Read metadata-only active auth mode and provider configuration state.
GET /v1/identity-provider
GET
/v1/identity-provider
Returns safe refs, claim mapping names, trusted-header contract, and SAML-through-proxy support. Raw tokens, SAML assertions, secrets, JWKS bodies, and claim payloads are never returned.
Authorizations
Section titled “Authorizations ”Responses
Section titled “ Responses ”Metadata-only identity provider state for admin UI.
object
schema_version
required
auth_mode
required
tenant_id
required
string
environment_id
required
string
oidc
required
object
configured
required
boolean
issuer_ref
required
string
jwks_ref
required
string
audience_ref
required
string
client_id_ref
required
string
claim_mapping
required
object
subject
required
string
groups
required
string
user_id
required
string
client_surface
required
string
tenant
required
string
environment
required
string
service_id
required
string
workload_id
required
string
agent_id
required
string
agent_instance_id
required
string
human_delegator_id
required
string
allowed_algorithms
required
Array
saml
required
object
proxy_supported
required
boolean
direct_acs_supported
required
boolean
metadata_ref
required
string
entity_id_ref
required
string
acs_ref
required
string
trusted_headers
required
object
enabled
required
boolean
required_headers
required
Array<string>
optional_headers
required
Array<string>
client_supplied_headers_trusted
required
boolean
local_identity
required
object
enabled
required
boolean
bootstrap_token_configured
required
boolean
Type set in Geist, Source Serif 4, and Departure Mono.