Sumo Logic Saml Configuration Management API

SAML configuration management API Organizations with Enterprise accounts can provision Security Assertion Markup Language (SAML) 2.0 to enable Single Sign-On (SSO) for user access to Sumo Logic. For more information, see [SAML Configuration](https://help.sumologic.com/?cid=4016).

Business capability
Identity & Access Management BC-620.20

Operations 10

GET /v1/saml/identityProviders Get A List Of SAML Configurations #
POST /v1/saml/identityProviders Create A New SAML Configuration #
PUT /v1/saml/identityProviders/{id} Update A SAML Configuration #
DELETE /v1/saml/identityProviders/{id} Delete A SAML Configuration #
GET /v1/saml/allowlistedUsers Get List Of Allowlisted Users #
POST /v1/saml/allowlistedUsers/{userId} Allowlist A User #
DELETE /v1/saml/allowlistedUsers/{userId} Remove An Allowlisted User #
POST /v1/saml/lockdown/enable Require SAML For Sign-in #
POST /v1/saml/lockdown/disable Disable SAML Lockdown #
GET /v1/saml/identityProviders/{id}/metadata Get SAML Configuration Metadata XML #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/sumo-logic-samlconfigurationmanagement-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

sumo-logic-samlconfigurationmanagement-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Sumo Logic Saml Configuration Management API
  description: '# Getting Started

    Welcome to the Sumo Logic API reference.'
  version: 1.0.0
  x-logo:
    url: ./sumologic_logo.png
servers:
- url: https://api.au.sumologic.com/api/
  description: AU deployment API server
- url: https://api.ca.sumologic.com/api/
  description: CA deployment API server
- url: https://api.de.sumologic.com/api/
  description: DE deployment API server
- url: https://api.eu.sumologic.com/api/
  description: EU deployment API server
- url: https://api.fed.sumologic.com/api/
  description: FED deployment API server
- url: https://api.jp.sumologic.com/api/
  description: JP deployment API server
- url: https://api.kr.sumologic.com/api/
  description: KR deployment API server
- url: https://api.in.sumologic.com/api/
  description: IN deployment API server
- url: https://api.sumologic.com/api/
  description: US1 deployment API server
- url: https://api.us2.sumologic.com/api/
  description: US2 deployment API server
security:
- basicAuth: []
tags:
- name: samlConfigurationManagement
  description: 'SAML configuration management API


