# SSO

**Canonical:** https://apis.io/providers/sso/  
**APIs profiled:** 8

Single Sign-On (SSO) is an authentication technology that allows users to log in once and gain access to multiple related applications and services without re-authenticating. SSO implementations rely on protocols such as SAML 2.0, OpenID Connect (OIDC), and OAuth 2.0. Major identity providers including Okta, Microsoft Entra ID, Google, Ping Identity, Auth0, and Keycloak expose SSO APIs that allow applications to integrate federated authentication, token exchange, assertion validation, and session management.

## Kin Score — 32.0 / 100 (thin)

Scored 2026-08-25 under rubric 0.14.0. Trend: flat (+0.0 from 32.0).

| Facet | Score |
|---|---|
| Discoverability | 68.5 |
| Contract Quality | 56.0 |
| Governance | 28.8 |
| Contract Governance | 28.8 |
| Operational Transparency | 13.2 |
| Developer Ergonomics | 14.3 |
| Commercial Clarity | 15.8 |
| Access Clarity | 15.8 |

## Agent readiness — 28.1 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | bearer |
| Idempotency | no |
| Error Semantics | verified |
| OpenAPI Examples | partial |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | no |
| Protected Resource Metadata | no |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## Access

Freemium · Self-serve signup — onboarding: self-serve, pricing: freemium, trial: no (confidence: high).

## APIs (8)

- **SSO Authentication API** — SAML 2.0 authentication request and response endpoints for initiating and completing SSO login flows.
- **SSO Authorization API** — OIDC authorization endpoints for initiating authentication flows and exchanging authorization codes for tokens.
- **SSO Discovery API** — OpenID Provider Discovery endpoint for retrieving provider configuration metadata.
- **SSO Keys API** — JSON Web Key Set (JWKS) endpoint for retrieving public keys used to verify ID token signatures.
- **SSO Logout API** — SAML 2.0 Single Logout (SLO) endpoints for terminating SSO sessions across all service providers.
- **SSO Metadata API** — SAML 2.0 metadata endpoints for exchanging federation configuration between identity providers and service providers.
- **SSO Token API** — Token endpoint operations for exchanging authorization codes and refresh tokens for access tokens and ID tokens.
- **SSO User Info API** — UserInfo endpoint for retrieving authenticated user profile claims.

## Agentic access (1)

- **Sso Agentic Access** — 11 operations · 4 acting · 1 human-in-the-loop

## Security (2)

- **Sso Authentication** — http · 1 scheme
- **Sso Domain Security** — TLSv1.3 · HSTS · DMARC

## Plans (1)

- **Sso Plans Pricing**

## Tags

Authentication, Authorization, Identity, OIDC, SAML, Security, Single Sign-On, SSO

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/sso/). Scores are computed from the provider's own public artifacts under a published rubric.
