User Federation API
User federation connects an external directory — LDAP or Active Directory — to a tenant, so employees keep authenticating against the directory they already have while Auris manages sessions, permissions, and organizations. Federated users can be pulled in automatically with synchronization, and attribute mappers control how directory attributes become Auris user fields.
Providers are managed in the console under User Federation. All endpoints require the x-tenant header and the admin:all permission unless noted otherwise.
Provider CRUD
/api/user-federationRequires: admin:allList all federation providers configured for the tenant (LDAP, Active Directory, and other directory types).
/api/user-federationRequires: admin:allCreate a federation provider. Body: name and providerId (both required), plus a
config object with the connection details (directory URL, bind credentials, base DN,
search settings). Returns the new provider id.
/api/user-federation/[id]Requires: admin:allFetch one provider with its full configuration.
/api/user-federation/[id]Requires: admin:allUpdate a provider’s name or configuration.
/api/user-federation/[id]Requires: admin:allRemove the provider. Already-imported users remain in Auris.
Treat provider config as sensitive: it contains the bind credentials the tenant uses
to reach the directory. Grant the admin:all permission
only to administrators who may see directory connection details.
Attribute mappers
/api/user-federation/[id]/mappersRequires: admin:allList the attribute mappers for the provider.
/api/user-federation/[id]/mappersRequires: admin:allCreate an attribute mapper — the rule that copies a directory attribute (for example
mail or displayName) into an Auris user field during import and sync.
Synchronization
/api/user-federation/[id]/syncRequires: admin:allSynchronize users from the directory: imports new users and updates mapped attributes for existing ones.
Run test-connection first when a sync unexpectedly returns no users — the most common cause is an unreachable directory or a wrong base DN.
Connection test
/api/user-federation/[id]/test-connectionRequires: admin:allVerifies that the provider’s URL, bind account, and base DN can reach the directory. Use it right after creating or editing a provider, before the first sync.