Skip to content

Update tenant identity provisioning config

PUT/tenants/{tenant_id}/identity/config

Updates the tenant's SSO and/or SCIM provisioning configuration. Fields can be provided as flat key-value overrides (e.g. okta_domain, scim_base_url) or as JSON blobs (sso_metadata_json, scim_config_json) for bulk replacement. Existing config keys not supplied in the request are preserved. Changes are audit-logged.

Request

Path parameters

NameTypeRequiredDescription
tenant_idstringYes

The tenant identifier.

Request body

Content type application/json (required).

FieldTypeRequiredDescription
sso_providerstring, nullableNo

Identity provider type to configure (e.g. "okta", "azure_ad").

sso_metadata_urlstring (uri), nullableNo

URL to the IdP's SAML metadata XML.

sso_client_idstring, nullableNo

OAuth/OIDC client ID issued by the identity provider.

okta_domainstring, nullableNo

Okta organisation domain (e.g. "acme.okta.com").

entra_tenant_idstring, nullableNo

Microsoft Entra (Azure AD) tenant ID.

sso_metadata_jsonstring, nullableNo

JSON blob for bulk-replacing the sso_metadata object (merged on top of existing values).

scim_enabledbooleanNo

Enable or disable SCIM provisioning.

scim_adapterstring, nullableNo

SCIM adapter key (e.g. "okta_scim", "azure_scim").

scim_base_urlstring (uri), nullableNo

Base URL of the SCIM provider endpoint.

scim_client_idstring, nullableNo
scim_client_secretstring, nullableNo

SCIM OAuth client secret (write-only; never returned in responses).

scim_bearer_tokenstring, nullableNo

SCIM bearer token (write-only; never returned in responses).

scim_directory_idstring, nullableNo
scim_mapping_jsonstring, nullableNo

JSON object defining attribute mapping from IdP schema to CRM user fields.

scim_config_jsonstring, nullableNo

JSON blob for bulk-replacing the scim_config object.

Example

{
  "sso_provider": "okta",
  "okta_domain": "acme.okta.com",
  "sso_metadata_url": "https://acme.okta.com/app/xxx/sso/saml/metadata",
  "sso_client_id": "0oa1b2c3d4e5",
  "scim_enabled": true,
  "scim_adapter": "okta_scim",
  "scim_base_url": "https://acme.faciotech.net/scim/v2",
  "scim_directory_id": "dir_01HXN8K2"
}

Responses

200 Identity configuration updated and audit event recorded

Content type application/json, object · TenantIdentityConfigV1.

FieldTypeRequiredDescription
tenant_idstringNo
sso_providerstring, nullableNo

Identity provider type (e.g. "okta", "azure_ad", "google", "saml_generic").

sso_metadataobject, nullableNo

SSO provider metadata (metadata_url, client_id, okta_domain, entra_tenant_id, etc.).

scim_enabledbooleanNo

Whether SCIM user provisioning is active for this tenant.

scim_adapterstring, nullableNo

SCIM adapter identifier (e.g. "okta_scim", "azure_scim", "google_directory").

scim_configobject, nullableNo

SCIM adapter configuration (base_url, directory_id, mapping, etc.). Credentials are write-only.

updated_atstring (date-time)No

404 Tenant not found

422 Validation failed — check URL formats, JSON validity, or adapter key

Example request

Paths are relative to the control-plane API base URL ($BASE_URL below).

curl -X PUT "$BASE_URL/tenants/{tenant_id}/identity/config" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{"sso_provider": "okta", "okta_domain": "acme.okta.com", "sso_metadata_url": "https://acme.okta.com/app/xxx/sso/saml/metadata", "sso_client_id": "0oa1b2c3d4e5", "scim_enabled": true, "scim_adapter": "okta_scim", "scim_base_url": "https://acme.faciotech.net/scim/v2", "scim_directory_id": "dir_01HXN8K2"}'
Loading