Skip to Content

User Federation API

User federation connects an external directory — LDAP or Active Directory — to a tenant, so employees keep authenticating against the directory they already have while Auris manages sessions, permissions, and organizations. Federated users can be pulled in automatically with synchronization, and attribute mappers control how directory attributes become Auris user fields.

Providers are managed in the console under User Federation. All endpoints require the x-tenant header and the admin:all permission unless noted otherwise.


Provider CRUD

GET/api/user-federationRequires: admin:all

List all federation providers configured for the tenant (LDAP, Active Directory, and other directory types).

POST/api/user-federationRequires: admin:all

Create a federation provider. Body: name and providerId (both required), plus a config object with the connection details (directory URL, bind credentials, base DN, search settings). Returns the new provider id.

GET/api/user-federation/[id]Requires: admin:all

Fetch one provider with its full configuration.

PUT/api/user-federation/[id]Requires: admin:all

Update a provider’s name or configuration.

DELETE/api/user-federation/[id]Requires: admin:all

Remove the provider. Already-imported users remain in Auris.

Treat provider config as sensitive: it contains the bind credentials the tenant uses to reach the directory. Grant the admin:all permission only to administrators who may see directory connection details.


Attribute mappers

GET/api/user-federation/[id]/mappersRequires: admin:all

List the attribute mappers for the provider.

POST/api/user-federation/[id]/mappersRequires: admin:all

Create an attribute mapper — the rule that copies a directory attribute (for example mail or displayName) into an Auris user field during import and sync.


Synchronization

POST/api/user-federation/[id]/syncRequires: admin:all

Synchronize users from the directory: imports new users and updates mapped attributes for existing ones.

Run test-connection first when a sync unexpectedly returns no users — the most common cause is an unreachable directory or a wrong base DN.

Connection test

POST/api/user-federation/[id]/test-connectionRequires: admin:all

Verifies that the provider’s URL, bind account, and base DN can reach the directory. Use it right after creating or editing a provider, before the first sync.