> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.getunleash.io/api/set-oidc-settings/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.getunleash.io/_mcp/server. # Set OIDC settings POST https://app.unleash-instance.example.com/api/admin/auth/oidc/settings Content-Type: application/json **Enterprise feature** Configure OpenID Connect as a login provider for Unleash. Reference: https://docs.getunleash.io/api/set-oidc-settings ## Authentication - `Authorization` header (required) — API key needed to access this API - `Authorization` header (bearer token, required) — API key needed to access this API, in Bearer token format ## Request ### Body (application/json) This endpoint expects an oidcSettingsSchema. - `oidcSettingsSchema` ## Response ### 200 oidcSettingsResponseSchema - `enabled` (boolean, optional) — Whether to enable or disable OpenID Connect for this instance - `discoverUrl` (string, optional) — The [.well-known OpenID discover URL](https://swagger.io/docs/specification/authentication/openid-connect-discovery/) - `clientId` (string, optional) — The OIDC client ID of this application. - `secret` (string, optional) — Shared secret from OpenID server. Used to authenticate login requests - `autoCreate` (boolean, optional) — Auto create users based on email addresses from login tokens - `enableSingleSignOut` (boolean, optional) — Support Single sign out when user clicks logout in Unleash. If `true` user is signed out of all OpenID Connect sessions against the clientId they may have active - `defaultRootRole` (enum, optional) — [Default role](https://docs.getunleash.io/concepts/rbac#standard-roles) granted to users auto-created from email. Only relevant if autoCreate is `true` - Allowed values: `Viewer`, `Editor`, `Admin` - `defaultRootRoleId` (double, optional) — Assign this root role to auto created users. Should be a role ID and takes precedence over `defaultRootRole`. - `emailDomains` (string, optional) — Comma separated list of email domains that are automatically approved for an account in the server. Only relevant if autoCreate is `true` - `acrValues` (string, optional) — Authentication Context Class Reference, used to request extra values in the acr claim returned from the server. If multiple values are required, they should be space separated. Consult [the OIDC reference](https://openid.net/specs/openid-connect-core-1_0.html#AuthorizationEndpoint) for more information - `idTokenSigningAlgorithm` (enum, optional) — The signing algorithm used to sign our token. Refer to the [JWT signatures](https://jwt.io/introduction) documentation for more information. - Allowed values: `RS256`, `RS384`, `RS512` - `enableGroupSyncing` (boolean, optional) — Should we enable group syncing. Refer to the documentation [Group syncing](https://docs.getunleash.io/single-sign-on/how-to-set-up-group-sso-sync) - `groupJsonPath` (string, optional) — Specifies the path in the OIDC token response to read which groups the user belongs to from. - `addGroupsScope` (boolean, optional) — When enabled Unleash will also request the 'groups' scope as part of the login request. - `enablePkce` (boolean, optional) — Enable PKCE (Proof Key for Code Exchange) for enhanced security. Recommended for public clients and provides additional protection against authorization code interception attacks. - `extraScopes` (string, optional) — Space-separated list of additional scopes to request during login, beyond the default `openid email profile` and `groups` if group syncing is enabled. ## Errors ### 400 Bad Request Error The request data does not match what we expect. - `id` (string, optional) — The ID of the error instance - `name` (string, optional) — The name of the error kind - `message` (string, optional) — A description of what went wrong. ### 401 Unauthorized Error Authorization information is missing or invalid. Provide a valid API token as the `authorization` header, e.g. `authorization:*.*.my-admin-token`. - `id` (string, optional) — The ID of the error instance - `name` (string, optional) — The name of the error kind - `message` (string, optional) — A description of what went wrong. ### 403 Forbidden Error The provided user credentials are valid, but the user does not have the necessary permissions to perform this operation - `id` (string, optional) — The ID of the error instance - `name` (string, optional) — The name of the error kind - `message` (string, optional) — A description of what went wrong. ### 415 Unsupported Media Type Error The operation does not support request payloads of the provided type. Please ensure that you're using one of the listed payload types and that you have specified the right content type in the "content-type" header. - `id` (string, optional) — The ID of the error instance - `name` (string, optional) — The name of the error kind - `message` (string, optional) — A description of what went wrong. ## Types ### OidcSettingsSchema0 - `enabled` (boolean, required) — Whether to enable or disable OpenID Connect for this instance - `clientId` (string, required) — The OIDC client ID of this application. - `secret` (string, required) — Shared secret from OpenID server. Used to authenticate login requests - `discoverUrl` (string, optional) — The [.well-known OpenID discover URL](https://swagger.io/docs/specification/authentication/openid-connect-discovery/) - `autoCreate` (boolean, optional) — Auto create users based on email addresses from login tokens - `enableSingleSignOut` (boolean, optional) — Support Single sign out when user clicks logout in Unleash. If `true` user is signed out of all OpenID Connect sessions against the clientId they may have active - `defaultRootRole` (enum, optional) — [Default role](https://docs.getunleash.io/concepts/rbac#standard-roles) granted to users auto-created from email. Only relevant if autoCreate is `true` - Allowed values: `Viewer`, `Editor`, `Admin` - `defaultRootRoleId` (double, optional) — Assign this root role to auto created users. Should be a role ID and takes precedence over `defaultRootRole`. - `emailDomains` (string, optional) — Comma separated list of email domains that are automatically approved for an account in the server. Only relevant if autoCreate is `true` - `acrValues` (string, optional) — Authentication Context Class Reference, used to request extra values in the acr claim returned from the server. If multiple values are required, they should be space separated. Consult [the OIDC reference](https://openid.net/specs/openid-connect-core-1_0.html#AuthorizationEndpoint) for more information - `idTokenSigningAlgorithm` (enum, optional) — The signing algorithm used to sign our token. Refer to the [JWT signatures](https://jwt.io/introduction) documentation for more information. - Allowed values: `RS256`, `RS384`, `RS512` - `enableGroupSyncing` (boolean, optional) — Should we enable group syncing. Refer to the documentation [Group syncing](https://docs.getunleash.io/single-sign-on/how-to-set-up-group-sso-sync) - `groupJsonPath` (string, optional) — Specifies the path in the OIDC token response to read which groups the user belongs to from. - `addGroupsScope` (boolean, optional) — When enabled Unleash will also request the 'groups' scope as part of the login request. - `enablePkce` (boolean, optional) — Enable PKCE (Proof Key for Code Exchange) for enhanced security. Recommended for public clients and provides additional protection against authorization code interception attacks. - `extraScopes` (string, optional) — Space-separated list of additional scopes to request during login, beyond the default `openid email profile` and `groups` if group syncing is enabled. ### OidcSettingsSchema1 - `enabled` (boolean, optional) — Whether to enable or disable OpenID Connect for this instance - `discoverUrl` (string, optional) — The [.well-known OpenID discover URL](https://swagger.io/docs/specification/authentication/openid-connect-discovery/) - `clientId` (string, optional) — The OIDC client ID of this application. - `secret` (string, optional) — Shared secret from OpenID server. Used to authenticate login requests - `autoCreate` (boolean, optional) — Auto create users based on email addresses from login tokens - `enableSingleSignOut` (boolean, optional) — Support Single sign out when user clicks logout in Unleash. If `true` user is signed out of all OpenID Connect sessions against the clientId they may have active - `defaultRootRole` (enum, optional) — [Default role](https://docs.getunleash.io/concepts/rbac#standard-roles) granted to users auto-created from email. Only relevant if autoCreate is `true` - Allowed values: `Viewer`, `Editor`, `Admin` - `defaultRootRoleId` (double, optional) — Assign this root role to auto created users. Should be a role ID and takes precedence over `defaultRootRole`. - `emailDomains` (string, optional) — Comma separated list of email domains that are automatically approved for an account in the server. Only relevant if autoCreate is `true` - `acrValues` (string, optional) — Authentication Context Class Reference, used to request extra values in the acr claim returned from the server. If multiple values are required, they should be space separated. Consult [the OIDC reference](https://openid.net/specs/openid-connect-core-1_0.html#AuthorizationEndpoint) for more information - `idTokenSigningAlgorithm` (enum, optional) — The signing algorithm used to sign our token. Refer to the [JWT signatures](https://jwt.io/introduction) documentation for more information. - Allowed values: `RS256`, `RS384`, `RS512` - `enableGroupSyncing` (boolean, optional) — Should we enable group syncing. Refer to the documentation [Group syncing](https://docs.getunleash.io/single-sign-on/how-to-set-up-group-sso-sync) - `groupJsonPath` (string, optional) — Specifies the path in the OIDC token response to read which groups the user belongs to