REST API
Platform Auth (Enterprise SSO)
Registers an enterprise identity provider so your own IdP's JWTs are accepted. Each issuer is bound to exactly one organization.
Register an auth provider
HTTP
POST /v1/observ/platform/auth-providers
Auth: platform key only — send x-opexia-platform-key. Neither a workspace
API key nor a user JWT is accepted. Contact your Evigauge representative to obtain
the platform key.
Headers
| Name | Type | Required | Description |
|---|---|---|---|
x-opexia-platform-key | string | ✅ | Platform-level registration key |
Request body — EnterpriseIn
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
org_name | string | ✅ | — | Organization this issuer is bound to |
kind | string | ✅ | — | Provider kind, e.g. oidc |
issuer | string | ✅ | — | JWT iss claim value |
jwks_url | string | ✅ | — | JWKS endpoint for signature verification |
audience | string | ✅ | — | Expected aud claim value |
algorithms | string | ➖ | RS256 | Accepted signing algorithms |
claim_map | object | ➖ | {} | Maps your IdP's claim names to Evigauge's expected fields |
admin_email | string | ✅ | — | Initial administrator for the organization |
Examples
import httpx
r = httpx.post(
"https://api.opexia.dev/v1/observ/platform/auth-providers",
headers={"x-opexia-platform-key": PLATFORM_KEY},
json={
"org_name": "Acme Corp",
"kind": "oidc",
"issuer": "https://acme.okta.com",
"jwks_url": "https://acme.okta.com/oauth2/v1/keys",
"audience": "evigauge",
"algorithms": "RS256",
"claim_map": {"email": "preferred_username"},
"admin_email": "ops@acme.com",
},
timeout=30,
)
r.raise_for_status()
print(r.json())
const res = await fetch("https://api.opexia.dev/v1/observ/platform/auth-providers", {
method: "POST",
headers: { "x-opexia-platform-key": PLATFORM_KEY, "content-type": "application/json" },
body: JSON.stringify({
org_name: "Acme Corp",
kind: "oidc",
issuer: "https://acme.okta.com",
jwks_url: "https://acme.okta.com/oauth2/v1/keys",
audience: "evigauge",
algorithms: "RS256",
claim_map: { email: "preferred_username" },
admin_email: "ops@acme.com",
}),
});
console.log(await res.json());
Errors
| Status | Cause |
|---|---|
403 | x-opexia-platform-key missing or does not match. The comparison is constant-time. |
503 | Platform registration is disabled — no platform key is configured on the deployment. This is the default state. |
A
503here is configuration, not an outage: registration stays off until a platform key is provisioned. Contact your Evigauge representative to enable it.