> ## Documentation Index
> Fetch the complete documentation index at: https://docs.idun-group.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get Sso



## OpenAPI

````yaml /standalone/openapi.json get /admin/api/v1/sso
openapi: 3.1.0
info:
  title: Idun Agent Engine Server
  description: A production-ready server for conversational AI agents
  version: 0.6.1
servers: []
security: []
tags:
  - name: Runtime
    description: >-
      Public agent run endpoints, engine operations, and chat-channel webhooks.
      SSE streaming via the AG-UI protocol.
  - name: Agent Configuration
    description: >-
      Singleton admin endpoints for the agent, prompts, memory, guardrails, and
      onboarding wizard.
  - name: Auth & SSO
    description: >-
      Login, sessions, password change, SSO config, and the public SSO discovery
      endpoint.
  - name: Integrations & Tools
    description: MCP server registry and external integration credentials.
  - name: Observability
    description: Tracing/logging provider configuration.
  - name: Traces
    description: >-
      Trace and span storage admin endpoints — list, detail, delete, and
      pipeline-health for the standalone trace store.
  - name: Dashboard
    description: >-
      Operator dashboard widgets — KPIs, time-series, top errors, and
      configuration summary.
paths:
  /admin/api/v1/sso:
    get:
      tags:
        - Auth & SSO
      summary: Get Sso
      operationId: get_sso_admin_api_v1_sso_get
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/StandaloneSsoRead'
components:
  schemas:
    StandaloneSsoRead:
      properties:
        sso:
          $ref: '#/components/schemas/SSOConfig'
        updatedAt:
          type: string
          format: date-time
          title: Updatedat
      type: object
      required:
        - sso
        - updatedAt
      title: StandaloneSsoRead
      description: GET response and the data payload of PATCH responses.
    SSOConfig:
      properties:
        enabled:
          type: boolean
          title: Enabled
          description: Toggle SSO enforcement on protected routes.
          default: true
        issuer:
          type: string
          title: Issuer
          description: >-
            OIDC issuer URL (e.g. https://accounts.google.com). Used to discover
            the JWKS endpoint via .well-known/openid-configuration.
        clientId:
          type: string
          title: Clientid
          description: >-
            OAuth 2.0 client ID. Used as the default audience for JWT validation
            when 'audience' is not set.
        audience:
          anyOf:
            - type: string
            - type: 'null'
          title: Audience
          description: >-
            Expected JWT 'aud' claim. Defaults to client_id if not set. Okta
            client credentials tokens use 'api://default'.
        allowedDomains:
          anyOf:
            - items:
                type: string
              type: array
            - type: 'null'
          title: Alloweddomains
          description: >-
            Optional list of allowed email domains (e.g. ['company.com']). When
            set, only tokens whose email claim matches one of these domains are
            accepted.
        allowedEmails:
          anyOf:
            - items:
                type: string
              type: array
            - type: 'null'
          title: Allowedemails
          description: >-
            Optional list of specific email addresses allowed access. When set,
            only tokens whose email claim exactly matches one of these values
            are accepted.
      type: object
      required:
        - issuer
        - clientId
      title: SSOConfig
      description: |-
        OIDC Single Sign-On configuration.

        When enabled, the engine validates JWT tokens on protected routes
        (``/agent/invoke``, ``/agent/stream``, ``/agent/copilotkit/stream``)
        against the configured OIDC provider's JWKS endpoint, discovered via
        ``{issuer}/.well-known/openid-configuration``.

````