# Workspace: sso

> Whether this workspace requires single sign-on, its connections and its domains; Require single sign-on for this workspace, or stop requiring it; A short-lived link into the identity provider's Admin Portal, to set up a connection or verify a domain

## Whether this workspace requires single sign-on, its connections and its domains

`GET /v1/workspace/sso` · operation `getSso`

Requires the `batondeck:workspace:read` permission (action `sso:read`).

**Responses**

| Status | Meaning |
|---|---|
| 200 | Whether this workspace requires single sign-on, its connections and its domains |
| 401 | No portal session, and no live API key. |
| 403 | The policy refused, or the request was cross-site. |
| 404 | No such resource, or none this session may see. |

<details>
<summary>200 response schema</summary>

```json
{
  "type": "object",
  "properties": {
    "entitled": {
      "type": "boolean"
    },
    "required": {
      "type": "boolean"
    },
    "provider_configured": {
      "type": "boolean"
    },
    "connections": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "type": {
            "type": "string"
          },
          "state": {
            "type": "string"
          }
        },
        "required": [
          "id",
          "type",
          "state"
        ],
        "additionalProperties": false
      }
    },
    "domains": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "domain": {
            "type": "string"
          },
          "state": {
            "type": "string"
          }
        },
        "required": [
          "domain",
          "state"
        ],
        "additionalProperties": false
      }
    },
    "signed_in_with_sso": {
      "type": "boolean"
    }
  },
  "required": [
    "entitled",
    "required",
    "provider_configured",
    "connections",
    "domains",
    "signed_in_with_sso"
  ],
  "additionalProperties": false
}
```

</details>

```sh
curl -X GET 'https://api.batondeck.com/v1/workspace/sso' \
  -H "Authorization: Bearer $BATONDECK_API_KEY"
```


## Require single sign-on for this workspace, or stop requiring it

`PATCH /v1/workspace/sso` · operation `setSsoRequired`

Requires the `batondeck:workspace:admin` permission (action `sso:manage`).

Requires a step-up: MFA enrolled and re-authenticated within 15 minutes. **Not reachable with an API key** — a key has no session and so can never step up.

Refused while the workspace is suspended or on deletion hold.

**Request body** (`application/json`)

| Field | Type | Required | Notes |
|---|---|---|---|
| `required` | boolean | yes |  |

<details>
<summary>Request schema</summary>

```json
{
  "type": "object",
  "properties": {
    "required": {
      "type": "boolean"
    }
  },
  "required": [
    "required"
  ],
  "additionalProperties": false
}
```

</details>

**Responses**

| Status | Meaning |
|---|---|
| 200 | Require single sign-on for this workspace, or stop requiring it |
| 400 | The arguments did not validate. |
| 401 | No portal session, and no live API key. |
| 403 | The policy refused, or the request was cross-site. |
| 404 | No such resource, or none this session may see. |

<details>
<summary>200 response schema</summary>

```json
{
  "type": "object",
  "properties": {
    "entitled": {
      "type": "boolean"
    },
    "required": {
      "type": "boolean"
    },
    "provider_configured": {
      "type": "boolean"
    },
    "connections": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "type": {
            "type": "string"
          },
          "state": {
            "type": "string"
          }
        },
        "required": [
          "id",
          "type",
          "state"
        ],
        "additionalProperties": false
      }
    },
    "domains": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "domain": {
            "type": "string"
          },
          "state": {
            "type": "string"
          }
        },
        "required": [
          "domain",
          "state"
        ],
        "additionalProperties": false
      }
    },
    "signed_in_with_sso": {
      "type": "boolean"
    }
  },
  "required": [
    "entitled",
    "required",
    "provider_configured",
    "connections",
    "domains",
    "signed_in_with_sso"
  ],
  "additionalProperties": false
}
```

</details>

```sh
curl -X PATCH 'https://api.batondeck.com/v1/workspace/sso' \
  -H "Authorization: Bearer $BATONDECK_API_KEY" \
  -H 'content-type: application/json' \
  -d @body.json
```


## A short-lived link into the identity provider's Admin Portal, to set up a connection or verify a domain

`POST /v1/workspace/sso/portal-link` · operation `createSsoPortalLink`

Requires the `batondeck:workspace:admin` permission (action `sso:manage`).

Requires a step-up: MFA enrolled and re-authenticated within 15 minutes. **Not reachable with an API key** — a key has no session and so can never step up.

Refused while the workspace is suspended or on deletion hold.

**Request body** (`application/json`)

| Field | Type | Required | Notes |
|---|---|---|---|
| `intent` | "sso" \\| "domain_verification" | yes |  |

<details>
<summary>Request schema</summary>

```json
{
  "type": "object",
  "properties": {
    "intent": {
      "type": "string",
      "enum": [
        "sso",
        "domain_verification"
      ]
    }
  },
  "required": [
    "intent"
  ],
  "additionalProperties": false
}
```

</details>

**Responses**

| Status | Meaning |
|---|---|
| 200 | A short-lived link into the identity provider's Admin Portal, to set up a connection or verify a domain |
| 400 | The arguments did not validate. |
| 401 | No portal session, and no live API key. |
| 403 | The policy refused, or the request was cross-site. |
| 404 | No such resource, or none this session may see. |

<details>
<summary>200 response schema</summary>

```json
{
  "type": "object",
  "properties": {
    "url": {
      "type": "string"
    }
  },
  "required": [
    "url"
  ],
  "additionalProperties": false
}
```

</details>

```sh
curl -X POST 'https://api.batondeck.com/v1/workspace/sso/portal-link' \
  -H "Authorization: Bearer $BATONDECK_API_KEY" \
  -H 'content-type: application/json' \
  -d @body.json
```
