v1

latestOpenAPI 3.0.02026-07-246171,3332.1 MB
v2

post/auth-method-create-oidc

Request body

access-expiresinteger

Access expiration date in Unix timestamp (select 0 for access without expiry date)

allowed-client-typestring[]

limit the auth method usage for specific client types [cli,ui,gateway-admin,sdk,mobile,extension]

allowed-redirect-uristring[]

Allowed redirect URIs after the authentication

audiencestring

Audience claim to be used as part of the authentication flow. In case set, it must match the one configured on the Identity Provider's Application

audit-logs-claimsstring[]

Subclaims to include in audit logs, e.g "--audit-logs-claims email --audit-logs-claims username"

bound-ipsstring[]

A CIDR whitelist with the IPs that the access is restricted to

client-idstring

Client ID

client-secretstring

Client Secret

delete_protectionstring

Protection from accidental deletion of this object [true/false]

descriptionstring

Auth Method description

expiration-event-instring[]

How many days before the expiration of the auth method would you like to be notified.

force-sub-claimsboolean

if true: enforce role-association must include sub claims

gw-bound-ipsstring[]

A CIDR whitelist with the GW IPs that the access is restricted to

issuerstring

Issuer URL

jsonboolean

Set output format to JSON

jwt-ttlinteger

Jwt TTL

namestring required

Auth Method name

product-typestring[]

Choose the relevant product type for the auth method [sm, sra, pm, dp, ca]

required-scopesstring[]

RequiredScopes is a list of required scopes that the oidc method will request from the oidc provider and the user must approve

required-scopes-prefixstring

RequiredScopesPrefix is a a prefix to add to all required-scopes when requesting them from the oidc server (for example, azures' Application ID URI)

subclaims-delimitersstring[]

A list of additional sub claims delimiters (relevant only for SAML, OIDC, OAuth2/JWT)

tokenstring

Authentication token (see /auth and /configure)

uid-tokenstring

The universal identity token, Required only for universal_identity authentication

unique-identifierstring required

A unique identifier (ID) value should be configured for OIDC, OAuth2, LDAP and SAML authentication method types and is usually a value such as the email, username, or upn for example. Whenever a user logs in with a token, these authentication types issue a "sub claim" that contains details uniquely identifying that user. This sub claim includes a key containing the ID value that you configured, and is used to distinguish between different users from within the same organization.

Response

authMethodCreateOIDCResponse wraps response body.

access_idstring
access_keystring
namestring
prv_keystring