Unary · Organizations
Creates or updates SSO configuration for organizational authentication.
Use this method to:
- Configure OIDC-based SSO providers
- Set up built-in providers (Google, GitHub, etc.)
- Define custom identity providers
- Manage authentication policies
Examples
-
Configure built-in Google SSO:
Sets up SSO using Google Workspace.
organizationId: "b0e12f6c-4c67-429d-a4a6-d9838b5da047" clientId: "012345678-abcdefghijklmnopqrstuvwxyz.apps.googleusercontent.com" clientSecret: "GOCSPX-abcdefghijklmnopqrstuvwxyz123456" issuerUrl: "https://accounts.google.com" emailDomain: "acme-corp.com" -
Configure custom OIDC provider:
Sets up SSO with a custom identity provider.
organizationId: "b0e12f6c-4c67-429d-a4a6-d9838b5da047" clientId: "acme-corp-gitpod" clientSecret: "secret-token-value" issuerUrl: "https://sso.acme-corp.com" emailDomain: "acme-corp.com"
Endpoint
POST /api/gitpod.v1.OrganizationService/CreateSSOConfiguration
https://app.ona.com with that domain.
Request example
export ONA_HOST=https://app.ona.com
export ONA_API_KEY=<your-token>
curl --request POST \
--url "$ONA_HOST/api/gitpod.v1.OrganizationService/CreateSSOConfiguration" \
--header "Authorization: Bearer $ONA_API_KEY" \
--header "Content-Type: application/json" \
--data '{
"clientId": "<client-id>",
"clientSecret": "<redacted>",
"issuerUrl": "https://example.com",
"organizationId": "<organization-id>"
}'
import gitpod.v1.organization_pb2 as organization_pb2
from ona_sdk import create_client_from_env
ona = create_client_from_env()
request = organization_pb2.CreateSSOConfigurationRequest(
organization_id="<organization-id>",
client_id="<client-id>",
client_secret="<redacted>",
issuer_url="https://example.com",
)
response = ona.services.organization.create_sso_configuration(request)
print(response)
import { create } from "@bufbuild/protobuf";
import { createClientFromEnv } from "@gitpod/sdk";
import { CreateSSOConfigurationRequestSchema } from "@gitpod/sdk/gitpod/v1/organization_pb";
async function main() {
const ona = createClientFromEnv();
const request = create(CreateSSOConfigurationRequestSchema, {
organizationId: "<organization-id>",
clientId: "<client-id>",
clientSecret: "<redacted>",
issuerUrl: "https://example.com",
});
const response = await ona.services.organization.createSSOConfiguration(request);
console.log(response);
}
main().catch(console.error);
package main
import (
"context"
"fmt"
"log"
"connectrpc.com/connect"
"github.com/gitpod-io/gitpod-sdk-go/sdk"
gitpodpb "github.com/gitpod-io/gitpod-sdk-go/v1"
)
func main() {
ona, err := sdk.NewFromEnv()
if err != nil {
log.Fatal(err)
}
request := connect.NewRequest(&gitpodpb.CreateSSOConfigurationRequest{
OrganizationId: "<organization-id>",
ClientId: "<client-id>",
ClientSecret: "<redacted>",
IssuerUrl: "https://example.com",
})
response, err := ona.Services.Organization.CreateSSOConfiguration(context.Background(), request)
if err != nil {
log.Fatal(err)
}
fmt.Println(response.Msg)
}
{
"clientId": "<client-id>",
"clientSecret": "<redacted>",
"issuerUrl": "https://example.com",
"organizationId": "<organization-id>"
}
Request
gitpod.v1.CreateSSOConfigurationRequest
| Field | Type | Required | Description |
|---|---|---|---|
organizationId | string | Yes | Constraints: required=true, string.uuid=true. |
clientId | string | Yes | client_id is the client ID of the OIDC application set on the IdP Constraints: required=true, string.min_len=1. |
clientSecret | string | Yes | client_secret is the client secret of the OIDC application set on the IdP Constraints: required=true, string.min_len=1. |
issuerUrl | string | Yes | issuer_url is the URL of the IdP issuer Constraints: required=true, string.uri=true. |
emailDomain | string | No | email_domain is the domain that is allowed to sign in to the organization Constraints: string.min_len=4. |
emailDomains | array of string | No | Constraints: repeated.items.string.max_len=253, repeated.items.string.min_len=4, repeated.items.string.pattern=^(?:[a-zA-Z0-9](?:[a-zA-Z0-9-]{0,61}[a-zA-Z0-9])?\.)+[a-zA-Z]{2,}$, repeated.unique=true. |
displayName | string | No | Constraints: string.max_len=128. |
additionalScopes | array of string | No | additional_scopes are extra OIDC scopes to request from the identity provider during sign-in. These are appended to the default scopes (openid, email, profile). Constraints: repeated.items.string.max_len=128, repeated.items.string.min_len=1, repeated.max_items=100. |
claimsExpression | string | No | claims_expression is an optional CEL expression evaluated against OIDC token claims during login. When set, the expression must evaluate to true for the login to succeed. Example: claims.email_verified && claims.email.endsWith("@example.com") Constraints: string.max_len=4096. |
Response
gitpod.v1.CreateSSOConfigurationResponse
| Field | Type | Required | Description |
|---|---|---|---|
ssoConfiguration | SSOConfiguration | Yes | sso_configuration is the created SSO configuration Constraints: required=true. |
Related types
SSOConfiguration
SSOConfiguration
gitpod.v1.SSOConfiguration| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | id is the unique identifier of the SSO configuration Constraints: required=true, string.uuid=true. |
organizationId | string | Yes | Constraints: required=true, string.uuid=true. |
clientId | string | No | client_id is the client ID of the OIDC application set on the IdP |
issuerUrl | string | Yes | issuer_url is the URL of the IdP issuer Constraints: required=true. |
state | SSOConfigurationState | Yes | state is the state of the SSO configuration Constraints: required=true. |
claims | map of string to string | No | claims are key/value pairs that defines a mapping of claims issued by the IdP. |
emailDomain | string | No | |
providerType | ProviderType | Yes | provider_type defines the type of the SSO configuration Constraints: required=true. |
emailDomains | array of string | No | Constraints: repeated.items.string.max_len=253, repeated.items.string.min_len=4, repeated.items.string.pattern=^(?:[a-zA-Z0-9](?:[a-zA-Z0-9-]{0,61}[a-zA-Z0-9])?\.)+[a-zA-Z]{2,}$, repeated.unique=true. |
displayName | string | No | Constraints: string.max_len=128. |
additionalScopes | array of string | No | additional_scopes are extra OIDC scopes requested from the identity provider during sign-in. |
claimsExpression | string | No | claims_expression is a CEL (Common Expression Language) expression evaluated against the OIDC token claims during login. When set, the expression must evaluate to true for the login to succeed. The expression has access to a claims variable containing all token claims as a map. Example: claims.email_verified && claims.email.endsWith("@example.com") Constraints: string.max_len=4096. |
ProviderType
ProviderType
| Value | Number | Description |
|---|---|---|
PROVIDER_TYPE_UNSPECIFIED | 0 | |
PROVIDER_TYPE_BUILTIN | 1 | |
PROVIDER_TYPE_CUSTOM | 2 |
SSOConfigurationState
SSOConfigurationState
| Value | Number | Description |
|---|---|---|
SSO_CONFIGURATION_STATE_UNSPECIFIED | 0 | |
SSO_CONFIGURATION_STATE_INACTIVE | 1 | |
SSO_CONFIGURATION_STATE_ACTIVE | 2 |