> ## Documentation Index
> Fetch the complete documentation index at: https://ona.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Update SSO Configuration

> Updates SSO provider settings and authentication rules.

`Unary` · [`Organizations`](/docs/api-reference/generated/organization/overview)

Updates SSO provider settings and authentication rules.

Use this method to:

* Rotate client credentials
* Update provider endpoints
* Modify claim mappings
* Change authentication policies
* Toggle SSO enforcement

### Examples

* Update credentials:

  Rotates client ID and secret.

  ```yaml theme={null}
  ssoConfigurationId: "d2c94c27-3b76-4a42-b88c-95a85e392c68"
  clientId: "new-client-id"
  clientSecret: "new-client-secret"
  ```

* Update provider status:

  Activates or deactivates SSO provider.

  ```yaml theme={null}
  ssoConfigurationId: "d2c94c27-3b76-4a42-b88c-95a85e392c68"
  state: SSO_CONFIGURATION_STATE_ACTIVE
  ```

## Endpoint

```text theme={null}
POST /api/gitpod.v1.OrganizationService/UpdateSSOConfiguration
```

Send a Bearer token as described in [Authentication](/docs/api-reference#authenticate-requests). If your organization uses a custom management-plane domain, replace `https://app.ona.com` with that domain.

## Request example

<CodeGroup>
  ```bash cURL theme={null}
  export ONA_HOST=https://app.ona.com
  export ONA_API_KEY=<your-token>

  curl --request POST \
    --url "$ONA_HOST/api/gitpod.v1.OrganizationService/UpdateSSOConfiguration" \
    --header "Authorization: Bearer $ONA_API_KEY" \
    --header "Content-Type: application/json" \
    --data '{
    "ssoConfigurationId": "<sso-configuration-id>"
  }'
  ```

  ```python Python theme={null}
  import gitpod.v1.organization_pb2 as organization_pb2
  from ona_sdk import create_client_from_env

  ona = create_client_from_env()
  request = organization_pb2.UpdateSSOConfigurationRequest(
      sso_configuration_id="<sso-configuration-id>",
  )
  response = ona.services.organization.update_sso_configuration(request)
  print(response)
  ```

  ```typescript TypeScript theme={null}
  import { create } from "@bufbuild/protobuf";
  import { createClientFromEnv } from "@gitpod/sdk";
  import { UpdateSSOConfigurationRequestSchema } from "@gitpod/sdk/gitpod/v1/organization_pb";

  async function main() {
    const ona = createClientFromEnv();
    const request = create(UpdateSSOConfigurationRequestSchema, {
      ssoConfigurationId: "<sso-configuration-id>",
    });
    const response = await ona.services.organization.updateSSOConfiguration(request);
    console.log(response);
  }

  main().catch(console.error);
  ```

  ```go Go theme={null}
  package main

  import (
  	"context"
  	"fmt"
  	"log"

  	"connectrpc.com/connect"
  	"github.com/gitpod-io/gitpod-sdk-go/sdk"
  	gitpodpb "github.com/gitpod-io/gitpod-sdk-go/v1"
  )

  func main() {
  	ona, err := sdk.NewFromEnv()
  	if err != nil {
  		log.Fatal(err)
  	}

  	request := connect.NewRequest(&gitpodpb.UpdateSSOConfigurationRequest{
  		SsoConfigurationId: "<sso-configuration-id>",
  	})
  	response, err := ona.Services.Organization.UpdateSSOConfiguration(context.Background(), request)
  	if err != nil {
  		log.Fatal(err)
  	}
  	fmt.Println(response.Msg)
  }
  ```

  ```json Request body theme={null}
  {
    "ssoConfigurationId": "<sso-configuration-id>"
  }
  ```
</CodeGroup>

## Request

`gitpod.v1.UpdateSSOConfigurationRequest`

| Field                | Type                                                               | Required | Description                                                                                                                                                                                                                                                         |
| -------------------- | ------------------------------------------------------------------ | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `ssoConfigurationId` | string                                                             | Yes      | sso\_configuration\_id is the ID of the SSO configuration to update Constraints: `required=true, string.uuid=true`.                                                                                                                                                 |
| `clientId`           | string                                                             | No       | client\_id is the client ID of the SSO provider Constraints: `string.min_len=1`.                                                                                                                                                                                    |
| `clientSecret`       | string                                                             | No       | client\_secret is the client secret of the SSO provider Constraints: `string.min_len=1`.                                                                                                                                                                            |
| `issuerUrl`          | string                                                             | No       | issuer\_url is the URL of the IdP issuer Constraints: `string.uri=true`.                                                                                                                                                                                            |
| `state`              | [SSOConfigurationState](#enum-gitpod-v1-sso-configuration-state)   | No       | state is the state of the SSO configuration                                                                                                                                                                                                                         |
| `claims`             | map of string to string                                            | No       | claims are key/value pairs that defines a mapping of claims issued by the IdP.                                                                                                                                                                                      |
| `emailDomain`        | string                                                             | No       | Constraints: `string.min_len=4`.                                                                                                                                                                                                                                    |
| `emailDomains`       | array of string                                                    | No       | Constraints: `repeated.items.string.max_len=253, repeated.items.string.min_len=4, repeated.items.string.pattern=^(?:[a-zA-Z0-9](?:[a-zA-Z0-9-]&#123;0,61&#125;[a-zA-Z0-9])?\.)+[a-zA-Z]&#123;2,&#125;$, repeated.unique=true`.                                      |
| `displayName`        | string                                                             | No       | Constraints: `string.max_len=128`.                                                                                                                                                                                                                                  |
| `additionalScopes`   | [AdditionalScopesUpdate](#type-gitpod-v1-additional-scopes-update) | No       | additional\_scopes replaces the configured OIDC scopes when present. When absent (nil), scopes are left unchanged. When present with an empty scopes list, all additional scopes are cleared.                                                                       |
| `claimsExpression`   | string                                                             | No       | claims\_expression is a CEL expression evaluated against OIDC token claims during login. When set, the expression must evaluate to true for the login to succeed. When present with an empty string, the expression is cleared. Constraints: `string.max_len=4096`. |

## Response

`gitpod.v1.UpdateSSOConfigurationResponse`

This message has no fields.

## Related types

<a id="type-gitpod-v1-additional-scopes-update" />

<Accordion title="AdditionalScopesUpdate">
  AdditionalScopesUpdate wraps a list of OIDC scopes so that the update request
  can distinguish "not changing scopes" (field absent) from "clearing all scopes"
  (field present, empty list).

  `gitpod.v1.AdditionalScopesUpdate`

  | Field    | Type            | Required | Description                                                                                                |
  | -------- | --------------- | -------- | ---------------------------------------------------------------------------------------------------------- |
  | `scopes` | array of string | No       | Constraints: `repeated.items.string.max_len=128, repeated.items.string.min_len=1, repeated.max_items=100`. |
</Accordion>

<a id="enum-gitpod-v1-sso-configuration-state" />

<Accordion title="SSOConfigurationState">
  | Value                                 | Number | Description |
  | ------------------------------------- | -----: | ----------- |
  | `SSO_CONFIGURATION_STATE_UNSPECIFIED` |      0 |             |
  | `SSO_CONFIGURATION_STATE_INACTIVE`    |      1 |             |
  | `SSO_CONFIGURATION_STATE_ACTIVE`      |      2 |             |
</Accordion>
