Read tenant identity provisioning config
GET/tenants/{tenant_id}/identity/config
Returns the tenant's SSO and SCIM identity provisioning configuration, including the SSO provider type, metadata URL, SCIM adapter, and provisioning sync status. Use to audit or prefill the identity configuration form in the admin panel.
Request
Path parameters
| Name | Type | Required | Description |
|---|---|---|---|
tenant_id | string | Yes | The tenant identifier. |
Responses
200 Tenant identity provisioning configuration
Content type application/json, object · TenantIdentityConfigV1.
| Field | Type | Required | Description |
|---|---|---|---|
tenant_id | string | No | |
sso_provider | string, nullable | No | Identity provider type (e.g. "okta", "azure_ad", "google", "saml_generic"). |
sso_metadata | object, nullable | No | SSO provider metadata (metadata_url, client_id, okta_domain, entra_tenant_id, etc.). |
scim_enabled | boolean | No | Whether SCIM user provisioning is active for this tenant. |
scim_adapter | string, nullable | No | SCIM adapter identifier (e.g. "okta_scim", "azure_scim", "google_directory"). |
scim_config | object, nullable | No | SCIM adapter configuration (base_url, directory_id, mapping, etc.). Credentials are write-only. |
updated_at | string (date-time) | No |
Example
{
"tenant_id": "acme",
"sso_provider": "okta",
"sso_metadata": {
"metadata_url": "https://acme.okta.com/app/xxx/sso/saml/metadata",
"client_id": "0oa1b2c3d4e5",
"okta_domain": "acme.okta.com"
},
"scim_enabled": true,
"scim_adapter": "okta_scim",
"scim_config": {
"base_url": "https://acme.faciotech.net/scim/v2",
"directory_id": "dir_01HXN8K2"
},
"updated_at": "2026-02-15T10:00:00Z"
}
404 Tenant not found
Example request
Paths are relative to the control-plane API base URL ($BASE_URL below).
curl -X GET "$BASE_URL/tenants/{tenant_id}/identity/config" \
-H "Accept: application/json"