Pure Storage SAML2 SSO API

SAML2 SSO allows customers to configure settings of SAML2 service provider and identity provider. It provides a multi-factor authentication (MFA) mechanism for customers to log in to FlashArray.

Documentation

Specifications

Code Examples

Schemas & Data

📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/flasharray-rest-api-array-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/flasharray-rest-api-volume-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/flasharray-rest-api-host-schema.json
📊
JSONStructure
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-structure/flasharray-rest-api-array-structure.json
📊
JSONStructure
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-structure/flasharray-rest-api-volume-structure.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/flashblade-rest-api-file-system-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/flashblade-rest-api-bucket-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/flashblade-rest-api-array-schema.json
📊
JSONStructure
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-structure/flashblade-rest-api-file-system-structure.json
📊
JSONStructure
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-structure/flashblade-rest-api-bucket-structure.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/pure1-cloud-api-array-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/pure1-cloud-api-metric-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/pure1-cloud-api-alert-schema.json
📊
JSONStructure
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-structure/pure1-cloud-api-array-structure.json

Other Resources

🔗
SDKs
https://pypi.org/project/py-pure-client/
🔗
SDKs
https://github.com/PureStorage-OpenConnect/PureStorage.Pure1
🔗
SDKs
https://github.com/PureStorage-OpenConnect/powershell-toolkit-3
🔗
SDKs
https://github.com/PureStorage-OpenConnect/rest-client
🔗
Integrations
https://github.com/PureStorage-OpenConnect/terraform-provider-flash
🔗
Integrations
https://github.com/PureStorage-OpenConnect/pure-fa-openmetrics-exporter
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-ld/pure-storage-flasharray-rest-api-context.jsonld
🔗
Examples
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/examples/flasharray-rest-api-volume-example.json
🔗
Examples
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/examples/flasharray-rest-api-array-example.json
🔗
SDKs
https://github.com/PureStorage-OpenConnect/flashblade-powershell
🔗
SDKs
https://github.com/purestorage/purity_fb_python_client
🔗
Integrations
https://github.com/PureStorage-OpenConnect/pure-fb-openmetrics-exporter
🔗
Tools
https://github.com/PureStorage-OpenConnect/flashblade-mcp-server
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-ld/pure-storage-flashblade-rest-api-context.jsonld
🔗
Examples
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/examples/flashblade-rest-api-file-system-example.json
🔗
Examples
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/examples/flashblade-rest-api-bucket-example.json
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-ld/pure-storage-pure1-cloud-api-context.jsonld
🔗
Examples
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/examples/pure1-cloud-api-array-example.json

OpenAPI Specification

pure-storage-saml2-sso-api-openapi.yml Raw ↑
openapi: 3.0.1
info:
  title: FlashArray REST Active Directory SAML2 SSO API
  version: '2.52'
  description: 'Active Directory configuration authenticates users for NFS using Kerberos or SMB using Kerberos

    or New Technology LAN Manager (NTLM). Active Directory is also used to authorize users by

    mapping identities across the NFS and SMB protocols by using LDAP queries.

    '
servers:
- url: /
tags:
- name: SAML2 SSO
  description: 'SAML2 SSO allows customers to configure settings of SAML2 service provider

    and identity provider. It provides a multi-factor authentication (MFA)

    mechanism for customers to log in to FlashArray.

    '
paths:
  /api/2.52/sso/saml2/idps:
    get:
      tags:
      - SAML2 SSO
      summary: Pure Storage List SAML2 SSO Configurations
      description: 'Displays the SAML2 SSO service provider and identity provider configuration

        settings in the array.

        '
      parameters:
      - $ref: '#/components/parameters/Authorization'
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Continuation_token'
      - $ref: '#/components/parameters/Filter'
      - $ref: '#/components/parameters/Ids'
      - $ref: '#/components/parameters/Limit'
      - $ref: '#/components/parameters/Names'
      - $ref: '#/components/parameters/Offset'
      - $ref: '#/components/parameters/Sort'
      - $ref: '#/components/parameters/Total_item_count'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Saml2SsoGetResponse'
    post:
      tags:
      - SAML2 SSO
      summary: Pure Storage Create SAML2 SSO Configurations
      description: 'Creates SAML2 SSO configurations.

