Skip to main content

SSOBypassAllowlistResource

The SSOBypassAllowlistResource object lets you manage which Organization members can sign in with an email code instead of using their enterprise single sign-on (SSO) connection. Access these methods through organization.ssoBypassAllowlist.

These methods only manage the allowlists of the Organization's own enterprise connections. To manage the allowlist for every connection on the instance, use the Clerk Dashboard or the Backend API.

Important

These methods require the org:sys_entconns_sso_bypass:manage System Permission.

Methods

getUsers()

Lists the Organization members on the SSO bypass allowlist. Returns an array of SSOBypassAllowlistUserResource objects.

function getUsers(): Promise<SSOBypassAllowlistUserResource[]>

addUser()

Adds an Organization member to the allowlist. The member must have a verified email address on a domain served by one of the Organization's enterprise connections. Returns the member's SSOBypassAllowlistUserResource object. Adding a member who's already on the allowlist returns their existing entry.

function addUser(params: { userId: string }): Promise<SSOBypassAllowlistUserResource>
  • Name
    userId
    Type
    string
    Description

    The ID of the Organization member to add.

addUsers()

Adds Organization members to the allowlist. The method sends one request per 100 IDs, one after another. If a request fails, the promise rejects, and members added by earlier requests stay on the allowlist.

function addUsers(params: { userIds: string[] }): Promise<SSOBypassAllowlistBulkCreateResult>
  • Name
    userIds
    Type
    string[]
    Description

    The IDs of the Organization members to add.

Returns

addUsers() returns an SSOBypassAllowlistBulkCreateResult object with the following properties:

  • Name
    data
    Type
    SSOBypassAllowlistUserResource[]
    Description

    The members on the allowlist, including members who were already on it.

  • Name
    errors
    Type
    { userId: string, code: string }[]
    Description

    The members who couldn't be added. The code is resource_not_found when the user isn't a member of the Organization, and sso_bypass_domain_not_served when the member has no verified email address on a domain served by one of the Organization's enterprise connections.

An error for one member doesn't prevent other members from being added.

removeUser()

Removes an Organization member from the allowlist. Entries on enterprise connections outside the Organization aren't affected. Returns a DeletedObjectResource object.

function removeUser(userId: string): Promise<DeletedObjectResource>
  • Name
    userId
    Type
    string
    Description

    The ID of the Organization member to remove.

SSOBypassAllowlistUserResource

An Organization member's entry on the SSO bypass allowlist.

  • Name
    createdAt
    Type
    Date
    Description

    The date when the member was added to the allowlist.

  • Name
    id
    Type
    string
    Description

    The unique identifier for the entry. Same as userId.

  • Name
    publicUserData
    Type
    PublicUserData
    Description

    Information about the member that's publicly available.

  • Name
    updatedAt
    Type
    Date
    Description

    The date when the entry was last updated.

  • Name
    userId
    Type
    string
    Description

    The ID of the member.

Feedback

What did you think of this content?

Last updated on