Skip to main content
POST
Disable organization SSO

Authorizations

Authorization
string
header
required

Account Service Key, prefixed with pho_ask_, sent as Authorization: Bearer <key>. Acts on behalf of its owning account, subject to the permissions and credential restrictions of each operation. Account access tokens and OAuth grants also use the Bearer header. In organizations that require SSO, Account Service Keys are not accepted for managing the organization's SSO settings, deleting the organization, or checking whether it can be deleted.

Headers

Idempotency-Key
string
required

Identifies one logical mutation across retries.

Required string length: 1 - 255
Pattern: ^[\x21-\x7e]{1,255}$

Path Parameters

orgId
string
required
Pattern: ^pho_org_[0-7][0-9a-hjkmnp-tv-z]{25}$

Body

application/json
expectedVersion
string
required
Pattern: ^(0|[1-9][0-9]{0,19})$
domains
string[]
Maximum array length: 100
Required string length: 1 - 253

Response

Current connection and independent local policy state.

connectionChangedAt
string<date-time> | null
required
Example:

"2026-01-01T00:00:00.000Z"

connectionGeneration
string
required
Pattern: ^(0|[1-9][0-9]{0,19})$
connectionState
enum<string>
required
Available options:
not_configured,
configuring,
ready,
error
desiredSsoEnforced
boolean
required
organizationId
string
required
policySyncStatus
enum<string>
required
Available options:
synced,
manual_required
ssoEnforced
boolean
required
ssoJitEnabled
boolean
required
version
string
required
Pattern: ^(0|[1-9][0-9]{0,19})$
connectionType
string
domains
object[]
providerAvailable
boolean
{key}
any