SSO connections API

SSO connections endpoints in the Brix REST API: 11 operations (GET, POST, PATCH, DELETE), with auth, permissions and curl examples.

View as Markdown

Base URL https://api.brixsignage.com. Send Authorization: Bearer $BRIX_API_KEY unless an operation says No auth. The permission chip names what the key must hold. See Authentication and scopes, Errors and rate limits and Pagination.

GET/v1/sso-connections

Bearer token settings.view

Returns the workspace's enterprise single sign-on connections, with client secrets masked. The key or person must have settings.view for the whole workspace. A caller limited to a location or to a franchise workspace gets 403. lastClaims holds the claims from the last sign-in: a person's email, name and groups. It is null unless the caller also has user.view for the whole workspace.

curl "https://api.brixsignage.com/v1/sso-connections" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 200 Success.

FieldTypeDescription
dataarray of SsoConnection
data[].idstring
data[].displayNamestring
data[].vendorstringFree text; `generic-oidc` when not set.
data[].issuerstringThe OpenID Connect issuer URL (`https://`, no trailing slash).
data[].clientIdstring
data[].clientSecretPreview"••••••••"Always this mask: the client secret is stored encrypted and is never returned.
data[].emailDomainsstringComma-separated, lower-case (a leading `@` and a trailing dot are removed).
data[].domainsVerifiedAtstring | nullWhen DNS proved the domains; null until verified. An unverified connection is not offered at sign-in.
data[].provenAtstring | nullWhen a sign-in first completed with the current issuer, client and domains; null until then.
data[].lastSignInAtstring | nullThe latest sign-in through this connection. Only the list fills it; create and update answer null.
data[].jitProvisioningbooleanCreate a person on their first sign-in.
data[].defaultRoleIdstring | nullThe role a new person gets at the workspace root when no rule applies.
data[].claimMappingSsoClaimMapping | null
data[].extraScopesstring | nullScopes requested on top of `openid email profile`, space-separated.
data[].lastClaimsobject | nullThe claims of the last sign-in (a person's email, name and groups). Null unless the caller also holds `user.view` for the whole workspace.
data[].lastClaimsAtstring | null
data[].enabledboolean
data[].redirectUristringThe redirect URI to register in the identity provider.
data[].createdAtstringISO-8601 timestamp (UTC).
data[].updatedAtstringISO-8601 timestamp (UTC).

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 You do not hold the permission for the whole workspace (a grant at one location, or in a franchise workspace, is not enough).

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

POST/v1/sso-connections

Bearer token settings.edit

Creates an enterprise single sign-on connection. The client secret is encrypted before it is stored. **Notes.** - A new connection is unverified: prove its domains (domain-challenge, then verify-domains) before it is offered at sign-in.

Request body application/json

FieldTypeRequiredDescription
displayNamestringyes
vendorstringnoFree text, e.g. `okta`, `entra`.
issuerstringyesMust start with `https://`. A trailing slash is removed.
clientIdstringyes
clientSecretstringyesEncrypted before it is stored; never returned.
emailDomainsstringyesComma-separated email domains, e.g. `acme.com,acme.org`.
jitProvisioningbooleannoDefault true.
enabledbooleannoDefault true.
defaultRoleIdstring | nullnoYou must be able to grant this role for the whole workspace.
claimMappingSsoClaimMapping | nullnoYou must be able to grant each rule's role where the rule grants it. Null clears it.
extraScopesstring | nullnoSpace- or comma-separated scope tokens (at most 20). Null or empty clears them.
curl -X POST "https://api.brixsignage.com/v1/sso-connections" \
  -H "Authorization: Bearer $BRIX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"displayName":"Acme Okta","issuer":"https://acme.okta.com","clientId":"0oa1b2c3d4","clientSecret":"example-client-secret","emailDomains":"acme.com"}'

Response 201 Success.

