Providers
Providers
List providers
Create provider
Get provider
Update provider
Delete provider
Validate provider connection
ModelsExpand Collapse
Provider = object { id, created_at, identifier, 12 more } A Provider is a system that supplies access to Resources and allows actors (Users or Applications) to authenticate.
A Provider is a system that supplies access to Resources and allows actors (Users or Applications) to authenticate.
Unique identifier of the provider
Entity creation timestamp
User specified identifier, unique within the zone
Human-readable name
Organization that owns this provider
owner_type: "platform" or "customer"Who owns this provider. Platform-owned providers cannot be modified via API.
Who owns this provider. Platform-owned providers cannot be modified via API.
URL-safe identifier, unique within the zone
Entity update timestamp
Zone this provider belongs to
OAuth 2.0 client identifier
Indicates whether a client secret is configured
Human-readable description
metadata: optional object { icon_url } Provider metadata
Provider metadata
Icon URL
protocols: optional object { oauth2, openid } Protocol-specific configuration
Protocol-specific configuration
oauth2: optional object { issuer, authorization_endpoint, authorization_parameters, 10 more } OAuth 2.0 protocol configuration
OAuth 2.0 protocol configuration
OIDC issuer URL used for discovery and token validation.
Custom query parameters appended to authorization redirect URLs. Use for non-standard providers (e.g. Google prompt=consent, access_type=offline).
Whether to include the resource parameter in authorization requests.
The resource parameter value to include in authorization requests. Defaults to "resource" when authorization_resource_enabled is true.
The query parameter name for scopes in authorization requests. Defaults to "scope". Slack v2 uses "user_scope".
The separator character for scope values. Defaults to " " (space). Slack v2 uses ",".
Dot-separated path to the access token in the token response body. Defaults to "access_token". Slack v2 uses "authed_user.access_token".
openid: optional object { external_id_claim, scopes, single_logout_enabled, 2 more } OpenID Connect protocol configuration
OpenID Connect protocol configuration
Name of the OIDC claim carrying the stable external id used to correlate logins with externally provisioned (SCIM) users. Defaults to "sub". Set to "oid" for Entra, whose pairwise "sub" differs from the SCIM externalId.
Additional OIDC scopes to request from this provider during authentication (e.g. "groups"). Merged with the default scopes (openid, profile, email).
When true, logging out of the zone propagates the logout to this provider's end_session_endpoint (RP-initiated logout). Defaults to false.
Name of a top-level string claim in this provider's ID Token to use as the user identifier on user creation. When not set, the user's Keycard ID is used.
type: optional "external" or "keycard-vault" or "keycard-sts"
ValidationResult = object { checks, provider_id, status, validated_at } Result of running the provider OIDC connection checks on demand. Not persisted.
Result of running the provider OIDC connection checks on demand. Not persisted.
checks: array of object { check, status, detail } Per-check results, in execution order
Per-check results, in execution order
check: "issuer_reachability" or "metadata_retrieval" or "endpoint_consistency" or 2 moreIdentifier of an individual provider validation check
Identifier of an individual provider validation check
status: "pass" or "fail" or "skipped_with_reason" or "not_applicable"Outcome of a single check. pass/fail mean the check ran. skipped_with_reason means it could not run because a prerequisite is missing on our side (e.g. no credential stored). not_applicable means the check does not apply to this provider class (e.g. a login-flow-only provider that does not advertise the client_credentials grant) — render as a neutral state, distinct from a failure. Neither skipped_with_reason nor not_applicable fails the overall run.
Outcome of a single check. pass/fail mean the check ran. skipped_with_reason means it could not run because a prerequisite is missing on our side (e.g. no credential stored). not_applicable means the check does not apply to this provider class (e.g. a login-flow-only provider that does not advertise the client_credentials grant) — render as a neutral state, distinct from a failure. Neither skipped_with_reason nor not_applicable fails the overall run.
Human-readable explanation, present on fail, skipped_with_reason, and not_applicable.
Provider that was validated
status: "pass" or "fail"Overall outcome. fail when any individual check failed; skipped checks do not fail the run.
Overall outcome. fail when any individual check failed; skipped checks do not fail the run.
When the validation run completed