curl --request PATCH \
--url https://app.hookie.ai/admin/api/sso/{sso_config_id} \
--cookie hookie_session=const options = {method: 'PATCH', headers: {cookie: 'hookie_session='}};
fetch('https://app.hookie.ai/admin/api/sso/{sso_config_id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.hookie.ai/admin/api/sso/{sso_config_id}"
headers = {"cookie": "hookie_session="}
response = requests.patch(url, headers=headers)
print(response.text){
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"reason": "sso_not_available",
"retry_after": 123,
"upgrade_url": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}Update a workspace SSO configuration (not available)
Single sign-on is not available yet (SEC-13a, #257): there is no SAML or OIDC sign-in, so this always answers 501 with reason: "sso_not_available" and changes nothing. It answers before the plan, the role or the body is looked at. A configuration saved before then is kept as it was; list it with listSsoConfigs.
curl --request PATCH \
--url https://app.hookie.ai/admin/api/sso/{sso_config_id} \
--cookie hookie_session=const options = {method: 'PATCH', headers: {cookie: 'hookie_session='}};
fetch('https://app.hookie.ai/admin/api/sso/{sso_config_id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.hookie.ai/admin/api/sso/{sso_config_id}"
headers = {"cookie": "hookie_session="}
response = requests.patch(url, headers=headers)
print(response.text){
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"reason": "sso_not_available",
"retry_after": 123,
"upgrade_url": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}Authorizations
The console's sealed session cookie, set by WorkOS AuthKit. Mutating requests also require the X-Requested-With CSRF header.
Path Parameters
Response
Not signed in.
Human-readable reason.
Seconds to wait. Present on 429.
Present only on a monthly-quota 429.
Machine-readable reason, where the status alone is ambiguous. workspace_suspended (403): the workspace is suspended; delivery_allowance_exhausted (429): a replay was refused because the monthly delivery allowance is used. endpoint_disabled (503): the endpoint is switched off; handshake_failed: a provider URL-verification challenge could not be answered (#193). missing_header, bad_signature, stale_timestamp (401): an endpoint's provider signature check failed; scheme names the check.
Present on a 403 to an OAuth-connected agent. agent_scope_insufficient: the agent's grant is below what the call needs, and widening it would let the call through (see required_scope and manage_url). insufficient_role: the user's OWN workspace role does not allow the call, so no grant can — and roles cannot be changed in the product yet, so the call is one for the workspace owner. agent_not_permitted: no connected agent may do this at any scope (billing, platform admin, managing connected agents, a destination's signing secret).
agent_scope_insufficient, insufficient_role, agent_not_permitted With code: the scope the refused call needs.
hookie:read, hookie:write, hookie:manage With code: the scopes the agent's grant holds now.
With code: "agent_scope_insufficient" only: the console's Settings → Connected agents page, opened on this agent (…/#/settings/agents?client=<client_id>), where its user widens the grant. The change applies on the agent's next request.
Present on a signature 401: the endpoint's verification scheme.