aimldocs
ReferenceApi

Sso

enterprise single sign-on and SCIM: brokered IdP, verified domains, directory tokens

GET
/v1/org/sso
AuthorizationBearer <token>

In: header

Response Body

application/json

application/json

curl -X GET "https://example.com/v1/org/sso"
{  "configured": true,  "sso": {    "kind": "saml",    "alias": "org-01j8",    "display_name": "Okta",    "status": "active",    "enforce": true,    "default_role": "member",    "role_map": {      "aiml-admins": "admin"    }  },  "service_provider": {    "acs_url": "https://auth.ai.ml/realms/aiml/broker/org-01j8/endpoint"  },  "domains": [    {      "domain": "acme.com",      "record": "_aiml-verify.acme.com",      "token": "aiml-verify=6f1c…",      "verified_at": "2026-09-02T09:00:00Z"    }  ],  "scim_tokens": [    {      "id": "scim_01J8",      "hint": "…4c2b",      "created_at": "2026-09-02T09:10:00Z"    }  ],  "scim_url": "https://api.ai.ml/scim/v2"}
DELETE
/v1/org/sso
AuthorizationBearer <token>

In: header

Response Body

application/json

curl -X DELETE "https://example.com/v1/org/sso"
Empty
PUT
/v1/org/sso
AuthorizationBearer <token>

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

curl -X PUT "https://example.com/v1/org/sso" \  -H "Content-Type: application/json" \  -d '{    "kind": "saml",    "display_name": "Okta",    "config": {      "singleSignOnServiceUrl": "https://acme.okta.com/app/sso/saml",      "entityId": "http://www.okta.com/acme"    },    "default_role": "member",    "role_map": {      "aiml-admins": "admin"    },    "status": "active"  }'
{  "configured": true,  "scim_url": "https://api.ai.ml/scim/v2",  "domains": [],  "scim_tokens": []}
POST
/v1/org/sso/domains
AuthorizationBearer <token>

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

curl -X POST "https://example.com/v1/org/sso/domains" \  -H "Content-Type: application/json" \  -d '{    "domain": "acme.com"  }'
{  "domain": {    "domain": "acme.com",    "record": "_aiml-verify.acme.com",    "token": "aiml-verify=6f1c…"  },  "instructions": "publish a TXT record at _aiml-verify.acme.com with the value aiml-verify=6f1c…, then verify"}
DELETE
/v1/org/sso/domains/{domain}
AuthorizationBearer <token>

In: header

Path Parameters

domain*string

Response Body

application/json

curl -X DELETE "https://example.com/v1/org/sso/domains/string"
Empty
POST
/v1/org/sso/domains/{domain}/verify
AuthorizationBearer <token>

In: header

Path Parameters

domain*string

Response Body

application/json

application/json

curl -X POST "https://example.com/v1/org/sso/domains/string/verify"
{  "verified": true,  "domain": {    "domain": "acme.com",    "verified_at": "2026-09-02T09:00:00Z"  }}
POST
/v1/org/scim/token
AuthorizationBearer <token>

In: header

Response Body

application/json

application/json

curl -X POST "https://example.com/v1/org/scim/token"
{  "id": "scim_01J8",  "token": "aiml_scim_01J8…",  "hint": "…4c2b",  "url": "https://api.ai.ml/scim/v2",  "warning": "this is the only time the token is shown; store it in your identity provider now"}
DELETE
/v1/org/scim/token/{id}
AuthorizationBearer <token>

In: header

Path Parameters

id*string

Response Body

application/json

curl -X DELETE "https://example.com/v1/org/scim/token/string"
Empty
GET
/v1/org/scim/log
AuthorizationBearer <token>

In: header

Query Parameters

cursor?string
limit?integer
Rangevalue <= 500

Response Body

application/json

application/json

curl -X GET "https://example.com/v1/org/scim/log"
{  "object": "list",  "data": [    {      "id": 3,      "at": "2026-09-10T06:00:00Z",      "method": "POST",      "path": "/Users",      "resource_type": "User",      "resource_id": "usr_01J8",      "status": 201    }  ]}