> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.getunleash.io/api/get-oidc-settings/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.getunleash.io/_mcp/server. # Get OIDC auth settings GET https://app.unleash-instance.example.com/api/admin/auth/oidc/settings **Enterprise feature** Returns the current settings for OIDC Authentication Reference: https://docs.getunleash.io/api/get-oidc-settings ## Authentication - `Authorization` header (required) — API key needed to access this API - `Authorization` header (bearer token, required) — API key needed to access this API, in Bearer token format ## Response ### 200 oidcSettingsResponseSchema - `enabled` (boolean, optional) — Whether to enable or disable OpenID Connect for this instance - `discoverUrl` (string, optional) — The [.well-known OpenID discover URL](https://swagger.io/docs/specification/authentication/openid-connect-discovery/) - `clientId` (string, optional) — The OIDC client ID of this application. - `secret` (string, optional) — Shared secret from OpenID server. Used to authenticate login requests - `autoCreate` (boolean, optional) — Auto create users based on email addresses from login tokens - `enableSingleSignOut` (boolean, optional) — Support Single sign out when user clicks logout in Unleash. If `true` user is signed out of all OpenID Connect sessions against the clientId they may have active - `defaultRootRole` (enum, optional) — [Default role](https://docs.getunleash.io/concepts/rbac#standard-roles) granted to users auto-created from email. Only relevant if autoCreate is `true` - Allowed values: `Viewer`, `Editor`, `Admin` - `defaultRootRoleId` (double, optional) — Assign this root role to auto created users. Should be a role ID and takes precedence over `defaultRootRole`. - `emailDomains` (string, optional) — Comma separated list of email domains that are automatically approved for an account in the server. Only relevant if autoCreate is `true` - `acrValues` (string, optional) — Authentication Context Class Reference, used to request extra values in the acr claim returned from the server. If multiple values are required, they should be space separated. Consult [the OIDC reference](https://openid.net/specs/openid-connect-core-1_0.html#AuthorizationEndpoint) for more information - `idTokenSigningAlgorithm` (enum, optional) — The signing algorithm used to sign our token. Refer to the [JWT signatures](https://jwt.io/introduction) documentation for more information. - Allowed values: `RS256`, `RS384`, `RS512` - `enableGroupSyncing` (boolean, optional) — Should we enable group syncing. Refer to the documentation [Group syncing](https://docs.getunleash.io/single-sign-on/how-to-set-up-group-sso-sync) - `groupJsonPath` (string, optional) — Specifies the path in the OIDC token response to read which groups the user belongs to from. - `addGroupsScope` (boolean, optional) — When enabled Unleash will also request the 'groups' scope as part of the login request. - `enablePkce` (boolean, optional) — Enable PKCE (Proof Key for Code Exchange) for enhanced security. Recommended for public clients and provides additional protection against authorization code interception attacks. - `extraScopes` (string, optional) — Space-separated list of additional scopes to request during login, beyond the default `openid email profile` and `groups` if group syncing is enabled. ## Errors ### 400 Bad Request Error The request data does not match what we expect. - `id` (string, optional) — The ID of the error instance - `name` (string, optional) — The name of the error kind - `message` (string, optional) — A description of what went wrong. ### 401 Unauthorized Error Authorization information is missing or invalid. Provide a valid API token as the `authorization` header, e.g. `authorization:*.*.my-admin-token`. - `id` (string, optional) — The ID of the error instance - `name` (string, optional) — The name of the error kind - `message` (string, optional) — A description of what went wrong. ### 403 Forbidden Error The provided user credentials are valid, but the user does not have the necessary permissions to perform this operation - `id` (string, optional) — The ID of the error instance - `name` (string, optional) — The name of the error kind - `message` (string, optional) — A description of what went wrong. ## Examples **Response** ```json { "enabled": true, "discoverUrl": "https://myoidchost.azure.com/.well-known/openid-configuration", "clientId": "FB87266D-CDDB-4BCF-BB1F-8392FD0EDC1B", "secret": "qjcVfeFjEfoYAF3AEsX2IMUWYuUzAbXO", "autoCreate": true, "enableSingleSignOut": true, "defaultRootRole": "Viewer", "defaultRootRoleId": 2, "emailDomains": "getunleash.io,getunleash.ai", "acrValues": "urn:okta:loa:2fa:any phr", "idTokenSigningAlgorithm": "RS256", "enableGroupSyncing": false, "groupJsonPath": "groups", "addGroupsScope": false, "enablePkce": false, "extraScopes": "custom_scope1 custom_scope2" } ``` **SDK Code** ```python import requests url = "https://app.unleash-instance.example.com/api/admin/auth/oidc/settings" headers = {"Authorization": ""} response = requests.get(url, headers=headers) print(response.json()) ``` ```javascript const url = 'https://app.unleash-instance.example.com/api/admin/auth/oidc/settings'; const options = {method: 'GET', headers: {Authorization: ''}}; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go package main import ( "fmt" "net/http" "io" ) func main() { url := "https://app.unleash-instance.example.com/api/admin/auth/oidc/settings" req, _ := http.NewRequest("GET", url, nil) req.Header.Add("Authorization", "") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby require 'uri' require 'net/http' url = URI("https://app.unleash-instance.example.com/api/admin/auth/oidc/settings") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Get.new(url) request["Authorization"] = '' response = http.request(request) puts response.read_body ``` ```java import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.get("https://app.unleash-instance.example.com/api/admin/auth/oidc/settings") .header("Authorization", "") .asString(); ``` ```php request('GET', 'https://app.unleash-instance.example.com/api/admin/auth/oidc/settings', [ 'headers' => [ 'Authorization' => '', ], ]); echo $response->getBody(); ``` ```csharp using RestSharp; var client = new RestClient("https://app.unleash-instance.example.com/api/admin/auth/oidc/settings"); var request = new RestRequest(Method.GET); request.AddHeader("Authorization", ""); IRestResponse response = client.Execute(request); ``` ```swift import Foundation let headers = ["Authorization": ""] let request = NSMutableURLRequest(url: NSURL(string: "https://app.unleash-instance.example.com/api/admin/auth/oidc/settings")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "GET" request.allHTTPHeaderFields = headers let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```