openapi: 3.0.1
info:
title: FlashArray REST Active Directory SAML2 SSO API
version: '2.52'
description: 'Active Directory configuration authenticates users for NFS using Kerberos or SMB using Kerberos
or New Technology LAN Manager (NTLM). Active Directory is also used to authorize users by
mapping identities across the NFS and SMB protocols by using LDAP queries.
'
servers:
- url: /
tags:
- name: SAML2 SSO
description: 'SAML2 SSO allows customers to configure settings of SAML2 service provider
and identity provider. It provides a multi-factor authentication (MFA)
mechanism for customers to log in to FlashArray.
'
paths:
/api/2.52/sso/saml2/idps:
get:
tags:
- SAML2 SSO
summary: Pure Storage List SAML2 SSO Configurations
description: 'Displays the SAML2 SSO service provider and identity provider configuration
settings in the array.
'
parameters:
- $ref: '#/components/parameters/Authorization'
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Continuation_token'
- $ref: '#/components/parameters/Filter'
- $ref: '#/components/parameters/Ids'
- $ref: '#/components/parameters/Limit'
- $ref: '#/components/parameters/Names'
- $ref: '#/components/parameters/Offset'
- $ref: '#/components/parameters/Sort'
- $ref: '#/components/parameters/Total_item_count'
responses:
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/Saml2SsoGetResponse'
post:
tags:
- SAML2 SSO
summary: Pure Storage Create SAML2 SSO Configurations
description: 'Creates SAML2 SSO configurations.
'
parameters:
- $ref: '#/components/parameters/Authorization'
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Names_required'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/Saml2SsoPost'
required: true
x-codegen-request-body-name: idp
responses:
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/Saml2SsoResponse'
x-codegen-request-body-name: idp
delete:
tags:
- SAML2 SSO
summary: Pure Storage Delete SAML2 SSO Configurations
description: 'Deletes SAML2 SSO configurations.
'
parameters:
- $ref: '#/components/parameters/Authorization'
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Ids'
- $ref: '#/components/parameters/Names'
responses:
'200':
description: OK
content: {}
patch:
tags:
- SAML2 SSO
summary: Pure Storage Modify SAML2 SSO Configurations
description: 'Modifies one or more attributes of SAML2 SSO configurations.
'
parameters:
- $ref: '#/components/parameters/Authorization'
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Ids'
- $ref: '#/components/parameters/Names'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/Saml2SsoPatch'
required: true
x-codegen-request-body-name: idp
responses:
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/Saml2SsoResponse'
x-codegen-request-body-name: idp
/api/2.52/sso/saml2/idps/test:
get:
tags:
- SAML2 SSO
summary: Pure Storage List Existing SAML2 SSO Configurations
description: 'Displays the existing SAML2 SSO configurations in the array.
'
parameters:
- $ref: '#/components/parameters/Authorization'
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Allow_errors'
- $ref: '#/components/parameters/Context_names_get'
- $ref: '#/components/parameters/Continuation_token'
- $ref: '#/components/parameters/Filter'
- $ref: '#/components/parameters/Ids'
- $ref: '#/components/parameters/Limit'
- $ref: '#/components/parameters/Names'
- $ref: '#/components/parameters/Offset'
- $ref: '#/components/parameters/Sort'
- $ref: '#/components/parameters/Total_item_count'
responses:
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/TestResultWithResourceResponse'
patch:
tags:
- SAML2 SSO
summary: Pure Storage Modify Provided SAML2 SSO Configurations
description: 'Modifies the provided SAML2 SSO configurations. If the configurations with the
specified `ids` or `names` exist, the provided configurations will overwrite
the existing configurations, but will not be persisted in the array.
'
parameters:
- $ref: '#/components/parameters/Authorization'
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Context_names'
- $ref: '#/components/parameters/Ids'
- $ref: '#/components/parameters/Names'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/Saml2SsoPost'
required: true
x-codegen-request-body-name: idp
responses:
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/TestResultWithResourcePatchResponse'
x-codegen-request-body-name: idp
/api/2.26/sso/saml2/idps:
get:
tags:
- SAML2 SSO
summary: Pure Storage List SAML2 SSO Configurations
description: 'Displays the SAML2 SSO service provider and identity provider configuration
settings in the array.