        '
      parameters:
      - $ref: '#/components/parameters/Authorization'
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Names_required'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Saml2SsoPost'
        required: true
        x-codegen-request-body-name: idp
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Saml2SsoResponse'
      x-codegen-request-body-name: idp
    delete:
      tags:
      - SAML2 SSO
      summary: Pure Storage Delete SAML2 SSO Configurations
      description: 'Deletes SAML2 SSO configurations.

        '
      parameters:
      - $ref: '#/components/parameters/Authorization'
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Ids'
      - $ref: '#/components/parameters/Names'
      responses:
        '200':
          description: OK
          content: {}
    patch:
      tags:
      - SAML2 SSO
      summary: Pure Storage Modify SAML2 SSO Configurations
      description: 'Modifies one or more attributes of SAML2 SSO configurations.

        '
      parameters:
      - $ref: '#/components/parameters/Authorization'
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Ids'
      - $ref: '#/components/parameters/Names'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Saml2SsoPatch'
        required: true
        x-codegen-request-body-name: idp
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Saml2SsoResponse'
      x-codegen-request-body-name: idp
  /api/2.52/sso/saml2/idps/test:
    get:
      tags:
      - SAML2 SSO
      summary: Pure Storage List Existing SAML2 SSO Configurations
      description: 'Displays the existing SAML2 SSO configurations in the array.

        '
      parameters:
      - $ref: '#/components/parameters/Authorization'
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Allow_errors'
      - $ref: '#/components/parameters/Context_names_get'
      - $ref: '#/components/parameters/Continuation_token'
      - $ref: '#/components/parameters/Filter'
      - $ref: '#/components/parameters/Ids'
      - $ref: '#/components/parameters/Limit'
      - $ref: '#/components/parameters/Names'
      - $ref: '#/components/parameters/Offset'
      - $ref: '#/components/parameters/Sort'
      - $ref: '#/components/parameters/Total_item_count'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TestResultWithResourceResponse'
    patch:
      tags:
      - SAML2 SSO
      summary: Pure Storage Modify Provided SAML2 SSO Configurations
      description: 'Modifies the provided SAML2 SSO configurations. If the configurations with the

        specified `ids` or `names` exist, the provided configurations will overwrite

        the existing configurations, but will not be persisted in the array.

        '
      parameters:
      - $ref: '#/components/parameters/Authorization'
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Context_names'
      - $ref: '#/components/parameters/Ids'
      - $ref: '#/components/parameters/Names'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Saml2SsoPost'
        required: true
        x-codegen-request-body-name: idp
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TestResultWithResourcePatchResponse'
      x-codegen-request-body-name: idp
  /api/2.26/sso/saml2/idps:
    get:
      tags:
      - SAML2 SSO
      summary: Pure Storage List SAML2 SSO Configurations
      description: 'Displays the SAML2 SSO service provider and identity provider configuration

        settings in the array.

        '
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Continuation_token'
      - $ref: '#/components/parameters/Filter'
      - $ref: '#/components/parameters/Ids_2'
      - $ref: '#/components/parameters/Limit'
      - $ref: '#/components/parameters/Names'
      - $ref: '#/components/parameters/Offset_2'
      - $ref: '#/components/parameters/Sort_2'
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Saml2SsoGetResponse'
    post:
      tags:
      - SAML2 SSO
      summary: Pure Storage Create SAML2 SSO Configurations
      description: Creates SAML2 SSO configurations.
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Names_required_2'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Saml2SsoPost_2'
        required: true
        x-codegen-request-body-name: idp
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Saml2SsoResponse'
      x-codegen-request-body-name: idp
    delete:
      tags:
      - SAML2 SSO
      summary: Pure Storage Delete SAML2 SSO Configurations
      description: Deletes SAML2 SSO configurations.
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Ids_2'
      - $ref: '#/components/parameters/Names'
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content: {}
    patch:
      tags:
      - SAML2 SSO
      summary: Pure Storage Modify SAML2 SSO Configurations
      description: Modifies one or more attributes of SAML2 SSO configurations.
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Ids_2'
      - $ref: '#/components/parameters/Names'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Saml2Sso_2'
        required: true
        x-codegen-request-body-name: idp
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Saml2SsoResponse'
      x-codegen-request-body-name: idp
  /api/2.26/sso/saml2/idps/test:
    get:
      tags:
      - SAML2 SSO
      summary: Pure Storage GET Sso/saml2/idps/test
      description: 'Test the existing SAML2 SSO configurations in the array.

