Remote SSO Configuration API
The SSO Configuration API from Remote — 2 operation(s) for sso configuration.
The SSO Configuration API from Remote — 2 operation(s) for sso configuration.
openapi: 3.0.0
info:
title: Remote Address Details SSO Configuration API
version: 0.1.0
servers:
- url: https://gateway.remote.com/
variables: {}
- url: https://gateway.remote-sandbox.com/
variables: {}
security:
- OAuth2: []
tags:
- name: SSO Configuration
paths:
/v1/sso-configuration/details:
get:
callbacks: {}
deprecated: false
description: 'Shows the SSO Configuration details for the company.
## Scopes
| Category | Read only Scope | Write only Scope (read access implicit) |
|---|---|---|
| Manage company resources (`company_admin`) | - | Manage SSO (`sso_configuration:write`) |
'
operationId: get_v1_sso-configuration_details
parameters: []
responses:
'200':
content:
application/json:
schema:
$ref: '#/components/schemas/SSOConfigurationDetailsResponse'
description: Success
'400':
content:
application/json:
schema:
$ref: '#/components/schemas/BadRequestResponse'
description: Bad Request
'401':
content:
application/json:
schema:
$ref: '#/components/schemas/UnauthorizedResponse'
description: Unauthorized
'404':
content:
application/json:
schema:
$ref: '#/components/schemas/NotFoundResponse'
description: Not Found
'429':
content:
application/json:
schema:
$ref: '#/components/schemas/TooManyRequestsResponse'
description: Unprocessable Entity
security:
- CustomerAPIToken:
- https://gateway.remote.com/company.manage
- sso_configuration:write
- company_admin
- all:write
OAuth2AuthorizationCode:
- https://gateway.remote.com/company.manage
- sso_configuration:write
- company_admin
- all:write
summary: Show the SSO Configuration Details
tags:
- SSO Configuration
/v1/sso-configuration:
get:
callbacks: {}
deprecated: false
description: 'Shows the current SSO Configuration for the company.
## Scopes
| Category | Read only Scope | Write only Scope (read access implicit) |
|---|---|---|
| Manage company resources (`company_admin`) | View SSO configuration (`sso_configuration:read`) | Manage SSO (`sso_configuration:write`) |
'
operationId: get_v1_sso-configuration
parameters: []
responses:
'200':
content:
application/json:
schema:
$ref: '#/components/schemas/SSOConfigurationResponse'
description: Success
'400':
content:
application/json:
schema:
$ref: '#/components/schemas/BadRequestResponse'
description: Bad Request
'401':
content:
application/json:
schema:
$ref: '#/components/schemas/UnauthorizedResponse'
description: Unauthorized
'404':
content:
application/json:
schema:
$ref: '#/components/schemas/NotFoundResponse'
description: Not Found
'429':
content:
application/json:
schema:
$ref: '#/components/schemas/TooManyRequestsResponse'
description: Unprocessable Entity
security:
- CustomerAPIToken:
- https://gateway.remote.com/company.manage
- sso_configuration:read
- sso_configuration:write
- company_admin
- all:write
- all:read
OAuth2AuthorizationCode:
- https://gateway.remote.com/company.manage
- sso_configuration:read
- sso_configuration:write
- company_admin
- all:write
- all:read
summary: Show the current SSO Configuration
tags:
- SSO Configuration
post:
callbacks: {}
deprecated: false
description: 'Creates the SSO Configuration for the company.
