Update SAML connection
Apply a partial update to a SAML connection. Omitted fields are left
unchanged. The IdP entity_id is immutable — delete and recreate the
connection to rotate it.
curl --request PUT \
--url https://api.prelude.dev/v2/session/apps/{appID}/config/login/saml/{providerID}/{connectionID} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"name": "<string>",
"enabled": true,
"mapping": {
"email": "<string>",
"first_name": "<string>",
"last_name": "<string>",
"groups": "<string>",
"custom": {}
}
}
'import requests
url = "https://api.prelude.dev/v2/session/apps/{appID}/config/login/saml/{providerID}/{connectionID}"
payload = {
"name": "<string>",
"enabled": True,
"mapping": {
"email": "<string>",
"first_name": "<string>",
"last_name": "<string>",
"groups": "<string>",
"custom": {}
}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: '<string>',
enabled: true,
mapping: {
email: '<string>',
first_name: '<string>',
last_name: '<string>',
groups: '<string>',
custom: {}
}
})
};
fetch('https://api.prelude.dev/v2/session/apps/{appID}/config/login/saml/{providerID}/{connectionID}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.prelude.dev/v2/session/apps/{appID}/config/login/saml/{providerID}/{connectionID}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'name' => '<string>',
'enabled' => true,
'mapping' => [
'email' => '<string>',
'first_name' => '<string>',
'last_name' => '<string>',
'groups' => '<string>',
'custom' => [
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.prelude.dev/v2/session/apps/{appID}/config/login/saml/{providerID}/{connectionID}"
payload := strings.NewReader("{\n \"name\": \"<string>\",\n \"enabled\": true,\n \"mapping\": {\n \"email\": \"<string>\",\n \"first_name\": \"<string>\",\n \"last_name\": \"<string>\",\n \"groups\": \"<string>\",\n \"custom\": {}\n }\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://api.prelude.dev/v2/session/apps/{appID}/config/login/saml/{providerID}/{connectionID}")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"<string>\",\n \"enabled\": true,\n \"mapping\": {\n \"email\": \"<string>\",\n \"first_name\": \"<string>\",\n \"last_name\": \"<string>\",\n \"groups\": \"<string>\",\n \"custom\": {}\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.prelude.dev/v2/session/apps/{appID}/config/login/saml/{providerID}/{connectionID}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"<string>\",\n \"enabled\": true,\n \"mapping\": {\n \"email\": \"<string>\",\n \"first_name\": \"<string>\",\n \"last_name\": \"<string>\",\n \"groups\": \"<string>\",\n \"custom\": {}\n }\n}"
response = http.request(request)
puts response.read_body{
"connection": {
"id": "<string>",
"provider_id": "<string>",
"name": "<string>",
"enabled": true,
"idp": {
"entity_id": "<string>",
"sso_url": "<string>",
"slo_url": "<string>",
"certificates": [
"<string>"
]
},
"sp": {
"entity_id": "<string>",
"acs_url": "<string>",
"slo_url": "<string>",
"metadata_url": "<string>",
"signing_certificate": "<string>"
},
"behavior": {
"allow_email_account_merge": true,
"jit_provisioning": true,
"enforce_login": true,
"default_redirect_uri": "<string>",
"sync_profile_on_login": true,
"email_domain_allowlist": [
"<string>"
]
},
"mapping": {
"email": "<string>",
"given_name": "<string>",
"family_name": "<string>",
"groups": "<string>",
"custom": {}
},
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z"
}
}{
"code": "invalid_request",
"status": "bad_request",
"message": "<string>"
}{
"code": "app_not_found",
"status": "not_found",
"message": "<string>"
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Path Parameters
The id of the app the request refers to. An application's unique identifier.
"54e9ujn"
"fvua38g"
The SAML provider identifier.
"okta"
"google"
"jumpcloud"
The SAML connection identifier (prefixed with samlc_).
