package main
import(
"context"
"github.com/conductorone/conductorone-sdk-go/pkg/models/shared"
conductoronesdkgo "github.com/conductorone/conductorone-sdk-go"
"log"
)
func main() {
ctx := context.Background()
s := conductoronesdkgo.New(
conductoronesdkgo.WithSecurity(shared.Security{
BearerAuth: "<YOUR_BEARER_TOKEN_HERE>",
Oauth: "<YOUR_OAUTH_HERE>",
}),
)
res, err := s.StepUpProvider.Create(ctx, nil)
if err != nil {
log.Fatal(err)
}
if res.CreateStepUpProviderResponse != nil {
// handle response
}
}import { ConductoroneSDKTypescript } from "conductorone-sdk-typescript";
const conductoroneSDKTypescript = new ConductoroneSDKTypescript({
security: {
bearerAuth: "<YOUR_BEARER_TOKEN_HERE>",
oauth: "<YOUR_OAUTH_HERE>",
},
});
async function run() {
const result = await conductoroneSDKTypescript.stepUpProvider.create();
console.log(result);
}
run();curl --request POST \
--url https://{tenantDomain}.conductor.one/api/v1/step-up/providers \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"clientId": "<string>",
"clientSecret": "<string>",
"displayName": "<string>",
"issuerUrl": "<string>",
"microsoft": {
"conditionalAccessIds": [
"<string>"
],
"tenant": "<string>"
},
"oauth2": {
"acrValues": [
"<string>"
]
}
}
'import requests
url = "https://{tenantDomain}.conductor.one/api/v1/step-up/providers"
payload = {
"clientId": "<string>",
"clientSecret": "<string>",
"displayName": "<string>",
"issuerUrl": "<string>",
"microsoft": {
"conditionalAccessIds": ["<string>"],
"tenant": "<string>"
},
"oauth2": { "acrValues": ["<string>"] }
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
clientId: '<string>',
clientSecret: '<string>',
displayName: '<string>',
issuerUrl: '<string>',
microsoft: {conditionalAccessIds: ['<string>'], tenant: '<string>'},
oauth2: {acrValues: ['<string>']}
})
};
fetch('https://{tenantDomain}.conductor.one/api/v1/step-up/providers', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{tenantDomain}.conductor.one/api/v1/step-up/providers",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'clientId' => '<string>',
'clientSecret' => '<string>',
'displayName' => '<string>',
'issuerUrl' => '<string>',
'microsoft' => [
'conditionalAccessIds' => [
'<string>'
],
'tenant' => '<string>'
],
'oauth2' => [
'acrValues' => [
'<string>'
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}HttpResponse<String> response = Unirest.post("https://{tenantDomain}.conductor.one/api/v1/step-up/providers")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"clientId\": \"<string>\",\n \"clientSecret\": \"<string>\",\n \"displayName\": \"<string>\",\n \"issuerUrl\": \"<string>\",\n \"microsoft\": {\n \"conditionalAccessIds\": [\n \"<string>\"\n ],\n \"tenant\": \"<string>\"\n },\n \"oauth2\": {\n \"acrValues\": [\n \"<string>\"\n ]\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://{tenantDomain}.conductor.one/api/v1/step-up/providers")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"clientId\": \"<string>\",\n \"clientSecret\": \"<string>\",\n \"displayName\": \"<string>\",\n \"issuerUrl\": \"<string>\",\n \"microsoft\": {\n \"conditionalAccessIds\": [\n \"<string>\"\n ],\n \"tenant\": \"<string>\"\n },\n \"oauth2\": {\n \"acrValues\": [\n \"<string>\"\n ]\n }\n}"
response = http.request(request)
puts response.read_body{
"stepUpProvider": {
"clientId": "<string>",
"createdAt": "2023-11-07T05:31:56Z",
"displayName": "<string>",
"enabled": true,
"id": "<string>",
"issuerUrl": "<string>",
"lastTestedAt": "2023-11-07T05:31:56Z",
"microsoft": {
"conditionalAccessIds": [
"<string>"
],
"tenant": "<string>"
},
"oauth2": {
"acrValues": [
"<string>"
]
},
"updatedAt": "2023-11-07T05:31:56Z"
}
}Create
Invokes the c1.api.stepup.v1.StepUpProviderService.Create method.
