Kong Auth Settings API

The Auth Settings API from Kong — 8 operation(s) for auth settings.

Operations 17

GET /v3/authentication-settings Get Auth Settings #
PATCH /v3/authentication-settings Update Auth Settings #
GET /v3/identity-provider Get the IdP Configuration #
PATCH /v3/identity-provider Update IdP Configuration #
GET /v3/identity-provider/team-group-mappings Get a Team Group Mappings #
PATCH /v3/identity-provider/team-group-mappings Patch Mappings by Team ID #
PUT /v3/identity-provider/team-mappings Update Team Mappings #
GET /v3/identity-provider/team-mappings Get a Team Mapping #
GET /v3/identity-providers List Identity Providers #
POST /v3/identity-providers Create Identity Provider #
GET /v3/identity-providers/{id} Get Identity Provider #
PATCH /v3/identity-providers/{id} Update Identity Provider #
DELETE /v3/identity-providers/{id} Delete Identity Provider #
GET /v3/identity-providers/{idpId}/team-group-mappings List Team Group Mappings #
POST /v3/identity-providers/{idpId}/team-group-mappings Create Team Group Mapping #
GET /v3/identity-providers/{idpId}/team-group-mappings/{id} Get Team Group Mapping #
DELETE /v3/identity-providers/{idpId}/team-group-mappings/{id} Delete Team Group Mapping #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/kong-auth-settings-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

kong-auth-settings-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Konnect API - Go SDK Auth Settings API
  version: 3.14.0
  description: The Konnect platform API
  contact:
    name: Kong Inc
    url: https://konghq.com
    email: support@konghq.com
  x-extensions-note: "This API uses the `x-expression` vendor extension to indicate that a string property is a DSL expression.\nSupported types:\n\n\n  - `boolean`: An expression evaluates to boolean. For example, `context.topic.name == 'my-topic'`\n  - `string`: A template string expression that evaluates to a string or a literal string value. For example,\n    `${context.topic.name.substring(0, context.topic.name.length-4)}` or `my-literal-value`\n\nAdditionally, `x-sensitive` flag indicates that a field contains sensitive information. When the value\nof the field is provided in plain text, it's encrypted at rest and it's never returned in API responses.\nWhen the value is an expression, the expression itself is stored and returned in API responses.\n\n`x-min-runtime-version` indicates the minimum Event Gateway runtime version required to use a certain policy or\npolicy feature. The runtime version can be configured at the Event Gateway entity level. It must be a string\ncontaining a semantic version in the `MAJOR.MINOR` format, e.g., `\"1.1\"`.\n"
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
  x-oas-source: kong/platform-api@
  x-oas-source-link: https://github.com/Kong/platform-api/commit/
servers:
- url: https://global.api.konghq.com
- url: https://us.api.konghq.com
- url: https://eu.api.konghq.com
- url: https://au.api.konghq.com
security:
- personalAccessToken: []
- systemAccountAccessToken: []
- konnectAccessToken: []
- serviceAccessToken: []
tags:
- name: Auth Settings
paths:
  /v3/authentication-settings:
    get:
      x-speakeasy-entity-operation:
        terraform-resource: AuthenticationSettings#read
        terraform-datasource: null
      operationId: get-authentication-settings
      summary: Get Auth Settings
      description: Returns authentication configuration, which determines how users can log in and how they are assigned to teams.
      responses:
        '200':
          $ref: '#/components/responses/AuthenticationSettings'
        '401':
          $ref: '#/components/responses/IdentityUnauthenticated'
      servers:
      - url: https://global.api.konghq.com/
      tags:
      - Auth Settings
    patch:
      x-speakeasy-entity-operation: AuthenticationSettings#create,update
      operationId: update-authentication-settings
      summary: Update Auth Settings
      description: Updates authentication configuration.
      requestBody:
        $ref: '#/components/requestBodies/UpdateAuthenticationSettings'
      responses:
        '200':
          $ref: '#/components/responses/AuthenticationSettings'
        '400':
          $ref: '#/components/responses/IdentityBadRequest'
        '401':
          $ref: '#/components/responses/IdentityUnauthenticated'
        '403':
          $ref: '#/components/responses/Unauthorized'
      servers:
      - url: https://global.api.konghq.com/
      tags:
      - Auth Settings
  /v3/identity-provider:
    get:
      operationId: get-idp-configuration
      summary: Get the IdP Configuration
      description: Fetch the IdP configuration.
      responses:
        '200':
          $ref: '#/components/responses/IdPConfiguration'
        '400':
          $ref: '#/components/responses/IdentityBadRequest'
        '401':
          $ref: '#/components/responses/IdentityUnauthenticated'
        '403':
          $ref: '#/components/responses/IdentityPermissionDenied'
        '404':
          $ref: '#/components/responses/IdentityNotFound'
      servers:
      - url: https://global.api.konghq.com/
      tags:
      - Auth Settings
    patch:
      operationId: update-idp-configuration
      summary: Update IdP Configuration
      description: Update the IdP configuration.
      requestBody:
        $ref: '#/components/requestBodies/UpdateIdPConfiguration'
      responses:
        '200':
          $ref: '#/components/responses/IdPConfiguration'
        '400':
          $ref: '#/components/responses/IdentityBadRequest'
        '401':
          $ref: '#/components/responses/IdentityUnauthenticated'
        '403':
          $ref: '#/components/responses/Unauthorized'
      servers:
      - url: https://global.api.konghq.com/
      tags:
      - Auth Settings
  /v3/identity-provider/team-group-mappings:
    get:
      operationId: get-team-group-mappings
      summary: Get a Team Group Mappings
      description: 'Retrieves the mappings between Konnect Teams and Identity Provider Groups.

