GET
/api/public/v1/ssoGet the SSO configuration
How the company signs in. Secrets are never returned — the client secret is write-only, so it can be set and never read back. `enforced` is the one to watch: with it on, password sign-in is closed and everybody comes through the provider. `breakGlassUsedAt` records the last time somebody bypassed SSO with the emergency code; that bypass is owner-only and deliberately not an API operation.
Required scope
The access token must carry this scope. A token missing it gets 403 Forbidden. Grant them to an API client under Settings → Company → API, and to a teammate under Employee → Permissions.
sso:read
GETExample request
curl
curl -X GET "https://www.pxb.app/api/public/v1/sso" \
-H "Authorization: Bearer your_access_token"200Example response
json
{
"message": "SSO configuration retrieved successfully!",
"content": {
"config": {
"enabled": true,
"enforced": false,
"provider": "ENTRA",
"issuer": "https://login.microsoftonline.com/…/v2.0",
"clientId": "a1b2c3",
"buttonLabel": "Sign in with Microsoft",
"sessionTtlMinutes": 480,
"breakGlassUsedAt": null
}
}
}In the console
The same thing done by hand, for anyone comparing the API against the screen they already use.
Settings → Company → SSO
/settings/company/sso