---
title: "Update SAML auth settings"
method: POST
path: "/api/admin/auth/saml/settings"
tags: ["Auth"]
---

# Update SAML auth settings

`POST /api/admin/auth/saml/settings`

**Enterprise feature**

Updates the settings for SAML Authentication

## Request body

- union — Settings used to authenticate via SAML
  - object
    - `enabled` true — Whether to enable or disable SAML 2.0 for this instance
    - `entityId` string, required — The SAML 2.0 entity ID
    - `signOnUrl` string, required — Which URL to use for Single Sign On
    - `certificate` string, required — The X509 certificate used to validate requests
    - `signOutUrl` string — Which URL to use for Single Sign Out
    - `spCertificate` string — Signing certificate for sign out requests
    - `autoCreate` boolean — Should Unleash create users based on the emails coming back in the authentication reply from the SAML server
    - `emailDomains` string — A comma separated list of email domains that Unleash will auto create user accounts for.
    - `defaultRootRole` 'Viewer' | 'Editor' | 'Admin' — Assign this root role to auto created users
    - `defaultRootRoleId` number — Assign this root role to auto created users. Should be a role ID and takes precedence over `defaultRootRole`.
    - `enableGroupSyncing` boolean — Should we enable group syncing. Refer to the documentation [Group syncing](https://docs.getunleash.io/single-sign-on/how-to-set-up-group-sso-sync)
    - `groupJsonPath` string — Specifies the path in the SAML token response from which to read the groups the user belongs to.
  - object
    - `enabled` false — Whether to enable or disable SAML 2.0 for this instance
    - `entityId` string — The SAML 2.0 entity ID
    - `signOnUrl` string — Which URL to use for Single Sign On
    - `certificate` string — The X509 certificate used to validate requests
    - `signOutUrl` string — Which URL to use for Single Sign Out
    - `spCertificate` string — Signing certificate for sign out requests
    - `autoCreate` boolean — Should Unleash create users based on the emails coming back in the authentication reply from the SAML server
    - `emailDomains` string — A comma separated list of email domains that Unleash will auto create user accounts for.
    - `defaultRootRole` 'Viewer' | 'Editor' | 'Admin' — Assign this root role to auto created users
    - `defaultRootRoleId` number — Assign this root role to auto created users. Should be a role ID and takes precedence over `defaultRootRole`.
    - `enableGroupSyncing` boolean — Should we enable group syncing. Refer to the documentation [Group syncing](https://docs.getunleash.io/single-sign-on/how-to-set-up-group-sso-sync)
    - `groupJsonPath` string — Specifies the path in the SAML token response from which to read the groups the user belongs to.

## Response `200`

samlSettingsResponseSchema

- SamlSettingsResponseSchema — Response for SAML settings
  - `enabled` true — Whether to enable or disable SAML 2.0 for this instance
  - `entityId` string — The SAML 2.0 entity ID
  - `signOnUrl` string — Which URL to use for Single Sign On
  - `certificate` string — The X509 certificate used to validate requests
  - `signOutUrl` string — Which URL to use for Single Sign Out
  - `spCertificate` string — Signing certificate for sign out requests
  - `autoCreate` boolean — Should Unleash create users based on the emails coming back in the authentication reply from the SAML server
  - `emailDomains` string — A comma separated list of email domains that Unleash will auto create user accounts for.
  - `defaultRootRole` 'Viewer' | 'Editor' | 'Admin' — Assign this root role to auto created users
  - `defaultRootRoleId` number — Assign this root role to auto created users. Should be a role ID and takes precedence over `defaultRootRole`.
  - `enableGroupSyncing` boolean — Should we enable group syncing. Refer to the documentation [Group syncing](https://docs.getunleash.io/single-sign-on/how-to-set-up-group-sso-sync)
  - `groupJsonPath` string — Specifies the path in the SAML token response from which to read the groups the user belongs to.

## Other responses

- `400` — The request data does not match what we expect.
- `401` — Authorization information is missing or invalid. Provide a valid API token as the `authorization` header, e.g. `authorization:*.*.my-admin-token`.
- `403` — The provided user credentials are valid, but the user does not have the necessary permissions to perform this operation
- `415` — The operation does not support request payloads of the provided type. Please ensure that you're using one of the listed payload types and that you have specified the right content type in the "content-type" header.

---

[API](https://skmtc.net/unleash/apis/unleash-api-3.md) · [All operations](https://skmtc.net/unleash/apis/unleash-api-3/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/unleash/unleash-api-3/revisions/b2c3116e633e/schema)
