> ## Documentation Index
> Fetch the complete documentation index at: https://conductorone-lee-tschetter-gemini-enterprise-mcp.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Parse Saml Service Provider Metadata

> ParseSAMLServiceProviderMetadata parses one uploaded SAML service-provider
 metadata document and returns the SAML configuration it implies, without
 creating or changing anything. The document is not stored. Use it to
 preview an SP's capabilities before creating a SAML application; edit the
 returned configuration before passing it to Create. Only upload or paste a
 customer-supplied document -- C1 does not fetch metadata URLs.



## OpenAPI

````yaml https://spec.speakeasy.com/conductor-one/conductorone/my-source-with-code-samples post /api/v1/sso/applications/saml/parse-sp-metadata
openapi: 3.1.0
info:
  description: The C1 API is a HTTP API for managing C1 resources.
  title: C1 API
  version: 0.1.0-alpha
servers:
  - description: The C1 API server for the current tenant.
    url: https://{tenantDomain}.conductor.one
    variables:
      tenantDomain:
        default: example
        description: The domain of the tenant to use for this request.
security:
  - bearerAuth: []
    oauth: []
paths:
  /api/v1/sso/applications/saml/parse-sp-metadata:
    post:
      tags:
        - SSO
      summary: Parse Saml Service Provider Metadata
      description: >-
        ParseSAMLServiceProviderMetadata parses one uploaded SAML
        service-provider
         metadata document and returns the SAML configuration it implies, without
         creating or changing anything. The document is not stored. Use it to
         preview an SP's capabilities before creating a SAML application; edit the
         returned configuration before passing it to Create. Only upload or paste a
         customer-supplied document -- C1 does not fetch metadata URLs.
      operationId: c1.api.sso.v1.SSOApplicationService.ParseSAMLServiceProviderMetadata
      requestBody:
        content:
          application/json:
            schema:
              $ref: >-
                #/components/schemas/c1.api.sso.v1.SSOApplicationServiceParseSAMLServiceProviderMetadataRequest
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: >-
                  #/components/schemas/c1.api.sso.v1.SSOApplicationServiceParseSAMLServiceProviderMetadataResponse
          description: >-
            SSOApplicationServiceParseSAMLServiceProviderMetadataResponse
            returns the
             SAML configuration derived from one metadata document and every finding the
             parser raised about it.
components:
  schemas:
    c1.api.sso.v1.SSOApplicationServiceParseSAMLServiceProviderMetadataRequest:
      description: |-
        SSOApplicationServiceParseSAMLServiceProviderMetadataRequest carries one
         SAML service-provider metadata document to parse.
      properties:
        metadataXml:
          description: >-
            The SP metadata XML document, exactly as downloaded or exported from
            the
             service provider. Maximum 1 MiB. The document is parsed, never stored.
          format: base64
          type: string
      required:
        - metadataXml
      title: Sso Application Service Parse Saml Service Provider Metadata Request
      type: object
      x-speakeasy-name-override: SSOApplicationServiceParseSAMLServiceProviderMetadataRequest
    c1.api.sso.v1.SSOApplicationServiceParseSAMLServiceProviderMetadataResponse:
      description: >-
        SSOApplicationServiceParseSAMLServiceProviderMetadataResponse returns
        the
         SAML configuration derived from one metadata document and every finding the
         parser raised about it.
      properties:
        config:
          oneOf:
            - $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationSAMLConfig'
            - type: 'null'
        findings:
          description: >-
            Everything the parser noticed about the document, including
            requirements
             it could not map into the configuration.
          items:
            $ref: '#/components/schemas/c1.api.sso.v1.SAMLMetadataFinding'
          type:
            - array
            - 'null'
      title: Sso Application Service Parse Saml Service Provider Metadata Response
      type: object
      x-speakeasy-name-override: SSOApplicationServiceParseSAMLServiceProviderMetadataResponse
    c1.api.sso.v1.SSOApplicationSAMLConfig:
      description: SSOApplicationSAMLConfig is the SAML-specific sign-in configuration.
      properties:
        acsUrls:
          description: |-
            The Assertion Consumer Service URLs the assertion may be posted to.
             Matched exactly; a URL that is not in this list is refused.
          items:
            type: string
          type:
            - array
            - 'null'
        attributeMappings:
          description: >-
            The attributes released in the assertion's AttributeStatement. SAML
            has no
             scopes, so this list is the whole release: the NameID carries the
             identifier and these carry everything else.
          items:
            $ref: '#/components/schemas/c1.api.sso.v1.SAMLAttributeMapping'
          type:
            - array
            - 'null'
        encryptAssertions:
          description: Encrypt the assertion.
          type: boolean
        encryptionAlgorithm:
          description: The algorithm used when encrypt_assertions is set.
          enum:
            - SAML_ENCRYPTION_ALGORITHM_UNSPECIFIED
            - SAML_ENCRYPTION_ALGORITHM_AES256_GCM
            - SAML_ENCRYPTION_ALGORITHM_AES128_GCM
            - SAML_ENCRYPTION_ALGORITHM_AES256_CBC
          type: string