    Organizations with Enterprise accounts can provision Security Assertion Markup Language (SAML) 2.0 to enable Single Sign-On (SSO) for user access to Sumo Logic. For more information, see SAML Configuration.'
  x-displayName: SAML Configuration
paths:
  /v1/saml/identityProviders:
    get:
      tags:
      - samlConfigurationManagement
      summary: Get A List Of SAML Configurations
      description: Get a list of all SAML configurations in the organization.
      operationId: getIdentityProviders
      responses:
        '200':
          description: A list of SAML configurations in the organization.
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/SamlIdentityProvider'
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
    post:
      tags:
      - samlConfigurationManagement
      summary: Create A New SAML Configuration
      description: Create a new SAML configuration in the organization.
      operationId: createIdentityProvider
      parameters: []
      requestBody:
        description: The configuration of the SAML identity provider.
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SamlIdentityProviderRequest'
        required: true
      responses:
        '200':
          description: The SAML configuration was successfully created.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SamlIdentityProvider'
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
  /v1/saml/identityProviders/{id}:
    put:
      tags:
      - samlConfigurationManagement
      summary: Update A SAML Configuration
      description: Update an existing SAML configuration in the organization.
      operationId: updateIdentityProvider
      parameters:
      - name: id
        in: path
        description: Identifier of the SAML configuration to update.
        required: true
        schema:
          type: string
      requestBody:
        description: Information to update in the SAML configuration.
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SamlIdentityProviderRequest'
        required: true
      responses:
        '200':
          description: The SAML configuration was successfully modified.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SamlIdentityProvider'
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
    delete:
      tags:
      - samlConfigurationManagement
      summary: Delete A SAML Configuration
      description: Delete a SAML configuration with the given identifier from the organization.
      operationId: deleteIdentityProvider
      parameters:
      - name: id
        in: path
        description: Identifier of the SAML configuration to delete.
        required: true
        schema:
          type: string
      responses:
        '204':
          description: The SAML configuration was deleted successfully.
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
  /v1/saml/allowlistedUsers:
    get:
      tags:
      - samlConfigurationManagement
      summary: Get List Of Allowlisted Users
      description: Get a list of allowlisted users.
      operationId: getAllowlistedUsers
      responses:
        '200':
          description: A list of allowlisted users from the organization.
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/AllowlistedUserResult'
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
  /v1/saml/allowlistedUsers/{userId}:
    post:
      tags:
      - samlConfigurationManagement
      summary: Allowlist A User
      description: Allowlist a user from SAML lockdown allowing them to sign in using a password in addition to SAML.
      operationId: createAllowlistedUser
      parameters:
      - name: userId
        in: path
        description: Identifier of the user.
        required: true
        schema:
          type: string
      responses:
        '200':
          description: User was successfully allowlisted.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AllowlistedUserResult'
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
    delete:
      tags:
      - samlConfigurationManagement
      summary: Remove An Allowlisted User
      description: Remove an allowlisted user requiring them to sign in using SAML.
      operationId: deleteAllowlistedUser
      parameters:
      - name: userId
        in: path
        description: Identifier of user that will no longer be allowlisted from SAML Lockdown.
        required: true
        schema:
          type: string
      responses:
        '204':
          description: User was successfully removed from the allowlist for SAML Lockdown.
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
  /v1/saml/lockdown/enable:
    post:
      tags:
      - samlConfigurationManagement
      summary: Require SAML For Sign-in
      description: Enabling SAML lockdown requires users to sign in using SAML preventing them from logging in with an email and password.
      operationId: enableSamlLockdown
      responses:
        '204':
          description: SAML lockdown was enabled successfully.
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
  /v1/saml/lockdown/disable:
    post:
      tags:
      - samlConfigurationManagement
      summary: Disable SAML Lockdown
      description: Disable SAML lockdown for the organization.
      operationId: disableSamlLockdown
      responses:
        '204':
          description: SAML lockdown was disabled successfully.
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
  /v1/saml/identityProviders/{id}/metadata:
    get:
      tags:
      - samlConfigurationManagement
      summary: Get SAML Configuration Metadata XML
      description: Get metadata XML for a specific SAML configuration within the organization.
      operationId: getSamlMetadata
      parameters:
      - name: id
        in: path