'
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Continuation_token'
- $ref: '#/components/parameters/Filter'
- $ref: '#/components/parameters/Ids_2'
- $ref: '#/components/parameters/Limit'
- $ref: '#/components/parameters/Names'
- $ref: '#/components/parameters/Offset_2'
- $ref: '#/components/parameters/Sort_2'
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/Saml2SsoGetResponse'
post:
tags:
- SAML2 SSO
summary: Pure Storage Create SAML2 SSO Configurations
description: Creates SAML2 SSO configurations.
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Names_required_2'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/Saml2SsoPost_2'
required: true
x-codegen-request-body-name: idp
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/Saml2SsoResponse'
x-codegen-request-body-name: idp
delete:
tags:
- SAML2 SSO
summary: Pure Storage Delete SAML2 SSO Configurations
description: Deletes SAML2 SSO configurations.
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Ids_2'
- $ref: '#/components/parameters/Names'
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content: {}
patch:
tags:
- SAML2 SSO
summary: Pure Storage Modify SAML2 SSO Configurations
description: Modifies one or more attributes of SAML2 SSO configurations.
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Ids_2'
- $ref: '#/components/parameters/Names'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/Saml2Sso_2'
required: true
x-codegen-request-body-name: idp
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/Saml2SsoResponse'
x-codegen-request-body-name: idp
/api/2.26/sso/saml2/idps/test:
get:
tags:
- SAML2 SSO
summary: Pure Storage GET Sso/saml2/idps/test
description: 'Test the existing SAML2 SSO configurations in the array.
'
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Filter'
- $ref: '#/components/parameters/Ids_2'
- $ref: '#/components/parameters/Limit'
- $ref: '#/components/parameters/Names'
- $ref: '#/components/parameters/Sort_2'
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/TestResultResponse'
patch:
tags:
- SAML2 SSO
summary: Pure Storage PATCH Sso/saml2/idps/test
description: 'Modifies and test the provided SAML2 SSO configurations. If the configurations with the
specified `ids` or `names` exist, the provided configurations will overwrite
the existing configurations, but will not be persisted in the array.
'
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Ids_2'
- $ref: '#/components/parameters/Names'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/Saml2Sso_2'
required: true
x-codegen-request-body-name: idp
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/TestResultResponse'
x-codegen-request-body-name: idp
components:
schemas:
_referenceWithoutType:
type: object
properties:
id:
description: 'A globally unique, system-generated ID.
The ID cannot be modified.
'
type: string
name:
description: 'The resource name, such as volume name, pod name,
snapshot name, and so on.
'
type: string
Saml2SsoPatch:
allOf:
- $ref: '#/components/schemas/Saml2SsoPost'
- type: object
properties:
enabled:
description: 'If set to `true`, the SAML2 SSO configuration is enabled.
'
type: boolean
_referenceNoId:
type: object
properties:
name:
description: 'The resource name, such as volume name, pod name, snapshot name, and so on.
'
type: string
_saml2SsoSp_2:
allOf:
- $ref: '#/components/schemas/_saml2SsoSpCredential_2'
- description: Properties specific to the service provider.
type: object
properties:
assertion_consumer_url:
description: 'The URL where the identity provider will send its SAML response after authenticating a user.
'
type: string
readOnly: true
example: https://myarray.mycompany.com/login/saml2/sso/myidp
metadata_url:
description: The URL of the service provider metadata.
type: string
readOnly: true
example: https://myarray.mycompany.com/saml2/service-provider-metadata/myidp
_saml2SsoManagement_2:
description: Properties specific to the management service.
type: object
properties:
trust_other_saml_sps_in_fleet:
description: 'Controls the validation strategy for remote command execution in fleet deployments.
When set to `false` (default), the array verifies that both the source and target
arrays have matching SAML configurations (same Identity Provider and same SP Entity ID)
before allowing remote command execution. When set to `true`, the array allows remote
command execution from other arrays in the fleet without verifying SAML configuration
consistency. For security, it is recommended to keep this set to `false` unless there
is a specific need to allow remote execution with different SAML configurations.
'
type: boolean
default: false
TestResult:
type: object
properties:
component_address:
description: Address of the component running the test.
type: string
example: 10.230.94.21
component_name:
description: Name of the component running the test.
type: string
example: CT0
description:
description: What the test is doing.
type: string
example: Testing phonehome connectivity
destination:
description: The URI of the target server being tested.
type: string
example: ra.cloud-support.purestorage.com
enabled:
description: 'Whether the object being tested is enabled or not.
