> ## Documentation Index
> Fetch the complete documentation index at: https://docs.artbucket.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Set up single sign-on

> One OpenID Connect provider (Okta, Entra ID, Google Workspace...) for the people at one email domain. Register `redirectUri` with the provider first, then save its issuer and client here: the endpoints are read from the issuer's discovery document now, and a 422 says what was wrong with it. Add the TXT record in `record`, then POST /api/v1/sso/verify. From then on anyone at the domain signs in through the provider and joins the organization able to read. A new domain is proved again; one another organization proved is refused.

Scope: `admin`.



## OpenAPI

````yaml /openapi.json put /api/v1/sso
openapi: 3.1.0
info:
  title: artbucket
  version: '1'
  description: >-
    Agent-first asset management. The web UI is built on this API and nothing
    else, beside signing in at /api/auth. Send `Authorization: Bearer <key>`: a
    key works in one workspace with one scope, and scopes are a ladder: read <
    propose < write < admin. People signed in to the app carry a session cookie
    instead, and their scope is what their grants add up to: on the
    organization, the workspace, or single collections and assets. A scope shown
    as needed on the workspace is also enough on the one collection or asset a
    route acts on. Agents (MCP at POST /api/v1/mcp) usually get `propose`: what
    they add waits for a human.
servers:
  - url: http://localhost:3000
security:
  - bearer: []
  - session: []
  - {}
paths:
  /api/v1/sso:
    put:
      summary: Set up single sign-on
      description: >-
        One OpenID Connect provider (Okta, Entra ID, Google Workspace...) for
        the people at one email domain. Register `redirectUri` with the provider
        first, then save its issuer and client here: the endpoints are read from
        the issuer's discovery document now, and a 422 says what was wrong with
        it. Add the TXT record in `record`, then POST /api/v1/sso/verify. From
        then on anyone at the domain signs in through the provider and joins the
        organization able to read. A new domain is proved again; one another
        organization proved is refused.


        Scope: `admin`.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                issuer:
                  type: string
                  maxLength: 2000
                  format: uri
                  description: >-
                    The provider's issuer URL: its discovery document is read
                    from {issuer}/.well-known/openid-configuration
                clientId:
                  type: string
                  minLength: 1
                  maxLength: 500
                  description: The app's client ID at the provider
                clientSecret:
                  description: >-
                    The app's client secret. Needed to set it up; left out on a
                    change, the one kept stays
                  type: string
                  minLength: 1
                  maxLength: 2000
                domain:
                  type: string
                  minLength: 1
                  maxLength: 253
                  description: >-
                    The email domain its people sign in with, e.g. acme.com.
                    Proved by a TXT record
              required:
                - issuer
                - clientId
                - domain
              additionalProperties: false
      responses:
        '200':
          description: Single sign-on
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: object
                    properties:
                      issuer:
                        type: string
                      clientId:
                        type: string
                      domain:
                        type: string
                      verified:
                        type: boolean
                        description: >-
                          The domain is proved: its people sign in through the
                          provider
                      record:
                        type: object
                        properties:
                          type:
                            type: string
                            const: TXT
                          name:
                            type: string
                          value:
                            type: string
                        required:
                          - type
                          - name
                          - value
                        additionalProperties: false
                        description: >-
                          What proves the domain: add this record at your DNS
                          host
                      redirectUri:
                        type: string
                        format: uri
                        description: >-
                          Register this with the provider as the app's redirect
                          URI
                    required:
                      - issuer
                      - clientId
                      - domain
                      - verified
                      - record
                      - redirectUri
                    additionalProperties: false
                required:
                  - data
                additionalProperties: false
        default:
          description: An error
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                      message:
                        type: string
                      detail: {}
                    required:
                      - code
                      - message
                    additionalProperties: false
                required:
                  - error
                additionalProperties: false
components:
  securitySchemes:
    bearer:
      type: http
      scheme: bearer
      description: 'An API key: ab_...'
    session:
      type: apiKey
      in: cookie
      name: better-auth.session_token
      description: Signed in, at /api/auth

````