        description: Identifier of the SAML configuration for which metadata should be returned.
        required: true
        schema:
          type: string
      responses:
        '200':
          description: A SAML configuration metadata XML within the organization.
          content:
            application/xml:
              schema:
                type: string
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
components:
  schemas:
    MetadataModel:
      required:
      - createdAt
      - createdBy
      - modifiedAt
      - modifiedBy
      type: object
      properties:
        createdAt:
          type: string
          description: Creation timestamp in UTC in [RFC3339](https://tools.ietf.org/html/rfc3339) format.
          format: date-time
          example: 2018-10-16 09:10:00+00:00
        createdBy:
          type: string
          description: Identifier of the user who created the resource.
          example: 0000000006743FDD
        modifiedAt:
          type: string
          description: Last modification timestamp in UTC.
          format: date-time
          example: 2018-10-16 09:10:00+00:00
        modifiedBy:
          type: string
          description: Identifier of the user who last modified the resource.
          example: 0000000006743FE8
    ErrorResponse:
      required:
      - errors
      - id
      type: object
      properties:
        id:
          type: string
          description: An identifier for the error; this is unique to the specific API request.
          example: IUUQI-DGH5I-TJ045
        errors:
          type: array
          description: A list of one or more causes of the error.
          example:
          - code: auth:password_too_short
            message: Your password was too short.
          - code: auth:password_character_classes
            message: Your password did not contain any non-alphanumeric characters
          items:
            $ref: '#/components/schemas/ErrorDescription'
    ErrorDescription:
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: string
          description: An error code describing the type of error.
          example: auth:password_too_short
        message:
          type: string
          description: A short English-language description of the error.
          example: Your password was too short.
        detail:
          type: string
          description: An optional fuller English-language description of the error.
          example: Your password was 5 characters long, the minimum length is 12 characters. See http://example.com/password for more information.
        meta:
          type: object
          description: An optional list of metadata about the error.
          example:
            minLength: 12
            actualLength: 5
    AllowlistedUserResult:
      required:
      - canManageSaml
      - email
      - firstName
      - isActive
      - lastLogin
      - lastName
      - userId
      type: object
      properties:
        userId:
          type: string
          description: Unique identifier of the user.
        firstName:
          type: string
          description: First name of the user.
        lastName:
          type: string
          description: Last name of the user.
        email:
          type: string
          description: Email of the user.
          example: john@sumologic.com
        canManageSaml:
          type: boolean
          description: If the user can manage SAML Configurations.
        isActive:
          type: boolean
          description: Checks if the user is active.
        lastLogin:
          type: string
          description: Timestamp of the last login of the user.
          format: date-time
    AuthnCertificateResult:
      required:
      - certificate
      type: object
      properties:
        certificate:
          type: string
          description: Authentication Request Signing Certificate for the user.
    OnDemandProvisioningInfo:
      required:
      - onDemandProvisioningRoles
      type: object
      properties:
        firstNameAttribute:
          type: string
          description: First name attribute of the new user account.
          example: http://schemas.microsoft.com/ws/2008/06/identity/claims/givenname
          default: ''
        lastNameAttribute:
          type: string
          description: Last name attribute of the new user account.
          example: http://schemas.microsoft.com/ws/2008/06/identity/claims/surname
          default: ''
        onDemandProvisioningRoles:
          type: array
          description: Sumo Logic RBAC roles to be assigned when user accounts are provisioned.
          example: '["Analyst", "Administrator"]'
          items:
            type: string
          default: []
    SamlIdentityProviderRequest:
      required:
      - configurationName
      - issuer
      - x509cert1
      type: object
      properties:
        spInitiatedLoginPath:
          type: string
          description: This property has been deprecated and is no longer used.
          example: http://www.okta.com/abxcseyuiwelflkdjh
          deprecated: true
          default: ''
        configurationName:
          type: string
          description: Name of the SSO policy or another name used to describe the policy internally.
          example: SumoLogic
        issuer:
          type: string
          description: The unique URL assigned to the organization by the SAML Identity Provider.
          example: http://www.okta.com/abxcseyuiwelflkdjh
        spInitiatedLoginEnabled:
          type: boolean
          description: True if Sumo Logic redirects users to your identity provider with a SAML AuthnRequest when signing in.
          default: false