Returns a value of `true` if the the service is enabled.
Returns a value of `false` if the service is disabled.
'
type: boolean
example: true
result_details:
description: Additional information about the test result.
type: string
example: Timeout connecting to phonehome endpoint
success:
description: 'Whether the object being tested passed the test or not.
Returns a value of `true` if the specified test has succeeded.
Returns a value of `false` if the specified test has failed.
'
type: boolean
test_type:
description: 'Displays the type of test being performed. The returned values are determined
by the `resource` being tested and its configuration.
Values include `array-admin-group-searching`, `binding`, `connecting`, `phonehome`,
`phonehome-ping`, `remote-assist`, `rootdse-searching`, `read-only-group-searching`,
`storage-admin-group-searching`, and `validate-ntp-configuration`.
'
type: string
example: phonehome
_resource:
description: 'An ordinary (as opposed to built-in) resource that can be created, named,
renamed or deleted by the user. This might be a virtual resource (e.g., a
file system), or correspond to something in the environment, like a host or a
server.
'
type: object
properties:
id:
description: 'A globally unique, system-generated ID.
The ID cannot be modified and cannot refer to another resource.
'
type: string
readOnly: true
name:
description: 'A user-specified name.
The name must be locally unique and can be changed.
'
type: string
TestResultResponse:
type: object
properties:
items:
type: array
items:
$ref: '#/components/schemas/TestResult_2'
_fixedReferenceWithoutType:
type: object
properties:
id:
description: 'A globally unique, system-generated ID.
The ID cannot be modified.
'
type: string
readOnly: true
name:
description: 'The resource name, such as volume name, file system name,
snapshot name, and so on.
'
type: string
readOnly: true
x-readOnly: true
TestResultWithResource:
allOf:
- $ref: '#/components/schemas/TestResult'
- $ref: '#/components/schemas/_context'
- type: object
properties:
resource:
description: A reference to the object being tested.
title: FixedReferenceNoId
allOf:
- $ref: '#/components/schemas/_fixedReferenceNoId'
_saml2SsoIdp:
description: 'Properties specific to the identity provider.
'
type: object
properties:
encrypt_assertion_enabled:
description: 'If set to `true`, SAML assertions will be encrypted by the identity provider.
'
type: boolean
entity_id:
description: 'A globally unique name for the identity provider.
'
type: string
example: http://myidp.mycompany.com/adfs/services/trust
metadata_url:
description: 'The URL of the identity provider metadata.
'
type: string
example: https://myidp.mycompany.com/federationmetadata/2007-06/federationmetadata.xml
sign_request_enabled:
description: 'If set to `true`, SAML requests will be signed by the service provider.
'
type: boolean
url:
description: 'The URL of the identity provider.
'
type: string
example: https://myidp.mycompany.com/adfs/ls
verification_certificate:
description: 'The X509 certificate that the service provider uses to verify the SAML response
signature from the identity provider.
'
type: string
_referenceWritable:
allOf:
- $ref: '#/components/schemas/_referenceWithoutType'
- type: object
properties:
resource_type:
description: 'Type of the object (full name of the endpoint).
Valid values are `hosts`, `host-groups`, `network-interfaces`, `pods`,
`ports`, `pod-replica-links`, `subnets`, `volumes`, `volume-snapshots`,
`volume-groups`, `directories`, `policies/nfs`, `policies/smb`, `policies/snapshot`, etc.
'
type: string
x-aliases:
- _reference
_saml2SsoManagement:
description: Properties specific to the management service.
type: object
properties:
trust_other_saml_sps_in_fleet:
description: 'The configuration that defines the validation strategy for remote
command execution within fleet deployments. When set to `false`
(the default), the array enforces a security check to ensure that
source and target arrays share identical `SAML` configurations,
including the same `Identity Provider` and `SP Entity ID`. When set
to `true`, the array permits remote command execution from other
fleet members without verifying `SAML` consistency. Maintaining
this value as `false` ensures a higher security posture by
restricting execution to verified, consistent environments
'
type: boolean
default: false
Saml2SsoPost:
type: object
properties:
array_url:
description: 'The URL of the array.
'
type: string
example: https://myarray.mycompany.com
idp:
$ref: '#/components/schemas/_saml2SsoIdp'
management:
$ref: '#/components/schemas/_saml2SsoManagement'
sp:
description: 'Properties specific to the service provider.
