Update tenant identity provisioning config
PUT/tenants/{tenant_id}/identity/config
Updates the tenant's SSO and/or SCIM provisioning configuration. Fields can be provided as flat key-value overrides (e.g. okta_domain, scim_base_url) or as JSON blobs (sso_metadata_json, scim_config_json) for bulk replacement. Existing config keys not supplied in the request are preserved. Changes are audit-logged.
Request
Path parameters
| Name | Type | Required | Description |
|---|---|---|---|
tenant_id | string | Yes | The tenant identifier. |
Request body
Content type application/json (required).
| Field | Type | Required | Description |
|---|---|---|---|
sso_provider | string, nullable | No | Identity provider type to configure (e.g. "okta", "azure_ad"). |
sso_metadata_url | string (uri), nullable | No | URL to the IdP's SAML metadata XML. |
sso_client_id | string, nullable | No | OAuth/OIDC client ID issued by the identity provider. |
okta_domain | string, nullable | No | Okta organisation domain (e.g. "acme.okta.com"). |
entra_tenant_id | string, nullable | No | Microsoft Entra (Azure AD) tenant ID. |
sso_metadata_json | string, nullable | No | JSON blob for bulk-replacing the sso_metadata object (merged on top of existing values). |
scim_enabled | boolean | No | Enable or disable SCIM provisioning. |
scim_adapter | string, nullable | No | SCIM adapter key (e.g. "okta_scim", "azure_scim"). |
scim_base_url | string (uri), nullable | No | Base URL of the SCIM provider endpoint. |
scim_client_id | string, nullable | No | |
scim_client_secret | string, nullable | No | SCIM OAuth client secret (write-only; never returned in responses). |
scim_bearer_token | string, nullable | No | SCIM bearer token (write-only; never returned in responses). |
scim_directory_id | string, nullable | No | |
scim_mapping_json | string, nullable | No | JSON object defining attribute mapping from IdP schema to CRM user fields. |
scim_config_json | string, nullable | No | JSON blob for bulk-replacing the scim_config object. |
Example
{
"sso_provider": "okta",
"okta_domain": "acme.okta.com",
"sso_metadata_url": "https://acme.okta.com/app/xxx/sso/saml/metadata",
"sso_client_id": "0oa1b2c3d4e5",
"scim_enabled": true,
"scim_adapter": "okta_scim",
"scim_base_url": "https://acme.faciotech.net/scim/v2",
"scim_directory_id": "dir_01HXN8K2"
}
Responses
200 Identity configuration updated and audit event recorded
Content type application/json, object · TenantIdentityConfigV1.
| Field | Type | Required | Description |
|---|---|---|---|
tenant_id | string | No | |
sso_provider | string, nullable | No | Identity provider type (e.g. "okta", "azure_ad", "google", "saml_generic"). |
sso_metadata | object, nullable | No | SSO provider metadata (metadata_url, client_id, okta_domain, entra_tenant_id, etc.). |
scim_enabled | boolean | No | Whether SCIM user provisioning is active for this tenant. |
scim_adapter | string, nullable | No | SCIM adapter identifier (e.g. "okta_scim", "azure_scim", "google_directory"). |
scim_config | object, nullable | No | SCIM adapter configuration (base_url, directory_id, mapping, etc.). Credentials are write-only. |
updated_at | string (date-time) | No |
404 Tenant not found
422 Validation failed — check URL formats, JSON validity, or adapter key
Example request
Paths are relative to the control-plane API base URL ($BASE_URL below).
curl -X PUT "$BASE_URL/tenants/{tenant_id}/identity/config" \
-H "Accept: application/json" \
-H "Content-Type: application/json" \
-d '{"sso_provider": "okta", "okta_domain": "acme.okta.com", "sso_metadata_url": "https://acme.okta.com/app/xxx/sso/saml/metadata", "sso_client_id": "0oa1b2c3d4e5", "scim_enabled": true, "scim_adapter": "okta_scim", "scim_base_url": "https://acme.faciotech.net/scim/v2", "scim_directory_id": "dir_01HXN8K2"}'