        Returns a 400 error if an Identity Provider has not yet been configured.'
      parameters:
      - $ref: '#/components/parameters/PageSize'
      - $ref: '#/components/parameters/PageNumber'
      responses:
        '200':
          $ref: '#/components/responses/TeamGroupMappingCollection'
        '400':
          $ref: '#/components/responses/IdentityBadRequest'
        '401':
          $ref: '#/components/responses/IdentityUnauthenticated'
        '403':
          $ref: '#/components/responses/IdentityPermissionDenied'
      servers:
      - url: https://global.api.konghq.com/
      tags:
      - Auth Settings
    patch:
      operationId: patch-team-group-mappings
      summary: Patch Mappings by Team ID
      description: 'Allows partial updates to the mappings between Konnect Teams and Identity Provider Groups.

        The request body must be keyed on team ID. For a given team ID, the given group list is a

        complete replacement. To remove all mappings for a given team, provide an empty group list.


        Returns a 400 error if an Identity Provider has not yet been configured, or if a team ID in

        the request body is not found or is not a UUID.'
      requestBody:
        $ref: '#/components/requestBodies/PatchTeamGroupMappings'
      responses:
        '200':
          $ref: '#/components/responses/TeamGroupMappingCollection'
        '400':
          $ref: '#/components/responses/IdentityBadRequest'
        '401':
          $ref: '#/components/responses/IdentityUnauthenticated'
        '403':
          $ref: '#/components/responses/IdentityPermissionDenied'
      servers:
      - url: https://global.api.konghq.com/
      tags:
      - Auth Settings
  /v3/identity-provider/team-mappings:
    put:
      operationId: update-idp-team-mappings
      summary: Update Team Mappings
      description: Updates the IdP group to Konnect team mapping.
      requestBody:
        $ref: '#/components/requestBodies/UpdateTeamMappings'
      responses:
        '200':
          $ref: '#/components/responses/TeamMappingCollection'
        '400':
          $ref: '#/components/responses/IdentityBadRequest'
        '401':
          $ref: '#/components/responses/IdentityPermissionDenied'
        '404':
          $ref: '#/components/responses/IdentityNotFound'
        '412':
          $ref: '#/components/responses/PreconditionFailed'
      servers:
      - url: https://global.api.konghq.com/
      tags:
      - Auth Settings
    get:
      operationId: get-idp-team-mappings
      summary: Get a Team Mapping
      description: Fetch the IdP group to Konnect team mapping.
      parameters:
      - $ref: '#/components/parameters/PageSize'
      - $ref: '#/components/parameters/PageNumber'
      responses:
        '200':
          $ref: '#/components/responses/TeamMappingResponse'
        '401':
          $ref: '#/components/responses/IdentityUnauthenticated'
        '403':
          $ref: '#/components/responses/IdentityPermissionDenied'
        '404':
          $ref: '#/components/responses/IdentityNotFound'
        '412':
          $ref: '#/components/responses/PreconditionFailed'
      servers:
      - url: https://global.api.konghq.com/
      tags:
      - Auth Settings
  /v3/identity-providers:
    get:
      operationId: get-identity-providers
      summary: List Identity Providers
      description: 'Retrieves the identity providers available within the organization. This operation provides information about

        various identity providers for SAML or OIDC authentication integrations.

