Stytch B2B IDP API

The B2B IDP API from Stytch — 2 operation(s) for b2b idp.

OpenAPI Specification

stytch-b2b-idp-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: Stytch B2B Authentication Application B2B IDP API
  version: 2.0.0
  description: Stytch's B2B API for multi-tenant authentication. Supports Organizations, Members, SSO (SAML/OIDC), Magic Links, OTP, OAuth, Discovery, Sessions, B2B RBAC, SCIM, TOTP, Recovery Codes, Passwords, Impersonation, and the B2B IDP.
  contact:
    name: Stytch
    url: https://stytch.com/docs
  license:
    name: Proprietary
servers:
- url: https://api.stytch.com
  description: Production
- url: https://test.stytch.com
  description: Test
tags:
- name: B2B IDP
paths:
  /v1/b2b/idp/oauth/authorize/start:
    post:
      summary: Authorizestart
      operationId: api_b2b_idp_v1_b2b_idp_oauth_AuthorizeStart
      tags:
      - B2B IDP
      description: 'Initiates a request for authorization of a Connected App to access a Member''s account.


        Call this endpoint using the query parameters from an OAuth Authorization request.

        This endpoint validates various fields (`scope`, `client_id`, `redirect_uri`, `prompt`, etc...) are correct and returns

        relevant information for rendering an OAuth Consent Screen.


        This endpoint returns:

        - A public representation of the Connected App requesting authorization

        - Whether _explicit_ consent must be granted before proceeding with the authorization

        - A list of scopes the Member has the ability to grant the Connected App


        Use this response to prompt the Member for consent (if necessary) before calling the [Submit OAuth Authorization](https://stytch.com/docs/b2b/api/connected-apps-oauth-authorize) endpoint.


        Exactly one of the following must be provided to identify the Member granting authorization:

        - `organization_id` + `member_id`

        - `session_token`

        - `session_jwt`


        If a `session_token` or `session_jwt` is passed, the OAuth Authorization will be linked to the Member''s session for tracking purposes.

