GET
/api/public/v1/sso

Get the SSO configuration

How the company signs in. Secrets are never returned — the client secret is write-only, so it can be set and never read back. `enforced` is the one to watch: with it on, password sign-in is closed and everybody comes through the provider. `breakGlassUsedAt` records the last time somebody bypassed SSO with the emergency code; that bypass is owner-only and deliberately not an API operation.

Required scope

The access token must carry this scope. A token missing it gets 403 Forbidden. Grant them to an API client under Settings → Company → API, and to a teammate under Employee → Permissions.

sso:read
GETExample request
curl
curl -X GET "https://www.pxb.app/api/public/v1/sso" \
  -H "Authorization: Bearer your_access_token"
200Example response
json
{
  "message": "SSO configuration retrieved successfully!",
  "content": {
    "config": {
      "enabled": true,
      "enforced": false,
      "provider": "ENTRA",
      "issuer": "https://login.microsoftonline.com/…/v2.0",
      "clientId": "a1b2c3",
      "buttonLabel": "Sign in with Microsoft",
      "sessionTtlMinutes": 480,
      "breakGlassUsedAt": null
    }
  }
}

In the console

The same thing done by hand, for anyone comparing the API against the screen they already use.

Settings → Company → SSO
/settings/company/sso