        '
      parameters:
      - name: filter
        in: query
        description: Filter identity providers returned in the response.
        required: false
        schema:
          type: object
          properties:
            type:
              $ref: '#/components/schemas/StringFieldEqualsFilter'
        style: deepObject
      responses:
        '200':
          $ref: '#/components/responses/IdentityProviders'
        '401':
          $ref: '#/components/responses/IdentityUnauthenticated'
        '403':
          $ref: '#/components/responses/IdentityPermissionDenied'
      servers:
      - url: https://global.api.konghq.com/
      tags:
      - Auth Settings
    post:
      x-speakeasy-entity-operation: IdentityProvider#create
      operationId: create-identity-provider
      summary: Create Identity Provider
      description: 'Creates a new identity provider. This operation allows the creation of a new identity provider for

        authentication purposes.

        '
      requestBody:
        $ref: '#/components/requestBodies/CreateIdentityProviderRequest'
      responses:
        '201':
          $ref: '#/components/responses/IdentityProvider'
        '400':
          $ref: '#/components/responses/IdentityBadRequest'
        '401':
          $ref: '#/components/responses/IdentityUnauthenticated'
        '403':
          $ref: '#/components/responses/CreateIdentityProviderPermissionDenied'
        '409':
          $ref: '#/components/responses/Conflict'
      servers:
      - url: https://global.api.konghq.com/
      tags:
      - Auth Settings
  /v3/identity-providers/{id}:
    parameters:
    - name: id
      in: path
      description: ID of the identity provider.
      required: true
      schema:
        type: string
        format: uuid
        example: d32d905a-ed33-46a3-a093-d8f536af9a8a
    get:
      x-speakeasy-entity-operation:
        terraform-resource: IdentityProvider#read
        terraform-datasource: null
      operationId: get-identity-provider
      summary: Get Identity Provider
      description: 'Retrieves the configuration of a single identity provider. This operation returns information about a

        specific identity provider''s settings and authentication integration details.

        '
      responses:
        '200':
          $ref: '#/components/responses/IdentityProvider'
        '400':
          $ref: '#/components/responses/IdentityBadRequest'
        '401':
          $ref: '#/components/responses/IdentityUnauthenticated'
        '403':
          $ref: '#/components/responses/IdentityPermissionDenied'
        '404':
          $ref: '#/components/responses/IdentityNotFound'
      servers:
      - url: https://global.api.konghq.com/
      tags:
      - Auth Settings
    patch:
      x-speakeasy-entity-operation: IdentityProvider#update
      operationId: update-identity-provider
      summary: Update Identity Provider
      description: 'Updates the configuration of an existing identity provider. This operation allows modifications to be made

        to an existing identity provider''s configuration.

        '
      requestBody:
        $ref: '#/components/requestBodies/UpdateIdentityProviderRequest'
      responses:
        '200':
          $ref: '#/components/responses/IdentityProvider'
        '400':
          $ref: '#/components/responses/IdentityBadRequest'
        '401':
          $ref: '#/components/responses/IdentityUnauthenticated'
        '403':
          $ref: '#/components/responses/IdentityPermissionDenied'
        '404':
          $ref: '#/components/responses/IdentityNotFound'
        '409':
          $ref: '#/components/responses/Conflict'
      servers:
      - url: https://global.api.konghq.com/
      tags:
      - Auth Settings
    delete:
      x-speakeasy-entity-operation: IdentityProvider#delete
      operationId: delete-identity-provider
      summary: Delete Identity Provider
      description: 'Deletes an existing identity provider configuration. This operation removes a specific identity provider

        from the organization.