        One of these fields must be used if the Connected App intends to complete the [Exchange Access Token](https://stytch.com/docs/b2b/api/connected-app-access-token-exchange) flow.'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/api_b2b_idp_v1_b2b_idp_oauth_AuthorizeStartRequest'
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/api_b2b_idp_v1_b2b_idp_oauth_AuthorizeStartResponse'
        '400':
          description: Bad request
        '401':
          description: Unauthorized
          content:
            application/json:
              example:
                status_code: 401
                request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141
                error_type: unauthorized_credentials
                error_message: Unauthorized credentials.
                error_url: https://stytch.com/docs/api/errors/401
        '429':
          description: Too Many Requests
          content:
            application/json:
              example:
                status_code: 429
                request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141
                error_type: too_many_requests
                error_message: Too many requests have been made.
                error_url: https://stytch.com/docs/api/errors/429
        '500':
          description: Internal server error
          content:
            application/json:
              example:
                status_code: 500
                request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141
                error_type: internal_server_error
                error_message: Oops, something seems to have gone wrong, please reach out to support@stytch.com to let us know what went wrong.
                error_url: https://stytch.com/docs/api/errors/500
      x-code-samples:
      - lang: csharp
        label: C#
        source: "// POST /v1/b2b/idp/oauth/authorize/start\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n  project_id: '${projectId}',\n  secret: '${secret}',\n});\n\nconst params = {\n  client_id: \"${exampleConnectedAppClientID}\",\n  redirect_uri: \"https://app.example/oauth/callback\",\n  response_type: \"code\",\n  scopes: [\"openid\"],\n};\n\nclient.IDP.OAuth.AuthorizeStart(params)\n  .then(resp => { console.log(resp) })\n  .catch(err => { console.log(err) });"
      - lang: go
        label: Go
        source: "// POST /v1/b2b/idp/oauth/authorize/start\npackage main\n\nimport (\n\t\"context\"\n\t\"log\"\n\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/b2bstytchapi\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/idp/oauth\"\n)\n\nfunc main() {\n\tclient, err := b2bstytchapi.NewClient(\n\t\t\"${projectId}\",\n\t\t\"${secret}\",\n\t)\n\tif err != nil {\n\t\tlog.Fatalf(\"error instantiating client: %v\", err)\n\t}\n\n\tparams := &oauth.AuthorizeStartParams{\n\t\tClientID:     \"${exampleConnectedAppClientID}\",\n\t\tRedirectURI:  \"https://app.example/oauth/callback\",\n\t\tResponseType: \"code\",\n\t\tScopes:       []string{\"openid\"},\n\t}\n\n\tresp, err := client.IDP.OAuth.AuthorizeStart(context.Background(), params)\n\tif err != nil {\n\t\tlog.Fatalf(\"error in method call: %v\", err)\n\t}\n\n\tlog.Println(resp)\n}\n"
      - lang: java
        label: Java
        source: "// POST /v1/b2b/idp/oauth/authorize/start\npackage com.example;\n\nimport com.stytch.java.b2b.models.idpoauth.AuthorizeStartRequest;\nimport com.stytch.java.b2b.StytchB2BClient;\nimport com.stytch.java.common.StytchResult;\n\npublic class Main {\n    public static void main(String[] args) {\n        StytchB2BClient.configure(\"${projectId}\", \"${secret}\");\n\n        AuthorizeStartRequest params = new AuthorizeStartRequest();\n        params.setClientId(\"${exampleConnectedAppClientID}\");\n        params.setRedirectUri(\"https://app.example/oauth/callback\");\n        params.setResponseType(\"code\");\n        params.setScopes(new String(\"openid\"));\n\n        Object result = StytchB2BClient.getIDP().getOAuth().authorizeStart(params);\n        if (result instanceof StytchResult.Success) {\n          System.out.println(((StytchResult.Success) result).getValue());\n        } else {\n          System.out.println(((StytchResult.Error) result).getException());\n        }\n    }\n}"
