---
title: "Update app SSO settings"
method: PUT
path: "/api/apps/{app_id}/sso/settings"
---

# Update app SSO settings

`PUT /api/apps/{app_id}/sso/settings`

<Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Sets up or changes the app's own SSO provider, and turns SSO sign-in on for the app. The app's other login methods stay as they are. Turn those off with [Update app](/api-reference/update-app).

The credentials and URLs you send take effect on the published app right away, including when you switch providers, so a switch can change or break live sign-ins before you deploy. The provider `name` and SSO being turned on reach the published app once you [deploy the app](/api-reference/deploy-an-app).

Send only the fields you want to change. A field you leave out keeps its stored value, and an empty string clears it. Sending the masked `client_secret` from [Get app SSO settings](/api-reference/get-app-sso-settings) keeps the stored secret.

Changing `name` to a different provider deletes everything stored for the previous one, so send the new provider's settings in the same request.

After the save, the app needs a `client_id`, a `client_secret`, and either a `discovery_url` or both an `auth_endpoint` and a `token_endpoint`. A request that would leave any of these missing is rejected and nothing is saved.

The `discovery_url` is fetched before saving. If it can't serve a sign-in, the request is rejected. If the check fails in a way that may be temporary, the settings are saved and the response carries a `warning`.

Turning SSO on for an app that doesn't use it yet needs a plan that includes SSO for apps. An app that already uses SSO can keep changing its settings.

The settings are stored as the app's secrets whose names start with `sso_`, and the app's backend functions, if it has any, redeploy to pick them up.

This is limited to 20 requests a minute per caller for each app. Some workspaces have a different limit.

<Note>This endpoint accepts a personal API key belonging to a user with editor access to the app. A read-only key is refused, and workspace API keys are not accepted.</Note>

## Path parameters

- `app_id` string, required — ID of the app.

## Request body

- AppSSOUpdateRequest — The app's SSO provider and the settings to change, sent together.
  - `name` string, nullable — Name of the SSO provider. Use `google`, `microsoft`, `github`, or `okta` for those providers, or a name of your choice for any other OpenID Connect or OAuth provider. Required unless the app already has a provider.
  - `client_id` string, nullable — OAuth client ID from the identity provider.
  - `client_secret` string, nullable — OAuth client secret from the identity provider. Leave it out to keep the stored one.
  - `discovery_url` string, nullable — OpenID Connect discovery URL. It must be an absolute `http` or `https` URL on a public address.
  - `scope` string, nullable — Scopes to request at sign-in, separated by spaces.
  - `auth_endpoint` string, nullable — Authorization endpoint, for a provider without a discovery URL.
  - `token_endpoint` string, nullable — Token endpoint, for a provider without a discovery URL.
  - `userinfo_endpoint` string, nullable — User info endpoint, for a provider without a discovery URL.
  - `jwks_uri` string, nullable — URL of the provider's signing keys, for a custom provider.
  - `tenant_id` string, nullable — Microsoft Entra tenant ID, for the `microsoft` provider.
  - `okta_domain` string, nullable — Okta domain, for the `okta` provider.

## Response `200`

The settings were saved.

- AppSSOUpdateResponse — The result of saving the app's SSO provider settings.
  - `status` string, required — Always `success`.
  - `auth_config` object, required — The app's sign-in settings as saved, with `sso_provider_name` set to the provider and `enable_sso_login` set to `true`.
  - `warning` string, nullable — Why the discovery URL couldn't be checked, present only when that happened. The settings are saved, but SSO sign-in fails while the problem lasts.

## Other responses

- `400` — No provider `name` was sent and the app has none, the settings would be incomplete, a URL isn't an absolute public `http` or `https` URL, or the `discovery_url` can't serve a sign-in.
- `401` — Missing or invalid credentials.
- `402` — You're turning SSO on, and the app's workspace plan doesn't include SSO for apps.
- `403` — You don't have editor access to this app, your API key is read-only, or you used a workspace API key.
- `404` — App not found.
- `422` — The body isn't a JSON object, or a field isn't a string.
- `429` — Too many SSO settings updates for this app from you in the last minute.

## Changes

> 22 revisions in range; 1 not diffed.

- **2026-09-28** `347e2afcf94a` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/adexad/apis/base44-app-management-api/changes/api/apps/:app_id/sso/settings/put.md)

---

[API](https://skmtc.dev/adexad/apis/base44-app-management-api.md) · [All operations](https://skmtc.dev/adexad/apis/base44-app-management-api/llms.txt) · [OpenAPI document](https://skmtc.dev/adexad/apis/base44-app-management-api/revisions/862b46d283f0?raw)
