Skip to main content
PUT
Replace a workspace SSO configuration (not available)

Authorizations

hookie_session
string
cookie
required

The console's sealed session cookie, set by WorkOS AuthKit. Mutating requests also require the X-Requested-With CSRF header.

Path Parameters

sso_config_id
string
required

Response

Not signed in.

error
string
required

Human-readable reason.

retry_after
integer

Seconds to wait. Present on 429.

upgrade_url
string<uri>

Present only on a monthly-quota 429.

reason
string

Machine-readable reason, where the status alone is ambiguous. workspace_suspended (403): the workspace is suspended; delivery_allowance_exhausted (429): a replay was refused because the monthly delivery allowance is used. endpoint_disabled (503): the endpoint is switched off; handshake_failed: a provider URL-verification challenge could not be answered (#193). missing_header, bad_signature, stale_timestamp (401): an endpoint's provider signature check failed; scheme names the check.

code
enum<string>

Present on a 403 to an OAuth-connected agent. agent_scope_insufficient: the agent's grant is below what the call needs, and widening it would let the call through (see required_scope and manage_url). insufficient_role: the user's OWN workspace role does not allow the call, so no grant can — and roles cannot be changed in the product yet, so the call is one for the workspace owner. agent_not_permitted: no connected agent may do this at any scope (billing, platform admin, managing connected agents, a destination's signing secret).

Available options:
agent_scope_insufficient,
insufficient_role,
agent_not_permitted
required_scope
enum<string>

With code: the scope the refused call needs.

Available options:
hookie:read,
hookie:write,
hookie:manage
granted_scopes
string[]

With code: the scopes the agent's grant holds now.

manage_url
string<uri>

With code: "agent_scope_insufficient" only: the console's Settings → Connected agents page, opened on this agent (…/#/settings/agents?client=<client_id>), where its user widens the grant. The change applies on the agent's next request.

scheme
string

Present on a signature 401: the endpoint's verification scheme.