      - lang: kotlin
        label: Kotlin
        source: "// POST /v1/b2b/idp/oauth/authorize/start\npackage com.example\n\nimport com.stytch.java.b2b.StytchB2BClient\nimport com.stytch.java.b2b.models.idpoauth.AuthorizeStartRequest\n\nfun main() {\n    StytchB2BClient.configure(\n        projectId = \"${projectId}\",\n        secret = \"${secret}\",\n    )\n\n    when (\n        val result =\n            StytchB2BClient.idp.oauth.authorizeStart(\n                AuthorizeStartRequest(\n                    clientId = \"${exampleConnectedAppClientID}\",\n                    redirectUri = \"https://app.example/oauth/callback\",\n                    responseType = \"code\",\n                    scopes = arrayOf(\"openid\"),\n                ),\n            )\n    ) {\n        is StytchResult.Success -> println(result.value)\n        is StytchResult.Error -> println(result.exception)\n    }\n}\n"
      - lang: javascript
        label: Node.js
        source: "// POST /v1/b2b/idp/oauth/authorize/start\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n  project_id: '${projectId}',\n  secret: '${secret}',\n});\n\nconst params = {\n  client_id: \"${exampleConnectedAppClientID}\",\n  redirect_uri: \"https://app.example/oauth/callback\",\n  response_type: \"code\",\n  scopes: [\"openid\"],\n};\n\nclient.idp.oauth.authorizeStart(params)\n  .then(resp => { console.log(resp) })\n  .catch(err => { console.log(err) });"
      - lang: php
        label: PHP
        source: "$response = $client->idp->oauth->authorize_start([\n    'client_id' => '${exampleConnectedAppClientID}',\n    'redirect_uri' => 'https://app.example/oauth/callback',\n    'response_type' => 'code',\n    'scopes' => ['openid'],\n]);"
      - lang: python
        label: Python
        source: "# POST /v1/b2b/idp/oauth/authorize/start\nfrom stytch import B2BClient\n\nclient = B2BClient(\n    project_id=\"${projectId}\",\n    secret=\"${secret}\",\n)\n\nresp = client.idp.oauth.authorize_start(\n    client_id=\"${exampleConnectedAppClientID}\",\n    redirect_uri=\"https://app.example/oauth/callback\",\n    response_type=\"code\",\n    scopes=[\"openid\"],\n)\n\nprint(resp)\n"
      - lang: ruby
        label: Ruby
        source: "# POST /v1/b2b/idp/oauth/authorize/start\nrequire 'stytch'\n\nclient = StytchB2B::Client.new(\n  project_id: \"${projectId}\",\n  secret: \"${secret}\"\n)\n\nresp = client.idp.oauth.authorize_start(\n  client_id: \"${exampleConnectedAppClientID}\",\n  redirect_uri: \"https://app.example/oauth/callback\",\n  response_type: \"code\",\n  scopes: ['openid']\n  \n)\n\nputs resp"
      - lang: rust
        label: Rust
        source: "// POST /v1/b2b/idp/oauth/authorize/start\nuse stytch::b2b::client::Client;\nuse stytch::b2b::idp_oauth::AuthorizeStartRequest;\n\nfn main() {\n    let client = Client::new(\"${projectId}\", \"${secret}\").unwrap();\n    let resp = client.idp.oauth.authorize_start(\n        AuthorizeStartRequest{\n            client_id: \"${exampleConnectedAppClientID}\",\n            redirect_uri: \"https://app.example/oauth/callback\",\n            response_type: \"code\",\n            scopes: vec![\"openid\"],\n            ..Default::default()\n        }\n    ).await;\n    println!(\"The response is {:?}\", resp);\n}"
      - lang: bash
        label: cURL
        source: "# POST /v1/b2b/idp/oauth/authorize/start\ncurl --request POST \\\n  --url https://test.stytch.com/v1/b2b/idp/oauth/authorize/start \\\n  -u '${projectId}:${secret}' \\\n  -H 'Content-Type: application/json' \\\n  -d '{\n    \"client_id\": \"${exampleConnectedAppClientID}\",\n    \"redirect_uri\": \"https://app.example/oauth/callback\",\n    \"response_type\": \"code\",\n    \"scopes\": [\"openid\"]\n  }'"
  /v1/b2b/idp/oauth/authorize:
    post:
      summary: Authorize
      operationId: api_b2b_idp_v1_b2b_idp_oauth_Authorize
      tags:
      - B2B IDP
      description: 'Completes a request for authorization of a Connected App to access a Member''s account.


