Get an SSO identity connection by id.
Connection
Masked view of a connection. Never includes the client secret.
OIDC client id. null for non-OIDC kinds.
Whether a client secret is configured. The secret itself is never returned.
Catch-all role granted to JIT members with no matching group mapping. null = no catch-all role.
Read-only here: SSO enforcement isn't configurable via the API yet.
OIDC issuer. null for non-OIDC kinds (e.g. SAML), whose connection details live in kind-specific fields added when those kinds ship.