FieldTypeDescription
dataSsoConnectionAn enterprise single sign-on (OpenID Connect) connection.
data.idstring
data.displayNamestring
data.vendorstringFree text; `generic-oidc` when not set.
data.issuerstringThe OpenID Connect issuer URL (`https://`, no trailing slash).
data.clientIdstring
data.clientSecretPreview"••••••••"Always this mask: the client secret is stored encrypted and is never returned.
data.emailDomainsstringComma-separated, lower-case (a leading `@` and a trailing dot are removed).
data.domainsVerifiedAtstring | nullWhen DNS proved the domains; null until verified. An unverified connection is not offered at sign-in.
data.provenAtstring | nullWhen a sign-in first completed with the current issuer, client and domains; null until then.
data.lastSignInAtstring | nullThe latest sign-in through this connection. Only the list fills it; create and update answer null.
data.jitProvisioningbooleanCreate a person on their first sign-in.
data.defaultRoleIdstring | nullThe role a new person gets at the workspace root when no rule applies.
data.claimMappingSsoClaimMapping | null
data.extraScopesstring | nullScopes requested on top of `openid email profile`, space-separated.
data.lastClaimsobject | nullThe claims of the last sign-in (a person's email, name and groups). Null unless the caller also holds `user.view` for the whole workspace.
data.lastClaimsAtstring | null
data.enabledboolean
data.redirectUristringThe redirect URI to register in the identity provider.
data.createdAtstringISO-8601 timestamp (UTC).
data.updatedAtstringISO-8601 timestamp (UTC).

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 You do not hold the permission for the whole workspace (a grant at one location, or in a franchise workspace, is not enough). Also: `defaultRoleId` or a rule's role holds permissions you cannot grant there.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 404 No such connection, role or location in this workspace.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 422 A required field is missing, `issuer` is not `https://`, an invalid `claimMapping`, or `extraScopes` is not a valid scope list.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

PATCH/v1/sso-connections/{id}

Bearer token settings.edit

Updates an enterprise single sign-on connection. clientSecret is optional: when provided, it replaces the stored secret; when omitted, the existing secret is left unchanged. **Notes.** - Changing emailDomains clears domainsVerifiedAt. Changing issuer, clientId, clientSecret or emailDomains clears provenAt.

ParameterInTypeRequiredDescription
idpathstringyesSSO connection id.

Request body application/json

FieldTypeRequiredDescription
displayNamestringno
vendorstringnoFree text, e.g. `okta`, `entra`.
issuerstringnoMust start with `https://`. A trailing slash is removed.
clientIdstringno
clientSecretstringnoReplaces the stored secret. Omitted or empty keeps it.
emailDomainsstringnoComma-separated email domains, e.g. `acme.com,acme.org`.
jitProvisioningbooleannoDefault true.
enabledbooleannoDefault true.
defaultRoleIdstring | nullnoYou must be able to grant this role for the whole workspace.
claimMappingSsoClaimMapping | nullnoYou must be able to grant each rule's role where the rule grants it. Null clears it.
extraScopesstring | nullnoSpace- or comma-separated scope tokens (at most 20). Null or empty clears them.
curl -X PATCH "https://api.brixsignage.com/v1/sso-connections/{id}" \
  -H "Authorization: Bearer $BRIX_API_KEY" \
  -H "Content-Type: application/json"

Response 200 Success.

FieldTypeDescription
dataSsoConnectionAn enterprise single sign-on (OpenID Connect) connection.
data.idstring
data.displayNamestring
data.vendorstringFree text; `generic-oidc` when not set.
data.issuerstringThe OpenID Connect issuer URL (`https://`, no trailing slash).
data.clientIdstring
data.clientSecretPreview"••••••••"Always this mask: the client secret is stored encrypted and is never returned.
data.emailDomainsstringComma-separated, lower-case (a leading `@` and a trailing dot are removed).
data.domainsVerifiedAtstring | nullWhen DNS proved the domains; null until verified. An unverified connection is not offered at sign-in.
data.provenAtstring | nullWhen a sign-in first completed with the current issuer, client and domains; null until then.
data.lastSignInAtstring | nullThe latest sign-in through this connection. Only the list fills it; create and update answer null.
data.jitProvisioningbooleanCreate a person on their first sign-in.
data.defaultRoleIdstring | nullThe role a new person gets at the workspace root when no rule applies.
data.claimMappingSsoClaimMapping | null
data.extraScopesstring | nullScopes requested on top of `openid email profile`, space-separated.
data.lastClaimsobject | nullThe claims of the last sign-in (a person's email, name and groups). Null unless the caller also holds `user.view` for the whole workspace.
data.lastClaimsAtstring | null
data.enabledboolean
data.redirectUristringThe redirect URI to register in the identity provider.
data.createdAtstringISO-8601 timestamp (UTC).
data.updatedAtstringISO-8601 timestamp (UTC).

