Skip to content

Commit a76af45

Browse files
committed
feat(api): expose credential sharing and SSO administration
1 parent 6df74d6 commit a76af45

68 files changed

Lines changed: 10222 additions & 2909 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎apps/docs/content/docs/cli/credentials.mdx‎

Lines changed: 89 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -37,6 +37,95 @@ Disconnect Credential (OAuth login or personal API key required)
3737

3838
</CommandTable>
3939

40+
## List credential members
41+
42+
```bash
43+
sim credentials members list <credentialId> [options]
44+
```
45+
46+
List Credential Members (OAuth login or personal API key required)
47+
48+
**Arguments**
49+
50+
<CommandTable>
51+
52+
| Argument | Required | Description |
53+
| --- | --- | --- |
54+
| `credentialId` | Yes | Credential whose sharing grants are managed. |
55+
56+
</CommandTable>
57+
58+
**Options**
59+
60+
<CommandTable>
61+
62+
| Option | Required | Description |
63+
| --- | --- | --- |
64+
| `--limit <n>` | No | Maximum items to return (0 for everything). Defaults to `100`. |
65+
| `--cursor <value>` | No | Continue from nextCursor returned by a previous result. |
66+
| `--sort-by <value>` | No | Field used to sort the result. Sorting by `name` is case-sensitive and follows the storage collation, so do not rely on a case-insensitive order. Accepted values: `email`, `name`. |
67+
| `--sort-order <value>` | No | Sort direction. Accepted values: `asc`, `desc`. |
68+
69+
</CommandTable>
70+
71+
## Remove credential member
72+
73+
```bash
74+
sim credentials members remove <credentialId> <userId> [options]
75+
```
76+
77+
Remove Credential Member (OAuth login or personal API key required)
78+
79+
**Arguments**
80+
81+
<CommandTable>
82+
83+
| Argument | Required | Description |
84+
| --- | --- | --- |
85+
| `credentialId` | Yes | Credential whose sharing grants are managed. |
86+
| `userId` | Yes | User whose explicit grant will be revoked. |
87+
88+
</CommandTable>
89+
90+
**Options**
91+
92+
<CommandTable>
93+
94+
| Option | Required | Description |
95+
| --- | --- | --- |
96+
| `-y, --yes` | Yes | Confirm this operation. |
97+
98+
</CommandTable>
99+
100+
## Upsert credential member
101+
102+
```bash
103+
sim credentials members upsert <credentialId> [options]
104+
```
105+
106+
Upsert Credential Member (OAuth login or personal API key required)
107+
108+
**Arguments**
109+
110+
<CommandTable>
111+
112+
| Argument | Required | Description |
113+
| --- | --- | --- |
114+
| `credentialId` | Yes | Credential whose sharing grants are managed. |
115+
116+
</CommandTable>
117+
118+
**Options**
119+
120+
<CommandTable>
121+
122+
| Option | Required | Description |
123+
| --- | --- | --- |
124+
| `--user <value>` | Yes | Existing workspace member to grant or change access for. |
125+
| `--role <value>` | Yes | Credential role to grant; workspace administrators cannot be demoted. Accepted values: `admin`, `member`. |
126+
127+
</CommandTable>
128+
40129
## List credential providers
41130

42131
```bash

‎apps/docs/content/docs/cli/organizations.mdx‎

Lines changed: 288 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,104 @@ import { CommandTable } from '@/components/ui/command-table'
77

88
Every command below also accepts the [global options](/cli/commands#global-options).
99

10+
## Add organization domain
11+
12+
```bash
13+
sim organizations domains add [options]
14+
```
15+
16+
Add Organization Domain (OAuth login or personal API key required)
17+
18+
**Options**
19+
20+
<CommandTable>
21+
22+
| Option | Required | Description |
23+
| --- | --- | --- |
24+
| `--organization <value>` | Yes | Organization identifier. |
25+
| `--domain <value>` | Yes | Domain to claim and verify through a DNS TXT record. |
26+
27+
</CommandTable>
28+
29+
## List organization domains
30+
31+
```bash
32+
sim organizations domains list [options]
33+
```
34+
35+
List Organization Domains (OAuth login or personal API key required)
36+
37+
**Options**
38+
39+
<CommandTable>
40+
41+
| Option | Required | Description |
42+
| --- | --- | --- |
43+
| `--organization <value>` | Yes | Organization identifier. |
44+
| `--limit <n>` | No | Maximum items to return (0 for everything). Defaults to `100`. |
45+
| `--cursor <value>` | No | Continue from nextCursor returned by a previous result. |
46+
| `--sort-by <value>` | No | Field used to sort the result. Accepted values: `domain`. |
47+
| `--sort-order <value>` | No | Sort direction. Accepted values: `asc`, `desc`. |
48+
49+
</CommandTable>
50+
51+
## Remove organization domain
52+
53+
```bash
54+
sim organizations domains remove <domainId> [options]
55+
```
56+
57+
Remove Organization Domain (OAuth login or personal API key required)
58+
59+
**Arguments**
60+
61+
<CommandTable>
62+
63+
| Argument | Required | Description |
64+
| --- | --- | --- |
65+
| `domainId` | Yes | Domain claim owned by this organization. |
66+
67+
</CommandTable>
68+
69+
**Options**
70+
71+
<CommandTable>
72+
73+
| Option | Required | Description |
74+
| --- | --- | --- |
75+
| `--organization <value>` | Yes | Organization identifier. |
76+
| `-y, --yes` | Yes | Confirm this operation. |
77+
78+
</CommandTable>
79+
80+
## Verify organization domain
81+
82+
```bash
83+
sim organizations domains verify <domainId> [options]
84+
```
85+
86+
Verify Organization Domain (OAuth login or personal API key required)
87+
88+
**Arguments**
89+
90+
<CommandTable>
91+
92+
| Argument | Required | Description |
93+
| --- | --- | --- |
94+
| `domainId` | Yes | Domain claim owned by this organization. |
95+
96+
</CommandTable>
97+
98+
**Options**
99+
100+
<CommandTable>
101+
102+
| Option | Required | Description |
103+
| --- | --- | --- |
104+
| `--organization <value>` | Yes | Organization identifier. |
105+
106+
</CommandTable>
107+
10108
## Cancel organization access request
11109

12110
```bash
@@ -386,6 +484,196 @@ Revoke Organization Invitation (OAuth login or personal API key required)
386484

