//Enterprise Admin APIs

Enterprise Admin APIs

These routes back the organization Security, SSO, and Audit Events pages.

Security Settings

GET /api/organizations/:org_uuid/security-settings

Returns the stored security policy for the organization.

PUT /api/organizations/:org_uuid/security-settings

Updates:

  • enforce_mfa
  • session_ttl_minutes
  • allowed_auth_methods
  • Supported auth methods today:

  • email_password
  • magic_link
  • otp
  • google
  • microsoft
  • oidc
  • SSO Connections

    GET /api/organizations/:org_uuid/sso-connections

    Lists the configured SSO connections for the organization.

    POST /api/organizations/:org_uuid/sso-connections

    Creates a new SSO connection.

    Required fields:

  • name
  • issuer_url
  • client_id
  • client_secret
  • Optional fields:

  • scopes
  • domains
  • is_active
  • Phase 1 currently supports provider_type: oidc only.

    PUT /api/organizations/:org_uuid/sso-connections/:connection_uuid

    Updates an existing connection. Leave client_secret blank to keep the current secret.

    DELETE /api/organizations/:org_uuid/sso-connections/:connection_uuid

    Deletes a stored SSO connection.

    Audit Events

    GET /api/organizations/:org_uuid/audit-events

    Lists structured admin audit events.

    Supported filters:

  • action
  • result
  • target_type
  • search
  • limit
  • Current coverage includes:

  • Security settings updates
  • SSO connection create/update/delete

CSV and JSON export are live. Retention policies, legal hold, and broader admin coverage are still in progress.

Service Identities

GET /api/organizations/:org_uuid/service-identities

Lists the service identities (non-human accounts) configured for the organization.

POST /api/organizations/:org_uuid/service-identities

Creates a new service identity. Service identities are used by agents and automated systems to interact with the API securely.

POST /api/organizations/:org_uuid/service-identities/automation-token

Generates or rotates a high-entropy automation token for a specific service identity.

Role Permissions (RBAC V2)

GET /api/roles/:role_id/permissions

Retrieves the current permission associations for a specific role.

PUT /api/roles/:role_id/permissions

Natively replaces the permission associations for a role.

Input: ~~~json { "permissions": [1, 2, 5, 12] } ~~~