---
title: "ListSSOConfigurations"
method: POST
path: "/gitpod.v1.OrganizationService/ListSSOConfigurations"
tags: ["gitpod.v1.OrganizationService"]
---

# ListSSOConfigurations

`POST /gitpod.v1.OrganizationService/ListSSOConfigurations`

Lists and filters SSO configurations for an organization.

 Use this method to:
 - View all SSO providers
 - Monitor authentication status
 - Audit security settings
 - Manage provider configurations

 ### Examples

 - List active configurations:

   Shows all active SSO providers.

   ```yaml
   organizationId: "b0e12f6c-4c67-429d-a4a6-d9838b5da047"
   pagination:
     pageSize: 20
   ```

 - List by provider type:

   Shows custom SSO configurations.

   ```yaml
   organizationId: "b0e12f6c-4c67-429d-a4a6-d9838b5da047"
   pagination:
     pageSize: 20
     token: "next-page-token-from-previous-response"
   ```

## Query parameters

- `pageSize` integer
- `token` string

## Request body

- GitpodV1ListSSOConfigurationsRequest
  - `organizationId` string, uuid, required — organization_id is the ID of the organization to list SSO configurations for.
  - `pagination` GitpodV1PaginationRequest
    - `pageSize` integer — Page size is the maximum number of results to retrieve per page. Defaults to 25. Maximum 100.
    - `token` string — Token for the next set of results that was returned as next_token of a PaginationResponse

## Response `200`

Success

- GitpodV1ListSSOConfigurationsResponse
  - `pagination` GitpodV1PaginationResponse, required
    - `nextToken` string — Token passed for retrieving the next set of results. Empty if there are no more results
  - `ssoConfigurations` GitpodV1SSOConfiguration[] — sso_configurations are the SSO configurations for the organization
    - `additionalScopes` string[] — additional_scopes are extra OIDC scopes requested from the identity provider during sign-in.
    - `claims` object — claims are key/value pairs that defines a mapping of claims issued by the IdP.
    - `claimsExpression` string — claims_expression is a CEL (Common Expression Language) expression evaluated against the OIDC token claims during login. When set, the expression must evaluate to true for the login to succeed. The expression has access to a `claims` variable containing all token claims as a map. Example: `claims.email_verified && claims.email.endsWith("@example.com")`
    - `clientId` string — client_id is the client ID of the OIDC application set on the IdP
    - `displayName` string
    - `emailDomain` string
    - `emailDomains` string[]
    - `id` string, uuid, required — id is the unique identifier of the SSO configuration
    - `issuerUrl` string, required — issuer_url is the URL of the IdP issuer
    - `organizationId` string, uuid, required
    - `providerType` 'PROVIDER_TYPE_UNSPECIFIED' | 'PROVIDER_TYPE_BUILTIN' | 'PROVIDER_TYPE_CUSTOM', required
    - `state` 'SSO_CONFIGURATION_STATE_UNSPECIFIED' | 'SSO_CONFIGURATION_STATE_INACTIVE' | 'SSO_CONFIGURATION_STATE_ACTIVE', required

## Other responses

- `default` — Error

---

[API](https://skmtc.net/gitpod-io/apis/gitpod-v1.md) · [All operations](https://skmtc.net/gitpod-io/apis/gitpod-v1/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/gitpod-io/gitpod-v1/revisions/44d50c2ac284/schema)
