providers
5 endpoints.
/api/providers Bearer tokenList the sign-in providers
Every registered OpenID Connect provider, disabled ones included. Rows name the env vars their secrets live in; the secrets themselves are never served.
Responses
| Status | Description | Body |
|---|---|---|
| 200 | The registered providers, oldest first. | SignInProviderList |
| 401 | The access token is missing or invalid. | ErrorResponse |
| 500 | The provider catalogue could not be read. | ErrorResponse |
/api/providers Bearer tokenRegister a sign-in provider
Registers an OpenID Connect provider whose sign-ins and access tokens this deployment accepts. Secrets stay in the environment: the row names the variables to read. Requires a superuser's access token.
| Field | Type | Required | Description |
|---|---|---|---|
| slug | string | yes | at most 100 characters · matches ^[a-z0-9]+(-[a-z0-9]+)*$ |
| display_name | string | yes | 1–200 characters |
| issuer_url | string (uri) | yes | at most 500 characters |
| client_id | string | yes | 1–500 characters |
| client_auth_method | string | yes | one of "client_secret_basic" | "client_secret_post" | "client_secret_jwt" | "private_key_jwt" | "none" |
| client_secret_env | string | no | at most 200 characters · matches ^[A-Z_][A-Z0-9_]*$ |
| client_private_key_env | string | no | at most 200 characters · matches ^[A-Z_][A-Z0-9_]*$ |
| client_assertion_algorithm | string | no | 1–20 characters |
| client_key_id | string | no | 1–200 characters |
| audience | string | no | 1–500 characters |
| request_resource | boolean | no | Defaults to false. Requires an audience. |
| introspection_client_id | string | null | no | Introspect tokens as this client instead of the login client (an API server id, on a SchemaVaults auth server). The introspection_* fields are replaced together: send this with the others; null (on update) drops the identity. 1–500 characters |
| introspection_auth_method | string | null | no | one of "client_secret_basic" | "client_secret_post" | "client_secret_jwt" | "private_key_jwt" | null |
| introspection_client_secret_env | string | null | no | at most 200 characters · matches ^[A-Z_][A-Z0-9_]*$ |
| introspection_private_key_env | string | null | no | at most 200 characters · matches ^[A-Z_][A-Z0-9_]*$ |
| introspection_client_assertion_algorithm | string | null | no | 1–20 characters |
| introspection_client_key_id | string | null | no | 1–200 characters |
| login_scope | string | no | Defaults to "openid profile email". 1–500 characters |
| access_token_algorithms | array of string | no | Omit to accept the default algorithm set. at most 20 items |
| email_verification_strictness | string | no | Defaults to "reject_unverified". one of "lenient" | "reject_unverified" | "require_verified" |
Responses
| Status | Description | Body |
|---|---|---|
| 201 | The registered provider. | SignInProvider |
| 400 | The request body failed validation. | ErrorResponse |
| 401 | The access token is missing or invalid. | ErrorResponse |
| 403 | The access token's subject is not a superuser. | ErrorResponse |
| 409 | The slug or issuer is taken. | ErrorResponse |
| 500 | The provider catalogue could not be written to. | ErrorResponse |
/api/providers/{provider_id} Bearer tokenRead one sign-in provider
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
| provider_id | path | string | yes | Provider UUID id or slug. |
Responses
| Status | Description | Body |
|---|---|---|
| 200 | The provider. | SignInProvider |
| 401 | The access token is missing or invalid. | ErrorResponse |
| 404 | No provider has that id or slug. | ErrorResponse |
| 500 | The provider catalogue could not be read. | ErrorResponse |
/api/providers/{provider_id} Bearer tokenUpdate a sign-in provider
Changes a provider's settings; omitted fields keep their values. Disabling a provider stops its sign-ins and token verification while keeping its identities. Requires a superuser's access token.
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
| provider_id | path | string | yes | Provider UUID id or slug. |
| Field | Type | Required | Description |
|---|---|---|---|
| slug | string | no | at most 100 characters · matches ^[a-z0-9]+(-[a-z0-9]+)*$ |
| display_name | string | no | 1–200 characters |
| issuer_url | string (uri) | no | at most 500 characters |
| client_id | string | no | 1–500 characters |
| enabled | boolean | no | — |
| client_auth_method | string | no | one of "client_secret_basic" | "client_secret_post" | "client_secret_jwt" | "private_key_jwt" | "none" |
| client_secret_env | string | null | no | Omit to keep the current value; null clears it. at most 200 characters · matches ^[A-Z_][A-Z0-9_]*$ |
| client_private_key_env | string | null | no | at most 200 characters · matches ^[A-Z_][A-Z0-9_]*$ |
| client_assertion_algorithm | string | null | no | 1–20 characters |
| client_key_id | string | null | no | 1–200 characters |
| audience | string | null | no | 1–500 characters |
| request_resource | boolean | no | — |
| introspection_client_id | string | null | no | Introspect tokens as this client instead of the login client (an API server id, on a SchemaVaults auth server). The introspection_* fields are replaced together: send this with the others; null (on update) drops the identity. 1–500 characters |
| introspection_auth_method | string | null | no | one of "client_secret_basic" | "client_secret_post" | "client_secret_jwt" | "private_key_jwt" | null |
| introspection_client_secret_env | string | null | no | at most 200 characters · matches ^[A-Z_][A-Z0-9_]*$ |
| introspection_private_key_env | string | null | no | at most 200 characters · matches ^[A-Z_][A-Z0-9_]*$ |
| introspection_client_assertion_algorithm | string | null | no | 1–20 characters |
| introspection_client_key_id | string | null | no | 1–200 characters |
| login_scope | string | no | 1–500 characters |
| access_token_algorithms | array of string | no | at most 20 items |
| email_verification_strictness | string | no | How the provider's `email_verified` claim gates claiming a pending email link at sign-in: `lenient` links regardless, `reject_unverified` links unless the claim is explicitly false, `require_verified` links only when it is explicitly true. one of "lenient" | "reject_unverified" | "require_verified" |
Responses
| Status | Description | Body |
|---|---|---|
| 200 | The updated provider. | SignInProvider |
| 400 | The request body failed validation, or the settings violate a constraint. | ErrorResponse |
| 401 | The access token is missing or invalid. | ErrorResponse |
| 403 | The access token's subject is not a superuser. | ErrorResponse |
| 404 | No provider has that id or slug. | ErrorResponse |
| 409 | The slug or issuer is taken. | ErrorResponse |
| 500 | The provider catalogue could not be written to. | ErrorResponse |
/api/providers/{provider_id} Bearer tokenDelete a sign-in provider
Removes a provider nothing references. A provider whose identities still exist cannot be deleted — disable it, or detach the identities first. Requires a superuser's access token.
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
| provider_id | path | string | yes | Provider UUID id or slug. |
Responses
| Status | Description | Body |
|---|---|---|
| 200 | The deleted provider. | SignInProvider |
| 401 | The access token is missing or invalid. | ErrorResponse |
| 403 | The access token's subject is not a superuser. | ErrorResponse |
| 404 | No provider has that id or slug. | ErrorResponse |
| 409 | Sign-in identities still reference the provider. | ErrorResponse |
| 500 | The provider catalogue could not be written to. | ErrorResponse |