---
title: "Update provider"
method: PATCH
path: "/zones/{zoneId}/providers/{id}"
tags: ["Providers"]
---

# Update provider

`PATCH /zones/{zoneId}/providers/{id}`

Updates a Provider's configuration and metadata

## Path parameters

- `zoneId` string, required
- `id` string, required

## Request body

- IamProviderUpdate — Schema for updating an existing provider
  - `name` string, safe-text — Human-readable name. Must not contain HTML tags (e.g. `<script>`, `<div>`) or control characters.
  - `description` string, safe-text, nullable — Human-readable description. Must not contain HTML tags (e.g. `<script>`, `<div>`) or control characters.
  - `identifier` string, safe-text — User specified identifier, unique within the zone. Must not contain HTML tags (e.g. `<script>`, `<div>`) or control characters.
  - `client_id` string, nullable — OAuth 2.0 client identifier. Set to null to remove.
  - `client_secret` string, nullable — OAuth 2.0 client secret (will be encrypted and stored securely). Set to null to remove.
  - `protocols` IamProviderProtocolUpdate, nullable — Protocol-specific configuration. Set to null to remove all protocols.
    - `oauth2` IamProviderOAuth2ProtocolUpdate, nullable — OAuth 2.0 protocol configuration. Set to null to remove all OAuth2 config.
      - `issuer` string, uri — OIDC issuer URL for discovery and token validation. Cannot be set to null.
      - `authorization_endpoint` string, uri, nullable
      - `token_endpoint` string, uri, nullable
      - `registration_endpoint` string, uri, nullable
      - `jwks_uri` string, uri, nullable
      - `code_challenge_methods_supported` string[], nullable
      - `scopes_supported` string[], nullable
      - `authorization_resource_enabled` boolean, nullable — Whether to include the resource parameter in authorization requests. Set to null to unset.
      - `authorization_resource_parameter` string, nullable — The resource parameter value to include in authorization requests. Defaults to "resource" when authorization_resource_enabled is true. Set to null to unset.
      - `scope_parameter` string, nullable — The query parameter name for scopes in authorization requests. Defaults to "scope". Set to null to unset.
      - `scope_separator` string, nullable — The separator character for scope values. Defaults to " " (space). Set to null to unset.
      - `token_response_access_token_pointer` string, nullable — Dot-separated path to the access token in the token response body. Defaults to "access_token". Set to null to unset.
      - `authorization_parameters` object, nullable — Custom query parameters appended to authorization redirect URLs. Set to null to unset.
    - `openid` IamProviderOpenIDProtocolUpdate, nullable — OpenID Connect protocol configuration. Set to null to remove all OpenID config.
      - `userinfo_endpoint` string, uri, nullable
      - `user_identifier_claim` string, nullable — Name of a top-level string claim in this provider's ID Token to use as the user identifier on user creation. Set to null to revert to default. Changing this value does not affect existing users.
      - `scopes` string[], nullable — Additional OIDC scopes to request from this provider during authentication (e.g. "groups"). Merged with the default scopes (openid, profile, email). Set to null to clear.
      - `single_logout_enabled` boolean, nullable — When true, logging out of the zone propagates the logout to this provider's end_session_endpoint (RP-initiated logout). Defaults to false.
  - `metadata` object, nullable — Provider metadata. Set to null to remove all metadata.

## Response `200`

A Provider is a system that supplies access to Resources and allows actors (Users or Applications) to authenticate.

- IamProvider — A Provider is a system that supplies access to Resources and allows actors (Users or Applications) to authenticate.
  - `id` string, required — Unique identifier of the provider
  - `organization_id` string, required — Organization that owns this provider
  - `zone_id` string, required — Zone this provider belongs to
  - `slug` string, required — URL-safe identifier, unique within the zone
  - `name` string, required — Human-readable name
  - `description` string, nullable — Human-readable description
  - `identifier` string, required — User specified identifier, unique within the zone
  - `type` 'external' | 'keycard-vault' | 'keycard-sts'
  - `client_id` string, nullable — OAuth 2.0 client identifier
  - `client_secret_set` boolean — Indicates whether a client secret is configured
  - `protocols` object, nullable — Protocol-specific configuration
    - `oauth2` IamProviderOAuth2Protocol, nullable — OAuth 2.0 protocol configuration
      - `issuer` string, uri, required — OIDC issuer URL used for discovery and token validation.
      - `authorization_endpoint` string, uri, nullable
      - `token_endpoint` string, uri, nullable
      - `registration_endpoint` string, uri, nullable
      - `jwks_uri` string, uri, nullable
      - `code_challenge_methods_supported` string[], nullable
      - `scopes_supported` string[], nullable
      - `authorization_resource_enabled` boolean, nullable — Whether to include the resource parameter in authorization requests.
      - `authorization_resource_parameter` string, nullable — The resource parameter value to include in authorization requests. Defaults to "resource" when authorization_resource_enabled is true.
      - `scope_parameter` string, nullable — The query parameter name for scopes in authorization requests. Defaults to "scope". Slack v2 uses "user_scope".
      - `scope_separator` string, nullable — The separator character for scope values. Defaults to " " (space). Slack v2 uses ",".
      - `token_response_access_token_pointer` string, nullable — Dot-separated path to the access token in the token response body. Defaults to "access_token". Slack v2 uses "authed_user.access_token".
      - `authorization_parameters` object, nullable — Custom query parameters appended to authorization redirect URLs. Use for non-standard providers (e.g. Google prompt=consent, access_type=offline).
    - `openid` IamProviderOpenIDProtocol, nullable — OpenID Connect protocol configuration
      - `userinfo_endpoint` string, uri, nullable
      - `user_identifier_claim` string, nullable — Name of a top-level string claim in this provider's ID Token to use as the user identifier on user creation. When not set, the user's Keycard ID is used.
      - `scopes` string[], nullable — Additional OIDC scopes to request from this provider during authentication (e.g. "groups"). Merged with the default scopes (openid, profile, email).
      - `single_logout_enabled` boolean, nullable — When true, logging out of the zone propagates the logout to this provider's end_session_endpoint (RP-initiated logout). Defaults to false.
  - `metadata` object, nullable — Provider metadata
  - `owner_type` 'platform' | 'customer', required — Who owns this provider. Platform-owned providers cannot be modified via API.
  - `created_at` string, date-time, required — Entity creation timestamp
  - `updated_at` string, date-time, required — Entity update timestamp

## Other responses

- `default` — Error response

---

[API](https://skmtc.net/keycardai/apis/untitled-api.md) · [All operations](https://skmtc.net/keycardai/apis/untitled-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/keycardai/untitled-api/revisions/2f5033ed4491/schema)