        '
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Filter'
      - $ref: '#/components/parameters/Ids_2'
      - $ref: '#/components/parameters/Limit'
      - $ref: '#/components/parameters/Names'
      - $ref: '#/components/parameters/Sort_2'
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TestResultResponse'
    patch:
      tags:
      - SAML2 SSO
      summary: Pure Storage PATCH Sso/saml2/idps/test
      description: 'Modifies and test the provided SAML2 SSO configurations. If the configurations with the

        specified `ids` or `names` exist, the provided configurations will overwrite

        the existing configurations, but will not be persisted in the array.

        '
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Ids_2'
      - $ref: '#/components/parameters/Names'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Saml2Sso_2'
        required: true
        x-codegen-request-body-name: idp
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TestResultResponse'
      x-codegen-request-body-name: idp
components:
  schemas:
    _referenceWithoutType:
      type: object
      properties:
        id:
          description: 'A globally unique, system-generated ID.

            The ID cannot be modified.

            '
          type: string
        name:
          description: 'The resource name, such as volume name, pod name,

            snapshot name, and so on.

            '
          type: string
    Saml2SsoPatch:
      allOf:
      - $ref: '#/components/schemas/Saml2SsoPost'
      - type: object
        properties:
          enabled:
            description: 'If set to `true`, the SAML2 SSO configuration is enabled.

              '
            type: boolean
    _referenceNoId:
      type: object
      properties:
        name:
          description: 'The resource name, such as volume name, pod name, snapshot name, and so on.

            '
          type: string
    _saml2SsoSp_2:
      allOf:
      - $ref: '#/components/schemas/_saml2SsoSpCredential_2'
      - description: Properties specific to the service provider.
        type: object
        properties:
          assertion_consumer_url:
            description: 'The URL where the identity provider will send its SAML response after authenticating a user.

              '
            type: string
            readOnly: true
            example: https://myarray.mycompany.com/login/saml2/sso/myidp
          metadata_url:
            description: The URL of the service provider metadata.
            type: string
            readOnly: true
            example: https://myarray.mycompany.com/saml2/service-provider-metadata/myidp
    _saml2SsoManagement_2:
      description: Properties specific to the management service.
      type: object
      properties:
        trust_other_saml_sps_in_fleet:
          description: 'Controls the validation strategy for remote command execution in fleet deployments.

            When set to `false` (default), the array verifies that both the source and target

            arrays have matching SAML configurations (same Identity Provider and same SP Entity ID)

            before allowing remote command execution. When set to `true`, the array allows remote

            command execution from other arrays in the fleet without verifying SAML configuration

            consistency. For security, it is recommended to keep this set to `false` unless there

            is a specific need to allow remote execution with different SAML configurations.

            '
          type: boolean
          default: false
    TestResult:
      type: object
      properties:
        component_address:
          description: Address of the component running the test.
          type: string
          example: 10.230.94.21
        component_name:
          description: Name of the component running the test.
          type: string
          example: CT0
        description:
          description: What the test is doing.
          type: string
          example: Testing phonehome connectivity
        destination:
          description: The URI of the target server being tested.
          type: string
          example: ra.cloud-support.purestorage.com
        enabled:
          description: 'Whether the object being tested is enabled or not.

            Returns a value of `true` if the the service is enabled.

            Returns a value of `false` if the service is disabled.

            '
          type: boolean
          example: true
        result_details:
          description: Additional information about the test result.
          type: string
          example: Timeout connecting to phonehome endpoint
        success:
          description: 'Whether the object being tested passed the test or not.

            Returns a value of `true` if the specified test has succeeded.

            Returns a value of `false` if the specified test has failed.

            '
          type: boolean
        test_type:
          description: 'Displays the type of test being performed. The returned values are determined

            by the `resource` being tested and its configuration.

            Values include `array-admin-group-searching`, `binding`, `connecting`, `phonehome`,

            `phonehome-ping`, `remote-assist`, `rootdse-searching`, `read-only-group-searching`,

            `storage-admin-group-searching`, and `validate-ntp-configuration`.

            '
          type: string
          example: phonehome
    _resource:
      description: 'An ordinary (as opposed to built-in) resource that can be created, named,

        renamed or deleted by the user. This might be a virtual resource (e.g., a

        file system), or correspond to something in the environment, like a host or a

        server.

        '
      type: object
      properties:
        id:
          description: 'A globally unique, system-generated ID.

