CAIN-42 CAIN Studio

API reference · schema

SSOConfig

7 fields · used by 1 operations

Last reviewed 2026-10-02

Fields

FieldTypeMeaning
issuer requiredstringmin length 8 · max length 500
client_id requiredstringmin length 1 · max length 500
client_secretstring or nullrequired the first time; omit to keep the stored one
max length 2000
default_rolestringviewer or member, for just-in-time joining and SCIM
default "viewer"
jitbooleanlet verified people from allowed_domains join on first sign-in
default false
allowed_domainsarray of stringmax items 50
email_claimstringemail, upn or preferred_username
default "email"

Smallest valid example

{
  "issuer": "issuer",
  "client_id": "client-id",
  "default_role": "viewer",
  "jit": false,
  "email_claim": "email"
}

Used by 1 operation

PUT/fabric/ssoRegister this workspace's OpenID Connect identity provider

JSON Schema

Show the raw definition
{
  "properties": {
    "issuer": {
      "type": "string",
      "maxLength": 500,
      "minLength": 8,
      "title": "Issuer"
    },
    "client_id": {
      "type": "string",
      "maxLength": 500,
      "minLength": 1,
      "title": "Client Id"
    },
    "client_secret": {
      "anyOf": [
        {
          "type": "string",
          "maxLength": 2000
        },
        {
          "type": "null"
        }
      ],
      "title": "Client Secret",
      "description": "required the first time; omit to keep the stored one"
    },
    "default_role": {
      "type": "string",
      "title": "Default Role",
      "description": "viewer or member, for just-in-time joining and SCIM",
      "default": "viewer"
    },
    "jit": {
      "type": "boolean",
      "title": "Jit",
      "description": "let verified people from allowed_domains join on first sign-in",
      "default": false
    },
    "allowed_domains": {
      "items": {
        "type": "string"
      },
      "type": "array",
      "maxItems": 50,
      "title": "Allowed Domains"
    },
    "email_claim": {
      "type": "string",
      "title": "Email Claim",
      "description": "email, upn or preferred_username",
      "default": "email"
    }
  },
  "type": "object",
  "required": [
    "issuer",
    "client_id"
  ],
  "title": "SSOConfig"
}

Try CAIN-42 on your own agents

Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.

Create a free account →  ·  Try the sandbox  ·  See the whole ecosystem