Skip to content

Commit 684b228

Browse files
authored
feat(api): expose credential sharing and SSO administration (#8770)
* feat(api): expose credential sharing and SSO administration * fix(api): make SSO administration atomic and align CLI actions * fix(auth): align SSO admission locks and reject stale provider links * fix(auth): serialize domain administration and align SSO validation * fix(auth): preserve SSO audit events across application operations
1 parent 31a911d commit 684b228

95 files changed

Lines changed: 11881 additions & 3434 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎apps/docs/content/docs/cli/credentials.mdx‎

Lines changed: 88 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -37,6 +37,94 @@ Disconnect Credential (OAuth login or personal API key required)
3737

3838
</CommandTable>
3939

40+
## List credential members
41+
42+
```bash
43+
sim credentials members list <credentialId> [options]
44+
```
45+
46+
List Credential Members (OAuth login or personal API key required)
47+
48+
**Arguments**
49+
50+
<CommandTable>
51+
52+
| Argument | Required | Description |
53+
| --- | --- | --- |
54+
| `credentialId` | Yes | Credential whose sharing grants are managed. |
55+
56+
</CommandTable>
57+
58+
**Options**
59+
60+
<CommandTable>
61+
62+
| Option | Required | Description |
63+
| --- | --- | --- |
64+
| `--limit <n>` | No | Maximum items to return (0 for everything). Defaults to `0`. |
65+
| `--sort-by <value>` | No | Field used to sort the result. Sorting by `name` is case-sensitive and follows the storage collation, so do not rely on a case-insensitive order. Accepted values: `email`, `name`. |
66+
| `--sort-order <value>` | No | Sort direction. Accepted values: `asc`, `desc`. |
67+
68+
</CommandTable>
69+
70+
## Remove credential member
71+
72+
```bash
73+
sim credentials members remove <credentialId> <userId> [options]
74+
```
75+
76+
Remove Credential Member (OAuth login or personal API key required)
77+
78+
**Arguments**
79+
80+
<CommandTable>
81+
82+
| Argument | Required | Description |
83+
| --- | --- | --- |
84+
| `credentialId` | Yes | Credential whose sharing grants are managed. |
85+
| `userId` | Yes | User whose explicit grant will be revoked. |
86+
87+
</CommandTable>
88+
89+
**Options**
90+
91+
<CommandTable>
92+
93+
| Option | Required | Description |
94+
| --- | --- | --- |
95+
| `-y, --yes` | Yes | Confirm this operation. |
96+
97+
</CommandTable>
98+
99+
## Upsert credential member
100+
101+
```bash
102+
sim credentials members upsert <credentialId> [options]
103+
```
104+
105+
Upsert Credential Member (OAuth login or personal API key required)
106+
107+
**Arguments**
108+
109+
<CommandTable>
110+
111+
| Argument | Required | Description |
112+
| --- | --- | --- |
113+
| `credentialId` | Yes | Credential whose sharing grants are managed. |
114+
115+
</CommandTable>
116+
117+
**Options**
118+
119+
<CommandTable>
120+
121+
| Option | Required | Description |
122+
| --- | --- | --- |
123+
| `--user <value>` | Yes | Existing workspace member to grant or change access for. |
124+
| `--role <value>` | Yes | Credential role to grant; workspace administrators cannot be demoted. Accepted values: `admin`, `member`. |
125+
126+
</CommandTable>
127+
40128
## List credential providers
41129

42130
```bash

‎apps/docs/content/docs/cli/organizations.mdx‎

Lines changed: 286 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,103 @@ import { CommandTable } from '@/components/ui/command-table'
77

88
Every command below also accepts the [global options](/cli/commands#global-options).
99

10+
## Add organization domain
11+
12+
```bash
13+
sim organizations domains add [options]
14+
```
15+
16+
Add Organization Domain (OAuth login or personal API key required)
17+
18+
**Options**
19+
20+
<CommandTable>
21+
22+
| Option | Required | Description |
23+
| --- | --- | --- |
24+
| `--organization <value>` | Yes | Organization identifier. |
25+
| `--domain <value>` | Yes | Domain to claim and verify through a DNS TXT record. |
26+
27+
</CommandTable>
28+
29+
## List organization domains
30+
31+
```bash
32+
sim organizations domains list [options]
33+
```
34+
35+
List Organization Domains (OAuth login or personal API key required)
36+
37+
**Options**
38+
39+
<CommandTable>
40+
41+
| Option | Required | Description |
42+
| --- | --- | --- |
43+
| `--organization <value>` | Yes | Organization identifier. |
44+
| `--limit <n>` | No | Maximum items to return (0 for everything). Defaults to `0`. |
45+
| `--sort-by <value>` | No | Field used to sort the result. Accepted values: `domain`. |
46+
| `--sort-order <value>` | No | Sort direction. Accepted values: `asc`, `desc`. |
47+
48+
</CommandTable>
49+
50+
## Remove organization domain
51+
52+
```bash
53+
sim organizations domains remove <domainId> [options]
54+
```
55+
56+
Remove Organization Domain (OAuth login or personal API key required)
57+
58+
**Arguments**
59+
60+
<CommandTable>
61+
62+
| Argument | Required | Description |
63+
| --- | --- | --- |
64+
| `domainId` | Yes | Domain claim owned by this organization. |
65+
66+
</CommandTable>
67+
68+
**Options**
69+
70+
<CommandTable>
71+
72+
| Option | Required | Description |
73+
| --- | --- | --- |
74+
| `--organization <value>` | Yes | Organization identifier. |
75+
| `-y, --yes` | Yes | Confirm this operation. |
76+
77+
</CommandTable>
78+
79+
## Verify organization domain
80+
81+
```bash
82+
sim organizations domains verify <domainId> [options]
83+
```
84+
85+
Verify Organization Domain (OAuth login or personal API key required)
86+
87+
**Arguments**
88+
89+
<CommandTable>
90+
91+
| Argument | Required | Description |
92+
| --- | --- | --- |
93+
| `domainId` | Yes | Domain claim owned by this organization. |
94+
95+
</CommandTable>
96+
97+
**Options**
98+
99+
<CommandTable>
100+
101+
| Option | Required | Description |
102+
| --- | --- | --- |
103+
| `--organization <value>` | Yes | Organization identifier. |
104+
105+
</CommandTable>
106+
10107
## Cancel organization access request
11108

12109
```bash
@@ -386,6 +483,195 @@ Revoke Organization Invitation (OAuth login or personal API key required)
386483

