Skip to content

Preview SAML metadata import.

POST
/api/admin/saml-metadata/preview
Code sample: Shell / cURL
curl --request POST \
--url https://auth.example.com/api/admin/saml-metadata/preview \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "metadataUrl": "https://federation.example.com/aggregate-metadata.xml" }'

The JSON request body is limited to 12 MiB; inline aggregate XML is limited to 10 MiB.

Media type application/json
object
metadataXml
string
<= 10485760 characters
metadataUrl
string format: uri
samlProfile
string
attributePresetId
string
Example
{
"metadataUrl": "https://federation.example.com/aggregate-metadata.xml"
}

Successful JSON response.

Media type application/json
One of:
object
kind
required
string
Allowed values: single
providerType
required
string
Allowed values: saml_idp saml_sp
config
required
object
entityId
string
ssoUrl
string format: uri
acsUrl
string format: uri
certificate
string
metadataUrl
string format: uri
metadataXml
string
<= 1048576 characters
metadataRefreshPolicy
object
mode
required

URL-backed providers default to automatic when this property is omitted.

string
Allowed values: automatic manual
intervalSeconds
required
integer
default: 21600 >= 900 <= 604800
nextRefreshAt
integer format: int64
lastAttemptAt
integer format: int64
lastSuccessAt
integer format: int64
consecutiveFailures
integer
sourceState
string
Allowed values: healthy stale error expired missing identity_change_pending
lastErrorCode
string
suspendedByMetadataSync

True when metadata lifecycle automation disabled the provider.

boolean
key
additional properties
nameIdFormat
string
metadataNameIdFormats
Array<string>
identityMapping
object
fieldMappingSetId
required
string
fieldMappingVersionId
string
destinationNamespace
string
destinationFieldPolicies

Per-SP release mode for every attribute in the active SAML Destination Profile.

object
key
additional properties
string
Allowed values: required optional hidden
key
additional properties
attributeReleaseConsent
object
enabled
boolean
mode
string
Allowed values: once every_time until_attributes_change
key
additional properties
key
additional properties
Example
{
"kind": "single",
"providerType": "saml_idp",
"config": {
"entityId": "https://idp.example.com/metadata",
"ssoUrl": "https://idp.example.com/sso",
"metadataHash": "sha256:..."
}
}