          x-speakeasy-unknown-values: allow
        nameIdFormat:
          description: >-
            Set this when the service provider requires a specific NameID
            format. This
             also selects the NameID value semantics: EMAIL_ADDRESS uses the user's
             primary email, TRANSIENT creates a new value for each sign-in, and
             PERSISTENT uses the application's pairwise subject. Immutable once set.
          enum:
            - SAML_NAME_ID_FORMAT_UNSPECIFIED
            - SAML_NAME_ID_FORMAT_PERSISTENT
            - SAML_NAME_ID_FORMAT_EMAIL_ADDRESS
            - SAML_NAME_ID_FORMAT_UNSPECIFIED_URN
            - SAML_NAME_ID_FORMAT_TRANSIENT
          type: string
          x-speakeasy-unknown-values: allow
        requireSignedAuthnRequests:
          description: |-
            Reject any AuthnRequest that is not signed by one of
             sp_signing_certificates. At least one signing certificate is required when
             this is set.
          type: boolean
        signAssertions:
          description: >-
            Sign the assertion. At least one of sign_assertions or
            sign_responses must
             be set.
          type: boolean
        signResponses:
          description: |-
            Sign the response envelope. At least one of sign_assertions or
             sign_responses must be set.
          type: boolean
        spEncryptionCertificate:
          description: >-
            The service provider's DER-encoded encryption certificate, taken
            from the
             encryption KeyDescriptor in its metadata. Required when encrypt_assertions
             is set.
          format: base64
          type: string
        spEntityId:
          description: |-
            The service provider's entity ID, taken from its metadata. It is the
             audience every assertion this application issues is restricted to, and it
             is what the service provider presents at sign-in. Set it at creation: it is
             fixed for the life of the application, because changing it re-points every
             assertion already issued. An entity ID already in use by another SSO
             application in the tenant is rejected.
          type: string
        spSigningCertificates:
          description: >-
            The service provider's DER-encoded signing certificates, taken from
            the
             signing KeyDescriptors in its metadata.
          items:
            format: base64
            type: string
          type:
            - array
            - 'null'
      required:
        - spEntityId
        - acsUrls
      title: Sso Application Saml Config
      type: object
      x-speakeasy-name-override: SSOApplicationSAMLConfig
    c1.api.sso.v1.SAMLMetadataFinding:
      description: >-
        SAMLMetadataFinding is one thing ConductorOne noticed while parsing a
        service
         provider's metadata document.
      properties:
        component:
          description: Where the finding fits in the parsed document.
          enum:
            - COMPONENT_UNSPECIFIED
            - COMPONENT_DOCUMENT
            - COMPONENT_ENTITY_ID
            - COMPONENT_ACS_URL
            - COMPONENT_NAME_ID_FORMAT
            - COMPONENT_SIGNING_CERTIFICATE
            - COMPONENT_ENCRYPTION_CERTIFICATE
            - COMPONENT_REQUIREMENT
            - COMPONENT_BINDING
          type: string
          x-speakeasy-unknown-values: allow
        level:
          description: The severity of this finding.
          enum:
            - LEVEL_UNSPECIFIED
            - LEVEL_BLOCKING
            - LEVEL_WARNING
          type: string
          x-speakeasy-unknown-values: allow
        reason:
          description: Plain-language explanation of why the finding was raised.
          type: string
      title: Saml Metadata Finding
      type: object
      x-speakeasy-name-override: SAMLMetadataFinding
    c1.api.sso.v1.SAMLAttributeMapping:
      description: |-
        SAMLAttributeMapping releases one user attribute to the service provider
         as one Attribute in the assertion's AttributeStatement.
      properties:
        friendlyName:
          description: Optional FriendlyName, for service providers that display it.
          type: string
        name:
          description: The Name attribute, dictated by the service provider.
          type: string
        nameFormat:
          description: The NameFormat attribute.
          enum:
            - SAML_ATTRIBUTE_NAME_FORMAT_UNSPECIFIED
            - SAML_ATTRIBUTE_NAME_FORMAT_URI
            - SAML_ATTRIBUTE_NAME_FORMAT_BASIC
            - SAML_ATTRIBUTE_NAME_FORMAT_UNSPECIFIED_URN
          type: string
          x-speakeasy-unknown-values: allow
        userAttributeMappingId:
          description: >-
            The user attribute mapping that resolves the value, including its
            fallback
             chain.
          type: string
      required:
        - userAttributeMappingId
        - name
      title: Saml Attribute Mapping
      type: object
      x-speakeasy-name-override: SAMLAttributeMapping
  securitySchemes:
    bearerAuth:
      scheme: bearer
      type: http
    oauth:
      description: >-
        This API uses OAuth2 with the Client Credential flow.

        Client Credentials must be sent in the BODY, not the headers.

        For an example of how to implement this, refer to the
        [c1TokenSource.Token()](https://github.com/ConductorOne/conductorone-sdk-go/blob/3375fe7c0126d17e7ec4e711693dee7b791023aa/token_source.go#L101-L187)
        function.
      flows:
        clientCredentials:
          scopes: {}
          tokenUrl: /auth/v1/token
      type: oauth2

````