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 You do not hold the permission for the whole workspace (a grant at one location, or in a franchise workspace, is not enough). Also: `defaultRoleId` or a rule's role holds permissions you cannot grant there.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 404 No such connection, role or location in this workspace.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 422 A required field is missing, `issuer` is not `https://`, an invalid `claimMapping`, or `extraScopes` is not a valid scope list.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

DELETE/v1/sso-connections/{id}

Bearer token settings.edit

Soft-deletes an enterprise single sign-on connection. **Notes.** - Answers { ok: true }, not the { id, deleted } shape of other deletes. The connection is also disabled.

ParameterInTypeRequiredDescription
idpathstringyesSSO connection id.
curl -X DELETE "https://api.brixsignage.com/v1/sso-connections/{id}" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 200 Success.

FieldTypeDescription
dataobject
data.oktrue

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 You do not hold the permission for the whole workspace (a grant at one location, or in a franchise workspace, is not enough).

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 404 No such connection in this workspace.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

GET/v1/sso-connections/{id}/domain-challenge

Bearer token settings.view

Returns the DNS TXT records you must publish to prove control of the email domains used by this SSO connection. The key or person must have settings.view for the whole workspace.

ParameterInTypeRequiredDescription
idpathstringyesSSO connection id.
curl "https://api.brixsignage.com/v1/sso-connections/{id}/domain-challenge" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 200 Success.

FieldTypeDescription
dataobject
data.recordsarray of object
data.records[].domainstring
data.records[].namestringThe record name: `_brix-verify.<domain>`.
data.records[].type"TXT"
data.records[].valuestringThe record value to publish: `brix-domain-verify=<token>`.
data.verifiedAtstring | null

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 You do not hold the permission for the whole workspace (a grant at one location, or in a franchise workspace, is not enough).

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 404 No such connection in this workspace.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

GET/v1/sso-connections/{id}/scim

Bearer token settings.view

Returns the SCIM base URL for this SSO connection and a preview of its currently live provisioning tokens. Token secrets themselves are never returned.

ParameterInTypeRequiredDescription
idpathstringyesSSO connection id.
curl "https://api.brixsignage.com/v1/sso-connections/{id}/scim" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 200 Success.

FieldTypeDescription
dataobject
data.baseUrlstringThe SCIM 2.0 base URL to give the identity provider.
data.tokensarray of objectLive tokens only.
data.tokens[].idstring
data.tokens[].previewstring`••••` and the last four characters.
data.tokens[].createdAtstringISO-8601 timestamp (UTC).
data.tokens[].lastUsedAtstring | null

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 You do not hold the permission for the whole workspace (a grant at one location, or in a franchise workspace, is not enough).

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 404 No such connection in this workspace.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

POST/v1/sso-connections/{id}/scim/tokens

Bearer token settings.edit

Creates a new SCIM provisioning token for this SSO connection. The token value is shown exactly once, in this response. A connection can have at most 5 live tokens at a time. This action cannot be taken while impersonating another user.

ParameterInTypeRequiredDescription
idpathstringyesSSO connection id.
curl -X POST "https://api.brixsignage.com/v1/sso-connections/{id}/scim/tokens" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 201 Success.

FieldTypeDescription
dataobject
data.idstring
data.tokenstringThe SCIM bearer token. Shown only here; store it now.
data.baseUrlstring

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 You do not hold the permission for the whole workspace (a grant at one location, or in a franchise workspace, is not enough).

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 404 No such connection in this workspace.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 409 `too_many_tokens`: the connection already has 5 live tokens.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

DELETE/v1/sso-connections/{id}/scim/tokens/{tokenId}

Bearer token settings.edit

Revokes one SCIM provisioning token belonging to this SSO connection.

ParameterInTypeRequiredDescription
idpathstringyesSSO connection id.
tokenIdpathstringyesSCIM token id.
curl -X DELETE "https://api.brixsignage.com/v1/sso-connections/{id}/scim/tokens/{tokenId}" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 200 Success.

