Skip to content
Docs

Providers

Providers

List providers
zones.providers.list(strzone_id, ProviderListParams**kwargs) -> ProviderListResponse
GET/zones/{zoneId}/providers
Create provider
zones.providers.create(strzone_id, ProviderCreateParams**kwargs) -> Provider
POST/zones/{zoneId}/providers
Get provider
zones.providers.retrieve(strid, ProviderRetrieveParams**kwargs) -> Provider
GET/zones/{zoneId}/providers/{id}
Update provider
zones.providers.update(strid, ProviderUpdateParams**kwargs) -> Provider
PATCH/zones/{zoneId}/providers/{id}
Delete provider
zones.providers.delete(strid, ProviderDeleteParams**kwargs)
DELETE/zones/{zoneId}/providers/{id}
Validate provider connection
zones.providers.validate(strid, ProviderValidateParams**kwargs) -> ValidationResult
POST/zones/{zoneId}/providers/{id}/validate
ModelsExpand Collapse
class Provider:

A Provider is a system that supplies access to Resources and allows actors (Users or Applications) to authenticate.

id: str

Unique identifier of the provider

created_at: datetime

Entity creation timestamp

formatdate-time
identifier: str

User specified identifier, unique within the zone

minLength1
maxLength2048
name: str

Human-readable name

minLength1
maxLength255
organization_id: str

Organization that owns this provider

owner_type: Literal["platform", "customer"]

Who owns this provider. Platform-owned providers cannot be modified via API.

Accepts one of the following:
"platform"
"customer"
slug: str

URL-safe identifier, unique within the zone

minLength1
maxLength63
updated_at: datetime

Entity update timestamp

formatdate-time
zone_id: str

Zone this provider belongs to

client_id: Optional[str]

OAuth 2.0 client identifier

client_secret_set: Optional[bool]

Indicates whether a client secret is configured

description: Optional[str]

Human-readable description

maxLength2048
metadata: Optional[Metadata]

Provider metadata

icon_url: Optional[str]

Icon URL

formaturi
maxLength2048
protocols: Optional[Protocols]

Protocol-specific configuration

oauth2: Optional[ProtocolsOauth2]

OAuth 2.0 protocol configuration

issuer: str

OIDC issuer URL used for discovery and token validation.

formaturi
authorization_endpoint: Optional[str]
formaturi
authorization_parameters: Optional[Dict[str, str]]

Custom query parameters appended to authorization redirect URLs. Use for non-standard providers (e.g. Google prompt=consent, access_type=offline).

authorization_resource_enabled: Optional[bool]

Whether to include the resource parameter in authorization requests.

authorization_resource_parameter: Optional[str]

The resource parameter value to include in authorization requests. Defaults to "resource" when authorization_resource_enabled is true.

code_challenge_methods_supported: Optional[List[str]]
jwks_uri: Optional[str]
formaturi
registration_endpoint: Optional[str]
formaturi
scope_parameter: Optional[str]

The query parameter name for scopes in authorization requests. Defaults to "scope". Slack v2 uses "user_scope".

scope_separator: Optional[str]

The separator character for scope values. Defaults to " " (space). Slack v2 uses ",".

scopes_supported: Optional[List[str]]
token_endpoint: Optional[str]
formaturi
token_response_access_token_pointer: Optional[str]

Dot-separated path to the access token in the token response body. Defaults to "access_token". Slack v2 uses "authed_user.access_token".

openid: Optional[ProtocolsOpenid]

OpenID Connect protocol configuration

external_id_claim: Optional[str]

Name of the OIDC claim carrying the stable external id used to correlate logins with externally provisioned (SCIM) users. Defaults to "sub". Set to "oid" for Entra, whose pairwise "sub" differs from the SCIM externalId.

scopes: Optional[List[str]]

Additional OIDC scopes to request from this provider during authentication (e.g. "groups"). Merged with the default scopes (openid, profile, email).

single_logout_enabled: Optional[bool]

When true, logging out of the zone propagates the logout to this provider's end_session_endpoint (RP-initiated logout). Defaults to false.

user_identifier_claim: Optional[str]

Name of a top-level string claim in this provider's ID Token to use as the user identifier on user creation. When not set, the user's Keycard ID is used.

userinfo_endpoint: Optional[str]
formaturi
type: Optional[Literal["external", "keycard-vault", "keycard-sts"]]
Accepts one of the following:
"external"
"keycard-vault"
"keycard-sts"
class ValidationResult:

Result of running the provider OIDC connection checks on demand. Not persisted.

checks: List[Check]

Per-check results, in execution order

check: Literal["issuer_reachability", "metadata_retrieval", "endpoint_consistency", 2 more]

Identifier of an individual provider validation check

Accepts one of the following:
"issuer_reachability"
"metadata_retrieval"
"endpoint_consistency"
"authorization_endpoint_reachability"
"credential_exchange"
status: Literal["pass", "fail", "skipped_with_reason", "not_applicable"]

Outcome of a single check. pass/fail mean the check ran. skipped_with_reason means it could not run because a prerequisite is missing on our side (e.g. no credential stored). not_applicable means the check does not apply to this provider class (e.g. a login-flow-only provider that does not advertise the client_credentials grant) — render as a neutral state, distinct from a failure. Neither skipped_with_reason nor not_applicable fails the overall run.

Accepts one of the following:
"pass"
"fail"
"skipped_with_reason"
"not_applicable"
detail: Optional[str]

Human-readable explanation, present on fail, skipped_with_reason, and not_applicable.

provider_id: str

Provider that was validated

status: Literal["pass", "fail"]

Overall outcome. fail when any individual check failed; skipped checks do not fail the run.

Accepts one of the following:
"pass"
"fail"
validated_at: datetime

When the validation run completed

formatdate-time