        '
      responses:
        '204':
          description: No Content
        '400':
          $ref: '#/components/responses/IdentityBadRequest'
        '401':
          $ref: '#/components/responses/IdentityUnauthenticated'
        '403':
          $ref: '#/components/responses/IdentityPermissionDenied'
        '404':
          $ref: '#/components/responses/IdentityNotFound'
      servers:
      - url: https://global.api.konghq.com/
      tags:
      - Auth Settings
  /v3/identity-providers/{idpId}/team-group-mappings:
    parameters:
    - name: idpId
      in: path
      description: ID of the identity provider.
      required: true
      schema:
        type: string
        format: uuid
        example: d32d905a-ed33-46a3-a093-d8f536af9a8a
    get:
      operationId: list-idp-team-group-mappings
      summary: List Team Group Mappings
      description: 'Returns a paginated list of team group mappings for the specified identity provider.

        Mappings define the relationship between identity provider groups and Konnect teams.

        '
      parameters:
      - $ref: '#/components/parameters/PageSize'
      - $ref: '#/components/parameters/PageAfter'
      - $ref: '#/components/parameters/PageBefore'
      - name: filter
        in: query
        description: Filter mappings by team ID or group name.
        required: false
        schema:
          type: object
          properties:
            team_id:
              $ref: '#/components/schemas/StringFieldEqualsFilter'
            group:
              $ref: '#/components/schemas/StringFieldEqualsFilter'
        style: deepObject
      responses:
        '200':
          $ref: '#/components/responses/IdpTeamGroupMappingsCollection'
        '400':
          $ref: '#/components/responses/IdentityBadRequest'
        '401':
          $ref: '#/components/responses/IdentityUnauthenticated'
        '403':
          $ref: '#/components/responses/IdentityPermissionDenied'
        '404':
          $ref: '#/components/responses/IdentityNotFound'
      servers:
      - url: https://global.api.konghq.com/
      tags:
      - Auth Settings
    post:
      x-speakeasy-entity-operation:
        terraform-resource: IdentityProviderTeamGroupMapping#create
        terraform-datasource: null
      operationId: create-idp-team-group-mapping
      summary: Create Team Group Mapping
      description: 'Creates a new team group mapping for the specified identity provider.

        A mapping associates an identity provider group with a Konnect team.

        '
      requestBody:
        $ref: '#/components/requestBodies/CreateIdpTeamGroupMappingRequest'
      responses:
        '201':
          $ref: '#/components/responses/IdpTeamGroupMapping'
        '400':
          $ref: '#/components/responses/IdentityBadRequest'
        '401':
          $ref: '#/components/responses/IdentityUnauthenticated'
        '403':
          $ref: '#/components/responses/IdentityPermissionDenied'
        '404':
          $ref: '#/components/responses/IdentityNotFound'
        '409':
          $ref: '#/components/responses/Conflict'
      servers:
      - url: https://global.api.konghq.com/
      tags:
      - Auth Settings
  /v3/identity-providers/{idpId}/team-group-mappings/{id}:
    parameters:
    - name: idpId
      in: path
      description: ID of the identity provider.
      required: true
      schema:
        type: string
        format: uuid
        example: d32d905a-ed33-46a3-a093-d8f536af9a8a
    - name: id
      in: path
      description: ID of the team group mapping.
      required: true
      schema:
        type: string
        format: uuid
        example: 7f9fd312-a987-4628-b4c5-bb4f4fddd5f7
    get:
      x-speakeasy-entity-operation:
        terraform-resource: IdentityProviderTeamGroupMapping#read
        terraform-datasource: null
      operationId: get-idp-team-group-mapping
      summary: Get Team Group Mapping
      description: Returns the team group mapping for the specified ID.
      responses:
        '200':
          $ref: '#/components/responses/IdpTeamGroupMapping'
        '400':
          $ref: '#/components/responses/IdentityBadRequest'
        '401':
          $ref: '#/components/responses/IdentityUnauthenticated'
        '403':
          $ref: '#/components/responses/IdentityPermissionDenied'
        '404':
          $ref: '#/components/responses/IdentityNotFound'
      servers:
      - url: https://global.api.konghq.com/
      tags:
      - Auth Settings
    delete:
      x-speakeasy-entity-operation:
        terraform-resource: IdentityProviderTeamGroupMapping#delete
        terraform-datasource: null
      operationId: delete-idp-team-group-mapping
      summary: Delete Team Group Mapping
      description: 'Deletes a team group mapping by ID.