'
title: Saml2SsoSpCredential
allOf:
- $ref: '#/components/schemas/_saml2SsoSpCredential'
TestResultWithResourcePatchResponse:
type: object
properties:
items:
type: array
items:
$ref: '#/components/schemas/TestResultWithResource'
_saml2SsoIdp_2:
description: Properties specific to the identity provider.
type: object
properties:
encrypt_assertion_enabled:
description: If set to `true`, SAML assertions will be encrypted by the identity provider.
type: boolean
entity_id:
description: A globally unique name for the identity provider.
type: string
example: https://myidp.mycompany.com/adfs/services/trust
metadata_url:
description: The URL of the identity provider metadata.
type: string
example: https://myidp.mycompany.com/federationmetadata/2007-06/federationmetadata.xml
metadata_url_ca_certificate:
description: 'CA certificate used to validate the authenticity of the configured
Identity Provider server.
'
title: ReferenceWritable
allOf:
- $ref: '#/components/schemas/_referenceWritable'
metadata_url_ca_certificate_group:
description: 'A certificate group containing CA certificates that can be used to
validate the authenticity of the configured Identity Provider server.
'
title: ReferenceWritable
allOf:
- $ref: '#/components/schemas/_referenceWritable'
sign_request_enabled:
description: If set to `true`, SAML requests will be signed by the service provider.
type: boolean
url:
description: The URL of the identity provider.
type: string
example: https://myidp.mycompany.com/adfs/ls
verification_certificate:
description: 'The certificate used by the service provider to verify the SAML response
signature from the identity provider. The credential is managed by
the `certificates` endpoint and `purecert` CLI commands.
'
title: ReferenceWritable
allOf:
- $ref: '#/components/schemas/_referenceWritable'
_fixedReferenceWithType:
allOf:
- $ref: '#/components/schemas/_fixedReference'
- type: object
properties:
resource_type:
description: 'Type of the object (full name of the endpoint).
Valid values are the unique part of the resource''s REST endpoint.
For example, a reference to a file system would have a
`resource_type` of `file-systems`.
'
type: string
readOnly: true
x-aliases:
- _fixedReference
_fixedReferenceNoId:
type: object
properties:
name:
description: 'The resource name,
such as volume name, pod name, snapshot name, and so on.
'
type: string
readOnly: true
x-readOnly: true
_saml2SsoSpCredential:
type: object
properties:
decryption_credential:
description: 'The credential used by the service provider to decrypt encrypted SAML
assertions from the identity provider. The credential is managed by
the `certificates` endpoint and `purecert` CLI commands.
'
title: ReferenceNoId
allOf:
- $ref: '#/components/schemas/_referenceNoId'
entity_id:
description: 'The `Service Provider Entity ID` used for `SAML` authentication. If
this value is not provided, it is auto-generated by the system. To
enable `SAML` users to operate across `remote arrays`, all members
of a fleet must be configured with the same identifier.
'
type: string
signing_credential:
description: 'The credential used by the service provider to sign SAML requests.
The credential is managed by the `certificates` endpoint and
`purecert` CLI commands.
'
title: ReferenceNoId
allOf:
- $ref: '#/components/schemas/_referenceNoId'
_resourceFixedNonUniqueName:
description: 'A resource with a non-unique name.
'
type: object
properties:
id:
description: 'A globally unique, system-generated ID. The ID cannot be modified.
'
type: string
readOnly: true
name:
description: 'Name of the resource. The name cannot be modified.
'
type: string
readOnly: true
Saml2Sso_2:
description: 'Configuration information for SAML2-based SSO for FlashArray.
'
allOf:
- $ref: '#/components/schemas/_resource'
- $ref: '#/components/schemas/Saml2SsoPost_2'
_saml2SsoSp:
allOf:
- $ref: '#/components/schemas/_saml2SsoSpCredential'
- description: 'Properties specific to the service provider.
'
type: object
properties:
assertion_consumer_url:
description: 'The URL where the identity provider will send its SAML response after authenticating a user.
'
type: string
example: https://myarray.mycompany.com/login/saml2/sso/myidp
entity_id:
description: 'A globally unique name for the service provider.
'
type: string
example: https://myarray.mycompany.com/saml2/service-provider-metadata/myidp
metadata_url:
description: 'The URL of the service provider metadata.
'
type: string
example: https://myarray.mycompany.com/saml2/service-provider-metadata/myidp
Saml2Sso:
allOf:
- $ref: '#/components/schemas/_resourceFixedNonUniqueName'
- description: 'Configuration information for SAML2-based SSO for FlashArray.
