SAML Federation API, REST: Federation.Create
Creates a federation in the specified organization.
HTTP request
POST https://organization-manager.api.cloud.yandex.net/organization-manager/v1/saml/federations
Body parameters
{
"organizationId": "string",
"name": "string",
"description": "string",
"cookieMaxAge": "string",
"autoCreateAccountOnLogin": "boolean",
"issuer": "string",
"ssoBinding": "string",
"ssoUrl": "string",
"securitySettings": {
"encryptedAssertions": "boolean",
"forceAuthn": "boolean"
},
"caseInsensitiveNameIds": "boolean",
"labels": "object"
}
|
Field |
Description |
|
organizationId |
string Required field. ID of the organization to create a federation in. The maximum string length in characters is 50. |
|
name |
string Required field. Name of the federation. Value must match the regular expression |
|
description |
string Description of the federation. The maximum string length in characters is 256. |
|
cookieMaxAge |
string (duration) Browser cookie lifetime in seconds. |
|
autoCreateAccountOnLogin |
boolean Add new users automatically on successful authentication. |
|
issuer |
string Required field. ID of the IdP server to be used for authentication. The maximum string length in characters is 8000. |
|
ssoBinding |
enum (BindingType) Required field. Single sign-on endpoint binding type. Most Identity Providers support the
|
|
ssoUrl |
string Required field. Single sign-on endpoint URL. The maximum string length in characters is 8000. |
|
securitySettings |
Federation security settings. |
|
caseInsensitiveNameIds |
boolean Use case insensitive Name IDs. |
|
labels |
object (map<string, string>) Resource labels as The maximum string length in characters for each value is 63. The string length in characters for each key must be 1-63. Each key must match the regular expression |
FederationSecuritySettings
Federation security settings.
|
Field |
Description |
|
encryptedAssertions |
boolean Enable encrypted assertions. |
|
forceAuthn |
boolean Value parameter ForceAuthn in SAMLRequest. |
Response
HTTP Code: 200 - OK
{
"id": "string",
"description": "string",
"createdAt": "string",
"createdBy": "string",
"modifiedAt": "string",
"done": "boolean",
"metadata": "object",
// Includes only one of the fields `error`, `response`
"error": {
"code": "integer",
"message": "string",
"details": [
"object"
]
},
"response": "object"
// end of the list of possible fields
}
An Operation resource. For more information, see Operation.
|
Field |
Description |
|
id |
string ID of the operation. |
|
description |
string Description of the operation. 0-256 characters long. |
|
createdAt |
string (date-time) Creation timestamp. String in RFC3339 To work with values in this field, use the APIs described in the |
|
createdBy |
string ID of the user or service account who initiated the operation. |
|
modifiedAt |
string (date-time) The time when the Operation resource was last modified. String in RFC3339 To work with values in this field, use the APIs described in the |
|
done |
boolean If the value is |
|
metadata |
object Service-specific metadata associated with the operation. |
|
error |
The error result of the operation in case of failure or cancellation. Includes only one of the fields The operation result. |
|
response |
object The normal response of the operation in case of success. Includes only one of the fields The operation result. |
Status
The error result of the operation in case of failure or cancellation.
|
Field |
Description |
|
code |
integer (int32) Error code. An enum value of google.rpc.Code |
|
message |
string An error message. |
|
details[] |
object A list of messages that carry the error details. |