curl --request PATCH \
--url https://api.photon.codes/v1/auth/organizations/{orgId}/sso \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"expectedVersion": "<string>",
"ssoJitEnabled": true
}
'import requests
url = "https://api.photon.codes/v1/auth/organizations/{orgId}/sso"
payload = {
"expectedVersion": "<string>",
"ssoJitEnabled": True
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PATCH',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({expectedVersion: '<string>', ssoJitEnabled: true})
};
fetch('https://api.photon.codes/v1/auth/organizations/{orgId}/sso', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.photon.codes/v1/auth/organizations/{orgId}/sso",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PATCH",
CURLOPT_POSTFIELDS => json_encode([
'expectedVersion' => '<string>',
'ssoJitEnabled' => true
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.photon.codes/v1/auth/organizations/{orgId}/sso"
payload := strings.NewReader("{\n \"expectedVersion\": \"<string>\",\n \"ssoJitEnabled\": true\n}")
req, _ := http.NewRequest("PATCH", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.patch("https://api.photon.codes/v1/auth/organizations/{orgId}/sso")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"expectedVersion\": \"<string>\",\n \"ssoJitEnabled\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.photon.codes/v1/auth/organizations/{orgId}/sso")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Patch.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"expectedVersion\": \"<string>\",\n \"ssoJitEnabled\": true\n}"
response = http.request(request)
puts response.read_body{
"connectionChangedAt": "2026-01-01T00:00:00.000Z",
"connectionGeneration": "<string>",
"connectionState": "not_configured",
"desiredSsoEnforced": true,
"organizationId": "<string>",
"policySyncStatus": "synced",
"ssoEnforced": true,
"ssoJitEnabled": true,
"version": "<string>",
"connectionType": "<string>",
"domains": [
{
"domain": "<string>",
"state": "verified"
}
],
"providerAvailable": true
}{
"code": "INVALID_RETURN_TO",
"status": 400,
"title": "Invalid Return To",
"type": "https://photon.codes/docs/problems/invalid-return-to"
}{
"code": "NOT_AUTHENTICATED",
"status": 401,
"title": "Not Authenticated",
"type": "https://photon.codes/docs/problems/not-authenticated"
}{
"code": "FORBIDDEN",
"status": 403,
"title": "Forbidden",
"type": "https://photon.codes/docs/problems/forbidden"
}{
"code": "ORGANIZATION_SSO_NOT_FOUND",
"status": 404,
"title": "Organization SSO Not Found",
"type": "https://photon.codes/docs/problems/organization-sso-not-found"
}{
"code": "ORGANIZATION_SSO_CONFLICT",
"status": 409,
"title": "Organization SSO Conflict",
"type": "https://photon.codes/docs/problems/organization-sso-conflict"
}{
"code": "ORGANIZATION_SSO_PRECONDITION_FAILED",
"status": 412,
"title": "Organization SSO Precondition Failed",
"type": "https://photon.codes/docs/problems/organization-sso-precondition-failed"
}{
"code": "VALIDATION_FAILED",
"issues": [
{
"code": "invalid_type",
"location": "json",
"message": "Expected a string.",
"path": "/name"
}
],
"status": 422,
"title": "Request Validation Failed",
"type": "https://photon.codes/docs/problems/validation-failed"
}{
"code": "INTERNAL_ERROR",
"status": 500,
"title": "Internal Server Error",
"type": "https://photon.codes/docs/problems/internal-error"
}{
"code": "UPSTREAM_FAILURE",
"status": 502,
"title": "Upstream Service Failure",
"type": "https://photon.codes/docs/problems/upstream-failure"
}{
"code": "UPSTREAM_UNAVAILABLE",
"status": 503,
"title": "Upstream Service Unavailable",
"type": "https://photon.codes/docs/problems/upstream-unavailable"
}{
"code": "UPSTREAM_TIMEOUT",
"status": 504,
"title": "Upstream Service Timeout",
"type": "https://photon.codes/docs/problems/upstream-timeout"
}Update organization SSO policy
Updates whether SSO can admit new members automatically using ssoJitEnabled and the current expectedVersion. Returns the organization’s SSO configuration and policy synchronization status; a successful response does not mean every desired policy setting has finished synchronizing.