        Returns 204 if the mapping was deleted, or 404 if the mapping was not found.

        '
      responses:
        '204':
          description: No Content
        '400':
          $ref: '#/components/responses/IdentityBadRequest'
        '401':
          $ref: '#/components/responses/IdentityUnauthenticated'
        '403':
          $ref: '#/components/responses/IdentityPermissionDenied'
        '404':
          $ref: '#/components/responses/IdentityNotFound'
      servers:
      - url: https://global.api.konghq.com/
      tags:
      - Auth Settings
components:
  schemas:
    IdentityProviderLoginPath:
      description: The path used for initiating login requests with the identity provider.
      type: string
      example: myapp
      title: Identity Provider Login Path Property
    BadRequestError:
      allOf:
      - $ref: '#/components/schemas/BaseError'
      - type: object
        required:
        - invalid_parameters
        properties:
          invalid_parameters:
            $ref: '#/components/schemas/InvalidParameters'
    OIDCIdentityProviderConfig:
      description: The identity provider that contains configuration data for the OIDC authentication integration.
      type: object
      properties:
        issuer_url:
          $ref: '#/components/schemas/OIDCIdentityProviderIssuer'
        client_id:
          $ref: '#/components/schemas/OIDCIdentityProviderClientId'
        client_secret:
          $ref: '#/components/schemas/OIDCIdentityProviderClientSecret'
        scopes:
          $ref: '#/components/schemas/OIDCIdentityProviderScopes'
        claim_mappings:
          $ref: '#/components/schemas/OIDCIdentityProviderClaimMappings'
      additionalProperties: false
      required:
      - issuer_url
      - client_id
      title: OIDC Identity Provider Config
    InvalidParameterMinimumLength:
      type: object
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          description: invalid parameters rules
          type: string
          enum:
          - min_length
          - min_digits
          - min_lowercase
          - min_uppercase
          - min_symbols
          - min_items
          - min
          nullable: false
          readOnly: true
          x-speakeasy-unknown-values: allow
        minimum:
          type: integer
          example: 8
        source:
          type: string
          example: body
        reason:
          type: string
          example: must have at least 8 characters
          readOnly: true
      additionalProperties: false
      required:
      - field
      - reason
      - rule
      - minimum
    BaseError:
      description: standard error
      type: object
      properties:
        status:
          description: 'The HTTP status code of the error. Useful when passing the response

            body to child properties in a frontend UI. Must be returned as an integer.

            '
          type: integer
          readOnly: true
        title:
          description: 'A short, human-readable summary of the problem. It should not

            change between occurences of a problem, except for localization.

            Should be provided as "Sentence case" for direct use in the UI.

            '
          type: string
          readOnly: true
        type:
          description: The error type.
          type: string
          readOnly: true
        instance:
          description: 'Used to return the correlation ID back to the user, in the format

            kong:trace:<correlation_id>. This helps us find the relevant logs

            when a customer reports an issue.

            '
          type: string
          readOnly: true
        detail:
          description: 'A human readable explanation specific to this occurence of the problem.

            This field may contain request/entity data to help the user understand

            what went wrong. Enclose variable values in square brackets. Should be

            provided as "Sentence case" for direct use in the UI.

