Skip to content

Get the team SSO overview

GET
/api/v1/team/sso
curl --request GET \
--url https://api.deploybase.eu/api/v1/api/v1/team/sso \
--header 'Authorization: <Authorization>'

Returns the redirect URI to register in the identity provider plus the team’s connections, oldest first. The redirect URI is the same for every connection and is available before any connection exists, which is the order the setup actually happens in: register the client in your IdP first, create the connection here second. Client secrets are never returned. Team admin or owner.

OK

Media type application/json
object
data
meta
object
request_id
string
timestamp
string
trace_id
string
data
object
connections

Connections is the team’s connections, oldest first. Never null: an empty list is the normal state of a team that has not set SSO up yet.

Array<object>
object
client_id
string
created_at
string
has_client_secret
boolean
id
string
is_active
boolean
is_id_token_mapping
boolean
issuer
string
name
string
provider
string
redirect_uri

RedirectURI is the callback the admin must register in their own IdP. It is Zitadel’s, not ours, and it is the same for every connection — which is exactly why it rides on every view instead of living in the frontend: the value depends on which Zitadel this deployment talks to, and a hard-coded copy would be wrong on every other environment.

string
scopes
Array<string>
trust_unverified_email

TrustUnverifiedEmail is the admin’s statement that this provider’s addresses may be used to match a user even when it does not report them as verified. Stored and returned in phase 1; read by phase 2 matching.

boolean
updated_at
string
warnings

Warnings are the discovery advisories for the issuer, present only on the responses to Create and Update — the two moments the admin is looking at the form and can still act on them. A list or a get does not re-fetch the issuer.

Array<object>
object
code
string
docs_url
string
message
string
redirect_uri

RedirectURI is Zitadel’s callback, the same for every connection of every team.

string
Example generated
{
"data": {
"connections": [
{
"client_id": "example",
"created_at": "example",
"has_client_secret": true,
"id": "example",
"is_active": true,
"is_id_token_mapping": true,
"issuer": "example",
"name": "example",
"provider": "example",
"redirect_uri": "example",
"scopes": [
"example"
],
"trust_unverified_email": true,
"updated_at": "example",
"warnings": [
{
"code": "example",
"docs_url": "example",
"message": "example"
}
]
}
],
"redirect_uri": "example"
},
"meta": {
"request_id": "example",
"timestamp": "example",
"trace_id": "example"
}
}

Unauthorized

Media type application/json
object
code
string
details
error
string
meta
object
request_id
string
timestamp
string
trace_id
string
Example generated
{
"code": "example",
"details": "example",
"error": "example",
"meta": {
"request_id": "example",
"timestamp": "example",
"trace_id": "example"
}
}

Forbidden

Media type application/json
object
code
string
details
error
string
meta
object
request_id
string
timestamp
string
trace_id
string
Example generated
{
"code": "example",
"details": "example",
"error": "example",
"meta": {
"request_id": "example",
"timestamp": "example",
"trace_id": "example"
}
}

Internal Server Error

Media type application/json
object
code
string
details
error
string
meta
object
request_id
string
timestamp
string
trace_id
string
Example generated
{
"code": "example",
"details": "example",
"error": "example",
"meta": {
"request_id": "example",
"timestamp": "example",
"trace_id": "example"
}
}