Label Studio Subpackage Sso.subpackage Sso/saml API

The subpackage_sso.subpackage_sso/saml API from Label Studio — 2 operation(s) for subpackage_sso.subpackage_sso/saml.

Business capability
Tenant Identity Federation BC-4230.50

Operations 4

GET /api/saml/settings ✨ Retrieve SAML2 Settings #
POST /api/saml/settings ✨ Update SAML2 Settings #
DELETE /api/saml/settings ✨ Reset SAML2 Settings #
POST /api/saml/settings/validate-metadata-url ✨ Validate SAML Metadata URL #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/label-studio-subpackage-sso-subpackage-sso-saml-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

label-studio-subpackage-sso-subpackage-sso-saml-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Reference Subpackage Sso.subpackage Sso/saml API
  version: 1.0.0
servers:
- url: http://localhost:8000
tags:
- name: subpackage_sso.subpackage_sso/saml
paths:
  /api/saml/settings:
    get:
      operationId: get
      summary: ✨ Retrieve SAML2 Settings
      description: 'This endpoint is not available in Label Studio Community Edition. Learn more about Label Studio Enterprise


        Retrieve SAML2 settings for the currently active organization.'
      tags:
      - subpackage_sso.subpackage_sso/saml
      parameters:
      - name: Authorization
        in: header
        description: 'The token (or API key) must be passed as a request header. You can find your user token on the User Account page in Label Studio. Example: <br><pre><code class="language-bash">curl https://label-studio-host/api/projects -H "Authorization: Token [your-token]"</code></pre>'
        required: true
        schema:
          type: string
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SamlSettings'
    post:
      operationId: update
      summary: ✨ Update SAML2 Settings
      description: 'This endpoint is not available in Label Studio Community Edition. Learn more about Label Studio Enterprise


        Update SAML2 settings for the currently active organization.'
      tags:
      - subpackage_sso.subpackage_sso/saml
      parameters:
      - name: Authorization
        in: header
        description: 'The token (or API key) must be passed as a request header. You can find your user token on the User Account page in Label Studio. Example: <br><pre><code class="language-bash">curl https://label-studio-host/api/projects -H "Authorization: Token [your-token]"</code></pre>'
        required: true
        schema:
          type: string
      responses:
        '201':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SamlSettingsUpdate'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SamlSettingsUpdateRequest'
    delete:
      operationId: reset
      summary: ✨ Reset SAML2 Settings
      description: 'This endpoint is not available in Label Studio Community Edition. Learn more about Label Studio Enterprise


        Reset SAML2 settings for the currently active organization. This clears all configured fields (domain, metadata, attribute mappings, group mappings) back to their defaults without deleting the underlying settings record.'
      tags:
      - subpackage_sso.subpackage_sso/saml
      parameters:
      - name: Authorization
        in: header
        description: 'The token (or API key) must be passed as a request header. You can find your user token on the User Account page in Label Studio. Example: <br><pre><code class="language-bash">curl https://label-studio-host/api/projects -H "Authorization: Token [your-token]"</code></pre>'
        required: true
        schema:
          type: string
      responses:
        '200':
          description: Successful response
  /api/saml/settings/validate-metadata-url:
    post:
      operationId: validate-metadata-url
      summary: ✨ Validate SAML Metadata URL
      description: 'This endpoint is not available in Label Studio Community Edition. Learn more about Label Studio Enterprise


        Validate a SAML metadata URL by fetching it and checking for valid XML, without saving.'
      tags:
      - subpackage_sso.subpackage_sso/saml
      parameters:
      - name: Authorization
        in: header
        description: 'The token (or API key) must be passed as a request header. You can find your user token on the User Account page in Label Studio. Example: <br><pre><code class="language-bash">curl https://label-studio-host/api/projects -H "Authorization: Token [your-token]"</code></pre>'
        required: true
        schema:
          type: string
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ValidateSamlMetadataUrlResponse'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ValidateSamlMetadataUrlRequestRequest'
components:
  schemas:
    SamlSettingsUpdate:
      type: object
      properties:
        domain:
          type: string
          description: 'Organization web domain or domains; use comma separated list with no spaces for multiple. Example:<br><br>labelstud.io,humansignal.com<br><br>IMPORTANT: DO NOT PUT COMMON DOMAINS LIKE GMAIL.COM, YAHOO.COM, ETC. IN THIS FIELD'
        idp_provider:
          type:
          - string
          - 'null'
          description: Identity Provider preset key (e.g. okta, azure, google, custom)
        manual_role_management:
          type:
          - boolean
          - 'null'
          description: Allow manually assigning organization roles instead of IdP-managed groups. None = use billing default.
        mapping_email:
          type:
          - string
          - 'null'
          description: 'Mapping attributes: user email from SAML request'
        mapping_first_name:
          type:
          - string
          - 'null'
          description: 'Mapping attributes: user first name from SAML request'
        mapping_groups:
          type:
          - string
          - 'null'
          description: 'Mapping attributes: groups attribute for user mapping to workspaces and roles'
        mapping_last_name:
          type:
          - string
          - 'null'
          description: 'Mapping attributes: user last name from SAML request'
        metadata_url:
          type: string
          description: URL SAML metadata from IdP
        metadata_xml:
          type: string
          description: Metadata XML file
        projects_groups:
          type: array
          items:
            $ref: '#/components/schemas/ProjectGroup'
          description: Projects to Groups Mapping. List of objects with project_id, group, role.
        roles_groups:
          type: array
          items:
            type: array
            items:
              type: string
          description: Organization Roles to Groups Mapping. List of [role_name, group_name] pairs.
        workspaces_groups:
          type: array
          items:
            type: array
            items:
              type: string
          description: Workspaces to Groups Mapping. List of [workspace_title, group_name] pairs.
      description: Serializer for updating SAML settings (POST requests).
      title: SamlSettingsUpdate
    SamlSettingsUpdateRequest:
      type: object
      properties:
        domain:
          type: string
          description: 'Organization web domain or domains; use comma separated list with no spaces for multiple. Example:<br><br>labelstud.io,humansignal.com<br><br>IMPORTANT: DO NOT PUT COMMON DOMAINS LIKE GMAIL.COM, YAHOO.COM, ETC. IN THIS FIELD'
        idp_provider:
          type:
          - string
          - 'null'
          description: Identity Provider preset key (e.g. okta, azure, google, custom)
        manual_role_management:
          type:
          - boolean
          - 'null'
          description: Allow manually assigning organization roles instead of IdP-managed groups. None = use billing default.
        mapping_email:
          type:
          - string
          - 'null'
          description: 'Mapping attributes: user email from SAML request'
        mapping_first_name:
          type:
          - string
          - 'null'
          description: 'Mapping attributes: user first name from SAML request'
        mapping_groups:
          type:
          - string
          - 'null'
          description: 'Mapping attributes: groups attribute for user mapping to workspaces and roles'
        mapping_last_name:
          type:
          - string
          - 'null'
          description: 'Mapping attributes: user last name from SAML request'
        metadata_url:
          type: string
          description: URL SAML metadata from IdP
        metadata_xml:
          type: string
          description: Metadata XML file
        projects_groups:
          type: array
          items:
            $ref: '#/components/schemas/ProjectGroupRequest'
          description: Projects to Groups Mapping. List of objects with project_id, group, role.
        roles_groups:
          type: array
          items:
            type: array
            items:
              type: string
          description: Organization Roles to Groups Mapping. List of [role_name, group_name] pairs.
        workspaces_groups:
          type: array
          items:
            type: array
            items:
              type: string
          description: Workspaces to Groups Mapping. List of [workspace_title, group_name] pairs.
      description: Serializer for updating SAML settings (POST requests).
      title: SamlSettingsUpdateRequest
    ProjectGroupRoleEnum:
      type: string
      enum:
      - Inherit
      - Annotator
      - Reviewer
      description: '* `Inherit` - Inherit