        Call this endpoint using the query parameters from an OAuth Authorization request, after previously validating those parameters using the

        [Preflight Check](https://stytch.com/docs/b2b/api/connected-apps-oauth-authorize-start) API.

        Note that this endpoint takes in a few additional parameters the preflight check does not- `state`, `nonce`, and `code_challenge`.


        If the authorization was successful, the `redirect_uri` will contain a valid `authorization_code` embedded as a query parameter.

        If the authorization was unsuccessful, the `redirect_uri` will contain an OAuth2.1 `error_code`.

        In both cases, redirect the Member to the location for the response to be consumed by the Connected App.


        Exactly one of the following must be provided to identify the Member granting authorization:

        - `organization_id` + `member_id`

        - `session_token`

        - `session_jwt`


        If a `session_token` or `session_jwt` is passed, the OAuth Authorization will be linked to the Member''s session for tracking purposes.

        One of these fields must be used if the Connected App intends to complete the [Exchange Access Token](https://stytch.com/docs/b2b/api/connected-app-access-token-exchange) flow.'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/api_b2b_idp_v1_b2b_idp_oauth_AuthorizeRequest'
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/api_b2b_idp_v1_b2b_idp_oauth_AuthorizeResponse'
        '400':
          description: Bad request
        '401':
          description: Unauthorized
          content:
            application/json:
              example:
                status_code: 401
                request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141
                error_type: unauthorized_credentials
                error_message: Unauthorized credentials.
                error_url: https://stytch.com/docs/api/errors/401
        '429':
          description: Too Many Requests
          content:
            application/json:
              example:
                status_code: 429
                request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141
                error_type: too_many_requests
                error_message: Too many requests have been made.
                error_url: https://stytch.com/docs/api/errors/429
        '500':
          description: Internal server error
          content:
            application/json:
              example:
                status_code: 500
                request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141
                error_type: internal_server_error
                error_message: Oops, something seems to have gone wrong, please reach out to support@stytch.com to let us know what went wrong.
                error_url: https://stytch.com/docs/api/errors/500
      x-code-samples:
      - lang: csharp
        label: C#
        source: "// POST /v1/b2b/idp/oauth/authorize\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n  project_id: '${projectId}',\n  secret: '${secret}',\n});\n\nconst params = {\n  consent_granted: true,\n  scopes: [\"openid\"],\n  client_id: \"${exampleConnectedAppClientID}\",\n  redirect_uri: \"https://app.example/oauth/callback\",\n  response_type: \"code\",\n};\n\nclient.IDP.OAuth.Authorize(params)\n  .then(resp => { console.log(resp) })\n  .catch(err => { console.log(err) });"
      - lang: go
        label: Go
        source: "// POST /v1/b2b/idp/oauth/authorize\npackage main\n\nimport (\n\t\"context\"\n\t\"log\"\n\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/b2bstytchapi\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/idp/oauth\"\n)\n\nfunc main() {\n\tclient, err := b2bstytchapi.NewClient(\n\t\t\"${projectId}\",\n\t\t\"${secret}\",\n\t)\n\tif err != nil {\n\t\tlog.Fatalf(\"error instantiating client: %v\", err)\n\t}\n\n\tparams := &oauth.AuthorizeParams{\n\t\tConsentGranted: true,\n\t\tScopes:         []string{\"openid\"},\n\t\tClientID:       \"${exampleConnectedAppClientID}\",\n\t\tRedirectURI:    \"https://app.example/oauth/callback\",\n\t\tResponseType:   \"code\",\n\t}\n\n\tresp, err := client.IDP.OAuth.Authorize(context.Background(), params)\n\tif err != nil {\n\t\tlog.Fatalf(\"error in method call: %v\", err)\n\t}\n\n\tlog.Println(resp)\n}\n"
      - lang: java
        label: Java
        source: "// POST /v1/b2b/idp/oauth/authorize\npackage com.example;\n\nimport com.stytch.java.b2b.models.idpoauth.AuthorizeRequest;\nimport com.stytch.java.b2b.StytchB2BClient;\nimport com.stytch.java.common.StytchResult;\n\npublic class Main {\n    public static void main(String[] args) {\n        StytchB2BClient.configure(\"${projectId}\", \"${secret}\");\n\n        AuthorizeRequest params = new AuthorizeRequest();\n        params.setConsentGranted(true);\n        params.setScopes(new String(\"openid\"));\n        params.setClientId(\"${exampleConnectedAppClientID}\");\n        params.setRedirectUri(\"https://app.example/oauth/callback\");\n        params.setResponseType(\"code\");\n\n        Object result = StytchB2BClient.getIDP().getOAuth().authorize(params);\n        if (result instanceof StytchResult.Success) {\n          System.out.println(((StytchResult.Success) result).getValue());\n        } else {\n          System.out.println(((StytchResult.Error) result).getException());\n        }\n    }\n}"
      - lang: kotlin
        label: Kotlin