## Scopes
| Category | Read only Scope | Write only Scope (read access implicit) |
|---|---|---|
| Manage company resources (`company_admin`) | - | Manage SSO (`sso_configuration:write`) |
'
operationId: post_v1_sso-configuration
parameters: []
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/CreateSSOConfigurationParams'
description: CreateSSOConfiguration
required: true
responses:
'201':
content:
application/json:
schema:
$ref: '#/components/schemas/CreateSSOConfigurationResponse'
description: Created
'400':
content:
application/json:
schema:
$ref: '#/components/schemas/BadRequestResponse'
description: Bad Request
'401':
content:
application/json:
schema:
$ref: '#/components/schemas/UnauthorizedResponse'
description: Unauthorized
'404':
content:
application/json:
schema:
$ref: '#/components/schemas/NotFoundResponse'
description: Not Found
'409':
content:
application/json:
schema:
$ref: '#/components/schemas/ConflictResponse'
description: Conflict
'422':
content:
application/json:
schema:
$ref: '#/components/schemas/UnprocessableEntityResponse'
description: Unprocessable Entity
'429':
content:
application/json:
schema:
$ref: '#/components/schemas/TooManyRequestsResponse'
description: Unprocessable Entity
security:
- CustomerAPIToken:
- https://gateway.remote.com/company.manage
- sso_configuration:write
- company_admin
- all:write
OAuth2AuthorizationCode:
- https://gateway.remote.com/company.manage
- sso_configuration:write
- company_admin
- all:write
summary: Create the SSO Configuration
tags:
- SSO Configuration
components:
schemas:
ParameterError:
example:
code: invalid_param
message: Invalid parameter
param: employment_id
properties:
code:
description: An error code that describes the nature of the error.
type: string
message:
description: A developer friendly error message that gives details on what the error was and how it may be remedied.
type: string
param:
description: The parameter that lead to the error message.
type: string
required:
- code
- message
- param
title: ParameterError
type: object
UnauthorizedResponse:
description: Returned when the request does not include valid authentication credentials. Ensure you are passing a valid OAuth2 access token or API token in the Authorization header.
example:
message: Unauthorized
properties:
message:
pattern: Unauthorized
type: string
required:
- message
title: UnauthorizedResponse
type: object
SSOConfiguration:
description: A complete SSO configuration for a company, including both Remote-generated values (sso_url, audience_uri) and company-provided values (domain, identity_provider_url).
example:
audience_uri: urn:auth:remote-sso:89c4fbb2-some-id-8e4b-280f8795bbd8
domain: yourcompanydomain1.com,yourcompanydomain2.com
identity_provider_url: https://someproviderurl.com/
sso_url: https://remote-sso.com/login/callback?connection=89c4fbb2-some-id-8e4b-280f8795bbd8
properties:
audience_uri:
description: The audience URI (Entity ID) for SAML assertions.
type: string
domain:
description: The email domain(s) that should be routed through SSO. Multiple domains can be comma-separated (e.g., "company.com,company.co.uk").
type: string
identity_provider_url:
description: The URL of the company's SAML identity provider (IdP) login endpoint.
type: string
sso_url:
description: The SSO login callback URL (Assertion Consumer Service URL).
type: string
required:
- sso_url
- audience_uri
- domain
- identity_provider_url
title: SSOConfiguration
type: object
SSOConfigurationDetailsResponse:
description: SSO Configuration Details response
example:
data:
audience_uri: urn:auth:remote-sso:89c4fbb2-some-id-8e4b-280f8795bbd8
sso_url: https://remote-sso.com/login/callback?connection=89c4fbb2-some-id-8e4b-280f8795bbd8
properties:
data:
$ref: '#/components/schemas/SSOConfigurationDetails'
title: SSOConfigurationDetailsResponse
type: object
CreateSSOConfigurationParams:
additionalProperties: false
description: Parameters for setting up SAML SSO for a company. Requires the email domain, identity provider URL, and the IdP's SAML signing certificate.
example:
certificate: c29tZSBjZXJ0aWZpY2F0ZSBleGFtcGxl...
domain: example.com
identity_provider_url: example.provider.com
properties:
certificate:
description: The SAML signing certificate from your identity provider, base64-encoded.
format: binary
type: string
domain:
description: The email domain(s) to route through SSO (e.g., "example.com").
type: string
identity_provider_url:
description: The URL of the SAML identity provider login endpoint.
type: string
required:
- domain
- identity_provider_url
- certificate
title: CreateSSOConfigurationParams
type: object
UnprocessableEntityResponse:
anyOf:
- properties:
errors:
type: object
required:
- errors
type: object
- properties:
message:
oneOf:
- type: string
- $ref: '#/components/schemas/ParameterError'
- items:
$ref: '#/components/schemas/ParameterError'
title: ParameterErrors
type: array
- $ref: '#/components/schemas/ActionError'
- items:
$ref: '#/components/schemas/ActionError'
title: ActionErrors
type: array
required:
- message
type: object
example:
errors:
some_field:
- is invalid
title: UnprocessableEntityResponse
type: object
NotFoundResponse:
description: Returned when the requested resource does not exist or is not accessible with the current authentication credentials.
