API reference · Enterprise sign-in (SSO, SCIM)
Register this workspace's OpenID Connect identity provider
PUT /fabric/sso
Last reviewed 2026-10-02
PUT /fabric/sso
Request body
SSOConfig (required)
| Field | Type | Meaning |
|---|---|---|
issuer required | string | min length 8 · max length 500 |
client_id required | string | min length 1 · max length 500 |
client_secret | string or null | required the first time; omit to keep the stored one max length 2000 |
default_role | string | viewer or member, for just-in-time joining and SCIM default "viewer" |
jit | boolean | let verified people from allowed_domains join on first sign-in default false |
allowed_domains | array of string | max items 50 |
email_claim | string | email, upn or preferred_username default "email" |
Responses
| Status | Meaning | Body |
|---|---|---|
200 | Successful Response | JSON |
422 | Validation Error | HTTPValidationError |
401 | No key, or a key that is not valid | JSON detail |
429 | Rate limit for your plan reached; retry after the Retry-After seconds | JSON detail |
Try it
This call changes data in the account the key belongs to.
The request goes from your browser straight to this site. Your key is not stored unless you tick the box, and then only in this tab's session storage.
Code
curl -sS -X PUT 'https://cainstudio.online/fabric/sso' \
-H "X-API-Key: $CAIN_API_KEY" \
-H 'Content-Type: application/json' \
-d '{"issuer": "issuer", "client_id": "client-id", "default_role": "viewer", "jit": false, "email_claim": "email"}'import json, os, urllib.request
req = urllib.request.Request('https://cainstudio.online/fabric/sso', method='PUT',
headers={"X-API-Key": os.environ["CAIN_API_KEY"], "Content-Type": "application/json"},
data=json.dumps({
"issuer": "issuer",
"client_id": "client-id",
"default_role": "viewer",
"jit": False,
"email_claim": "email"
}).encode())
with urllib.request.urlopen(req, timeout=60) as r:
print(r.status, json.load(r))const res = await fetch("https://cainstudio.online/fabric/sso", {
method: "PUT",
headers: {
"X-API-Key": process.env.CAIN_API_KEY!,
"Content-Type": "application/json",
},
body: JSON.stringify({
"issuer": "issuer",
"client_id": "client-id",
"default_role": "viewer",
"jit": false,
"email_claim": "email"
}),
});
console.log(res.status, await res.json());Schemas used
HTTPValidationError · SSOConfig · ValidationError
← This workspace's single sign-on connection · all 5 Enterprise sign-in (SSO, SCIM) calls · Remove single sign-on (members keep their memberships) →
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem