DEVELOPER DOCS

REST API

Platform Auth (Enterprise SSO)

Registers an enterprise identity provider so your own IdP's JWTs are accepted. Each issuer is bound to exactly one organization.


Register an auth provider

HTTP
POST /v1/observ/platform/auth-providers

Auth: platform key only — send x-opexia-platform-key. Neither a workspace API key nor a user JWT is accepted. Contact your Evigauge representative to obtain the platform key.

Headers

NameTypeRequiredDescription
x-opexia-platform-keystring✅Platform-level registration key

Request body — EnterpriseIn

FieldTypeRequiredDefaultDescription
org_namestring✅—Organization this issuer is bound to
kindstring✅—Provider kind, e.g. oidc
issuerstring✅—JWT iss claim value
jwks_urlstring✅—JWKS endpoint for signature verification
audiencestring✅—Expected aud claim value
algorithmsstring➖RS256Accepted signing algorithms
claim_mapobject➖{}Maps your IdP's claim names to Evigauge's expected fields
admin_emailstring✅—Initial administrator for the organization

Examples

import httpx

r = httpx.post(
    "https://api.opexia.dev/v1/observ/platform/auth-providers",
    headers={"x-opexia-platform-key": PLATFORM_KEY},
    json={
        "org_name": "Acme Corp",
        "kind": "oidc",
        "issuer": "https://acme.okta.com",
        "jwks_url": "https://acme.okta.com/oauth2/v1/keys",
        "audience": "evigauge",
        "algorithms": "RS256",
        "claim_map": {"email": "preferred_username"},
        "admin_email": "ops@acme.com",
    },
    timeout=30,
)
r.raise_for_status()
print(r.json())

Errors

StatusCause
403x-opexia-platform-key missing or does not match. The comparison is constant-time.
503Platform registration is disabled — no platform key is configured on the deployment. This is the default state.

A 503 here is configuration, not an outage: registration stays off until a platform key is provisioned. Contact your Evigauge representative to enable it.