example:
message: '{resource} not found'
properties:
message:
description: A message indicating which resource was not found.
pattern: Not Found
type: string
title: NotFoundResponse
type: object
SSOConfigurationResponse:
description: SSO Configuration response
example:
data:
audience_uri: urn:auth:remote-sso:89c4fbb2-some-id-8e4b-280f8795bbd8
domain: yourcompanydomain1.com,yourcompanydomain2.com
identity_provider_url: https://someproviderurl.com/
sso_url: https://remote-sso.com/login/callback?connection=89c4fbb2-some-id-8e4b-280f8795bbd8
properties:
data:
$ref: '#/components/schemas/SSOConfiguration'
title: SSOConfigurationResponse
type: object
SSOConfigurationDetails:
description: The SSO configuration details needed to set up your identity provider (IdP) to connect with Remote.
example:
audience_uri: urn:auth:remote-sso:89c4fbb2-some-id-8e4b-280f8795bbd8
sso_url: https://remote-sso.com/login/callback?connection=89c4fbb2-some-id-8e4b-280f8795bbd8
properties:
audience_uri:
description: The audience URI (Entity ID) for the SAML assertion. Configure this in your identity provider's SAML settings.
type: string
sso_url:
description: The SSO login callback URL. Configure this as the Assertion Consumer Service (ACS) URL in your identity provider.
type: string
required:
- sso_url
- audience_uri
title: SSOConfigurationDetails
type: object
BadRequestResponse:
description: Returned when the request is malformed or contains invalid parameters. The message may be a simple string or a structured object with a code and detailed message.
example:
message: invalid {resource}
oneOf:
- properties:
message:
description: A human-readable error message describing what was wrong with the request.
type: string
required:
- message
type: object
- properties:
message:
properties:
code:
type: string
message:
type: string
required:
- code
- message
type: object
type: object
title: BadRequestResponse
type: object
CreateSSOConfigurationResult:
example:
audience_uri: urn:auth:remote-sso:89c4fbb2-some-id-8e4b-280f8795bbd8
certificate: c29tZSBjZXJ0aWZpY2F0ZSBleGFtcGxl...
domain: example.com
identity_provider_url: example.provider.com
sso_url: https://remote-sso.com/login/callback?connection=89c4fbb2-some-id-8e4b-280f8795bbd8
properties:
audience_uri:
type: string
certificate:
format: binary
type: string
domain:
type: string
identity_provider_url:
type: string
sso_url:
type: string
required:
- sso_url
- audience_uri
- domain
- identity_provider_url
- certificate
title: CreateSSOConfigurationResult
type: object
TooManyRequestsResponse:
description: Returned when the API rate limit has been exceeded (HTTP 429). Wait before retrying. Check the `Retry-After` response header for the recommended wait time.
example:
message: Too many requests
properties:
message:
pattern: Too many requests
type: string
title: TooManyRequestsResponse
type: object
CreateSSOConfigurationResponse:
example:
data:
audience_uri: urn:auth:remote-sso:89c4fbb2-some-id-8e4b-280f8795bbd8
certificate: c29tZSBjZXJ0aWZpY2F0ZSBleGFtcGxl...
domain: example.com
identity_provider_url: example.provider.com
sso_url: https://remote-sso.com/login/callback?connection=89c4fbb2-some-id-8e4b-280f8795bbd8
properties:
data:
$ref: '#/components/schemas/CreateSSOConfigurationResult'
required:
- data
title: CreateSSOConfigurationResponse
type: object
ConflictResponse:
description: Returned when the request conflicts with the current state of a resource (HTTP 409). For example, trying to create a resource that already exists or performing an action that requires the resource to be in a different state.
example:
message: Company needs to be in status active to manage employments
properties:
message:
description: A human-readable message describing the conflict and the expected state.
type: string
title: ConflictResponse
type: object
ActionError:
properties:
action:
description: The action that lead to the error message.
type: string
code:
description: An error code that describes the nature of the error.
type: string
message:
description: A developer friendly error message that gives details on what the error was and how it may be remedied.
type: string
required:
- code
- message
- action
title: ActionError
type: object
securitySchemes:
BasicAuth:
description: 'Authenticate using the basic authentication for partners.
