of the URL that issues OAuth2.0 access tokens and OIDC ID tokens. This will be provided by the IdP. userinfo_url: type: string description: The location of the IDP's [UserInfo Endpoint](https://openid.net/specs/openid-connect-core-1_0.html#UserInfo). This will be provided by the IdP. jwks_url: type: string description: The location of the IdP's JSON Web Key Set, used to verify credentials issued by the IdP. This will be provided by the IdP. identity_provider: type: string description: 'Name of the IdP. Enum with possible values: `classlink`, `cyberark`, `duo`, `google-workspace`, `jumpcloud`, `keycloak`, `miniorange`, `microsoft-entra`, `okta`, `onelogin`, `pingfederate`, `rippling`, `salesforce`, `shibboleth`, or `generic`. Specifying a known provider allows Stytch to handle any provider-specific logic.' custom_scopes: type: string description: 'A space-separated list of custom scopes that will be requested on every SSOStart call. If set, this value will replace the default set of OIDC scopes requested: `openid email profile`. Additional scopes can be requested using the `custom_scopes` query parameter on individual SSOStart calls.' attribute_mapping: type: object additionalProperties: true description: An object that represents the attributes used to identify a Member. This object will map the IdP-defined User attributes to Stytch-specific values, which will appear on the member's Trusted Metadata. required: - organization_id - connection_id - status - display_name - redirect_url - client_id - client_secret - issuer - authorization_url - token_url - userinfo_url - jwks_url - identity_provider - custom_scopes api_b2b_scim_v1_Name: type: object properties: formatted: type: string family_name: type: string given_name: type: string middle_name: type: string honorific_prefix: type: string honorific_suffix: type: string required: - formatted - family_name - given_name - middle_name - honorific_prefix - honorific_suffix api_session_v1_EmailFactor: type: object properties: email_id: type: string description: The globally unique UUID of the Member's email. email_address: type: string description: The email address of the Member. required: - email_id - email_address api_sso_v1_ConnectionImplicitRoleAssignment: type: object properties: role_id: type: string description: "The unique identifier of the RBAC Role, provided by the developer and intended to be human-readable.\n\n Reserved `role_id`s that are predefined by Stytch include:\n\n * `stytch_member`\n * `stytch_admin`\n\n Check out the [guide on Stytch default Roles](https://stytch.com/docs/b2b/guides/rbac/stytch-default) for a more detailed explanation.\n\n " required: - role_id api_session_v1_SteamOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_sso_v1_sso_external_CreateConnectionResponse: type: object properties: request_id: type: string description: Globally unique UUID that is returned with every API call. This value is important to log for debugging purposes; we may ask for this value to help identify a specific API call when helping you debug an issue. status_code: type: integer format: int32 description: The HTTP status code of the response. Stytch follows standard HTTP response status code patterns, e.g. 2XX values equate to success, 3XX values are redirects, 4XX are client errors, and 5XX are server errors. connection: $ref: '#/components/schemas/api_sso_v1_Connection' description: The [External Connection Object](https://stytch.com/docs/b2b/api/external-connection-object). required: - request_id - status_code api_sso_v1_Connection: type: object properties: organization_id: type: string description: Globally unique UUID that identifies a specific Organization. The `organization_id` is critical to perform operations on an Organization, so be sure to preserve this value. You may also use the organization_slug or organization_external_id here as a convenience. connection_id: type: string description: Globally unique UUID that identifies a specific External SSO Connection. external_organization_id: type: string description: Globally unique UUID that identifies a different Organization within your Project. external_connection_id: type: string description: Globally unique UUID that identifies a specific SSO connection configured for a different Organization in your Project. display_name: type: string description: A human-readable display name for the connection. status: type: string description: The status of the connection. External connections are always active. external_connection_implicit_role_assignments: type: array items: $ref: '#/components/schemas/api_sso_v1_ConnectionImplicitRoleAssignment' description: 'All Members who log in with this External connection will implicitly receive the specified Roles. See the [RBAC guide](https://stytch.com/docs/b2b/guides/rbac/role-assignment) for more information about role assignment. Implicit role assignments are not supported for External connections if the underlying SSO connection is an OIDC connection. ' external_group_implicit_role_assignments: type: array items: $ref: '#/components/schemas/api_sso_v1_GroupImplicitRoleAssignment' description: "Defines the names of the groups\n that grant specific role assignments. For each group-Role pair, if a Member logs in with this external connection and\n belongs to the specified group, they will be granted the associated Role. See the\n [RBAC guide](https://stytch.com/docs/b2b/guides/rbac/role-assignment) for more information about role assignment." required: - organization_id - connection_id - external_organization_id - external_connection_id - display_name - status - external_connection_implicit_role_assignments - external_group_implicit_role_assignments api_sso_v1_sso_oidc_CreateConnectionRequest: type: object properties: display_name: type: string description: A human-readable display name for the connection. identity_provider: $ref: '#/components/schemas/api_sso_v1_CreateConnectionRequestIdentityProvider' description: 'Name of the IdP. Enum with possible values: `classlink`, `cyberark`, `duo`, `google-workspace`, `jumpcloud`, `keycloak`, `miniorange`, `microsoft-entra`, `okta`, `onelogin`, `pingfederate`, `rippling`, `salesforce`, `shibboleth`, or `generic`. Specifying a known provider allows Stytch to handle any provider-specific logic.' description: Request type api_sso_v1_SAMLConnectionImplicitRoleAssignment: type: object properties: role_id: type: string description: "The unique identifier of the RBAC Role, provided by the developer and intended to be human-readable.\n\n Reserved `role_id`s that are predefined by Stytch include:\n\n * `stytch_member`\n * `stytch_admin`\n\n Check out the [guide on Stytch default Roles](https://stytch.com/docs/b2b/guides/rbac/stytch-default) for a more detailed explanation.\n\n " required: - role_id api_b2b_scim_v1_X509Certificate: type: object properties: value: type: string type: type: string primary: type: boolean required: - value - type - primary api_session_v1_OAuthAccessTokenExchangeFactor: type: object properties: client_id: type: string description: The ID of the Connected App client. required: - client_id api_sso_v1_sso_oidc_UpdateConnectionRequest: type: object properties: display_name: type: string description: A human-readable display name for the connection. client_id: type: string description: The OAuth2.0 client ID used to authenticate login attempts. This will be provided by the IdP. client_secret: type: string description: The secret belonging to the OAuth2.0 client used to authenticate login attempts. This will be provided by the IdP. issuer: type: string description: A case-sensitive `https://` URL that uniquely identifies the IdP. This will be provided by the IdP. authorization_url: type: string description: The location of the URL that starts an OAuth login at the IdP. This will be provided by the IdP. token_url: type: string description: The location of the URL that issues OAuth2.0 access tokens and OIDC ID tokens. This will be provided by the IdP. userinfo_url: type: string description: The location of the IDP's [UserInfo Endpoint](https://openid.net/specs/openid-connect-core-1_0.html#UserInfo). This will be provided by the IdP. jwks_url: type: string description: The location of the IdP's JSON Web Key Set, used to verify credentials issued by the IdP. This will be provided by the IdP. identity_provider: $ref: '#/components/schemas/api_sso_v1_UpdateConnectionRequestIdentityProvider' description: 'Name of the IdP. Enum with possible values: `classlink`, `cyberark`, `duo`, `google-workspace`, `jumpcloud`, `keycloak`, `miniorange`, `microsoft-entra`, `okta`, `onelogin`, `pingfederate`, `rippling`, `salesforce`, `shibboleth`, or `generic`. Specifying a known provider allows Stytch to handle any provider-specific logic.' custom_scopes: type: string description: Include a space-separated list of custom scopes that you'd like to include. Note that this list must be URL encoded, e.g. the spaces must be expressed as %20. attribute_mapping: type: object additionalProperties: true description: An object that represents the attributes used to identify a Member. This object will map the IdP-defined User attributes to Stytch-specific values, which will appear on the member's Trusted Metadata. description: Request type api_session_v1_TrustedAuthTokenFactor: type: object properties: token_id: type: string description: The ID of the trusted auth token. required: - token_id api_session_v1_AppleOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_session_v1_ShopifyOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_session_v1_AuthenticationFactorDeliveryMethod: type: string enum: - email - sms - whatsapp - embedded - oauth_google - oauth_microsoft - oauth_apple - webauthn_registration - authenticator_app - oauth_github - recovery_code - oauth_facebook - crypto_wallet - oauth_amazon - oauth_bitbucket - oauth_coinbase - oauth_discord - oauth_figma - oauth_gitlab - oauth_instagram - oauth_linkedin - oauth_shopify - oauth_slack - oauth_snapchat - oauth_spotify - oauth_steam - oauth_tiktok - oauth_twitch - oauth_twitter - knowledge - biometric - sso_saml - sso_oidc - oauth_salesforce - oauth_yahoo - oauth_hubspot - imported_auth0 - oauth_exchange_slack - oauth_exchange_hubspot - oauth_exchange_github - oauth_exchange_google - impersonation - oauth_access_token_exchange - trusted_token_exchange api_session_v1_AuthenticationFactorType: type: string enum: - magic_link - otp - oauth - webauthn - totp - crypto - password - signature_challenge - sso - imported - recovery_codes - email_otp - impersonated - trusted_auth_token api_session_v1_GoogleOAuthFactor: type: object properties: id: type: string description: The unique ID of an OAuth registration. provider_subject: type: string description: The unique identifier for the User within a given OAuth provider. Also commonly called the `sub` or "Subject field" in OAuth protocols. email_id: type: string description: The globally unique UUID of the Member's email. required: - id - provider_subject api_sso_v1_GroupImplicitRoleAssignment: type: object properties: role_id: type: string group: type: string required: - role_id - group api_organization_v1_EmailImplicitRoleAssignment: type: object properties: domain: type: string description: Email domain that grants the specified Role. role_id: type: string description: "The unique identifier of the RBAC Role, provided by the developer and intended to be human-readable.