> ## Documentation Index
> Fetch the complete documentation index at: https://docs.artbucket.io/llms.txt
> Use this file to discover all available pages before exploring further.

# The organization's single sign-on

> Its OpenID Connect provider, or null, and the redirect URI to register with the provider before setting it up. Never the client secret. Organization admin.

Scope: `admin`.



## OpenAPI

````yaml /openapi.json get /api/v1/sso
openapi: 3.1.0
info:
  title: artbucket
  version: '1'
  description: >-
    Agent-first asset management. The web UI is built on this API and nothing
    else, beside signing in at /api/auth. Send `Authorization: Bearer <key>`: a
    key works in one workspace with one scope, and scopes are a ladder: read <
    propose < write < admin. People signed in to the app carry a session cookie
    instead, and their scope is what their grants add up to: on the
    organization, the workspace, or single collections and assets. A scope shown
    as needed on the workspace is also enough on the one collection or asset a
    route acts on. Agents (MCP at POST /api/v1/mcp) usually get `propose`: what
    they add waits for a human.
servers:
  - url: http://localhost:3000
security:
  - bearer: []
  - session: []
  - {}
paths:
  /api/v1/sso:
    get:
      summary: The organization's single sign-on
      description: >-
        Its OpenID Connect provider, or null, and the redirect URI to register
        with the provider before setting it up. Never the client secret.
        Organization admin.


        Scope: `admin`.
      responses:
        '200':
          description: Single sign-on
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    anyOf:
                      - type: object
                        properties:
                          issuer:
                            type: string
                          clientId:
                            type: string
                          domain:
                            type: string
                          verified:
                            type: boolean
                            description: >-
                              The domain is proved: its people sign in through
                              the provider
                          record:
                            type: object
                            properties:
                              type:
                                type: string
                                const: TXT
                              name:
                                type: string
                              value:
                                type: string
                            required:
                              - type
                              - name
                              - value
                            additionalProperties: false
                            description: >-
                              What proves the domain: add this record at your
                              DNS host
                          redirectUri:
                            type: string
                            format: uri
                            description: >-
                              Register this with the provider as the app's
                              redirect URI
                        required:
                          - issuer
                          - clientId
                          - domain
                          - verified
                          - record
                          - redirectUri
                        additionalProperties: false
                      - type: 'null'
                  redirectUri:
                    type: string
                    format: uri
                required:
                  - data
                  - redirectUri
                additionalProperties: false
        default:
          description: An error
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                      message:
                        type: string
                      detail: {}
                    required:
                      - code
                      - message
                    additionalProperties: false
                required:
                  - error
                additionalProperties: false
components:
  securitySchemes:
    bearer:
      type: http
      scheme: bearer
      description: 'An API key: ab_...'
    session:
      type: apiKey
      in: cookie
      name: better-auth.session_token
      description: Signed in, at /api/auth

````