            The ID cannot be modified and cannot refer to another resource.

            '
          type: string
          readOnly: true
        name:
          description: 'A user-specified name.

            The name must be locally unique and can be changed.

            '
          type: string
    TestResultResponse:
      type: object
      properties:
        items:
          type: array
          items:
            $ref: '#/components/schemas/TestResult_2'
    _fixedReferenceWithoutType:
      type: object
      properties:
        id:
          description: 'A globally unique, system-generated ID.

            The ID cannot be modified.

            '
          type: string
          readOnly: true
        name:
          description: 'The resource name, such as volume name, file system name,

            snapshot name, and so on.

            '
          type: string
          readOnly: true
      x-readOnly: true
    TestResultWithResource:
      allOf:
      - $ref: '#/components/schemas/TestResult'
      - $ref: '#/components/schemas/_context'
      - type: object
        properties:
          resource:
            description: A reference to the object being tested.
            title: FixedReferenceNoId
            allOf:
            - $ref: '#/components/schemas/_fixedReferenceNoId'
    _saml2SsoIdp:
      description: 'Properties specific to the identity provider.

        '
      type: object
      properties:
        encrypt_assertion_enabled:
          description: 'If set to `true`, SAML assertions will be encrypted by the identity provider.

            '
          type: boolean
        entity_id:
          description: 'A globally unique name for the identity provider.

            '
          type: string
          example: http://myidp.mycompany.com/adfs/services/trust
        metadata_url:
          description: 'The URL of the identity provider metadata.

            '
          type: string
          example: https://myidp.mycompany.com/federationmetadata/2007-06/federationmetadata.xml
        sign_request_enabled:
          description: 'If set to `true`, SAML requests will be signed by the service provider.

            '
          type: boolean
        url:
          description: 'The URL of the identity provider.

            '
          type: string
          example: https://myidp.mycompany.com/adfs/ls
        verification_certificate:
          description: 'The X509 certificate that the service provider uses to verify the SAML response

            signature from the identity provider.

            '
          type: string
    _referenceWritable:
      allOf:
      - $ref: '#/components/schemas/_referenceWithoutType'
      - type: object
        properties:
          resource_type:
            description: 'Type of the object (full name of the endpoint).

              Valid values are `hosts`, `host-groups`, `network-interfaces`, `pods`,

              `ports`, `pod-replica-links`, `subnets`, `volumes`, `volume-snapshots`,

              `volume-groups`, `directories`, `policies/nfs`, `policies/smb`, `policies/snapshot`, etc.

              '
            type: string
      x-aliases:
      - _reference
    _saml2SsoManagement:
      description: Properties specific to the management service.
      type: object
      properties:
        trust_other_saml_sps_in_fleet:
          description: 'The configuration that defines the validation strategy for remote

            command execution within fleet deployments. When set to `false`

            (the default), the array enforces a security check to ensure that

            source and target arrays share identical `SAML` configurations,

            including the same `Identity Provider` and `SP Entity ID`. When set

            to `true`, the array permits remote command execution from other

            fleet members without verifying `SAML` consistency. Maintaining

            this value as `false` ensures a higher security posture by

            restricting execution to verified, consistent environments

            '
          type: boolean
          default: false
    Saml2SsoPost:
      type: object
      properties:
        array_url:
          description: 'The URL of the array.

            '
          type: string
          example: https://myarray.mycompany.com
        idp:
          $ref: '#/components/schemas/_saml2SsoIdp'
        management:
          $ref: '#/components/schemas/_saml2SsoManagement'
        sp:
          description: 'Properties specific to the service provider.

            '
          title: Saml2SsoSpCredential
          allOf:
          - $ref: '#/components/schemas/_saml2SsoSpCredential'
    TestResultWithResourcePatchResponse:
      type: object
      properties:
        items:
          type: array
          items:
            $ref: '#/components/schemas/TestResultWithResource'
    _saml2SsoIdp_2:
      description: Properties specific to the identity provider.
      type: object
      properties:
        encrypt_assertion_enabled:
          description: If set to `true`, SAML assertions will be encrypted by the identity provider.
          type: boolean
        entity_id:
          description: A globally unique name for the identity provider.
          type: string
          example: https://myidp.mycompany.com/adfs/services/trust
        metadata_url:
          description: The URL of the identity provider metadata.
          type: string
          example: https://myidp.mycompany.com/federationmetadata/2007-06/federationmetadata.xml
        metadata_url_ca_certificate:
          description: 'CA certificate used to validate the authenticity of the configured

            Identity Provider server.

