OIDC Configuration REST API

OIDC Configuration REST API

OIDC allows you to integrate IQ Server with your organization’s single sign-on (SSO) infrastructure using the OpenID Connect (OIDC) and OAuth2 protocols. This REST API enables system administrators to create, update, retrieve, or delete the OIDC configuration for IQ Server.

Consult the OIDC/OAuth2 Integration page for details on integrating IQ Server with an identity provider or configuring OIDC through the user interface instead of the REST API explained here.

You can also configure OIDC programmatically using the public REST API. All operations require the CONFIGURE_SYSTEM permission and are audited.

Enabling the Feature

Before you can configure OIDC, you will need to enable the feature using the Feature Configuration API:

curl -u <username>:<password> -X POST "http://<host>:<port>/api/v2/config/features/OAUTH2_ENABLED"(need to also refresh the UI after enabling)

Query Current OIDC Configuration

Use the following request to retrieve the OIDC configuration currently in effect:

GET /api/v2/config/oidc

Example using cURL:

curl -u admin:admin123 http://localhost:8070/api/v2/config/oidc

If OIDC is not configured, the request returns HTTP status code 404.

If OIDC is configured, the response is a JSON document similar to the following:

{
  "oauth2Configuration": {
    "idpIssuer": "https://identity-dev.sonatype.com/",
    "idpJwksUrl": "https://identity-dev.sonatype.com/.well-known/jwks.json",
    "idpJwsAlgorithm": "RS256",
    "usernameClaim": "email",
    "groupsClaim": "groups",
    "emailClaim": "email",
    "firstNameClaim": "given_name",
    "lastNameClaim": "family_name"
  },
  "oidcConfiguration": {
    "idpIssuer": "https://identity-dev.sonatype.com/",
    "clientId": "client-id",
    "idpAuthorizationUrl": "https://identity-dev.sonatype.com/authorize",
    "idpTokenUrl": "https://identity-dev.sonatype.com/oauth/token"
  }
}

Configure OIDC Integration

curl -u <username>:<password> -X POST "http://<host>:<port>/api/v2/config/features/OAUTH2_ENABLED"(need to also refresh the UI after enabling)

To enable single sign-on using OIDC, send a PUT request to the same path:

PUT /api/v2/config/oidc

This request uses application/json as its content type.

Provide both the OIDC and OAuth2 configuration objects within the request body as shown below.

Example:

curl -u admin:admin123 -X PUT -H "Content-Type: application/json" -d '{
  "oauth2Configuration": {
    "idpIssuer": "https://identity-dev.sonatype.com/",
    "idpJwksUrl": "https://identity-dev.sonatype.com/.well-known/jwks.json",
    "idpJwsAlgorithm": "RS256",
    "usernameClaim": "email",
    "groupsClaim": "groups",
    "emailClaim": "email",
    "firstNameClaim": "given_name",
    "lastNameClaim": "family_name"
  },
  "oidcConfiguration": {
    "idpIssuer": "https://identity-dev.sonatype.com/",
    "clientId": "client-id",
    "clientSecret": "client-secret",
    "idpAuthorizationUrl": "https://identity-dev.sonatype.com/authorize",
    "idpTokenUrl": "https://identity-dev.sonatype.com/oauth/token"
  }
}' http://localhost:8070/api/v2/config/oidc

If successful, the request returns HTTP status code 204.

If the configuration is invalid, the server returns 400, and the existing configuration remains unchanged.

Disable OIDC Integration

To remove the existing OIDC configuration, use a DELETE request:

DELETE /api/v2/config/oidc

Example:

curl -u admin:admin123 -X DELETE http://localhost:8070/api/v2/config/oidc

If OIDC was configured, the request responds with HTTP status code 204.

If no configuration existed, the request returns 404.