        authnRequestUrl:
          type: string
          description: The URL that the identity provider has assigned for Sumo Logic to submit SAML authentication requests to the identity provider.
          example: https://www.okta.com/app/sumologic/abxcseyuiwelflkdjh/sso/saml
          default: ''
        x509cert1:
          type: string
          description: The certificate is used to verify the signature in SAML assertions.
        x509cert2:
          type: string
          description: The backup certificate used to verify the signature in SAML assertions when x509cert1 expires.
          default: ''
        x509cert3:
          type: string
          description: The backup certificate used to verify the signature in SAML assertions when x509cert1 expires and x509cert2 is empty.
          default: ''
        onDemandProvisioningEnabled:
          $ref: '#/components/schemas/OnDemandProvisioningInfo'
        rolesAttribute:
          type: string
          description: The role that Sumo Logic will assign to users when they sign in.
          example: Sumo_Role
          default: ''
        logoutEnabled:
          type: boolean
          description: True if users are redirected to a URL after signing out of Sumo Logic.
          default: false
        logoutUrl:
          type: string
          description: The URL that users will be redirected to after signing out of Sumo Logic.
          example: https://www.sumologic.com
          default: ''
        emailAttribute:
          type: string
          description: The email address of the new user account.
          example: attribute/subject
          default: ''
        debugMode:
          type: boolean
          description: True if additional details are included when a user fails to sign in.
          default: false
        signAuthnRequest:
          type: boolean
          description: True if Sumo Logic will send signed Authn requests to the identity provider.
          default: false
        disableRequestedAuthnContext:
          type: boolean
          description: True if Sumo Logic will include the RequestedAuthnContext element of the SAML AuthnRequests it sends to the identity provider.
          default: false
        isRedirectBinding:
          type: boolean
          description: True if the SAML binding is of HTTP Redirect type.
          default: false
    SamlIdentityProvider:
      type: object
      allOf:
      - $ref: '#/components/schemas/SamlIdentityProviderRequest'
      - $ref: '#/components/schemas/AuthnCertificateResult'
      - $ref: '#/components/schemas/MetadataModel'
      - required:
        - id
        properties:
          id:
            type: string
            description: Unique identifier of the SAML Identity Provider.
            example: 00000000361130F7
          assertionConsumerUrl:
            type: string
            description: The URL on Sumo Logic where the IdP will redirect to with its authentication response.
            example: https://service.sumologic.com/sumo/saml/consume/9483922
            default: ''
          entityId:
            type: string
            description: A unique identifier that is the intended audience of the SAML assertion.
            example: https://service.sumologic.com/sumo/saml/9483922
            default: ''
          metadataUrl:
            type: string
            description: The URL to fetch SAML metadata XML.
            example: https://api.sumologic.com/api/v1/saml/identityProviders/00000000361130F7/metadata
            default: ''
  securitySchemes:
    basicAuth:
      type: http
      scheme: basic
x-tagGroups:
- name: Archive Management
  tags:
  - archiveManagement
- name: Health Events
  tags:
  - healthEvents
- name: Infrequent Data Tier
  tags:
  - logSearchesEstimatedUsage
- name: Ingest Budgets Management V2
  tags:
  - ingestBudgetManagementV2
- name: Library Management
  tags:
  - appManagement
  - appManagementV2
  - contentManagement
  - dashboardManagement
  - folderManagement
  - lookupManagement
  - contentPermissions
  - logSearchesManagement
  - parsersLibraryManagement
- name: Metrics
  tags:
  - metricsSearchesManagement
  - transformationRuleManagement
  - metricsQuery
  - metricsSearchesManagementV2
- name: Security Management
  tags:
  - accessKeyManagement
  - oauthManagement
  - accountManagement
  - passwordPolicy
  - policiesManagement
  - samlConfigurationManagement
  - serviceAllowlistManagement
  - serviceAccountManagement
  - scimUserManagement
- name: Organizations Management
  tags:
  - orgsManagement
- name: Settings Management
  tags:
  - connectionManagement
  - dynamicParsingRuleManagement
  - extractionRuleManagement
  - fieldManagementV1
  - partitionManagement
  - scheduledViewManagement
  - logsDataForwardingManagement
  - dataDeletionRules
- name: Tokens Management
  tags:
  - tokensLibraryManagement
- name: Tracing
  tags:
  - traces
  - spanAnalytics
  - serviceMap
- name: Users and Roles Management
  tags:
  - roleManagement
  - roleManagementV2
  - userManagement
- name: Threat Intel Ingest Management
  tags:
  - threatIntelIngest
  - threatIntelIngestProducer
- name: OpenTelemetry Collector Management
  tags:
  - otCollectorManagementExternal
- name: Source Template Management
  tags:
  - sourceTemplateManagementExternal
- name: Schema Base Management
  tags:
  - schemaBaseManagement
- name: Event Analytics Management
  tags:
  - eventAnalytics
- name: Budget Management
  tags:
  - budgetManagement
- name: Macro Management
  tags:
  - macroManagement
- name: Muting Schedules Management
  tags:
  - mutingSchedulesLibraryManagement
- name: SLO Management
  tags:
  - slosLibraryManagement
- name: Monitor Management
  tags:
  - monitorsLibraryManagement