            '
          title: ReferenceWritable
          allOf:
          - $ref: '#/components/schemas/_referenceWritable'
        metadata_url_ca_certificate_group:
          description: 'A certificate group containing CA certificates that can be used to

            validate the authenticity of the configured Identity Provider server.

            '
          title: ReferenceWritable
          allOf:
          - $ref: '#/components/schemas/_referenceWritable'
        sign_request_enabled:
          description: If set to `true`, SAML requests will be signed by the service provider.
          type: boolean
        url:
          description: The URL of the identity provider.
          type: string
          example: https://myidp.mycompany.com/adfs/ls
        verification_certificate:
          description: 'The certificate used by the service provider to verify the SAML response

            signature from the identity provider. The credential is managed by

            the `certificates` endpoint and `purecert` CLI commands.

            '
          title: ReferenceWritable
          allOf:
          - $ref: '#/components/schemas/_referenceWritable'
    _fixedReferenceWithType:
      allOf:
      - $ref: '#/components/schemas/_fixedReference'
      - type: object
        properties:
          resource_type:
            description: 'Type of the object (full name of the endpoint).

              Valid values are the unique part of the resource''s REST endpoint.

              For example, a reference to a file system would have a

              `resource_type` of `file-systems`.

              '
            type: string
            readOnly: true
      x-aliases:
      - _fixedReference
    _fixedReferenceNoId:
      type: object
      properties:
        name:
          description: 'The resource name,

            such as volume name, pod name, snapshot name, and so on.

            '
          type: string
          readOnly: true
      x-readOnly: true
    _saml2SsoSpCredential:
      type: object
      properties:
        decryption_credential:
          description: 'The credential used by the service provider to decrypt encrypted SAML

            assertions from the identity provider. The credential is managed by

            the `certificates` endpoint and `purecert` CLI commands.

            '
          title: ReferenceNoId
          allOf:
          - $ref: '#/components/schemas/_referenceNoId'
        entity_id:
          description: 'The `Service Provider Entity ID` used for `SAML` authentication. If

            this value is not provided, it is auto-generated by the system. To

            enable `SAML` users to operate across `remote arrays`, all members

            of a fleet must be configured with the same identifier.

            '
          type: string
        signing_credential:
          description: 'The credential used by the service provider to sign SAML requests.

            The credential is managed by the `certificates` endpoint and

            `purecert` CLI commands.

            '
          title: ReferenceNoId
          allOf:
          - $ref: '#/components/schemas/_referenceNoId'
    _resourceFixedNonUniqueName:
      description: 'A resource with a non-unique name.

        '
      type: object
      properties:
        id:
          description: 'A globally unique, system-generated ID. The ID cannot be modified.

            '
          type: string
          readOnly: true
        name:
          description: 'Name of the resource. The name cannot be modified.

            '
          type: string
          readOnly: true
    Saml2Sso_2:
      description: 'Configuration information for SAML2-based SSO for FlashArray.

        '
      allOf:
      - $ref: '#/components/schemas/_resource'
      - $ref: '#/components/schemas/Saml2SsoPost_2'
    _saml2SsoSp:
      allOf:
      - $ref: '#/components/schemas/_saml2SsoSpCredential'
      - description: 'Properties specific to the service provider.

          '
        type: object
        properties:
          assertion_consumer_url:
            description: 'The URL where the identity provider will send its SAML response after authenticating a user.

              '
            type: string
            example: https://myarray.mycompany.com/login/saml2/sso/myidp
          entity_id:
            description: 'A globally unique name for the service provider.

              '
            type: string
            example: https://myarray.mycompany.com/saml2/service-provider-metadata/myidp
          metadata_url:
            description: 'The URL of the service provider metadata.

              '
            type: string
            example: https://myarray.mycompany.com/saml2/service-provider-metadata/myidp
    Saml2Sso:
      allOf:
      - $ref: '#/components/schemas/_resourceFixedNonUniqueName'
      - description: 'Configuration information for SAML2-based SSO for FlashArray.

          '
        type: object
        properties:
          array_url:
            description: 'The URL of the array.

              '
            type: string
            example: https://myarray.mycompany.com
          enabled:
            description: 'If set to `true`, the SAML2 SSO configuration is enabled.

