Update the IDP configuration for widget authentication. Only admins can update this. Set idp_type to configure which identity provider to trust for widget authentication.
WorkOS JWT token. Obtain via WorkOS AuthKit authentication flow. The token must include organization_id claim for organization-scoped endpoints.
Fields to update in the IDP configuration
Identity provider type: okta, azure, auth0, google, workos, firebase, onelogin, logto, or custom_oidc
okta, azure, auth0, google, custom_oidc, workos, firebase, onelogin, logto OK
Identity provider configuration for SSO-first widget authentication
Type of identity provider
okta, azure, auth0, google, custom_oidc, workos, firebase, onelogin, logto Allowed OIDC client IDs for audience validation (required for production)
Provider domain (e.g., acme.okta.com)
Full issuer URL for custom OIDC providers
Allowed domains for widget embedding (e.g., https://crm.acme.com)