UpdateSignInProviderRequest
A request or response body; the type column links to the schemas it refers to.
UpdateSignInProviderRequest
| Field | Type | Required | Description |
|---|---|---|---|
| slug | string | no | at most 100 characters · matches ^[a-z0-9]+(-[a-z0-9]+)*$ |
| display_name | string | no | 1–200 characters |
| issuer_url | string (uri) | no | at most 500 characters |
| client_id | string | no | 1–500 characters |
| enabled | boolean | no | — |
| client_auth_method | string | no | one of "client_secret_basic" | "client_secret_post" | "client_secret_jwt" | "private_key_jwt" | "none" |
| client_secret_env | string | null | no | Omit to keep the current value; null clears it. at most 200 characters · matches ^[A-Z_][A-Z0-9_]*$ |
| client_private_key_env | string | null | no | at most 200 characters · matches ^[A-Z_][A-Z0-9_]*$ |
| client_assertion_algorithm | string | null | no | 1–20 characters |
| client_key_id | string | null | no | 1–200 characters |
| audience | string | null | no | 1–500 characters |
| request_resource | boolean | no | — |
| introspection_client_id | string | null | no | Introspect tokens as this client instead of the login client (an API server id, on a SchemaVaults auth server). The introspection_* fields are replaced together: send this with the others; null (on update) drops the identity. 1–500 characters |
| introspection_auth_method | string | null | no | one of "client_secret_basic" | "client_secret_post" | "client_secret_jwt" | "private_key_jwt" | null |
| introspection_client_secret_env | string | null | no | at most 200 characters · matches ^[A-Z_][A-Z0-9_]*$ |
| introspection_private_key_env | string | null | no | at most 200 characters · matches ^[A-Z_][A-Z0-9_]*$ |
| introspection_client_assertion_algorithm | string | null | no | 1–20 characters |
| introspection_client_key_id | string | null | no | 1–200 characters |
| login_scope | string | no | 1–500 characters |
| access_token_algorithms | array of string | no | at most 20 items |
| email_verification_strictness | string | no | How the provider's `email_verified` claim gates claiming a pending email link at sign-in: `lenient` links regardless, `reject_unverified` links unless the claim is explicitly false, `require_verified` links only when it is explicitly true. one of "lenient" | "reject_unverified" | "require_verified" |
{
"slug": "string",
"display_name": "string",
"issuer_url": "string",
"client_id": "string",
"enabled": true,
"client_auth_method": "client_secret_basic",
"client_secret_env": "string",
"client_private_key_env": "string",
"client_assertion_algorithm": "string",
"client_key_id": "string",
"audience": "string",
"request_resource": true,
"introspection_client_id": "string",
"introspection_auth_method": "client_secret_basic",
"introspection_client_secret_env": "string",
"introspection_private_key_env": "string",
"introspection_client_assertion_algorithm": "string",
"introspection_client_key_id": "string",
"login_scope": "string",
"access_token_algorithms": [
"string"
],
"email_verification_strictness": "reject_unverified"
}