              '
            type: boolean
          idp:
            $ref: '#/components/schemas/_saml2SsoIdp'
          management:
            $ref: '#/components/schemas/_saml2SsoManagement'
          services:
            description: 'The list of services for which `SAML2 SSO` `authentication` is

              enabled. The default value is `management`, indicating that the

              single sign-on configuration applies to the administrative

              interface of the system.

              '
            type: array
            items:
              type: string
          sp:
            $ref: '#/components/schemas/_saml2SsoSp'
    TestResultWithResourceResponse:
      allOf:
      - $ref: '#/components/schemas/PageInfo'
      - type: object
        properties:
          items:
            type: array
            items:
              $ref: '#/components/schemas/TestResultWithResource'
    Saml2SsoGetResponse:
      allOf:
      - $ref: '#/components/schemas/PageInfo'
      - $ref: '#/components/schemas/Saml2SsoResponse'
    _context:
      type: object
      properties:
        context:
          description: 'The context in which the operation was performed.


            Valid values include a reference to any array which is a member of the same fleet

            or to the fleet itself.


            Other parameters provided with the request, such as names of volumes or snapshots,

            are resolved relative to the provided `context`.

            '
          readOnly: true
          title: FixedReferenceWithType
          allOf:
          - $ref: '#/components/schemas/_fixedReferenceWithType'
    Saml2SsoPost_2:
      type: object
      properties:
        array_url:
          description: The URL of the array.
          type: string
          example: https://myarray.mycompany.com
        binding:
          description: 'SAML2 binding to use for the request from Flashblade to the Identity

            Provider.

            Valid values: `http-redirect`, `none`.

            Defaults to `http-redirect`.

            '
          type: string
        enabled:
          description: If set to `true`, the SAML2 SSO configuration is enabled.
          type: boolean
        idp:
          $ref: '#/components/schemas/_saml2SsoIdp_2'
        management:
          $ref: '#/components/schemas/_saml2SsoManagement_2'
        prn:
          description: Pure Resource Name of the identity provider
          type: string
          readOnly: true
          example: prn::iam:array-id/local::saml-provider/myidp
        services:
          description: 'Services that the SAML2 SSO authentication is used for.

            Valid values: `management`, `object`.

            Defaults to `management`.

            '
          type: array
          items:
            type: string
        sp:
          $ref: '#/components/schemas/_saml2SsoSp_2'
    _fixedReference_2:
      allOf:
      - $ref: '#/components/schemas/_fixedReferenceWithoutType'
      - type: object
        properties:
          resource_type:
            description: 'Type of the object (full name of the endpoint).

              Valid values are the unique part of the resource''s REST endpoint.

              For example, a reference to a file system would have a

              `resource_type` of `file-systems`.

              '
            type: string
            readOnly: true
    _saml2SsoSpCredential_2:
      type: object
      properties:
        decryption_credential:
          description: 'The credential used by the service provider to decrypt encrypted SAML

            assertions from the identity provider. The credential is managed by

            the `certificates` endpoint and `purecert` CLI commands.

            '
          title: ReferenceWritable
          allOf:
          - $ref: '#/components/schemas/_referenceWritable'
        entity_id:
          description: 'Service Provider Entity ID: If not provided, it will be auto-generated.

            All fleet members must use the same Service Provider Entity ID in order

            to allow SAML users to operate on remote arrays.

            '
          type: string
        signing_credential:
          description: 'The credential used by the service provider to sign SAML requests.

            The credential is managed by the `certificates` endpoint and

            `purecert` CLI commands.

            '
          title: ReferenceWritable
          allOf:
          - $ref: '#/components/schemas/_referenceWritable'
    _fixedReference:
      type: object
      properties:
        id:
          description: 'A globally unique, system-generated ID.

            The ID cannot be modified.

            '
          type: string
          readOnly: true
        name:
          description: 'The resource name, such as volume name, file system name,

            snapshot name, and so on.

            '
          type: string
          readOnly: true
      x-readOnly: true
      x-aliases:
      - _fixedReferenceWithoutType
    PageInfo:
      type: object
      properties:
        continuation_token:
          description: 'Continuation token that can be provided in the `continuation_token`

            query param to get the next page of data.

            If you use the continuation token to page through data you

            are guaranteed to get all items exactly once regardless of

            how items are modified. If an item is adde

# --- truncated at 32 KB (42 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/openapi/pure-storage-saml2-sso-api-openapi.yml