"samlc_01jqebhswje1ka1z7ahr9rfsgt"
Body
Partial update; omitted fields are left unchanged.
Explicit IdP block. Provide this only when you are not using
idp_metadata_url or idp_metadata_xml. Certificates accept raw PEM
or base64-wrapped PEM.
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Maps SAML assertion attributes to user profile fields. Defaults are applied per provider when omitted.
Show child attributes
Show child attributes
Response
OK
Show child attributes
Show child attributes
curl --request PUT \
--url https://api.prelude.dev/v2/session/apps/{appID}/config/login/saml/{providerID}/{connectionID} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"name": "<string>",
"enabled": true,
"mapping": {
"email": "<string>",
"first_name": "<string>",
"last_name": "<string>",
"groups": "<string>",
"custom": {}
}
}
'import requests
url = "https://api.prelude.dev/v2/session/apps/{appID}/config/login/saml/{providerID}/{connectionID}"
payload = {
"name": "<string>",
"enabled": True,
"mapping": {
"email": "<string>",
"first_name": "<string>",
"last_name": "<string>",
"groups": "<string>",
"custom": {}
}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: '<string>',
enabled: true,
mapping: {
email: '<string>',
first_name: '<string>',
last_name: '<string>',
groups: '<string>',
custom: {}
}
})
};
fetch('https://api.prelude.dev/v2/session/apps/{appID}/config/login/saml/{providerID}/{connectionID}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.prelude.dev/v2/session/apps/{appID}/config/login/saml/{providerID}/{connectionID}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'name' => '<string>',
'enabled' => true,
'mapping' => [
'email' => '<string>',
'first_name' => '<string>',
'last_name' => '<string>',
'groups' => '<string>',
'custom' => [
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.prelude.dev/v2/session/apps/{appID}/config/login/saml/{providerID}/{connectionID}"
payload := strings.NewReader("{\n \"name\": \"<string>\",\n \"enabled\": true,\n \"mapping\": {\n \"email\": \"<string>\",\n \"first_name\": \"<string>\",\n \"last_name\": \"<string>\",\n \"groups\": \"<string>\",\n \"custom\": {}\n }\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://api.prelude.dev/v2/session/apps/{appID}/config/login/saml/{providerID}/{connectionID}")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"<string>\",\n \"enabled\": true,\n \"mapping\": {\n \"email\": \"<string>\",\n \"first_name\": \"<string>\",\n \"last_name\": \"<string>\",\n \"groups\": \"<string>\",\n \"custom\": {}\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.prelude.dev/v2/session/apps/{appID}/config/login/saml/{providerID}/{connectionID}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"<string>\",\n \"enabled\": true,\n \"mapping\": {\n \"email\": \"<string>\",\n \"first_name\": \"<string>\",\n \"last_name\": \"<string>\",\n \"groups\": \"<string>\",\n \"custom\": {}\n }\n}"
response = http.request(request)
puts response.read_body{
"connection": {
"id": "<string>",
"provider_id": "<string>",
"name": "<string>",
"enabled": true,
"idp": {
"entity_id": "<string>",
"sso_url": "<string>",
"slo_url": "<string>",
"certificates": [
"<string>"
]
},
"sp": {
"entity_id": "<string>",
"acs_url": "<string>",
"slo_url": "<string>",
"metadata_url": "<string>",
"signing_certificate": "<string>"
},
"behavior": {
"allow_email_account_merge": true,
"jit_provisioning": true,
"enforce_login": true,
"default_redirect_uri": "<string>",
"sync_profile_on_login": true,
"email_domain_allowlist": [
"<string>"
]
},
"mapping": {
"email": "<string>",
"given_name": "<string>",
"family_name": "<string>",
"groups": "<string>",
"custom": {}
},
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z"
}
}{
"code": "invalid_request",
"status": "bad_request",
"message": "<string>"
}{
"code": "app_not_found",
"status": "not_found",
"message": "<string>"
}