from. - `addGroupsScope` (boolean, optional) — When enabled Unleash will also request the 'groups' scope as part of the login request. - `enablePkce` (boolean, optional) — Enable PKCE (Proof Key for Code Exchange) for enhanced security. Recommended for public clients and provides additional protection against authorization code interception attacks. - `extraScopes` (string, optional) — Space-separated list of additional scopes to request during login, beyond the default `openid email profile` and `groups` if group syncing is enabled. ## Examples **Request** ```json { "clientId": "FB87266D-CDDB-4BCF-BB1F-8392FD0EDC1B", "enabled": true, "secret": "qjcVfeFjEfoYAF3AEsX2IMUWYuUzAbXO" } ``` **Response** ```json { "enabled": true, "discoverUrl": "https://myoidchost.azure.com/.well-known/openid-configuration", "clientId": "FB87266D-CDDB-4BCF-BB1F-8392FD0EDC1B", "secret": "qjcVfeFjEfoYAF3AEsX2IMUWYuUzAbXO", "autoCreate": true, "enableSingleSignOut": true, "defaultRootRole": "Viewer", "defaultRootRoleId": 2, "emailDomains": "getunleash.io,getunleash.ai", "acrValues": "urn:okta:loa:2fa:any phr", "idTokenSigningAlgorithm": "RS256", "enableGroupSyncing": false, "groupJsonPath": "groups", "addGroupsScope": false, "enablePkce": false, "extraScopes": "custom_scope1 custom_scope2" } ``` **SDK Code** ```python import requests url = "https://app.unleash-instance.example.com/api/admin/auth/oidc/settings" payload = { "clientId": "FB87266D-CDDB-4BCF-BB1F-8392FD0EDC1B", "enabled": True, "secret": "qjcVfeFjEfoYAF3AEsX2IMUWYuUzAbXO" } headers = { "Authorization": "", "Content-Type": "application/json" } response = requests.post(url, json=payload, headers=headers) print(response.json()) ``` ```javascript const url = 'https://app.unleash-instance.example.com/api/admin/auth/oidc/settings'; const options = { method: 'POST', headers: {Authorization: '', 'Content-Type': 'application/json'}, body: '{"clientId":"FB87266D-CDDB-4BCF-BB1F-8392FD0EDC1B","enabled":true,"secret":"qjcVfeFjEfoYAF3AEsX2IMUWYuUzAbXO"}' }; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go package main import ( "fmt" "strings" "net/http" "io" ) func main() { url := "https://app.unleash-instance.example.com/api/admin/auth/oidc/settings" payload := strings.NewReader("{\n \"clientId\": \"FB87266D-CDDB-4BCF-BB1F-8392FD0EDC1B\",\n \"enabled\": true,\n \"secret\": \"qjcVfeFjEfoYAF3AEsX2IMUWYuUzAbXO\"\n}") req, _ := http.NewRequest("POST", url, payload) req.Header.Add("Authorization", "") req.Header.Add("Content-Type", "application/json") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby require 'uri' require 'net/http' url = URI("https://app.unleash-instance.example.com/api/admin/auth/oidc/settings") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Post.new(url) request["Authorization"] = '' request["Content-Type"] = 'application/json' request.body = "{\n \"clientId\": \"FB87266D-CDDB-4BCF-BB1F-8392FD0EDC1B\",\n \"enabled\": true,\n \"secret\": \"qjcVfeFjEfoYAF3AEsX2IMUWYuUzAbXO\"\n}" response = http.request(request) puts response.read_body ``` ```java import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.post("https://app.unleash-instance.example.com/api/admin/auth/oidc/settings") .header("Authorization", "") .header("Content-Type", "application/json") .body("{\n \"clientId\": \"FB87266D-CDDB-4BCF-BB1F-8392FD0EDC1B\",\n \"enabled\": true,\n \"secret\": \"qjcVfeFjEfoYAF3AEsX2IMUWYuUzAbXO\"\n}") .asString(); ``` ```php request('POST', 'https://app.unleash-instance.example.com/api/admin/auth/oidc/settings', [ 'body' => '{ "clientId": "FB87266D-CDDB-4BCF-BB1F-8392FD0EDC1B", "enabled": true, "secret": "qjcVfeFjEfoYAF3AEsX2IMUWYuUzAbXO" }', 'headers' => [ 'Authorization' => '', 'Content-Type' => 'application/json', ], ]); echo $response->getBody(); ``` ```csharp using RestSharp; var client = new RestClient("https://app.unleash-instance.example.com/api/admin/auth/oidc/settings"); var request = new RestRequest(Method.POST); request.AddHeader("Authorization", ""); request.AddHeader("Content-Type", "application/json"); request.AddParameter("application/json", "{\n \"clientId\": \"FB87266D-CDDB-4BCF-BB1F-8392FD0EDC1B\",\n \"enabled\": true,\n \"secret\": \"qjcVfeFjEfoYAF3AEsX2IMUWYuUzAbXO\"\n}", ParameterType.RequestBody); IRestResponse response = client.Execute(request); ``` ```swift import Foundation let headers = [ "Authorization": "", "Content-Type": "application/json" ] let parameters = [ "clientId": "FB87266D-CDDB-4BCF-BB1F-8392FD0EDC1B", "enabled": true, "secret": "qjcVfeFjEfoYAF3AEsX2IMUWYuUzAbXO" ] as [String : Any] let postData = JSONSerialization.data(withJSONObject: parameters, options: []) let request = NSMutableURLRequest(url: NSURL(string: "https://app.unleash-instance.example.com/api/admin/auth/oidc/settings")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "POST" request.allHTTPHeaderFields = headers request.httpBody = postData as Data let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```