387485
</CommandTable>
388486

487+
## Delete SSO provider
488+
489+
```bash
490+
sim organizations sso providers delete <providerId> [options]
491+
```
492+
493+
Delete SSO Provider (OAuth login or personal API key required)
494+
495+
**Arguments**
496+
497+
<CommandTable>
498+
499+
| Argument | Required | Description |
500+
| --- | --- | --- |
501+
| `providerId` | Yes | Identity provider identifier. |
502+
503+
</CommandTable>
504+
505+
**Options**
506+
507+
<CommandTable>
508+
509+
| Option | Required | Description |
510+
| --- | --- | --- |
511+
| `--organization <value>` | Yes | Organization identifier. |
512+
| `-y, --yes` | Yes | Confirm this operation. |
513+
514+
</CommandTable>
515+
516+
## Get SSO provider
517+
518+
```bash
519+
sim organizations sso providers get <providerId> [options]
520+
```
521+
522+
Get SSO Provider (OAuth login or personal API key required)
523+
524+
**Arguments**
525+
526+
<CommandTable>
527+
528+
| Argument | Required | Description |
529+
| --- | --- | --- |
530+
| `providerId` | Yes | Identity provider identifier. |
531+
532+
</CommandTable>
533+
534+
**Options**
535+
536+
<CommandTable>
537+
538+
| Option | Required | Description |
539+
| --- | --- | --- |
540+
| `--organization <value>` | Yes | Organization identifier. |
541+
542+
</CommandTable>
543+
544+
## List SSO providers
545+
546+
```bash
547+
sim organizations sso providers list [options]
548+
```
549+
550+
List SSO Providers (OAuth login or personal API key required)
551+
552+
**Options**
553+
554+
<CommandTable>
555+
556+
| Option | Required | Description |
557+
| --- | --- | --- |
558+
| `--organization <value>` | Yes | Organization identifier. |
559+
| `--limit <n>` | No | Maximum items to return (0 for everything). Defaults to `100`. |
560+
| `--cursor <value>` | No | Continue from nextCursor returned by a previous result. |
561+
| `--sort-by <value>` | No | Field used to sort the result. Accepted values: `providerId`, `domain`. |
562+
| `--sort-order <value>` | No | Sort direction. Accepted values: `asc`, `desc`. |
563+
564+
</CommandTable>
565+
566+
## Save SSO provider
567+
568+
```bash
569+
sim organizations sso providers save [options]
570+
```
571+
572+
Save SSO Provider (OAuth login or personal API key required)
573+
574+
**Options**
575+
576+
<CommandTable>
577+
578+
| Option | Required | Description |
579+
| --- | --- | --- |
580+
| `--organization <value>` | Yes | Organization identifier. |
581+
| `--provider-type <value>` | Yes | oidc: Configure an OpenID Connect identity provider. saml: Configure a SAML identity provider. Accepted values: `oidc`, `saml`. |
582+
| `--provider-id <value>` | Yes | Globally unique provider ID; saving an existing provider replaces its supplied configuration. |
583+
| `--issuer <value>` | Yes | Identity provider issuer URL. |
584+
| `--domain <value>` | Yes | Email domain already verified by this organization. |
585+
| `--jit-provisioning-enabled` | No | Allow SSO sign-in to provision organization membership, subject to eligibility and available seats. |
586+
| `--no-jit-provisioning-enabled` | No | Send --jit-provisioning-enabled as false. |
587+
| `--mapping <json\|@file>` | No | Identity-provider claims mapped to user fields. (JSON, or @path / @- to read a file or stdin). |
588+
| `--client-id <value>` | No | Identity provider client identifier. Available when providerType is oidc. Required when providerType is oidc. |
589+
| `--client-secret <value>` | No | Write-only client secret; the redacted marker from Get SSO Provider preserves an existing secret. Available when providerType is oidc. Required when providerType is oidc. |
590+
| `--scopes <json\|@file>` | No | OIDC scopes; offline_access is omitted. Available when providerType is oidc. (JSON, or @path / @- to read a file or stdin). |
591+
| `--pkce` | No | Use PKCE for the authorization flow. Available when providerType is oidc. |
592+
| `--no-pkce` | No | Send --pkce as false. |
