Updated on 2026-07-22 GMT+08:00

Querying All SAML Providers

Function

This API is used to query the list of all SAML 2.0 IdPs.

Authorization Information

Each account root user has all the permissions required to call all APIs, but IAM users must be assigned the following required identity policy-based permissions. For details about the required permissions, see Permissions Policies and Supported Actions.

Action

Access Level

Resource Type (*: required)

Condition Key

Alias

Dependencies

iam:samlProviders:listV5

List

samlProvider *

-

-

-

URI

GET /v5/saml-providers

Table 1 Query Parameters

Parameter

Mandatory

Type

Description

limit

No

Integer

Definition:

Number of records displayed per page.

Constraints:

N/A

Range:

The value ranges from 1 to 200.

Default Value:

The default value is 100.

marker

No

String

Definition:

Pagination marker automatically generated by the service to mark the start position of this request. The value can be obtained from next_marker in the response body of the previous pagination request.

Constraints:

The value contains 4 to 400 characters. Only letters, digits, plus signs (+), slashes (/), equal signs (=), hyphens (-), and underscores (_) are allowed.

Range:

N/A

Default Value:

N/A

Request Parameters

None

Response Parameters

Status code: 200

Table 2 Response body parameters

Parameter

Type

Description

saml_providers

Array of saml_providers objects

Definition

SAML provider.

Range

N/A

page_info

page_info object

Definition

Pagination information.

Range

N/A

Table 3 saml_providers

Parameter

Type

Description

provider_id

String

Definition

ID of the SAML identity provider.

Range

The value must contain 1 to 64 characters, including only letters, digits, and hyphens (-).

name

String

Definition

Name of the SAML identity provider.

Range

The value must contain 1 to 64 characters, including only letters, digits, underscores (_), and hyphens (-).

description

String

Definition

Description of an identity provider.

Range

The value cannot contain the following special characters: @#%&<>$^*.

urn

String

Definition

Uniform resource name.

Range

The value must contain 16 to 1,500 characters, including letters, digits, slashes (/), equal signs (=), underscores (_), colons (:), and hyphens (-).

saml_metadata_document

String

Definition

XML document of an IdP that supports SAML 2.0.

Range

Length range: 1,000 to 512,000.

assertion_encryption_mode

String

Definition

Encryption settings of the SAML identity provider.

Range

The value can be "Required" or "Allowed".

private_keys

Array of private_keys objects

Definition

Private key used to decrypt SAML assertions.

Range

N/A

created_at

String

Definition

Time when the SAML identity provider was created.

Range

N/A

expires_at

String

Definition

Time when the SAML identity provider expires.

Range

N/A

Table 4 private_keys

Parameter

Type

Description

key_id

String

Definition

ID of the private key for decrypting SAML assertions.

Range

N/A

timestamp

String

Definition

Time when the private key for decrypting SAML assertions was uploaded. The value must comply with the ISO 8601 format.

Range

N/A

Table 5 page_info

Parameter

Type

Description

next_marker

String

Definition

If this parameter is returned, there are subsequent items that are not displayed in the current response body. Use this value as the pagination marker for the next request to obtain information in the next page. Call this API repeatedly until this field is not returned.

Range

N/A

current_count

Integer

Definition

Number of records returned on this page.

Range

N/A

Status code: 400

Table 6 Response body parameters

Parameter

Type

Description

error_code

String

Definition :

Error code. For details, see Error Code.

Range:

The format is PAP5.XXXX, for example, PAP5.0012.

error_msg

String

Definition :

Error message. For details, see Error Message.

Range:

N/A.

request_id

String

Definition:

Unique identifier of an API request, which is used to locate API calling exceptions.

Range:

N/A

Status code: 403

Table 7 Response body parameters

Parameter

Type

Description

error_code

String

Definition :

Error code. For details, see Error Code.

Range:

The format is PAP5.XXXX, for example, PAP5.0012.

error_msg

String

Definition :

Error message. For details, see Error Message.

Range:

N/A.

request_id

String

Definition:

Unique identifier of an API request, which is used to locate API calling exceptions.

Range:

N/A

encoded_authorization_message

String

Definition :

Encrypted details returned when the authentication fails, which are used to locate authentication problems. The STS5 decryption API can be used for decryption. For details, see API link.

Range:

N/A.

Example Requests

None

Example Responses

Status code: 200

Request succeeded.

{
  "saml_providers" : [ {
    "provider_id" : "string",
    "name" : "string",
    "urn" : "iam::accountid:user:name",
    "description" : "",
    "saml_metadata_document" : "<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n<md:EntityDescriptor entityID=\"http://***.***.com/****************************\"\n                     xmlns:md=\"urn:oasis:names:tc:SAML:2.0:metadata\">\n\t<md:IDPSSODescriptor WantAuthnRequestsSigned=\"false\"\n\t                     protocolSupportEnumeration=\"urn:oasis:names:tc:SAML:2.0:protocol\">\n\t\t<md:KeyDescriptor use=\"signing\">\n\t\t\t<ds:KeyInfo xmlns:ds=\"http://www.w3.org/2000/09/xmldsig#\">\n\t\t\t\t<ds:X509Data>\n\t\t\t\t\t<ds:X509Certificate>example************************************************************************************************************************************************************************************************************************************************************************************************************************************************example</ds:X509Certificate>\n\t\t\t\t</ds:X509Data>\n\t\t\t</ds:KeyInfo>\n\t\t</md:KeyDescriptor>\n\t\t<md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</md:NameIDFormat>\n\t\t<md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress</md:NameIDFormat>\n\t\t<md:SingleSignOnService Binding=\"urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST\"\n\t\t                        Location=\"https://***************.okta.com/app/***************_oktaaws_1/****************************/sso/saml\"/>\n\t\t<md:SingleSignOnService Binding=\"urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect\"\n\t\t                        Location=\"https://***************.okta.com/app/***************_oktaaws_1/****************************/sso/saml\"/>\n\t</md:IDPSSODescriptor>\n</md:EntityDescriptor>",
    "assertion_encryption_mode" : "Allowed",
    "private_keys" : [ ],
    "created_at" : "2026-06-29T11:31:04.334Z",
    "expires_at" : "2126-06-05T11:31:04.221Z"
  } ],
  "page_info" : {
    "current_count" : 1
  }
}

Status Codes

Status Code

Description

200

Request succeeded.

400

Abnormal request body.

403

No operation permissions.

Error Codes

See Error Codes.