        * `Annotator` - Annotator

        * `Reviewer` - Reviewer'
      title: ProjectGroupRoleEnum
    ProjectGroup:
      type: object
      properties:
        group:
          type: string
          description: Group name
        project_id:
          type: integer
          description: Project ID
        role:
          $ref: '#/components/schemas/ProjectGroupRoleEnum'
          description: 'Project role (Inherit, Annotator, Reviewer)


            * `Inherit` - Inherit

            * `Annotator` - Annotator

            * `Reviewer` - Reviewer'
      required:
      - group
      - project_id
      - role
      title: ProjectGroup
    ProjectGroupRequest:
      type: object
      properties:
        group:
          type: string
          description: Group name
        project_id:
          type: integer
          description: Project ID
        role:
          $ref: '#/components/schemas/ProjectGroupRoleEnum'
          description: 'Project role (Inherit, Annotator, Reviewer)


            * `Inherit` - Inherit

            * `Annotator` - Annotator

            * `Reviewer` - Reviewer'
      required:
      - group
      - project_id
      - role
      title: ProjectGroupRequest
    ValidateSamlMetadataUrlResponse:
      type: object
      properties:
        valid:
          type: boolean
      required:
      - valid
      title: ValidateSamlMetadataUrlResponse
    SamlSettings:
      type: object
      properties:
        acs_url:
          type:
          - string
          - 'null'
        domain:
          type: string
          description: 'Organization web domain or domains; use comma separated list with no spaces for multiple. Example:<br><br>labelstud.io,humansignal.com<br><br>IMPORTANT: DO NOT PUT COMMON DOMAINS LIKE GMAIL.COM, YAHOO.COM, ETC. IN THIS FIELD'
        idp_provider:
          type:
          - string
          - 'null'
          description: Identity Provider preset key (e.g. okta, azure, google, custom)
        login_url:
          type:
          - string
          - 'null'
        logout_url:
          type:
          - string
          - 'null'
        manual_role_management:
          type:
          - boolean
          - 'null'
          description: Allow manually assigning organization roles instead of IdP-managed groups. None = use billing default.
        mapping_email:
          type:
          - string
          - 'null'
          description: 'Mapping attributes: user email from SAML request'
        mapping_first_name:
          type:
          - string
          - 'null'
          description: 'Mapping attributes: user first name from SAML request'
        mapping_groups:
          type:
          - string
          - 'null'
          description: 'Mapping attributes: groups attribute for user mapping to workspaces and roles'
        mapping_last_name:
          type:
          - string
          - 'null'
          description: 'Mapping attributes: user last name from SAML request'
        metadata_url:
          type: string
          description: URL SAML metadata from IdP
        metadata_xml:
          type: string
          description: Metadata XML file
        metadata_xml_url:
          type:
          - string
          - 'null'
        nameid_format:
          type: string
        projects_groups:
          type:
          - array
          - 'null'
          items:
            $ref: '#/components/schemas/ProjectGroup'
          description: Projects to Groups Mapping. List of objects with project_id, group, role.
        roles_groups:
          type:
          - array
          - 'null'
          items:
            type: array
            items:
              type: string
          description: Organization Roles to Groups Mapping. List of [role_name, group_name] pairs.
        token:
          type: string
        workspaces_groups:
          type:
          - array
          - 'null'
          items:
            type: array
            items:
              type: string
          description: Workspaces to Groups Mapping. List of [workspace_title, group_name] pairs.
      required:
      - acs_url
      - login_url
      - logout_url
      - metadata_xml_url
      - nameid_format
      description: 'Serializer for reading SAML settings (GET requests).


        Includes all model fields plus computed read-only fields for SP URLs

        that are needed for IdP configuration.'
      title: SamlSettings
    ValidateSamlMetadataUrlRequestRequest:
      type: object
      properties:
        metadata_url:
          type: string
          format: uri
      required:
      - metadata_url
      title: ValidateSamlMetadataUrlRequestRequest
  securitySchemes:
    Token:
      type: apiKey
      in: header
      name: Authorization
      description: 'The token (or API key) must be passed as a request header. You can find your user token on the User Account page in Label Studio. Example: <br><pre><code class="language-bash">curl https://label-studio-host/api/projects -H "Authorization: Token [your-token]"</code></pre>'