package main
import(
"context"
"github.com/conductorone/conductorone-sdk-go/pkg/models/shared"
conductoronesdkgo "github.com/conductorone/conductorone-sdk-go"
"log"
)
func main() {
ctx := context.Background()
s := conductoronesdkgo.New(
conductoronesdkgo.WithSecurity(shared.Security{
BearerAuth: "<YOUR_BEARER_TOKEN_HERE>",
Oauth: "<YOUR_OAUTH_HERE>",
}),
)
res, err := s.StepUpProvider.Create(ctx, nil)
if err != nil {
log.Fatal(err)
}
if res.CreateStepUpProviderResponse != nil {
// handle response
}
}import { ConductoroneSDKTypescript } from "conductorone-sdk-typescript";
const conductoroneSDKTypescript = new ConductoroneSDKTypescript({
security: {
bearerAuth: "<YOUR_BEARER_TOKEN_HERE>",
oauth: "<YOUR_OAUTH_HERE>",
},
});
async function run() {
const result = await conductoroneSDKTypescript.stepUpProvider.create();
console.log(result);
}
run();curl --request POST \
--url https://{tenantDomain}.conductor.one/api/v1/step-up/providers \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"clientId": "<string>",
"clientSecret": "<string>",
"displayName": "<string>",
"issuerUrl": "<string>",
"microsoft": {
"conditionalAccessIds": [
"<string>"
],
"tenant": "<string>"
},
"oauth2": {
"acrValues": [
"<string>"
]
}
}
'import requests
url = "https://{tenantDomain}.conductor.one/api/v1/step-up/providers"
payload = {
"clientId": "<string>",
"clientSecret": "<string>",
"displayName": "<string>",
"issuerUrl": "<string>",
"microsoft": {
"conditionalAccessIds": ["<string>"],
"tenant": "<string>"
},
"oauth2": { "acrValues": ["<string>"] }
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
clientId: '<string>',
clientSecret: '<string>',
displayName: '<string>',
issuerUrl: '<string>',
microsoft: {conditionalAccessIds: ['<string>'], tenant: '<string>'},
oauth2: {acrValues: ['<string>']}
})
};
fetch('https://{tenantDomain}.conductor.one/api/v1/step-up/providers', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{tenantDomain}.conductor.one/api/v1/step-up/providers",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'clientId' => '<string>',
'clientSecret' => '<string>',
'displayName' => '<string>',
'issuerUrl' => '<string>',
'microsoft' => [
'conditionalAccessIds' => [
'<string>'
],
'tenant' => '<string>'
],
'oauth2' => [
'acrValues' => [
'<string>'
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}HttpResponse<String> response = Unirest.post("https://{tenantDomain}.conductor.one/api/v1/step-up/providers")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"clientId\": \"<string>\",\n \"clientSecret\": \"<string>\",\n \"displayName\": \"<string>\",\n \"issuerUrl\": \"<string>\",\n \"microsoft\": {\n \"conditionalAccessIds\": [\n \"<string>\"\n ],\n \"tenant\": \"<string>\"\n },\n \"oauth2\": {\n \"acrValues\": [\n \"<string>\"\n ]\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://{tenantDomain}.conductor.one/api/v1/step-up/providers")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"clientId\": \"<string>\",\n \"clientSecret\": \"<string>\",\n \"displayName\": \"<string>\",\n \"issuerUrl\": \"<string>\",\n \"microsoft\": {\n \"conditionalAccessIds\": [\n \"<string>\"\n ],\n \"tenant\": \"<string>\"\n },\n \"oauth2\": {\n \"acrValues\": [\n \"<string>\"\n ]\n }\n}"
response = http.request(request)
puts response.read_body{
"stepUpProvider": {
"clientId": "<string>",
"createdAt": "2023-11-07T05:31:56Z",
"displayName": "<string>",
"enabled": true,
"id": "<string>",
"issuerUrl": "<string>",
"lastTestedAt": "2023-11-07T05:31:56Z",
"microsoft": {
"conditionalAccessIds": [
"<string>"
],
"tenant": "<string>"
},
"oauth2": {
"acrValues": [
"<string>"
]
},
"updatedAt": "2023-11-07T05:31:56Z"
}
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
This API uses OAuth2 with the Client Credential flow. Client Credentials must be sent in the BODY, not the headers. For an example of how to implement this, refer to the c1TokenSource.Token() function.
Body
The CreateStepUpProviderRequest message.
This message contains a oneof named settings. Only a single field of the following list may be set at a time:
- oauth2
- microsoft
The clientId field.
The clientSecret field.
The displayName field.
The issuerUrl field.
StepUpMicrosoftSettings represents a Microsoft Entra Provider using Conditional Access Policies to enforce step-up authentication.
Show child attributes
Show child attributes
StepUpOAuth2Settings repersents an OAuth2 provider that supports RFC 9470 https://www.rfc-editor.org/rfc/rfc9470
Common ACR values for OAuth2 providers include:
- "urn:okta:loa:1fa:any" (okta)
- "urn:okta:loa:1fa:pwd" (okta)
- "urn:okta:loa:2fa:any" (okta)
- "urn:okta:loa:2fa:any:ifpossible" (okta)
- "phr" (okta)
- "phrh" (okta)
Show child attributes
Show child attributes
Response
Successful response
The CreateStepUpProviderResponse message.
The StepUpProvider message.
This message contains a oneof named settings. Only a single field of the following list may be set at a time:
- oauth2
- microsoft
Show child attributes
Show child attributes
Was this page helpful?