593+
| `--authorization-endpoint <value>` | No | Optional authorization endpoint; otherwise resolved through issuer discovery. Available when providerType is oidc. |
594+
| `--token-endpoint <value>` | No | Optional token endpoint; otherwise resolved through issuer discovery. Available when providerType is oidc. |
595+
| `--user-info-endpoint <value>` | No | Optional UserInfo endpoint. Available when providerType is oidc. |
596+
| `--skip-user-info-endpoint` | No | Read identity claims from the ID token instead of calling UserInfo. Available when providerType is oidc. |
597+
| `--no-skip-user-info-endpoint` | No | Send --skip-user-info-endpoint as false. |
598+
| `--jwks-endpoint <value>` | No | Optional signing-key endpoint; otherwise resolved through issuer discovery. Available when providerType is oidc. |
599+
| `--entry-point <value>` | No | Identity provider SAML sign-in endpoint. Available when providerType is saml. Required when providerType is saml. |
600+
| `--cert <value>` | No | Identity provider signing certificate. Available when providerType is saml. Required when providerType is saml. |
601+
| `--callback-url <value>` | No | SAML callback URL; defaults to this provider’s Sim callback. Available when providerType is saml. |
602+
| `--audience <value>` | No | SAML audience; omission preserves the saved value. Available when providerType is saml. |
603+
| `--want-assertions-signed` | No | Require signed assertions; omission preserves the saved value. Available when providerType is saml. |
604+
| `--no-want-assertions-signed` | No | Send --want-assertions-signed as false. |
605+
| `--signature-algorithm <value>` | No | Signature algorithm accepted by the SAML configuration validator; omission preserves the saved value. Available when providerType is saml. |
606+
| `--digest-algorithm <value>` | No | Digest algorithm accepted by the SAML configuration validator; omission preserves the saved value. Available when providerType is saml. |
607+
| `--identifier-format <value>` | No | SAML NameID format; omission clears the saved value. Available when providerType is saml. |
608+
| `--idp-metadata <value>` | No | Identity provider metadata XML; omission clears the saved document. Available when providerType is saml. |
609+
610+
</CommandTable>
611+
612+
## Set primary SSO provider
613+
614+
```bash
615+
sim organizations sso providers primary <providerId> [options]
616+
```
617+
618+
Set Primary SSO Provider (OAuth login or personal API key required)
619+
620+
**Arguments**
621+
622+
<CommandTable>
623+
624+
| Argument | Required | Description |
625+
| --- | --- | --- |
626+
| `providerId` | Yes | Identity provider identifier. |
627+
628+
</CommandTable>
629+
630+
**Options**
631+
632+
<CommandTable>
633+
634+
| Option | Required | Description |
635+
| --- | --- | --- |
636+
| `--organization <value>` | Yes | Organization identifier. |
637+
638+
</CommandTable>
639+
640+
## Get SSO policy
641+
642+
```bash
643+
sim organizations sso policy get [options]
644+
```
645+
646+
Get SSO Policy (OAuth login or personal API key required)
647+
648+
**Options**
649+
650+
<CommandTable>
651+
652+
| Option | Required | Description |
653+
| --- | --- | --- |
654+
| `--organization <value>` | Yes | Organization identifier. |
655+
656+
</CommandTable>
657+
658+
## Update SSO policy
659+
660+
```bash
661+
sim organizations sso policy update [options]
662+
```
663+
664+
Update SSO Policy (OAuth login or personal API key required)
665+
666+
**Options**
667+
668+
<CommandTable>
669+
670+
| Option | Required | Description |
671+
| --- | --- | --- |
672+
| `--organization <value>` | Yes | Organization identifier. |
673+
| `--require-sso <true\|false>` | Yes | Require organization SSO on future sign-ins; existing sessions remain active. Accepted values: `true`, `false`. |
674+
675+
</CommandTable>
676+
389677
## Get organization
390678

391679
```bash

0 commit comments

Comments
 (0)