---
title: "Create Provider"
method: POST
path: "/api/v1/workload_federation/providers"
tags: ["Workload Federation"]
---

# Create Provider

`POST /api/v1/workload_federation/providers`

CreateProvider registers a new external OIDC issuer for the tenant.
 Validates the issuer URL via OIDC discovery synchronously.

## Request body

- C1ApiWorkloadFederationV1WorkloadFederationServiceCreateProviderRequest — The WorkloadFederationServiceCreateProviderRequest message. This message contains a oneof named settings. Only a single field of the following list may be set at a time: - oidc - spiffe
  - `description` string — A description of what this provider is for.
  - `displayName` string — The display name for the new provider.
  - `issuerUrl` string — The issuer URL. For OIDC providers, this is an HTTPS URL validated via OIDC discovery. For SPIFFE providers, this is the SPIFFE trust-domain URI (e.g., spiffe://prod.example.com). Normalized on write: lowercase scheme/host, no trailing slash. Unique within tenant.
  - `oidc` C1ApiWorkloadFederationV1OIDCSettings, nullable — OIDCSettings is the kind-specific configuration block for classic OIDC providers (GitHub Actions, GitLab CI, HCP Terraform, AWS IAM Outbound, any CUSTOM provider). Empty for now; future fields like custom_jwks_url, audience overrides, and required_claims land here.
  - `spiffe` C1ApiWorkloadFederationV1SPIFFESettings, nullable — SPIFFESettings is the kind-specific configuration block for SPIFFE trust-domain providers (issuer_url = spiffe://<trust-domain>).
    - `bundleEndpointUrl` string — HTTPS URL of the JWKS endpoint serving the trust domain's signing keys. Required: the spiffe:// scheme has no discovery mechanism. Typically the SPIRE OIDC Discovery Provider's /keys endpoint. Mutable: updates re-validate the new URL by fetching its JWKS before persisting; the issuer (trust domain) itself remains immutable.
  - `wellKnownProvider` 'WELL_KNOWN_WORKLOAD_PROVIDER_UNSPECIFIED' | 'WELL_KNOWN_WORKLOAD_PROVIDER_CUSTOM' | 'WELL_KNOWN_WORKLOAD_PROVIDER_GITHUB_ACTIONS' | 'WELL_KNOWN_WORKLOAD_PROVIDER_GITLAB_CI' | 'WELL_KNOWN_WORKLOAD_PROVIDER_HCP_TERRAFORM' | 'WELL_KNOWN_WORKLOAD_PROVIDER_AWS_IAM_OUTBOUND' | 'WELL_KNOWN_WORKLOAD_PROVIDER_SPIFFE' — Well-known provider type. Required -- UNSPECIFIED is rejected. When set to a named source, the backend validates issuer_url consistency. SPIFFE wkp requires `settings.spiffe`; all other wkp values require `settings.oidc`.

## Response `200`

Successful response

- C1ApiWorkloadFederationV1WorkloadFederationServiceCreateProviderResponse — The WorkloadFederationServiceCreateProviderResponse message.
  - `provider` C1ApiWorkloadFederationV1WorkloadFederationProvider — WorkloadFederationProvider represents a tenant-level workload identity issuer registration. Two issuer schemes are supported: - https://... classic OIDC issuer; `settings.oidc` MUST be set. - spiffe://... SPIFFE trust-domain URI; `settings.spiffe` MUST be set. The (well_known_provider, issuer_url scheme, settings oneof) tuple is a tri-invariant: SPIFFE wkp ⟺ spiffe:// issuer ⟺ settings.spiffe set; any other wkp ⟺ https:// issuer ⟺ settings.oidc set. Issuer URLs are unique within tenant. This message contains a oneof named settings. Only a single field of the following list may be set at a time: - oidc - spiffe
    - `createdAt` string, date-time
    - `description` string — A description of what this provider is for.
    - `disabled` boolean — Whether the provider is disabled. Disabled providers reject all token exchanges.
    - `displayName` string — The display name of the provider.
    - `id` string — The unique ID of the provider.
    - `issuerUrl` string — Canonical issuer URL. https:// for OIDC providers, spiffe:// for SPIFFE trust domains. Unique within tenant. Immutable after creation.
    - `oidc` C1ApiWorkloadFederationV1OIDCSettings, nullable — OIDCSettings is the kind-specific configuration block for classic OIDC providers (GitHub Actions, GitLab CI, HCP Terraform, AWS IAM Outbound, any CUSTOM provider). Empty for now; future fields like custom_jwks_url, audience overrides, and required_claims land here.
    - `spiffe` C1ApiWorkloadFederationV1SPIFFESettings, nullable — SPIFFESettings is the kind-specific configuration block for SPIFFE trust-domain providers (issuer_url = spiffe://<trust-domain>).
      - `bundleEndpointUrl` string — HTTPS URL of the JWKS endpoint serving the trust domain's signing keys. Required: the spiffe:// scheme has no discovery mechanism. Typically the SPIRE OIDC Discovery Provider's /keys endpoint. Mutable: updates re-validate the new URL by fetching its JWKS before persisting; the issuer (trust domain) itself remains immutable.
    - `updatedAt` string, date-time
    - `wellKnownProvider` 'WELL_KNOWN_WORKLOAD_PROVIDER_UNSPECIFIED' | 'WELL_KNOWN_WORKLOAD_PROVIDER_CUSTOM' | 'WELL_KNOWN_WORKLOAD_PROVIDER_GITHUB_ACTIONS' | 'WELL_KNOWN_WORKLOAD_PROVIDER_GITLAB_CI' | 'WELL_KNOWN_WORKLOAD_PROVIDER_HCP_TERRAFORM' | 'WELL_KNOWN_WORKLOAD_PROVIDER_AWS_IAM_OUTBOUND' | 'WELL_KNOWN_WORKLOAD_PROVIDER_SPIFFE' — Well-known provider type. Drives UX (wizard presets, docs, icons). Set at creation time, immutable.

---

[API](https://skmtc.net/conductorone/apis/c1-api.md) · [All operations](https://skmtc.net/conductorone/apis/c1-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/conductorone/c1-api/versions/d391405a35d3/schema)