        source: "// POST /v1/b2b/idp/oauth/authorize\npackage com.example\n\nimport com.stytch.java.b2b.StytchB2BClient\nimport com.stytch.java.b2b.models.idpoauth.AuthorizeRequest\n\nfun main() {\n    StytchB2BClient.configure(\n        projectId = \"${projectId}\",\n        secret = \"${secret}\",\n    )\n\n    when (\n        val result =\n            StytchB2BClient.idp.oauth.authorize(\n                AuthorizeRequest(\n                    consentGranted = true,\n                    scopes = arrayOf(\"openid\"),\n                    clientId = \"${exampleConnectedAppClientID}\",\n                    redirectUri = \"https://app.example/oauth/callback\",\n                    responseType = \"code\",\n                ),\n            )\n    ) {\n        is StytchResult.Success -> println(result.value)\n        is StytchResult.Error -> println(result.exception)\n    }\n}\n"
      - lang: javascript
        label: Node.js
        source: "// POST /v1/b2b/idp/oauth/authorize\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n  project_id: '${projectId}',\n  secret: '${secret}',\n});\n\nconst params = {\n  consent_granted: true,\n  scopes: [\"openid\"],\n  client_id: \"${exampleConnectedAppClientID}\",\n  redirect_uri: \"https://app.example/oauth/callback\",\n  response_type: \"code\",\n};\n\nclient.idp.oauth.authorize(params)\n  .then(resp => { console.log(resp) })\n  .catch(err => { console.log(err) });"
      - lang: php
        label: PHP
        source: "$response = $client->idp->oauth->authorize([\n    'consent_granted' => true,\n    'scopes' => ['openid'],\n    'client_id' => '${exampleConnectedAppClientID}',\n    'redirect_uri' => 'https://app.example/oauth/callback',\n    'response_type' => 'code',\n]);"
      - lang: python
        label: Python
        source: "# POST /v1/b2b/idp/oauth/authorize\nfrom stytch import B2BClient\n\nclient = B2BClient(\n    project_id=\"${projectId}\",\n    secret=\"${secret}\",\n)\n\nresp = client.idp.oauth.authorize(\n    consent_granted=True,\n    scopes=[\"openid\"],\n    client_id=\"${exampleConnectedAppClientID}\",\n    redirect_uri=\"https://app.example/oauth/callback\",\n    response_type=\"code\",\n)\n\nprint(resp)\n"
      - lang: ruby
        label: Ruby
        source: "# POST /v1/b2b/idp/oauth/authorize\nrequire 'stytch'\n\nclient = StytchB2B::Client.new(\n  project_id: \"${projectId}\",\n  secret: \"${secret}\"\n)\n\nresp = client.idp.oauth.authorize(\n  consent_granted: true,\n  scopes: ['openid'],\n  client_id: \"${exampleConnectedAppClientID}\",\n  redirect_uri: \"https://app.example/oauth/callback\",\n  response_type: \"code\"\n  \n)\n\nputs resp"
      - lang: rust
        label: Rust
        source: "// POST /v1/b2b/idp/oauth/authorize\nuse stytch::b2b::client::Client;\nuse stytch::b2b::idp_oauth::AuthorizeRequest;\n\nfn main() {\n    let client = Client::new(\"${projectId}\", \"${secret}\").unwrap();\n    let resp = client.idp.oauth.authorize(\n        AuthorizeRequest{\n            consent_granted: true,\n            scopes: vec![\"openid\"],\n            client_id: \"${exampleConnectedAppClientID}\",\n            redirect_uri: \"https://app.example/oauth/callback\",\n            response_type: \"code\",\n            ..Default::default()\n        }\n    ).await;\n    println!(\"The response is {:?}\", resp);\n}"
      - lang: bash
        label: cURL
        source: "# POST /v1/b2b/idp/oauth/authorize\ncurl --request POST \\\n  --url https://test.stytch.com/v1/b2b/idp/oauth/authorize \\\n  -u '${projectId}:${secret}' \\\n  -H 'Content-Type: application/json' \\\n  -d '{\n    \"consent_granted\": true,\n    \"scopes\": [\"openid\"],\n    \"client_id\": \"${exampleConnectedAppClientID}\",\n    \"redirect_uri\": \"https://app.example/oauth/callback\",\n    \"response_type\": \"code\"\n  }'"
components:
  schemas:
    api_b2b_idp_v1_b2b_idp_oauth_AuthorizeRequest:
      type: object
      properties:
        consent_granted:
          type: boolean
          description: Indicates whether the user granted the requested scopes.
        scopes:
          type: array
          items:
            type: string
          description: An array of scopes requested by the client.
        client_id:
          type: string
          description: The ID of the Connected App client.
        redirect_uri:
          type: string
          description: The callback URI used to redirect the user after authentication. This is the same URI provided at the start of the OAuth flow.  This field is required when using the `authorization_code` grant.
        response_type:
          type: string
          description: The OAuth 2.0 response type. For authorization code flows this value is `code`.
        organization_id:
          type: string
          description: Globally unique UUID that identifies a specific Organization. The `organization_id` is critical to perform operations on an Organization, so be sure to preserve this value. You may also use the organization_slug or organization_external_id here as a convenience.
        member_id:
          type: string
          description: Globally unique UUID that identifies a specific Member. The `member_id` is critical to perform operations on a Member, so be sure to preserve this value. You may use an external_id here if one is set for the member.
        session_token:
          type: string
          description: A secret token for a given Stytch Session.
        session_jwt:
          type: string
          description: The JSON Web Token (JWT) for a given Stytch Session.
        prompt:
          type: string
