Optionalallowed_Email domains allowed for SSO (required for strict mode)
Optionalclaim_Maps Contio user fields to IdP claim names. Defaults to {"email": "email", "name": "name"}
OIDC discovery endpoint URL from your Identity Provider (should end with /.well-known/openid-configuration)
OAuth Client ID from your Identity Provider's OIDC application. This is NOT your Contio Partner client_id.
OAuth Client Secret from your Identity Provider's OIDC application. This is NOT your Contio Partner client_secret. Stored encrypted at rest.
Domain validation mode: "strict" requires allowed_email_domains, "partner_managed" trusts your IdP
Display name for this IdP configuration
OptionalscopesOIDC scopes to request during authentication. Defaults to ["openid", "email", "profile"]
Request to create an IdP configuration.
IMPORTANT: The idp_client_id and idp_client_secret are the OIDC credentials from your Identity Provider (e.g., Okta, Azure AD, Auth0), NOT your Contio Partner OAuth credentials.