UpdateSignInProviderRequest

A request or response body; the type column links to the schemas it refers to.

UpdateSignInProviderRequest

FieldTypeRequiredDescription
slugstringno

at most 100 characters · matches ^[a-z0-9]+(-[a-z0-9]+)*$

display_namestringno

1–200 characters

issuer_urlstring (uri)no

at most 500 characters

client_idstringno

1–500 characters

enabledbooleanno—
client_auth_methodstringno

one of "client_secret_basic" | "client_secret_post" | "client_secret_jwt" | "private_key_jwt" | "none"

client_secret_envstring | nullno

Omit to keep the current value; null clears it.

at most 200 characters · matches ^[A-Z_][A-Z0-9_]*$

client_private_key_envstring | nullno

at most 200 characters · matches ^[A-Z_][A-Z0-9_]*$

client_assertion_algorithmstring | nullno

1–20 characters

client_key_idstring | nullno

1–200 characters

audiencestring | nullno

1–500 characters

request_resourcebooleanno—
introspection_client_idstring | nullno

Introspect tokens as this client instead of the login client (an API server id, on a SchemaVaults auth server). The introspection_* fields are replaced together: send this with the others; null (on update) drops the identity.

1–500 characters

introspection_auth_methodstring | nullno

one of "client_secret_basic" | "client_secret_post" | "client_secret_jwt" | "private_key_jwt" | null

introspection_client_secret_envstring | nullno

at most 200 characters · matches ^[A-Z_][A-Z0-9_]*$

introspection_private_key_envstring | nullno

at most 200 characters · matches ^[A-Z_][A-Z0-9_]*$

introspection_client_assertion_algorithmstring | nullno

1–20 characters

introspection_client_key_idstring | nullno

1–200 characters

login_scopestringno

1–500 characters

access_token_algorithmsarray of stringno

at most 20 items

email_verification_strictnessstringno

How the provider's `email_verified` claim gates claiming a pending email link at sign-in: `lenient` links regardless, `reject_unverified` links unless the claim is explicitly false, `require_verified` links only when it is explicitly true.

one of "lenient" | "reject_unverified" | "require_verified"

jsonExample
{
  "slug": "string",
  "display_name": "string",
  "issuer_url": "string",
  "client_id": "string",
  "enabled": true,
  "client_auth_method": "client_secret_basic",
  "client_secret_env": "string",
  "client_private_key_env": "string",
  "client_assertion_algorithm": "string",
  "client_key_id": "string",
  "audience": "string",
  "request_resource": true,
  "introspection_client_id": "string",
  "introspection_auth_method": "client_secret_basic",
  "introspection_client_secret_env": "string",
  "introspection_private_key_env": "string",
  "introspection_client_assertion_algorithm": "string",
  "introspection_client_key_id": "string",
  "login_scope": "string",
  "access_token_algorithms": [
    "string"
  ],
  "email_verification_strictness": "reject_unverified"
}