387484
</CommandTable>
388485

486+
## Delete SSO provider
487+
488+
```bash
489+
sim organizations sso providers delete <providerId> [options]
490+
```
491+
492+
Delete SSO Provider (OAuth login or personal API key required)
493+
494+
**Arguments**
495+
496+
<CommandTable>
497+
498+
| Argument | Required | Description |
499+
| --- | --- | --- |
500+
| `providerId` | Yes | Identity provider identifier. |
501+
502+
</CommandTable>
503+
504+
**Options**
505+
506+
<CommandTable>
507+
508+
| Option | Required | Description |
509+
| --- | --- | --- |
510+
| `--organization <value>` | Yes | Organization identifier. |
511+
| `-y, --yes` | Yes | Confirm this operation. |
512+
513+
</CommandTable>
514+
515+
## Get SSO provider
516+
517+
```bash
518+
sim organizations sso providers get <providerId> [options]
519+
```
520+
521+
Get SSO Provider (OAuth login or personal API key required)
522+
523+
**Arguments**
524+
525+
<CommandTable>
526+
527+
| Argument | Required | Description |
528+
| --- | --- | --- |
529+
| `providerId` | Yes | Identity provider identifier. |
530+
531+
</CommandTable>
532+
533+
**Options**
534+
535+
<CommandTable>
536+
537+
| Option | Required | Description |
538+
| --- | --- | --- |
539+
| `--organization <value>` | Yes | Organization identifier. |
540+
541+
</CommandTable>
542+
543+
## List SSO providers
544+
545+
```bash
546+
sim organizations sso providers list [options]
547+
```
548+
549+
List SSO Providers (OAuth login or personal API key required)
550+
551+
**Options**
552+
553+
<CommandTable>
554+
555+
| Option | Required | Description |
556+
| --- | --- | --- |
557+
| `--organization <value>` | Yes | Organization identifier. |
558+
| `--limit <n>` | No | Maximum items to return (0 for everything). Defaults to `0`. |
559+
| `--sort-by <value>` | No | Field used to sort the result. Accepted values: `providerId`, `domain`. |
560+
| `--sort-order <value>` | No | Sort direction. Accepted values: `asc`, `desc`. |
561+
562+
</CommandTable>
563+
564+
## Save SSO provider
565+
566+
```bash
567+
sim organizations sso providers save [options]
568+
```
569+
570+
Save SSO Provider (OAuth login or personal API key required)
571+
572+
**Options**
573+
574+
<CommandTable>
575+
576+
| Option | Required | Description |
577+
| --- | --- | --- |
578+
| `--organization <value>` | Yes | Organization identifier. |
579+
| `--provider-type <value>` | Yes | oidc: Configure an OpenID Connect identity provider. saml: Configure a SAML identity provider. Accepted values: `oidc`, `saml`. |
580+
| `--provider-id <value>` | Yes | Globally unique provider ID; saving an existing provider replaces its supplied configuration. |
581+
| `--issuer <value>` | Yes | Identity provider issuer URL. |
582+
| `--domain <value>` | Yes | Email domain already verified by this organization. |
583+
| `--jit-provisioning-enabled` | No | Allow SSO sign-in to provision organization membership, subject to eligibility and available seats. |
584+
| `--no-jit-provisioning-enabled` | No | Send --jit-provisioning-enabled as false. |
585+
| `--mapping <json\|@file>` | No | Identity-provider claims mapped to user fields. (JSON, or @path / @- to read a file or stdin). |
586+
| `--client-id <value>` | No | Identity provider client identifier. Available when providerType is oidc. Required when providerType is oidc. |
587+
| `--client-secret <value\|@file>` | No | Write-only OIDC client secret; the redacted marker from providers get preserves an existing secret. Passing it inline exposes it to shell history and process listings. Required when --provider-type is oidc (@path / @- reads a file or stdin verbatim, including trailing newlines; @@value for a literal leading @). |
588+
| `--scopes <json\|@file>` | No | OIDC scopes; offline_access is omitted. Available when providerType is oidc. (JSON, or @path / @- to read a file or stdin). |
589+
| `--pkce` | No | Use PKCE for the authorization flow. Available when providerType is oidc. |
590+
| `--no-pkce` | No | Send --pkce as false. |
591+
| `--authorization-endpoint <value>` | No | Optional authorization endpoint; otherwise resolved through issuer discovery. Available when providerType is oidc. |
592+
| `--token-endpoint <value>` | No | Optional token endpoint; otherwise resolved through issuer discovery. Available when providerType is oidc. |
593+
| `--user-info-endpoint <value>` | No | Optional UserInfo endpoint. Available when providerType is oidc. |
594+
| `--skip-user-info-endpoint` | No | Read identity claims from the ID token instead of calling UserInfo. Available when providerType is oidc. |
595+
| `--no-skip-user-info-endpoint` | No | Send --skip-user-info-endpoint as false. |
596+
| `--jwks-endpoint <value>` | No | Optional signing-key endpoint; otherwise resolved through issuer discovery. Available when providerType is oidc. |
597+
| `--entry-point <value>` | No | Identity provider SAML sign-in endpoint. Available when providerType is saml. Required when providerType is saml. |
598+
| `--cert <value>` | No | Identity provider signing certificate. Available when providerType is saml. Required when providerType is saml. |
599+
| `--callback-url <value>` | No | SAML callback URL; defaults to this provider’s Sim callback. Available when providerType is saml. |
600+
| `--audience <value>` | No | SAML audience; omission preserves the saved value. Available when providerType is saml. |
601+
| `--want-assertions-signed` | No | Require signed assertions; omission preserves the saved value. Available when providerType is saml. |
602+
| `--no-want-assertions-signed` | No | Send --want-assertions-signed as false. |
603+
| `--signature-algorithm <value>` | No | Signature algorithm accepted by the SAML configuration validator; omission preserves the saved value. Available when providerType is saml. |
604+
| `--digest-algorithm <value>` | No | Digest algorithm accepted by the SAML configuration validator; omission preserves the saved value. Available when providerType is saml. |
605+
| `--identifier-format <value>` | No | SAML NameID format; omission clears the saved value. Available when providerType is saml. |
606+
| `--idp-metadata <value>` | No | Identity provider metadata XML; omission clears the saved document. Available when providerType is saml. |
607+
608+
</CommandTable>
609+
610+
## Set primary SSO provider
611+
612+
```bash
613+
sim organizations sso providers primary <providerId> [options]
614+
```
615+
616+
Set Primary SSO Provider (OAuth login or personal API key required)
617+
618+
**Arguments**
619+
620+
<CommandTable>
621+
622+
| Argument | Required | Description |
623+
| --- | --- | --- |
624+
| `providerId` | Yes | Identity provider identifier. |
625+
626+
</CommandTable>
627+
628+
**Options**
629+
630+
<CommandTable>
631+
632+
| Option | Required | Description |
633+
| --- | --- | --- |
634+
| `--organization <value>` | Yes | Organization identifier. |
635+
636+
</CommandTable>
637+
638+
## Get SSO policy
639+
640+
```bash
641+
sim organizations sso policy get [options]
642+
```
643+
644+
Get SSO Policy (OAuth login or personal API key required)
645+
646+
**Options**
647+
648+
<CommandTable>
649+
650+
| Option | Required | Description |
651+
| --- | --- | --- |
652+
| `--organization <value>` | Yes | Organization identifier. |
653+
654+
</CommandTable>
655+
656+
## Update SSO policy
657+
658+
```bash
659+
sim organizations sso policy update [options]
660+
```
661+
662+
Update SSO Policy (OAuth login or personal API key required)
663+
664+
**Options**
665+
666+
<CommandTable>
667+
668+
| Option | Required | Description |
669+
| --- | --- | --- |
670+
| `--organization <value>` | Yes | Organization identifier. |
671+
| `--require-sso <true\|false>` | Yes | Require organization SSO on future sign-ins; existing sessions remain active. Accepted values: `true`, `false`. |
672+
673+
</CommandTable>
674+
389675
## Get organization
390676

391677
```bash

0 commit comments

Comments
 (0)