\n\n Reserved `role_id`s that are predefined by Stytch include:\n\n * `stytch_member`\n * `stytch_admin`\n\n Check out the [guide on Stytch default Roles](https://stytch.com/docs/b2b/guides/rbac/stytch-default) for a more detailed explanation.\n\n " required: - domain - role_id api_sso_v1_sso_external_UpdateConnectionRequest: type: object properties: display_name: type: string description: A human-readable display name for the connection. external_connection_implicit_role_assignments: type: array items: $ref: '#/components/schemas/api_sso_v1_ConnectionImplicitRoleAssignment' description: 'All Members who log in with this External connection will implicitly receive the specified Roles. See the [RBAC guide](https://stytch.com/docs/b2b/guides/rbac/role-assignment) for more information about role assignment. Implicit role assignments are not supported for External connections if the underlying SSO connection is an OIDC connection. ' external_group_implicit_role_assignments: type: array items: $ref: '#/components/schemas/api_sso_v1_GroupImplicitRoleAssignment' description: "Defines the names of the groups\n that grant specific role assignments. For each group-Role pair, if a Member logs in with this external connection and\n belongs to the specified group, they will be granted the associated Role. See the\n [RBAC guide](https://stytch.com/docs/b2b/guides/rbac/role-assignment) for more information about role assignment. Before adding any group implicit role assignments to an external connection, you must add a \"groups\" key to the underlying SAML connection's\n `attribute_mapping`. Make sure that the SAML connection IdP is configured to correctly send the group information. Implicit role assignments are not supported\n for External connections if the underlying SSO connection is an OIDC connection." description: Request type api_device_history_v1_DeviceAttributeDetails: type: object properties: is_new: type: boolean description: Whether this `ip_geo_country` has been seen before for this user. first_seen_at: type: string description: When this `ip_geo_country` was first seen for this user. Values conform to the RFC 3339 standard and are expressed in UTC, e.g. `2021-12-29T12:33:09Z`. last_seen_at: type: string description: When this `ip_geo_country` was last seen for this user. Values conform to the RFC 3339 standard and are expressed in UTC, e.g. `2021-12-29T12:33:09Z`. required: - is_new api_session_v1_FigmaOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_session_v1_SnapchatOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_b2b_scim_v1_Role: type: object properties: value: type: string type: type: string primary: type: boolean required: - value - type - primary api_b2b_scim_v1_PhoneNumber: type: object properties: value: type: string type: type: string primary: type: boolean required: - value - type - primary api_organization_v1_CustomRolePermission: type: object properties: resource_id: type: string actions: type: array items: type: string required: - resource_id - actions api_session_v1_InstagramOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_session_v1_GoogleOAuthExchangeFactor: type: object properties: email_id: type: string description: The globally unique UUID of the Member's email. required: - email_id api_session_v1_WebAuthnFactor: type: object properties: webauthn_registration_id: type: string domain: type: string user_agent: type: string required: - webauthn_registration_id - domain api_b2b_scim_v1_EnterpriseExtension: type: object properties: employee_number: type: string cost_center: type: string division: type: string department: type: string organization: type: string manager: $ref: '#/components/schemas/api_b2b_scim_v1_Manager' required: - employee_number - cost_center - division - department - organization api_session_v1_SlackOAuthExchangeFactor: type: object properties: email_id: type: string description: The globally unique UUID of the Member's email. required: - email_id api_sso_v1_sso_saml_DeleteEncryptionPrivateKeyResponse: type: object properties: request_id: type: string description: Globally unique UUID that is returned with every API call. This value is important to log for debugging purposes; we may ask for this value to help identify a specific API call when helping you debug an issue. private_key_id: type: string description: The ID of the encryption private key. status_code: type: integer format: int32 description: The HTTP status code of the response. Stytch follows standard HTTP response status code patterns, e.g. 2XX values equate to success, 3XX values are redirects, 4XX are client errors, and 5XX are server errors. required: - request_id - private_key_id - status_code api_session_v1_MicrosoftOAuthFactor: type: object properties: id: type: string description: The unique ID of an OAuth registration. provider_subject: type: string description: The unique identifier for the User within a given OAuth provider. Also commonly called the `sub` or "Subject field" in OAuth protocols. email_id: type: string description: The globally unique UUID of the Member's email. required: - id - provider_subject securitySchemes: basicAuth: type: http scheme: basic