> ## Documentation Index
> Fetch the complete documentation index at: https://ona.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Create SSO Configuration

> Creates or updates SSO configuration for organizational authentication.

`Unary` · [`Organizations`](/docs/api-reference/generated/organization/overview)

Creates or updates SSO configuration for organizational authentication.

Use this method to:

* Configure OIDC-based SSO providers
* Set up built-in providers (Google, GitHub, etc.)
* Define custom identity providers
* Manage authentication policies

### Examples

* Configure built-in Google SSO:

  Sets up SSO using Google Workspace.

  ```yaml theme={null}
  organizationId: "b0e12f6c-4c67-429d-a4a6-d9838b5da047"
  clientId: "012345678-abcdefghijklmnopqrstuvwxyz.apps.googleusercontent.com"
  clientSecret: "GOCSPX-abcdefghijklmnopqrstuvwxyz123456"
  issuerUrl: "https://accounts.google.com"
  emailDomain: "acme-corp.com"
  ```

* Configure custom OIDC provider:

  Sets up SSO with a custom identity provider.

  ```yaml theme={null}
  organizationId: "b0e12f6c-4c67-429d-a4a6-d9838b5da047"
  clientId: "acme-corp-gitpod"
  clientSecret: "secret-token-value"
  issuerUrl: "https://sso.acme-corp.com"
  emailDomain: "acme-corp.com"
  ```

## Endpoint

```text theme={null}
POST /api/gitpod.v1.OrganizationService/CreateSSOConfiguration
```

Send a Bearer token as described in [Authentication](/docs/api-reference#authenticate-requests). If your organization uses a custom management-plane domain, replace `https://app.ona.com` with that domain.

## Request example

<CodeGroup>
  ```bash cURL theme={null}
  export ONA_HOST=https://app.ona.com
  export ONA_API_KEY=<your-token>

  curl --request POST \
    --url "$ONA_HOST/api/gitpod.v1.OrganizationService/CreateSSOConfiguration" \
    --header "Authorization: Bearer $ONA_API_KEY" \
    --header "Content-Type: application/json" \
    --data '{
    "clientId": "<client-id>",
    "clientSecret": "<redacted>",
    "issuerUrl": "https://example.com",
    "organizationId": "<organization-id>"
  }'
  ```

  ```python Python theme={null}
  import gitpod.v1.organization_pb2 as organization_pb2
  from ona_sdk import create_client_from_env

  ona = create_client_from_env()
  request = organization_pb2.CreateSSOConfigurationRequest(
      organization_id="<organization-id>",
      client_id="<client-id>",
      client_secret="<redacted>",
      issuer_url="https://example.com",
  )
  response = ona.services.organization.create_sso_configuration(request)
  print(response)
  ```

  ```typescript TypeScript theme={null}
  import { create } from "@bufbuild/protobuf";
  import { createClientFromEnv } from "@gitpod/sdk";
  import { CreateSSOConfigurationRequestSchema } from "@gitpod/sdk/gitpod/v1/organization_pb";

  async function main() {
    const ona = createClientFromEnv();
    const request = create(CreateSSOConfigurationRequestSchema, {
      organizationId: "<organization-id>",
      clientId: "<client-id>",
      clientSecret: "<redacted>",
      issuerUrl: "https://example.com",
    });
    const response = await ona.services.organization.createSSOConfiguration(request);
    console.log(response);
  }

  main().catch(console.error);
  ```

  ```go Go theme={null}
  package main

  import (
  	"context"
  	"fmt"
  	"log"

  	"connectrpc.com/connect"
  	"github.com/gitpod-io/gitpod-sdk-go/sdk"
  	gitpodpb "github.com/gitpod-io/gitpod-sdk-go/v1"
  )

  func main() {
  	ona, err := sdk.NewFromEnv()
  	if err != nil {
  		log.Fatal(err)
  	}

  	request := connect.NewRequest(&gitpodpb.CreateSSOConfigurationRequest{
  		OrganizationId: "<organization-id>",
  		ClientId: "<client-id>",
  		ClientSecret: "<redacted>",
  		IssuerUrl: "https://example.com",
  	})
  	response, err := ona.Services.Organization.CreateSSOConfiguration(context.Background(), request)
  	if err != nil {
  		log.Fatal(err)
  	}
  	fmt.Println(response.Msg)
  }
  ```

  ```json Request body theme={null}
  {
    "clientId": "<client-id>",
    "clientSecret": "<redacted>",
    "issuerUrl": "https://example.com",
    "organizationId": "<organization-id>"
  }
  ```
</CodeGroup>

