---
title: "Get User or Organization Info via Webfinger for SSO"
method: GET
path: "/.well-known/webfinger"
tags: ["Webfinger"]
---

# Get User or Organization Info via Webfinger for SSO

`GET /.well-known/webfinger`

Gets data from an Identity Provider (IdP) configuration for SSO authentication based on a user email or organization ID via the [WebFinger protocol](https://en.wikipedia.org/wiki/WebFinger).

## Query parameters

- `resource` string, uri, required
- `rel` array[]
  - string[]

## Headers

- `Accept` 'application/json' | 'application/hal+json' | 'application/xml' | 'text/xml' | 'text/csv'

## Response `200`

Returns the Webfinger result.

- object
  - `subject` string
  - `links` object[]
    - `rel` 'idp'
    - `properties` union
      - object
        - `idp:type` 'none'
      - object
        - `idp:type` 'oidc'
        - `idp:callback` string, url
        - `idp:login` string, url
        - `idp:logout` string, url
        - `idp:logout:fc` string, url
      - object
        - `idp:type` 'oidc'
        - `idp:login` string, url
        - `idp:logout` string, url

## Other responses

- `400` — The server cannot or will not process the request due to something that is perceived to be a client error (e.g., malformed request syntax, invalid request message framing, or deceptive request routing)
- `401` — The request has not been applied because it lacks valid authentication credentials for the target resource.
- `402` — Upgrade your Plan to increase your Quota.
- `403` — The server understood the request but refuses to authorize it.
- `404` — The origin server did not find a current representation for the target resource or is not willing to disclose that one exists.
- `405` — The method received in the request-line is known by the origin server but not supported by the target resource.
- `409` — The request conflicts with current state of the server.
- `413` — The request entity is larger than limits defined by server.
- `500` — The server encountered an unexpected condition that prevented it from fulfilling the request.
- `501` — The server does not support the functionality required to fulfill the request.
- `502` — The server, while acting as a gateway or proxy, received an invalid response from an inbound server it accessed while attempting to fulfill the request.
- `503` — The server is not ready to handle the request.
- `504` — The server, while acting as a gateway or proxy, did not receive a timely response from an upstream server it needed to access in order to complete the request.

---

[API](https://skmtc.net/cognigy/apis/simulator-openapi-rest-ful-api-reference.md) · [All operations](https://skmtc.net/cognigy/apis/simulator-openapi-rest-ful-api-reference/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/cognigy/simulator-openapi-rest-ful-api-reference/revisions/85b2872bdfb7/schema)
