Skip to main content
POST
Error

Authorizations

Authorization
string
header
required

Bearer authentication. Send Authorization: Bearer .

Body

application/json

Candidate SSO Provider Configuration

SSOProviderConfigInput payload

clientId
string
required
clientSecret
string
required

#nosec G117 -- write-only credential, never echoed back in any response

type
enum<string>
required
Available options:
Google,
AzureAD,
Okta,
Custom
Example:

"Google"

customAuthUrl
string
customTokenUrl
string
customUserInfoUrl
string
disablePasswordLogin
boolean
Example:

true

domain
string

Domain is REQUIRED for Type=Okta and ignored otherwise: Casdoor derives an Okta provider's authorize, token and userinfo endpoints from it, and no constant can stand in because they are per-org. Either the org URL (https://.okta.com) or an authorization server base (https://.okta.com/oauth2/default) is accepted; the org URL is completed to its authorization server on write.

Example:

"https://your-org.okta.com"

issuerUrl
string
name
string
scopes
string

Response

OK

SSOProviderPreflight payload

authorizationEndpoint
string
Example:

"https://accounts.google.com/o/oauth2/v2/auth"

configValid
boolean
credentialsValid
boolean
discoveryOk
boolean
redirectUriAcceptedByIdp
boolean

RedirectUriAcceptedByIdp reports whether the identity provider redirected the probe back to this deployment's SSO callback. RFC 6749 §3.1.2.4 forbids an authorization server from redirecting to an unregistered redirect_uri, so a redirect that arrives proves the callback is authorized. False means "not proven": an unreachable authorization endpoint, a reply carrying no Location and any other inconclusive answer all read false, so read it as not confirmed rather than as proof the callback is absent from the provider's authorized-redirect list.

tokenEndpoint
string
Example:

"https://oauth2.googleapis.com/token"

userinfoEndpoint
string
Example:

"https://openidconnect.googleapis.com/v1/userinfo"