---
title: "Get app SSO settings"
method: GET
path: "/api/apps/{app_id}/sso/settings"
---

# Get app SSO settings

`GET /api/apps/{app_id}/sso/settings`

<Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Returns the app's own SSO provider and its settings. This is the provider set up for this app, not the workspace's SSO.

The client secret is never returned. `client_secret` reads as a fixed mask when one is stored. Each provider only returns the settings it uses, so the rest read as empty strings.

Change them with [Update app SSO settings](/api-reference/update-app-sso-settings).

This is limited to 60 requests a minute per caller for each app. Some workspaces have a different limit.

<Note>This endpoint accepts a personal API key belonging to a user with editor access to the app. A read-only key is refused, and workspace API keys are not accepted.</Note>

## Path parameters

- `app_id` string, required — ID of the app.

## Response `200`

The app's SSO provider settings.

- AppSSOSettingsResponse — The app's own SSO provider settings, with the client secret masked.
  - `settings` AppSSOSettings, required
    - `name` string, required — Name of the app's SSO provider, or an empty string when none is set. The builder uses `google`, `microsoft`, `github`, or `okta` for those providers. Any other name is a custom OpenID Connect or OAuth provider.
    - `client_id` string, required — OAuth client ID from the identity provider, or an empty string when none is stored.
    - `client_secret` string, required — Reads `XXXXXXXXXXXXXXXXXXXX` when a client secret is stored, and an empty string when none is. The secret itself is never returned.
    - `discovery_url` string, required — OpenID Connect discovery URL, or an empty string when none is stored or the provider doesn't use one.
    - `scope` string, required — Scopes requested at sign-in, separated by spaces. Reads `openid email profile` when none is stored or the provider doesn't use one.
    - `auth_endpoint` string, required — Authorization endpoint for a provider without a discovery URL, or an empty string when none is stored or the provider doesn't use one.
    - `token_endpoint` string, required — Token endpoint for a provider without a discovery URL, or an empty string when none is stored or the provider doesn't use one.
    - `userinfo_endpoint` string, required — User info endpoint for a provider without a discovery URL, or an empty string when none is stored or the provider doesn't use one.
    - `jwks_uri` string, required — URL of the provider's signing keys, for a custom provider. The value is an empty string when none is stored or the provider doesn't use one.
    - `tenant_id` string, required — Microsoft Entra tenant ID, or an empty string when none is stored or the provider isn't `microsoft`.
    - `okta_domain` string, required — Okta domain, or an empty string when none is stored or the provider isn't `okta`.

## Other responses

- `401` — Missing or invalid credentials.
- `403` — You don't have editor access to this app, your API key is read-only, or you used a workspace API key.
- `404` — App not found.
- `429` — Too many requests for this app's SSO settings from you in the last minute.

## Changes

> 22 revisions in range; 1 not diffed.

- **2026-09-28** `347e2afcf94a` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/adexad/apis/base44-app-management-api/changes/api/apps/:app_id/sso/settings/get.md)

---

[API](https://skmtc.dev/adexad/apis/base44-app-management-api.md) · [All operations](https://skmtc.dev/adexad/apis/base44-app-management-api/llms.txt) · [OpenAPI document](https://skmtc.dev/adexad/apis/base44-app-management-api/revisions/862b46d283f0?raw)