            '
          type: string
          readOnly: true
      required:
      - status
      - title
      - instance
      - detail
      title: Error
    UpdatedAt:
      description: An ISO-8601 timestamp representation of entity update date.
      type: string
      format: date-time
      example: '2022-11-04T20:10:06.927Z'
      readOnly: true
      x-speakeasy-param-suppress-computed-diff: true
    CreatedAt:
      description: An ISO-8601 timestamp representation of entity creation date.
      type: string
      format: date-time
      example: '2022-11-04T20:10:06.927Z'
      readOnly: true
      x-speakeasy-param-suppress-computed-diff: true
    OIDCIdentityProviderIssuer:
      description: The issuer URI of the identity provider. This is the URL where the provider's metadata can be obtained.
      type: string
      format: uri
      example: https://konghq.okta.com/oauth2/default
      title: OIDC Identity Provider Issuer Property
    UUID:
      description: Contains a unique identifier used for this resource.
      type: string
      format: uuid
      example: 5f9fd312-a987-4628-b4c5-bb4f4fddd5f7
      readOnly: true
    PaginatedMeta:
      description: returns the pagination information
      type: object
      properties:
        page:
          $ref: '#/components/schemas/PageMeta'
      required:
      - page
      title: PaginatedMeta
      x-speakeasy-terraform-ignore: true
    CursorMetaPage:
      type: object
      properties:
        first:
          description: URI to the first page
          type: string
          format: path
        last:
          description: URI to the last page
          type: string
          format: path
        next:
          description: URI to the next page
          type: string
          format: path
          nullable: true
        previous:
          description: URI to the previous page
          type: string
          format: path
          nullable: true
        size:
          description: Requested page size
          type: number
          example: 10
      required:
      - size
      - next
      - previous
    OIDCIdentityProviderClaimMappings:
      description: "Defines the mappings between OpenID Connect (OIDC) claims and local claims used by your application for \nauthentication.\n"
      type: object
      properties:
        name:
          description: The claim mapping for the user's name.
          type: string
          example: name
          default: name
        email:
          description: The claim mapping for the user's email address.
          type: string
          example: email
          default: email
        groups:
          description: The claim mapping for the user's group membership information.
          type: string
          example: groups
          default: groups
      title: OIDC Claim Mappings
    SAMLIdentityProviderConfig:
      description: The identity provider that contains configuration data for the SAML authentication integration.
      type: object
      properties:
        idp_metadata_url:
          $ref: '#/components/schemas/SAMLIdentityProviderMetadataURL'
        idp_metadata_xml:
          $ref: '#/components/schemas/SAMLIdentityProviderMetadata'
        sp_metadata_url:
          type: string
          format: path
          example: /api/v2/developer/authenticate/saml/metadata
          readOnly: true
        sp_entity_id:
          description: The entity ID of the service provider (SP).
          type: string
          example: https://cloud.konghq.com/sp/00000000-0000-0000-0000-000000000000
          readOnly: true
        login_url:
          description: The URL to redirect users to for initiating login with the identity provider.
          type: string
          example: https://cloud.konghq.com/login/the-saml-konnect-org
          readOnly: true
        callback_url:
          description: The path URL where the SAML identity provider sends authentication responses after successful login attempts.
          type: string
          format: path
          example: /api/v2/developer/authenticate/saml/acs
          readOnly: true
      additionalProperties: false
      title: SAML Identity Provider Config
    UnauthorizedError:
      allOf:
      - $ref: '#/components/schemas/BaseError'
      - type: object
        properties:
          status:
            example: 401
          title:
            example: Unauthorized
          type:
            example: https://httpstatuses.com/401
          instance:
            example: kong:trace:1234567890
          detail:
            example: Invalid credentials
    NotFoundError:
      allOf:
      - $ref: '#/components/schemas/BaseError'
      - type: object
        properties:
          status:
            example: 404
          title:
            example: Not Found
          type:
            example: https://httpstatuses.com/404
          instance:
            example: kong:trace:1234567890
          detail:
            example: Not found
    IdpTeamGroupMapping:
      description: A mapping between a Konnect team and an identity provider group.
      type: object
      properties:
        id:
          $ref: '#/components/schemas/UUID'
        team_id:
          description: The Konnect team ID.
          type: string
          format: uuid
          example: 6801e673-cc10-498a-94cd-4271de07a0d3
        group:
          description: The identity provider group name. Group names are case sensitive.
          type: string
          example: Tech Leads
        created_at:
          $ref: '#/components/schemas/CreatedAt'
        updated_at:
          $ref: '#/components/schemas/UpdatedAt'
      required:
      - id
      - team_id
      - group
      - created_at
      - updated_at
      title: IdpTeamGroupMapping
    IdentityProviderType:
      description: Specifies the type of identity provider.
      type: string
      example: oidc
      enum:
      - oidc
      - saml
      x-speakeasy-unknown-values: allow
    IdentityProviderEnabled:
      description: 'Indicates whether the identity provider is enabled.

        Only one identity provider can be active at a time, such as SAML or OIDC.