curl --request PATCH \
--url https://api.photon.codes/v1/auth/organizations/{orgId}/sso \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"expectedVersion": "<string>",
"ssoJitEnabled": true
}
'import requests
url = "https://api.photon.codes/v1/auth/organizations/{orgId}/sso"
payload = {
"expectedVersion": "<string>",
"ssoJitEnabled": True
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PATCH',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({expectedVersion: '<string>', ssoJitEnabled: true})
};
fetch('https://api.photon.codes/v1/auth/organizations/{orgId}/sso', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.photon.codes/v1/auth/organizations/{orgId}/sso",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PATCH",
CURLOPT_POSTFIELDS => json_encode([
'expectedVersion' => '<string>',
'ssoJitEnabled' => true
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.photon.codes/v1/auth/organizations/{orgId}/sso"
payload := strings.NewReader("{\n \"expectedVersion\": \"<string>\",\n \"ssoJitEnabled\": true\n}")
req, _ := http.NewRequest("PATCH", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.patch("https://api.photon.codes/v1/auth/organizations/{orgId}/sso")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"expectedVersion\": \"<string>\",\n \"ssoJitEnabled\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.photon.codes/v1/auth/organizations/{orgId}/sso")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Patch.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"expectedVersion\": \"<string>\",\n \"ssoJitEnabled\": true\n}"
response = http.request(request)
puts response.read_body{
"connectionChangedAt": "2026-01-01T00:00:00.000Z",
"connectionGeneration": "<string>",
"connectionState": "not_configured",
"desiredSsoEnforced": true,
"organizationId": "<string>",
"policySyncStatus": "synced",
"ssoEnforced": true,
"ssoJitEnabled": true,
"version": "<string>",
"connectionType": "<string>",
"domains": [
{
"domain": "<string>",
"state": "verified"
}
],
"providerAvailable": true
}{
"code": "INVALID_RETURN_TO",
"status": 400,
"title": "Invalid Return To",
"type": "https://photon.codes/docs/problems/invalid-return-to"
}{
"code": "NOT_AUTHENTICATED",
"status": 401,
"title": "Not Authenticated",
"type": "https://photon.codes/docs/problems/not-authenticated"
}{
"code": "FORBIDDEN",
"status": 403,
"title": "Forbidden",
"type": "https://photon.codes/docs/problems/forbidden"
}{
"code": "ORGANIZATION_SSO_NOT_FOUND",
"status": 404,
"title": "Organization SSO Not Found",
"type": "https://photon.codes/docs/problems/organization-sso-not-found"
}{
"code": "ORGANIZATION_SSO_CONFLICT",
"status": 409,
"title": "Organization SSO Conflict",
"type": "https://photon.codes/docs/problems/organization-sso-conflict"
}{
"code": "ORGANIZATION_SSO_PRECONDITION_FAILED",
"status": 412,
"title": "Organization SSO Precondition Failed",
"type": "https://photon.codes/docs/problems/organization-sso-precondition-failed"
}{
"code": "VALIDATION_FAILED",
"issues": [
{
"code": "invalid_type",
"location": "json",
"message": "Expected a string.",
"path": "/name"
}
],
"status": 422,
"title": "Request Validation Failed",
"type": "https://photon.codes/docs/problems/validation-failed"
}{
"code": "INTERNAL_ERROR",
"status": 500,
"title": "Internal Server Error",
"type": "https://photon.codes/docs/problems/internal-error"
}{
"code": "UPSTREAM_FAILURE",
"status": 502,
"title": "Upstream Service Failure",
"type": "https://photon.codes/docs/problems/upstream-failure"
}{
"code": "UPSTREAM_UNAVAILABLE",
"status": 503,
"title": "Upstream Service Unavailable",
"type": "https://photon.codes/docs/problems/upstream-unavailable"
}{
"code": "UPSTREAM_TIMEOUT",
"status": 504,
"title": "Upstream Service Timeout",
"type": "https://photon.codes/docs/problems/upstream-timeout"
}Authorizations
Account Service Key, prefixed with pho_ask_, sent as Authorization: Bearer <key>. Acts on behalf of its owning account, subject to the permissions and credential restrictions of each operation. Account access tokens and OAuth grants also use the Bearer header. In organizations that require SSO, Account Service Keys are not accepted for managing the organization's SSO settings, deleting the organization, or checking whether it can be deleted.
Path Parameters
^pho_org_[0-7][0-9a-hjkmnp-tv-z]{25}$Body
Response
Current connection and independent local policy state.
"2026-01-01T00:00:00.000Z"
^(0|[1-9][0-9]{0,19})$not_configured, configuring, ready, error synced, manual_required ^(0|[1-9][0-9]{0,19})$Show child attributes
Show child attributes
Was this page helpful?