          description: Space separated list that specifies how the Authorization Server should prompt the user for reauthentication and consent. Only `consent` is supported today.
        state:
          type: string
          description: An opaque value used to maintain state between the request and callback.
        nonce:
          type: string
          description: A string used to associate a client session with an ID token to mitigate replay attacks.
        code_challenge:
          type: string
          description: A base64url encoded challenge derived from the code verifier for PKCE flows.
        resources:
          type: array
          items:
            type: string
      description: Request type
      required:
      - consent_granted
      - scopes
      - client_id
      - redirect_uri
      - response_type
    api_b2b_scim_v1_IMs:
      type: object
      properties:
        value:
          type: string
        type:
          type: string
        primary:
          type: boolean
      required:
      - value
      - type
      - primary
    api_b2b_scim_v1_SCIMAttributes:
      type: object
      properties:
        user_name:
          type: string
        id:
          type: string
        external_id:
          type: string
        active:
          type: boolean
        groups:
          type: array
          items:
            $ref: '#/components/schemas/api_b2b_scim_v1_Group'
        display_name:
          type: string
        nick_name:
          type: string
        profile_url:
          type: string
        user_type:
          type: string
        title:
          type: string
        preferred_language:
          type: string
        locale:
          type: string
        timezone:
          type: string
        emails:
          type: array
          items:
            $ref: '#/components/schemas/api_b2b_scim_v1_Email'
        phone_numbers:
          type: array
          items:
            $ref: '#/components/schemas/api_b2b_scim_v1_PhoneNumber'
        addresses:
          type: array
          items:
            $ref: '#/components/schemas/api_b2b_scim_v1_Address'
        ims:
          type: array
          items:
            $ref: '#/components/schemas/api_b2b_scim_v1_IMs'
        photos:
          type: array
          items:
            $ref: '#/components/schemas/api_b2b_scim_v1_Photo'
        entitlements:
          type: array
          items:
            $ref: '#/components/schemas/api_b2b_scim_v1_Entitlement'
        roles:
          type: array
          items:
            $ref: '#/components/schemas/api_b2b_scim_v1_Role'
        x509certificates:
          type: array
          items:
            $ref: '#/components/schemas/api_b2b_scim_v1_X509Certificate'
        name:
          $ref: '#/components/schemas/api_b2b_scim_v1_Name'
        enterprise_extension:
          $ref: '#/components/schemas/api_b2b_scim_v1_EnterpriseExtension'
      required:
      - user_name
      - id
      - external_id
      - active
      - groups
      - display_name
      - nick_name
      - profile_url
      - user_type
      - title
      - preferred_language
      - locale
      - timezone
      - emails
      - phone_numbers
      - addresses
      - ims
      - photos
      - entitlements
      - roles
      - x509certificates
    api_organization_v1_MemberRoleSource:
      type: object
      properties:
        type:
          type: string
          description: "The type of role assignment. The possible values are:\n \n  `direct_assignment` – an explicitly assigned Role.\n\n  Directly assigned roles can be updated by passing in the `roles` argument to the\n  [Update Member](https://stytch.com/docs/b2b/api/update-member) endpoint.\n \n  `email_assignment` – an implicit Role granted by the Member's email domain, regardless of their login method.\n\n  Email implicit role assignments can be updated by passing in the `rbac_email_implicit_role_assignments` argument to\n  the [Update Organization](https://stytch.com/docs/b2b/api/update-organization) endpoint.\n \n  `sso_connection` – an implicit Role granted by the Member's SSO connection. This is currently only available\n  for SAML connections and not for OIDC. If the Member has a SAML Member registration with the given connection, this\n  role assignment will appear in the list. However, for authorization check purposes (in\n  [sessions authenticate](https://stytch.com/docs/b2b/api/authenticate-session) or in any endpoint that enforces RBAC with session\n  headers), the Member will only be granted the Role if their session contains an authentication factor with the\n  specified SAML connection.\n\n  SAML connection implicit role assignments can be updated by passing in the\n  `saml_connection_implicit_role_assignments` argument to the\n  [Update SAML connection](https://stytch.com/docs/b2b/api/update-saml-connection) endpoint.\n \n  `sso_connection_group` – an implicit Role granted by the Member's SSO connection and group. This is currently only\n  available for SAML connections and not for OIDC. If the Member has a SAML Member registration with the given\n  connection, and belongs to a specific group within the IdP, this role assignment will appear in the list. However,\n  for authorization check purposes (in [sessions authenticate](https://stytch.com/docs/b2b/api/authenticate-session) or in any endpoint\n  that enforces RBAC with session headers), the Member will only be granted the role if their session contains an\n  authentication factor with the specified SAML connection.\n\n  SAML group implicit role assignments can be updated by passing in the `saml_group_implicit_role_assignments`\n  argument to the [Update SAML connection](https://stytch.com/docs/b2b/api/update-saml-connection) endpoint.\n\n    `scim_connection_group` – an implicit Role granted by the Member's SCIM connection and group. If the Member has\n  a SCIM Member registration with the given connection, and belongs to a specific group within the IdP, this role assignment will appear in the list.\n\n  SCIM group implicit role assignments can be updated by passing in the `scim_group_implicit_role_assignments`\n  argument to the [Update SCIM connection](https://stytch.com/docs/b2b/api/update-scim-connection) endpoint.\n  "
