The identity and technical contract details declared by the specification.
ConnectionSignupBehaviorEnum
string
Specifies the signup behavior for password authentication
GetConnectionResponseContent
object
12 properties
ConnectionOptions
object
In order to return options in the response, the read:connectionsoptions scope must be present
ConnectionEmailOtpAuthenticationMethod
object
Email OTP authentication enablement
1 property
UpdateConnectionResponseContent
object
12 properties
GetScimTokensResponseContent
array
The list of scim tokens for scim clients
CreateDirectorySynchronizationResponseContent
object
3 properties
3 required
ConnectionValidationOptions
objectnull
Options for validation
1 property
ConnectionFederatedConnectionsAccessTokens
objectnull
Federated Connections Access Tokens
1 property
ConnectionIdentifierPrecedenceEnum
string
Order of precedence for attribute types
ConnectionPhoneOtpAuthenticationMethod
object
Phone OTP authentication enablement
1 property
ConnectionUpstreamAlias
object
1 property
PostConnectionsKeysResponseContent
array
CreateScimTokenResponseContent
object
5 properties
PasswordDefaultDictionariesEnum
string
Default dictionary to use for password validation. Options: "en10k" (10,000 common words) or "en100k" (100,000 common words)
ScimTokenItem
object
5 properties
SynchronizedGroupPayload
object
1 property
1 required
ConnectionPropertiesOptions
object
The connection's options (depend on the connection strategy)
36 properties
ListConnectionsCheckpointPaginatedResponseContent
object
2 properties
UpdateConnectionRequestContent
object
9 properties
ConnectionApiBehaviorEnum
string
Specifies the API behavior for password authentication
PasswordCharacterTypeEnum
string
ConnectionUpstreamAliasEnum
string
ConnectionKeyUseEnum
string
Signing key use, whether for encryption or signing
PhoneAttribute
object
Configuration for the phone number attribute for users.
3 properties
ConnectionPasskeyChallengeUIEnum
string
Controls the UI used to challenge the user for their passkey.
ConnectionAuthenticationMethods
objectnull
Options for enabling authentication methods.
4 properties
CreateConnectionResponseContent
object
12 properties
CreateDirectoryProvisioningRequestContent
objectnull
3 properties
ConnectionPasswordOptionsDictionary
object
Dictionary-based password restriction policy to prevent common passwords
3 properties
ConnectionStrategyEnum
string
UsernameAttribute
object
Configuration for the username attribute for users.
4 properties
RotateConnectionsKeysResponseContent
object
9 properties
4 required
ConnectionAttributeIdentifier
object
2 properties
ScimMappingItem
object
2 properties
EmailAttribute
object
Configuration for the email attribute for users.
5 properties
UpdateConnectionOptions
objectnull
The connection's options (depend on the connection strategy). To update these options, the update:connectionsoptions scope must be present. To verify your chan…
36 properties
ConnectionPasswordNoPersonalInfoOptions
objectnull
Options for personal info in passwords policy
1 property
1 required
ConnectionPasswordPolicyEnum
stringnull
Password strength level
ConnectionForList
object
11 properties
ConnectionAttributes
object
Attribute configuration
3 properties
ConnectionIdentityProviderEnum
string
The identity provider identifier for the connection
ConnectionUpstreamParams
objectnull
Options for adding parameters in the request to the upstream IdP
SignupSchema
object
1 property
RotateConnectionKeysSigningAlgEnum
string
Selected Signing Algorithm
SignupVerified
object
2 properties
PasswordSequentialCharactersPolicyEnum
string
Controls whether sequential characters are allowed in passwords
CreateScimConfigurationResponseContent
object
8 properties
8 required
ConnectionsMetadata
object
Metadata associated with the connection in the form of an object with string values (max 255 chars). Maximum of 10 metadata properties allowed.
ConnectionUpstreamAdditionalProperties
object
GetDirectoryProvisioningDefaultMappingResponseContent
object
1 property
UpdateDirectoryProvisioningResponseContent
object
11 properties
7 required
ConnectionPasskeyOptions
objectnull
Options for the passkey authentication method
3 properties
ConnectionPasswordOptions
object
Password policy options for flexible password policy configuration
4 properties
VerificationMethodEnum
string
ListConnectionsResponseContent
ConnectionPasswordOptionsComplexity
object
Password complexity requirements configuration
6 properties
PasswordIdenticalCharactersPolicyEnum
string
Controls whether identical consecutive characters are allowed in passwords
ConnectionConnectedAccountsPurpose
object
Configure the purpose of a connection to be used for connected accounts and Token Vault.