FieldTypeDescription
dataobject
data.oktrue

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 You do not hold the permission for the whole workspace (a grant at one location, or in a franchise workspace, is not enough).

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 404 No such connection, or no live token with this id.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

POST/v1/sso-connections/{id}/test-mapping

Bearer token settings.view

Previews the role and location a person would be granted, given a set of example identity-provider claims, by running the same mapping logic used at sign-in. This is read-only and does not sign anyone in or change anything.

ParameterInTypeRequiredDescription
idpathstringyesSSO connection id.

Request body application/json

FieldTypeRequiredDescription
claimsobjectyesExample identity-provider claims.
claimMappingSsoClaimMapping | nullnoAn unsaved mapping to test; omitted = the saved one.
curl -X POST "https://api.brixsignage.com/v1/sso-connections/{id}/test-mapping" \
  -H "Authorization: Bearer $BRIX_API_KEY" \
  -H "Content-Type: application/json"

Response 200 Success.

FieldTypeDescription
dataobject
data.mappedbooleanFalse when there is no mapping: `grants` is then the default role at the root, without names.
data.grantsarray of object
data.grants[].nodeIdstringLocation id (the workspace id for the root).
data.grants[].roleIdstring
data.grants[].roleNamestring | nullAbsent when `mapped` is false.
data.grants[].nodeNamestring | nullAbsent when `mapped` is false.
data.matchedRulesarray of integerIndexes of the rules that matched.
data.unmatchedLocationsarray of stringLocation values that matched no location.
data.ambiguousLocationsarray of stringLocation values that matched more than one location.
data.usedDefaultboolean
data.deniedbooleanTrue when the sign-in would be refused (`noMatch: deny`).

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 You do not hold the permission for the whole workspace (a grant at one location, or in a franchise workspace, is not enough).

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 404 No such connection in this workspace.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 422 `claims` is not an object, or `claimMapping` is invalid.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

POST/v1/sso-connections/{id}/verify-domains

Bearer token settings.edit

Verifies an SSO connection's email domains using a DNS TXT record lookup. Verified domains control whether the connection is offered at sign-in and whether cross-workspace sign-in is allowed for that domain. **Notes.** - Answers 200 with verified: false when a domain fails; the connection stays unverified.

ParameterInTypeRequiredDescription
idpathstringyesSSO connection id.
curl -X POST "https://api.brixsignage.com/v1/sso-connections/{id}/verify-domains" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 200 Success.

FieldTypeDescription
dataobject
data.verifiedbooleanTrue only when every domain proved out.
data.resultsarray of object
data.results[].domainstring
data.results[].okboolean
data.results[].reasonstringWhy a domain failed: `claimed_by_another_workspace`, `dns_<status>`, or a lookup error. Absent when the lookup answered.
data.verifiedAtstring | null

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 You do not hold the permission for the whole workspace (a grant at one location, or in a franchise workspace, is not enough).

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 404 No such connection in this workspace.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 422 `no_domains`: the connection has no email domains.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

POST/v1/sso-connections/test

Bearer token settings.view

Fetches the identity provider's OpenID Connect discovery document and returns its parsed authorization, token, and key endpoints, so the connection can be confirmed as reachable before the setup form is submitted. **Notes.** - Needs settings.view held anywhere, unlike the other SSO routes, which need it for the whole workspace.

Request body application/json

FieldTypeRequiredDescription
issuerstringyesMust start with `https://`.
curl -X POST "https://api.brixsignage.com/v1/sso-connections/test" \
  -H "Authorization: Bearer $BRIX_API_KEY" \
  -H "Content-Type: application/json"

Response 200 Success.

FieldTypeDescription
dataobject
data.oktrue
data.issuerstringThe issuer the discovery document names; absent when it names none.
data.authorizationEndpointstring
data.tokenEndpointstring
data.jwksUristring

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 The token lacks the permission this operation needs (see `x-brix-permission`).

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 422 `issuer` is not `https://`.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 502 `discovery_failed` (the provider answered an error), `discovery_incomplete` (an endpoint is missing), or `discovery_threw` (not reachable).

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.