'
type: object
properties:
array_url:
description: 'The URL of the array.
'
type: string
example: https://myarray.mycompany.com
enabled:
description: 'If set to `true`, the SAML2 SSO configuration is enabled.
'
type: boolean
idp:
$ref: '#/components/schemas/_saml2SsoIdp'
management:
$ref: '#/components/schemas/_saml2SsoManagement'
services:
description: 'The list of services for which `SAML2 SSO` `authentication` is
enabled. The default value is `management`, indicating that the
single sign-on configuration applies to the administrative
interface of the system.
'
type: array
items:
type: string
sp:
$ref: '#/components/schemas/_saml2SsoSp'
TestResultWithResourceResponse:
allOf:
- $ref: '#/components/schemas/PageInfo'
- type: object
properties:
items:
type: array
items:
$ref: '#/components/schemas/TestResultWithResource'
Saml2SsoGetResponse:
allOf:
- $ref: '#/components/schemas/PageInfo'
- $ref: '#/components/schemas/Saml2SsoResponse'
_context:
type: object
properties:
context:
description: 'The context in which the operation was performed.
Valid values include a reference to any array which is a member of the same fleet
or to the fleet itself.
Other parameters provided with the request, such as names of volumes or snapshots,
are resolved relative to the provided `context`.
'
readOnly: true
title: FixedReferenceWithType
allOf:
- $ref: '#/components/schemas/_fixedReferenceWithType'
Saml2SsoPost_2:
type: object
properties:
array_url:
description: The URL of the array.
type: string
example: https://myarray.mycompany.com
binding:
description: 'SAML2 binding to use for the request from Flashblade to the Identity
Provider.
Valid values: `http-redirect`, `none`.
Defaults to `http-redirect`.
'
type: string
enabled:
description: If set to `true`, the SAML2 SSO configuration is enabled.
type: boolean
idp:
$ref: '#/components/schemas/_saml2SsoIdp_2'
management:
$ref: '#/components/schemas/_saml2SsoManagement_2'
prn:
description: Pure Resource Name of the identity provider
type: string
readOnly: true
example: prn::iam:array-id/local::saml-provider/myidp
services:
description: 'Services that the SAML2 SSO authentication is used for.
Valid values: `management`, `object`.
Defaults to `management`.
'
type: array
items:
type: string
sp:
$ref: '#/components/schemas/_saml2SsoSp_2'
_fixedReference_2:
allOf:
- $ref: '#/components/schemas/_fixedReferenceWithoutType'
- type: object
properties:
resource_type:
description: 'Type of the object (full name of the endpoint).
Valid values are the unique part of the resource''s REST endpoint.
For example, a reference to a file system would have a
`resource_type` of `file-systems`.
'
type: string
readOnly: true
_saml2SsoSpCredential_2:
type: object
properties:
decryption_credential:
description: 'The credential used by the service provider to decrypt encrypted SAML
assertions from the identity provider. The credential is managed by
the `certificates` endpoint and `purecert` CLI commands.
'
title: ReferenceWritable
allOf:
- $ref: '#/components/schemas/_referenceWritable'
entity_id:
description: 'Service Provider Entity ID: If not provided, it will be auto-generated.
All fleet members must use the same Service Provider Entity ID in order
to allow SAML users to operate on remote arrays.
'
type: string
signing_credential:
description: 'The credential used by the service provider to sign SAML requests.
The credential is managed by the `certificates` endpoint and
`purecert` CLI commands.
'
title: ReferenceWritable
allOf:
- $ref: '#/components/schemas/_referenceWritable'
_fixedReference:
type: object
properties:
id:
description: 'A globally unique, system-generated ID.
The ID cannot be modified.
'
type: string
readOnly: true
name:
description: 'The resource name, such as volume name, file system name,
snapshot name, and so on.
'
type: string
readOnly: true
x-readOnly: true
x-aliases:
- _fixedReferenceWithoutType
PageInfo:
type: object
properties:
continuation_token:
description: 'Continuation token that can be provided in the `continuation_token`
query param to get the next page of data.
If you use the continuation token to page through data you
are guaranteed to get all items exactly once regardless of
how items are modified. If an item is adde
# --- truncated at 32 KB (42 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/openapi/pure-storage-saml2-sso-api-openapi.yml