Workday Security Authentication Configuration API

Manage authentication policies and configurations including SSO, SAML, and multi-factor authentication settings.

Operations 1

GET /api/v1/{tenant}/authenticationPolicies Workday Security List authentication policies #

Documentation

Specifications

Other Resources

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/workday-security-authentication-configuration-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

workday-security-authentication-configuration-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Workday Security Workday Authentication Authentication…
  description: Manage authentication methods, single sign-on configuration, and session management within the Workday platform. Supports OAuth 2.0 token-based authentication for REST API access including client registration, token issuance, and token refresh workflows. Provides endpoints for obtaining access tokens using authorization codes and refresh tokens, as well as managing API client registrations and scopes.
  version: v1
  contact:
    name: Workday Support
    url: https://community.workday.com
    email: support@workday.com
  termsOfService: https://www.workday.com/en-us/legal.html
servers:
- url: https://{host}/ccx
  description: Workday Production Server
  variables:
    host:
      description: Workday host for your tenant environment
      default: wd2-impl-services1.workday.com
- url: https://{host}/ccx/oauth2/{tenant}
  description: Workday OAuth 2.0 Token Server
  variables:
    host:
      description: Workday host for your tenant environment
      default: wd2-impl-services1.workday.com
    tenant:
      description: Workday tenant identifier
      default: your-tenant
security:
- bearerAuth: []
tags:
- name: Authentication Configuration
  description: Manage authentication policies and configurations including SSO, SAML, and multi-factor authentication settings.
paths:
  /api/v1/{tenant}/authenticationPolicies:
    get:
      operationId: listAuthenticationPolicies
      summary: Workday Security List authentication policies
      description: Retrieve the collection of authentication policies configured for the tenant, including SSO settings, multi-factor authentication requirements, and password policies.
      tags:
      - Authentication Configuration
      parameters:
      - $ref: '#/components/parameters/tenant'
      - $ref: '#/components/parameters/limit'
      - $ref: '#/components/parameters/offset'
      responses:
        '200':
          description: Collection of authentication policies
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items:
                      $ref: '#/components/schemas/AuthenticationPolicy'
                  total:
                    type: integer
                    description: Total number of authentication policies
        '401':
          description: Unauthorized - invalid or expired access token
        '403':
          description: Forbidden - insufficient permissions
components:
  parameters:
    offset:
      name: offset
      in: query
      description: Number of results to skip for pagination
      schema:
        type: integer
        default: 0
        minimum: 0
    limit:
      name: limit
      in: query
      description: Maximum number of results to return per page
      schema:
        type: integer
        default: 20
        minimum: 1
        maximum: 100
    tenant:
      name: tenant
      in: path
      required: true
      description: Workday tenant identifier
      schema:
        type: string
  schemas:
    AuthenticationPolicy:
      type: object
      description: An authentication policy that defines the rules and requirements for authenticating users, including SSO configuration, password policies, and multi-factor authentication requirements.
      properties:
        id:
          type: string
          description: Unique identifier for the authentication policy
        descriptor:
          type: string
          description: Human-readable name of the authentication policy
        ssoEnabled:
          type: boolean
          description: Whether single sign-on is enabled for this policy
        samlIdentityProvider:
          type: string
          description: The SAML identity provider configured for SSO authentication
        mfaRequired:
          type: boolean
          description: Whether multi-factor authentication is required
        passwordPolicyEnabled:
          type: boolean
          description: Whether a custom password policy is enforced
        sessionTimeoutMinutes:
          type: integer
          minimum: 1
          description: Session timeout duration in minutes before re-authentication is required
        allowedAuthenticationTypes:
          type: array
          items:
            type: string
          description: List of authentication methods permitted under this policy
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: OAuth 2.0 bearer token obtained from the token endpoint. Tokens are issued after authentication through the Workday authorization server.
    oauth2:
      type: oauth2
      description: OAuth 2.0 authorization code flow for obtaining access tokens to Workday REST APIs.
      flows:
        authorizationCode:
          authorizationUrl: https://{host}/authorize
          tokenUrl: https://{host}/ccx/oauth2/{tenant}/token
          scopes:
            System: Access to system-level resources
            Integration: Access to integration resources
            Tenant_Non-Configurable: Access to tenant non-configurable resources
externalDocs:
  description: Workday Authentication API Documentation
  url: https://community.workday.com/sites/default/files/file-hosting/productionapi/Security/v44.0/Authentication.html