Use the CLIENT_ID as login and CLIENT_SECRET as password.
'
scheme: basic
type: http
ClientToken:
description: 'Authenticate a partner using only the the provided `client_token`.
This authentication method only allows accessing marketing endpoints.
'
scheme: bearer
type: http
CustomerAPIToken:
description: 'Authenticate using API Key generated by the customer in their Integration Settings page.
'
scheme: bearer
type: http
OAuth2:
description: 'Authenticate using OAuth 2.0 protocol.
'
flows:
authorizationCode:
authorizationUrl: /auth/oauth2/authorize
scopes:
company_department:read: company_department:read
webhook:write: webhook:write
magic_link:write: magic_link:write
offboarding:write: offboarding:write
custom_field:write: custom_field:write
address:write: address:write
expense:read: expense:read
employment:write: employment:write
identity_verification:write: identity_verification:write
timesheet:write: timesheet:write
travel_letter:write: travel_letter:write
incentive:read: incentive:read
personal_detail:read: personal_detail:read
invoices:write: invoices:write
work_authorization:write: work_authorization:write
timeoff:write: timeoff:write
company_structure:read: company_structure:read
benefit_renewal:write: benefit_renewal:write
benefit_offer:read: benefit_offer:read
employment_documents: employment_documents
onboarding:write: onboarding:write
payroll_run:read: payroll_run:read
risk_reserve:write: risk_reserve:write
invoices: invoices
resignation_letter:read: resignation_letter:read
resignation:read: resignation:read
convert_currency:read: convert_currency:read
employments: employments
probation_document:read: probation_document:read
company_admin: company_admin
payroll: payroll
help_center_article:read: help_center_article:read
timesheet:read: timesheet:read
custom_field_value:write: custom_field_value:write
company_currencies:read: company_currencies:read
payslip:read: payslip:read
pay_item:write: pay_item:write
resignation:write: resignation:write
custom_field:read: custom_field:read
payroll_calendar:read: payroll_calendar:read
contract_amendment:write: contract_amendment:write
offboarding:read: offboarding:read
timeoff:read: timeoff:read
probation_document:write: probation_document:write
country:read: country:read
webhook:read: webhook:read
company_department:write: company_department:write
company_manager:read: company_manager:read
pay_item:read: pay_item:read
contract_amendment:read: contract_amendment:read
company:read: company:read
sso_configuration:write: sso_configuration:write
benefit_offer:write: benefit_offer:write
contract_eligibility:write: contract_eligibility:write
benefit_renewal:read: benefit_renewal:read
background_check:read: background_check:read
custom_field_value:read: custom_field_value:read
expense:write: expense:write
identity_verification:read: identity_verification:read
address:read: address:read
document:write: document:write
time_and_attendance: time_and_attendance
employment_payments: employment_payments
form:read: form:read
work_authorization:read: work_authorization:read
invoices:read: invoices:read
incentive:write: incentive:write
employment:read: employment:read
contract:read: contract:read
company_manager:write: company_manager:write
travel_letter:read: travel_letter:read
document:read: document:read
sso_configuration:read: sso_configuration:read
tokenUrl: /auth/oauth2/token
clientCredentials:
scopes:
company:read: company:read
company:write: company:write
company_admin: company_admin
company_management: company_management
convert_currency:read: convert_currency:read
country:read: country:read
employment_documents: employment_documents
employment_payments: employment_payments
employments: employments
help_center_article:read: help_center_article:read
invoices: invoices
payroll: payroll
payroll_calendar:read: payroll_calendar:read
pricing_plan:read: pricing_plan:read
pricing_plan:write: pricing_plan:write
time_and_attendance: time_and_attendance
webhook:read: webhook:read
webhook:write: webhook:write
tokenUrl: /auth/oauth2/token
type: oauth2
OAuth2Assertion:
description: 'Authenticate as the employee using the `urn:ietf:params:oauth:grant-type:jwt-bearer` grant in the OAuth2 protocol.
