CAIN-42 CAIN Studio

API reference · Enterprise sign-in (SSO, SCIM)

Register this workspace's OpenID Connect identity provider

PUT /fabric/sso

Last reviewed 2026-10-02

PUT /fabric/sso

Request body

SSOConfig (required)

FieldTypeMeaning
issuer requiredstringmin length 8 · max length 500
client_id requiredstringmin length 1 · max length 500
client_secretstring or nullrequired the first time; omit to keep the stored one
max length 2000
default_rolestringviewer or member, for just-in-time joining and SCIM
default "viewer"
jitbooleanlet verified people from allowed_domains join on first sign-in
default false
allowed_domainsarray of stringmax items 50
email_claimstringemail, upn or preferred_username
default "email"

Responses

StatusMeaningBody
200Successful ResponseJSON
422Validation ErrorHTTPValidationError
401No key, or a key that is not validJSON detail
429Rate limit for your plan reached; retry after the Retry-After secondsJSON detail

Try it

This call changes data in the account the key belongs to.

The request goes from your browser straight to this site. Your key is not stored unless you tick the box, and then only in this tab's session storage.

Code

curl -sS -X PUT 'https://cainstudio.online/fabric/sso' \
  -H "X-API-Key: $CAIN_API_KEY" \
  -H 'Content-Type: application/json' \
  -d '{"issuer": "issuer", "client_id": "client-id", "default_role": "viewer", "jit": false, "email_claim": "email"}'

Schemas used

HTTPValidationError · SSOConfig · ValidationError

← This workspace's single sign-on connection · all 5 Enterprise sign-in (SSO, SCIM) calls · Remove single sign-on (members keep their memberships) →

Try CAIN-42 on your own agents

Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.

Create a free account →  ·  Try the sandbox  ·  See the whole ecosystem