2 properties
1 required
ConnectionPasswordDictionaryOptions
objectnull
Options for password dictionary policy
2 properties
1 required
ConnectionEnabledClient
object
1 property
1 required
ConnectionAuthenticationPurpose
object
Configure the purpose of a connection to be used for authentication during login.
1 property
1 required
GetConnectionEnabledClientsResponseContent
object
2 properties
1 required
GetScimConfigurationDefaultMappingResponseContent
object
1 property
ConnectionCustomScripts
object
A map of scripts used to integrate with a custom database.
9 properties
SynchronizeGroupsEnum
string
Group synchronization configuration
DirectoryProvisioningMappingItem
object
2 properties
2 required
UsernameValidation
object
3 properties
GetDirectoryProvisioningResponseContent
object
11 properties
7 required
UpdateScimConfigurationResponseContent
object
8 properties
8 required
GetScimConfigurationResponseContent
object
8 properties
8 required
ConnectionTokenEndpointJwtcaAudFormatEnumOIDC
string
Specifies the format of the aud (audience) claim included in the JWT used for client authentication at the token endpoint. Accepted values are: 'issuer' (the a…
UpdateScimConfigurationRequestContent
object
2 properties
2 required
ConnectionPasswordComplexityOptions
objectnull
Password complexity options
1 property
ConnectionUsernameValidationOptions
objectnull
2 properties
2 required
ListSynchronizedGroupsResponseContent
object
2 properties
1 required
CreateDirectoryProvisioningResponseContent
object
11 properties
7 required
ReplaceSynchronizedGroupsRequestContent
object
1 property
1 required
PostConnectionKeysRequestContent
objectnull
1 property
ConnectionAssertionDecryptionSettings
object
Settings for SAML assertion decryption.
2 properties
1 required
ConnectionIdTokenSignedResponseAlgEnum
string
Algorithm allowed to verify the ID tokens.
ConnectionUpstreamValue
object
1 property
ConnectionKey
object
12 properties
4 required
ConnectionGatewayAuthentication
objectnull
Token-based authentication settings to be applied when connection is using an sms strategy.
5 properties
3 required
ConnectionPasskeyAuthenticationMethod
object
Passkey authentication enablement
1 property
PasswordMaxLengthExceededPolicyEnum
string
Controls whether passwords that exceed the maximum length are truncated or rejected
ConnectionTokenEndpointAuthMethodEnum
stringnull
Authentication method used at the identity provider's token endpoint. 'clientsecretpost' sends credentials in the request body; 'privatekeyjwt' uses a signed J…
SignupVerification
object
1 property
ConnectionTokenEndpointAuthSigningAlgEnum
stringnull
Algorithm used to sign clientassertions.
ConnectionPasswordOptionsHistory
object
Password history policy configuration to prevent password reuse
2 properties
CreateScimConfigurationRequestContent
objectnull
2 properties
ConnectionPasswordOptionsProfileData
object
Personal information restriction policy to prevent use of profile data in passwords
2 properties
UpdateEnabledClientConnectionsRequestContent
array
CreateConnectionRequestContent
object
11 properties
2 required
DefaultMethodEmailIdentifierEnum
string
Default authentication method for email identifier
UpdateDirectoryProvisioningRequestContent
objectnull
3 properties
ConnectionPasswordHistoryOptions
objectnull
Options for password history policy
2 properties
1 required
ConnectionAssertionDecryptionAlgorithmProfileEnum
string
The algorithm profile to use for decrypting SAML assertions.
UsernameAllowedTypes
object
2 properties
PasswordCharacterTypeRulePolicyEnum
string
When enabled, passwords must contain at least 3 out of 4 character types. Can only be enabled when all 4 character types are specified
ListConnectionsOffsetPaginatedResponseContent
object
4 properties
PostConnectionKeysAlgEnum
string
Selected Signing Algorithm
ConnectionSetUserRootAttributesEnum
string
When using an external IdP, this flag determines whether 'name', 'givenname', 'familyname', 'nickname', and 'picture' attributes are updated. In addition, it a…
RotateConnectionKeysRequestContent
objectnull
1 property
CreateScimTokenRequestContent
object
SCIM Token
2 properties
ConnectionPasswordAuthenticationMethod
object
Password authentication enablement
3 properties
ConnectionIdTokenSignedResponseAlgs
arraynull
List of algorithms allowed to verify the ID tokens.
The full machine-readable OpenAPI contract behind this narrative.
Other APIs Auth0 publishes across the network.