        '
      type: boolean
      example: true
      default: false
      title: Identity Provider Enabled Property
    InvalidParameterMaximumLength:
      type: object
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          description: invalid parameters rules
          type: string
          enum:
          - max_length
          - max_items
          - max
          nullable: false
          readOnly: true
          x-speakeasy-unknown-values: allow
        maximum:
          type: integer
          example: 8
        source:
          type: string
          example: body
        reason:
          type: string
          example: must not have more than 8 characters
          readOnly: true
      additionalProperties: false
      required:
      - field
      - reason
      - rule
      - maximum
    InvalidParameterStandard:
      type: object
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          $ref: '#/components/schemas/InvalidRules'
        source:
          type: string
          example: body
        reason:
          type: string
          example: is a required field
          readOnly: true
      additionalProperties: false
      required:
      - field
      - reason
    PageMeta:
      description: Contains pagination query parameters and the total number of objects returned.
      type: object
      properties:
        number:
          type: number
          example: 1
          x-speakeasy-terraform-ignore: true
        size:
          type: number
          example: 10
          x-speakeasy-terraform-ignore: true
        total:
          type: number
          example: 100
          x-speakeasy-terraform-ignore: true
      required:
      - number
      - size
      - total
    OIDCIdentityProviderScopes:
      description: The scopes requested by your application when authenticating with the identity provider.
      type: array
      items:
        type: string
      default:
      - email
      - openid
      - profile
      title: OIDC Identity Provider Scopes Property
    OIDCIdentityProviderClientSecret:
      description: The Client Secret assigned to your application by the identity provider.
      type: string
      example: YOUR_CLIENT_SECRET
      title: OIDC Identity Provider Login Client Secret Property
      writeOnly: true
      x-speakeasy-param-sensitive: true
      x-speakeasy-terraform-plan-only: true
    InvalidParameterChoiceItem:
      type: object
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          description: invalid parameters rules
          type: string
          enum:
          - enum
          nullable: false
          readOnly: true
        reason:
          type: string
          example: is a required field
          readOnly: true
        choices:
          type: array
          items: {}
          minItems: 1
          nullable: false
          readOnly: true
          uniqueItems: true
        source:
          type: string
          example: body
      additionalProperties: false
      required:
      - field
      - reason
      - rule
      - choices
    TeamMapping:
      description: A team assignment is a mapping of an IdP group to a Konnect Team.
      type: object
      properties:
        group:
          description: The IdP group.
          type: string
          example: Service Developers
        team_ids:
          description: An array of ID's that are mapped to the specified group.
          type: array
          items:
            type: string
            format: uuid
            example: 6801e673-cc10-498a-94cd-4271de07a0d3
          uniqueItems: true
      example:
        group: Service Developers
        team_ids:
        - 6801e673-cc10-498a-94cd-4271de07a0d3
      title: TeamMapping
    TeamGroupMapping:
      description: A map of Konnect Team to IdP groups.
      type: object
      properties:
        team_id:
          description: The Konnect team ID.
          type: string
          format: uuid
          example: 6801e673-cc10-498a-94cd-4271de07a0d3
        groups:
          description: The IdP groups that are mapped to the specified team.
          type: array
          items:
            type: string
            example: API Engineers
          uniqueItems: true
      example:
        team_id: 6801e673-cc10-498a-94cd-4271de07a0d3
        groups:
        - Tech Leads
        - API Engineers
      title: TeamGroupMapping
    InvalidParameters:
      description: invalid parameters
      type: array
      items:
        oneOf:
        - $ref: '#/components/schemas/InvalidParameterStandard'
        - $ref: '#/components/schemas/InvalidParameterMinimumLength'
        - $ref: '#/components/schemas/InvalidParameterMaximumLength'
        - $ref: '#/components/schemas/InvalidParameterChoiceItem'
        - $ref: '#/components/schemas/InvalidParameterDependentItem'
      minItems: 1
      nullable: false
      uniqueItems: true
    SAMLIdentityProviderMetadata:
      description: 'The identity provider''s SAML metadata. If the identity provider supports a metadata URL, you can use the `idp_metadata_url` field instead.

        '
      type: string
      example: "<?xml ver

# --- truncated at 32 KB (54 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/kong/refs/heads/main/openapi/kong-auth-settings-api-openapi.yml