CreateSignInProviderRequest
A request or response body; the type column links to the schemas it refers to.
CreateSignInProviderRequest
| Field | Type | Required | Description |
|---|---|---|---|
| slug | string | yes | at most 100 characters · matches ^[a-z0-9]+(-[a-z0-9]+)*$ |
| display_name | string | yes | 1–200 characters |
| issuer_url | string (uri) | yes | at most 500 characters |
| client_id | string | yes | 1–500 characters |
| client_auth_method | string | yes | one of "client_secret_basic" | "client_secret_post" | "client_secret_jwt" | "private_key_jwt" | "none" |
| client_secret_env | string | no | at most 200 characters · matches ^[A-Z_][A-Z0-9_]*$ |
| client_private_key_env | string | no | at most 200 characters · matches ^[A-Z_][A-Z0-9_]*$ |
| client_assertion_algorithm | string | no | 1–20 characters |
| client_key_id | string | no | 1–200 characters |
| audience | string | no | 1–500 characters |
| request_resource | boolean | no | Defaults to false. Requires an audience. |
| introspection_client_id | string | null | no | Introspect tokens as this client instead of the login client (an API server id, on a SchemaVaults auth server). The introspection_* fields are replaced together: send this with the others; null (on update) drops the identity. 1–500 characters |
| introspection_auth_method | string | null | no | one of "client_secret_basic" | "client_secret_post" | "client_secret_jwt" | "private_key_jwt" | null |
| introspection_client_secret_env | string | null | no | at most 200 characters · matches ^[A-Z_][A-Z0-9_]*$ |
| introspection_private_key_env | string | null | no | at most 200 characters · matches ^[A-Z_][A-Z0-9_]*$ |
| introspection_client_assertion_algorithm | string | null | no | 1–20 characters |
| introspection_client_key_id | string | null | no | 1–200 characters |
| login_scope | string | no | Defaults to "openid profile email". 1–500 characters |
| access_token_algorithms | array of string | no | Omit to accept the default algorithm set. at most 20 items |
| email_verification_strictness | string | no | Defaults to "reject_unverified". one of "lenient" | "reject_unverified" | "require_verified" |
{
"slug": "string",
"display_name": "string",
"issuer_url": "string",
"client_id": "string",
"client_auth_method": "client_secret_basic",
"client_secret_env": "string",
"client_private_key_env": "string",
"client_assertion_algorithm": "string",
"client_key_id": "string",
"audience": "string",
"request_resource": true,
"introspection_client_id": "string",
"introspection_auth_method": "client_secret_basic",
"introspection_client_secret_env": "string",
"introspection_private_key_env": "string",
"introspection_client_assertion_algorithm": "string",
"introspection_client_key_id": "string",
"login_scope": "string",
"access_token_algorithms": [
"string"
],
"email_verification_strictness": "reject_unverified"
}