Update an SSO connection
const url = 'https://api.deploybase.eu/api/v1/api/v1/team/sso/connections/example';const options = { method: 'PATCH', headers: {Authorization: '<Authorization>', 'Content-Type': 'application/json'}, body: '{"client_id":"example","client_secret":"example","is_active":true,"is_id_token_mapping":true,"issuer":"example","name":"example","scopes":["example"],"trust_unverified_email":true}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request PATCH \ --url https://api.deploybase.eu/api/v1/api/v1/team/sso/connections/example \ --header 'Authorization: <Authorization>' \ --header 'Content-Type: application/json' \ --data '{ "client_id": "example", "client_secret": "example", "is_active": true, "is_id_token_mapping": true, "issuer": "example", "name": "example", "scopes": [ "example" ], "trust_unverified_email": true }'Partial update: an omitted field is left alone. Omit client_secret to keep the stored one — an empty string is refused rather than saved. Changing the issuer re-runs discovery; changing anything else does not, so a rename cannot fail because the provider is briefly unreachable. Setting is_active toggles whether the provider appears on the sign-in screen. Team admin or owner.
Authorizations
Section titled “ Authorizations ”Parameters
Section titled “ Parameters ”Path Parameters
Section titled “ Path Parameters ”Connection UUID
Request Body
Section titled “ Request Body ”Fields to change; omit a field to leave it alone
object
TrustUnverifiedEmail is a pointer like the rest: omitted leaves the stored decision alone, false withdraws it.
Example generated
{ "client_id": "example", "client_secret": "example", "is_active": true, "is_id_token_mapping": true, "issuer": "example", "name": "example", "scopes": [ "example" ], "trust_unverified_email": true}Responses
Section titled “ Responses ”OK
object
object
object
RedirectURI is the callback the admin must register in their own IdP. It is Zitadel’s, not ours, and it is the same for every connection — which is exactly why it rides on every view instead of living in the frontend: the value depends on which Zitadel this deployment talks to, and a hard-coded copy would be wrong on every other environment.
TrustUnverifiedEmail is the admin’s statement that this provider’s addresses may be used to match a user even when it does not report them as verified. Stored and returned in phase 1; read by phase 2 matching.
Warnings are the discovery advisories for the issuer, present only on the responses to Create and Update — the two moments the admin is looking at the form and can still act on them. A list or a get does not re-fetch the issuer.
object
Example generated
{ "data": { "client_id": "example", "created_at": "example", "has_client_secret": true, "id": "example", "is_active": true, "is_id_token_mapping": true, "issuer": "example", "name": "example", "provider": "example", "redirect_uri": "example", "scopes": [ "example" ], "trust_unverified_email": true, "updated_at": "example", "warnings": [ { "code": "example", "docs_url": "example", "message": "example" } ] }, "meta": { "request_id": "example", "timestamp": "example", "trace_id": "example" }}Bad Request
object
object
Example generated
{ "code": "example", "details": "example", "error": "example", "meta": { "request_id": "example", "timestamp": "example", "trace_id": "example" }}Unauthorized
object
object
Example generated
{ "code": "example", "details": "example", "error": "example", "meta": { "request_id": "example", "timestamp": "example", "trace_id": "example" }}Forbidden
object
object
Example generated
{ "code": "example", "details": "example", "error": "example", "meta": { "request_id": "example", "timestamp": "example", "trace_id": "example" }}Not Found
object
object
Example generated
{ "code": "example", "details": "example", "error": "example", "meta": { "request_id": "example", "timestamp": "example", "trace_id": "example" }}INVALID_INPUT, SSO_ISSUER_INVALID, SSO_ISSUER_UNREACHABLE, SSO_ISSUER_MISMATCH or SSO_DISCOVERY_INCOMPLETE
object
object
Example generated
{ "code": "example", "details": "example", "error": "example", "meta": { "request_id": "example", "timestamp": "example", "trace_id": "example" }}SSO_PROVIDER_ERROR
object
object
Example generated
{ "code": "example", "details": "example", "error": "example", "meta": { "request_id": "example", "timestamp": "example", "trace_id": "example" }}SSO_NOT_CONFIGURED
object
object
Example generated
{ "code": "example", "details": "example", "error": "example", "meta": { "request_id": "example", "timestamp": "example", "trace_id": "example" }}