## Request

`gitpod.v1.CreateSSOConfigurationRequest`

| Field              | Type            | Required | Description                                                                                                                                                                                                                                                                                       |
| ------------------ | --------------- | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `organizationId`   | string          | Yes      | Constraints: `required=true, string.uuid=true`.                                                                                                                                                                                                                                                   |
| `clientId`         | string          | Yes      | client\_id is the client ID of the OIDC application set on the IdP Constraints: `required=true, string.min_len=1`.                                                                                                                                                                                |
| `clientSecret`     | string          | Yes      | client\_secret is the client secret of the OIDC application set on the IdP Constraints: `required=true, string.min_len=1`.                                                                                                                                                                        |
| `issuerUrl`        | string          | Yes      | issuer\_url is the URL of the IdP issuer Constraints: `required=true, string.uri=true`.                                                                                                                                                                                                           |
| `emailDomain`      | string          | No       | email\_domain is the domain that is allowed to sign in to the organization Constraints: `string.min_len=4`.                                                                                                                                                                                       |
| `emailDomains`     | array of string | No       | Constraints: `repeated.items.string.max_len=253, repeated.items.string.min_len=4, repeated.items.string.pattern=^(?:[a-zA-Z0-9](?:[a-zA-Z0-9-]&#123;0,61&#125;[a-zA-Z0-9])?\.)+[a-zA-Z]&#123;2,&#125;$, repeated.unique=true`.                                                                    |
| `displayName`      | string          | No       | Constraints: `string.max_len=128`.                                                                                                                                                                                                                                                                |
| `additionalScopes` | array of string | No       | additional\_scopes are extra OIDC scopes to request from the identity provider during sign-in. These are appended to the default scopes (openid, email, profile). Constraints: `repeated.items.string.max_len=128, repeated.items.string.min_len=1, repeated.max_items=100`.                      |
| `claimsExpression` | string          | No       | claims\_expression is an optional CEL expression evaluated against OIDC token claims during login. When set, the expression must evaluate to true for the login to succeed. Example: `claims.email_verified &amp;&amp; claims.email.endsWith("@example.com")` Constraints: `string.max_len=4096`. |

## Response

`gitpod.v1.CreateSSOConfigurationResponse`

| Field              | Type                                                  | Required | Description                                                                       |
| ------------------ | ----------------------------------------------------- | -------- | --------------------------------------------------------------------------------- |
| `ssoConfiguration` | [SSOConfiguration](#type-gitpod-v1-sso-configuration) | Yes      | sso\_configuration is the created SSO configuration Constraints: `required=true`. |

## Related types

<a id="type-gitpod-v1-sso-configuration" />

<Accordion title="SSOConfiguration">
  `gitpod.v1.SSOConfiguration`

  | Field              | Type                                                             | Required | Description                                                                                                                                                                                                                                                                                                                                                                                                     |
  | ------------------ | ---------------------------------------------------------------- | -------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
  | `id`               | string                                                           | Yes      | id is the unique identifier of the SSO configuration Constraints: `required=true, string.uuid=true`.                                                                                                                                                                                                                                                                                                            |
  | `organizationId`   | string                                                           | Yes      | Constraints: `required=true, string.uuid=true`.                                                                                                                                                                                                                                                                                                                                                                 |
  | `clientId`         | string                                                           | No       | client\_id is the client ID of the OIDC application set on the IdP                                                                                                                                                                                                                                                                                                                                              |
  | `issuerUrl`        | string                                                           | Yes      | issuer\_url is the URL of the IdP issuer Constraints: `required=true`.                                                                                                                                                                                                                                                                                                                                          |
  | `state`            | [SSOConfigurationState](#enum-gitpod-v1-sso-configuration-state) | Yes      | state is the state of the SSO configuration Constraints: `required=true`.                                                                                                                                                                                                                                                                                                                                       |
  | `claims`           | map of string to string                                          | No       | claims are key/value pairs that defines a mapping of claims issued by the IdP.                                                                                                                                                                                                                                                                                                                                  |
  | `emailDomain`      | string                                                           | No       |                                                                                                                                                                                                                                                                                                                                                                                                                 |
  | `providerType`     | [ProviderType](#enum-gitpod-v1-sso-configuration-provider-type)  | Yes      | provider\_type defines the type of the SSO configuration Constraints: `required=true`.                                                                                                                                                                                                                                                                                                                          |
  | `emailDomains`     | array of string                                                  | No       | Constraints: `repeated.items.string.max_len=253, repeated.items.string.min_len=4, repeated.items.string.pattern=^(?:[a-zA-Z0-9](?:[a-zA-Z0-9-]&#123;0,61&#125;[a-zA-Z0-9])?\.)+[a-zA-Z]&#123;2,&#125;$, repeated.unique=true`.                                                                                                                                                                                  |
  | `displayName`      | string                                                           | No       | Constraints: `string.max_len=128`.                                                                                                                                                                                                                                                                                                                                                                              |
  | `additionalScopes` | array of string                                                  | No       | additional\_scopes are extra OIDC scopes requested from the identity provider during sign-in.                                                                                                                                                                                                                                                                                                                   |
  | `claimsExpression` | string                                                           | No       | claims\_expression is a CEL (Common Expression Language) expression evaluated against the OIDC token claims during login. When set, the expression must evaluate to true for the login to succeed. The expression has access to a `claims` variable containing all token claims as a map. Example: `claims.email_verified &amp;&amp; claims.email.endsWith("@example.com")` Constraints: `string.max_len=4096`. |
</Accordion>

<a id="enum-gitpod-v1-sso-configuration-provider-type" />

<Accordion title="ProviderType">
  | Value                       | Number | Description |
  | --------------------------- | -----: | ----------- |
  | `PROVIDER_TYPE_UNSPECIFIED` |      0 |             |
  | `PROVIDER_TYPE_BUILTIN`     |      1 |             |
  | `PROVIDER_TYPE_CUSTOM`      |      2 |             |
</Accordion>

<a id="enum-gitpod-v1-sso-configuration-state" />

<Accordion title="SSOConfigurationState">
  | Value                                 | Number | Description |
  | ------------------------------------- | -----: | ----------- |
  | `SSO_CONFIGURATION_STATE_UNSPECIFIED` |      0 |             |
  | `SSO_CONFIGURATION_STATE_INACTIVE`    |      1 |             |
  | `SSO_CONFIGURATION_STATE_ACTIVE`      |      2 |             |
</Accordion>