        details:
          type: object
          additionalProperties: true
          description: "An object containing additional metadata about the source assignment. The fields will vary depending\n  on the role assignment type as follows:\n \n  `direct_assignment` – no additional details.\n \n  `email_assignment` – will contain the email domain that granted the assignment.\n  \n  `sso_connection` – will contain the `connection_id` of the SAML connection that granted the assignment.\n \n  `sso_connection_group` – will contain the `connection_id` of the SAML connection and the name of the `group`\n  that granted the assignment.\n \n  `scim_connection_group` – will contain the `connection_id` of the SAML connection and the `group_id`\n  that granted the assignment.\n  "
      required:
      - type
    api_b2b_scim_v1_Entitlement:
      type: object
      properties:
        value:
          type: string
        type:
          type: string
        primary:
          type: boolean
      required:
      - value
      - type
      - primary
    api_b2b_scim_v1_X509Certificate:
      type: object
      properties:
        value:
          type: string
        type:
          type: string
        primary:
          type: boolean
      required:
      - value
      - type
      - primary
    api_organization_v1_SCIMRegistration:
      type: object
      properties:
        connection_id:
          type: string
          description: The ID of the SCIM connection.
        registration_id:
          type: string
          description: The unique ID of a SCIM Registration.
        external_id:
          type: string
          description: The ID of the member given by the identity provider.
        scim_attributes:
          $ref: '#/components/schemas/api_b2b_scim_v1_SCIMAttributes'
          description: An object for storing SCIM attributes brought over from the identity provider.
      required:
      - connection_id
      - registration_id
    api_b2b_idp_v1_b2b_idp_oauth_AuthorizeResponse:
      type: object
      properties:
        request_id:
          type: string
          description: Globally unique UUID that is returned with every API call. This value is important to log for debugging purposes; we may ask for this value to help identify a specific API call when helping you debug an issue.
        redirect_uri:
          type: string
          description: The callback URI used to redirect the user after authentication. This is the same URI provided at the start of the OAuth flow.  This field is required when using the `authorization_code` grant.
        status_code:
          type: integer
          format: int32
        authorization_code:
          type: string
          description: A one-time use code that can be exchanged for tokens.
      required:
      - request_id
      - redirect_uri
      - status_code
    api_b2b_scim_v1_Email:
      type: object
      properties:
        value:
          type: string
        type:
          type: string
        primary:
          type: boolean
      required:
      - value
      - type
      - primary
    api_organization_v1_Organization:
      type: object
      properties:
        organization_id:
          type: string
          description: Globally unique UUID that identifies a specific Organization. The `organization_id` is critical to perform operations on an Organization, so be sure to preserve this value. You may also use the organization_slug or organization_external_id here as a convenience.
        organization_name:
          type: string
          description: The name of the Organization. Must be between 1 and 128 characters in length.
        organization_logo_url:
          type: string
          description: The image URL of the Organization logo.
        organization_slug:
          type: string
          description: 'The unique URL slug of the Organization. The slug only accepts alphanumeric characters and the following reserved characters: `-` `.` `_` `~`. Must be between 2 and 128 characters in length. Wherever an organization_id is expected in a path or request parameter, you may also use the organization_slug as a convenience.'
        sso_jit_provisioning:
          type: string
          description: "The authentication setting that controls the JIT provisioning of Members when authenticating via SSO. The accepted values are:\n \n  `ALL_ALLOWED` – the default setting, new Members will be automatically provisioned upon successful authentication via any of the Organization's `sso_active_connections`.\n \n  `RESTRICTED` – only new Members wit

# --- truncated at 32 KB (61 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/stytch/refs/heads/main/openapi/stytch-b2b-idp-api-openapi.yml