'
flows:
clientCredentials:
scopes:
address:read: address:read
address:write: address:write
bank_account:read: bank_account:read
bank_account:write: bank_account:write
document:read: document:read
document:write: document:write
emergency_contact:read: emergency_contact:read
emergency_contact:write: emergency_contact:write
employment_documents: employment_documents
employment_payments: employment_payments
employments: employments
expense:read: expense:read
incentive:read: incentive:read
payroll: payroll
payslip:read: payslip:read
personal_detail:read: personal_detail:read
personal_detail:write: personal_detail:write
time_and_attendance: time_and_attendance
timeoff:read: timeoff:read
timeoff:write: timeoff:write
timesheet:read: timesheet:read
tokenUrl: /auth/oauth2/token
x-assertionType: urn:ietf:params:oauth:client-assertion-type:jwt-bearer
type: oauth2
OAuth2AuthorizationCode:
description: 'Authenticate as the token authorizer using `authorization_code` / `refresh_token` grants in the OAuth 2.0 protocol.
'
flows:
authorizationCode:
authorizationUrl: /auth/oauth2/authorize
refreshUrl: /auth/oauth2/token
scopes:
company_department:read: company_department:read
webhook:write: webhook:write
magic_link:write: magic_link:write
offboarding:write: offboarding:write
custom_field:write: custom_field:write
address:write: address:write
expense:read: expense:read
employment:write: employment:write
identity_verification:write: identity_verification:write
timesheet:write: timesheet:write
travel_letter:write: travel_letter:write
incentive:read: incentive:read
personal_detail:read: personal_detail:read
invoices:write: invoices:write
work_authorization:write: work_authorization:write
timeoff:write: timeoff:write
company_structure:read: company_structure:read
benefit_renewal:write: benefit_renewal:write
benefit_offer:read: benefit_offer:read
employment_documents: employment_documents
onboarding:write: onboarding:write
payroll_run:read: payroll_run:read
risk_reserve:write: risk_reserve:write
invoices: invoices
resignation_letter:read: resignation_letter:read
resignation:read: resignation:read
convert_currency:read: convert_currency:read
employments: employments
probation_document:read: probation_document:read
company_admin: company_admin
payroll: payroll
help_center_article:read: help_center_article:read
timesheet:read: timesheet:read
custom_field_value:write: custom_field_value:write
company_currencies:read: company_currencies:read
payslip:read: payslip:read
pay_item:write: pay_item:write
resignation:write: resignation:write
custom_field:read: custom_field:read
payroll_calendar:read: payroll_calendar:read
contract_amendment:write: contract_amendment:write
offboarding:read: offboarding:read
timeoff:read: timeoff:read
probation_document:write: probation_document:write
country:read: country:read
webhook:read: webhook:read
company_department:write: company_department:write
company_manager:read: company_manager:read
pay_item:read: pay_item:read
contract_amendment:read: contract_amendment:read
company:read: company:read
sso_configuration:write: sso_configuration:write
benefit_offer:write: benefit_offer:write
contract_eligibility:write: contract_eligibility:write
benefit_renewal:read: benefit_renewal:read
background_check:read: background_check:read
custom_field_value:read: custom_field_value:read
expense:write: expense:write
identity_verification:read: identity_verification:read
address:read: address:read
document:write: document:write
time_and_attendance: time_and_attendance
employment_payments: employment_payments
form:read: form:read
work_authorization:read: work_authorization:read
invoices:read: invoices:read
incentive:write: incentive:write
employment:read: employment:read
contract:read: contract:read
company_manager:write: company_manager:write
travel_letter:read: travel_letter:read
document:read: document:read
sso_configuration:read: sso_configuration:read
tokenUrl: /auth/oauth2/token
type: oauth2
OAuth2ClientCredentials:
description: 'Authenticate using `client_credentials` grant in the OAuth 2.0 protocol.
'
flows:
clientCredentials:
scopes:
company:read: company:read
company:write: company:write
company_admin: company_admin
company_management: company_management
convert_currency:read: convert_currency:read
country:read: country:read
employment_documents: employment_documents
employment_payments: employment_payments
employments: employments
help_center_article:read: help_center_article:read
invoices: invoices
payroll: payroll
payroll_calendar:read: payroll_calendar:read
pricing_plan:read: pricing_plan:read
pricing_plan:write: pricing_plan:write
time_and_attendance: time_and_attendance
webhook:read: webhook:read
webhook:write: webhook:write
tokenUrl: /auth/oauth2/token
type: oauth2