SSOBypassAllowlistResource
The SSOBypassAllowlistResource object lets you manage which Organization members can sign in with an email code instead of using their enterprise single sign-on (SSO) connection. Access these methods through organization.ssoBypassAllowlist.
These methods only manage the allowlists of the Organization's own enterprise connections. To manage the allowlist for every connection on the instance, use the Clerk Dashboard or the Backend API.
Methods
getUsers()
Lists the Organization members on the SSO bypass allowlist. Returns an array of SSOBypassAllowlistUserResource objects.
function getUsers(): Promise<SSOBypassAllowlistUserResource[]>addUser()
Adds an Organization member to the allowlist. The member must have a verified email address on a domain served by one of the Organization's enterprise connections. Returns the member's SSOBypassAllowlistUserResource object. Adding a member who's already on the allowlist returns their existing entry.
function addUser(params: { userId: string }): Promise<SSOBypassAllowlistUserResource>- Name
userId- Type
string- Description
The ID of the Organization member to add.
addUsers()
Adds Organization members to the allowlist. The method sends one request per 100 IDs, one after another. If a request fails, the promise rejects, and members added by earlier requests stay on the allowlist.
function addUsers(params: { userIds: string[] }): Promise<SSOBypassAllowlistBulkCreateResult>- Name
userIds- Type
string[]- Description
The IDs of the Organization members to add.
Returns
addUsers() returns an SSOBypassAllowlistBulkCreateResult object with the following properties:
- Name
data- Type
- SSOBypassAllowlistUserResource[]
- Description
The members on the allowlist, including members who were already on it.
- Name
errors- Type
{ userId: string, code: string }[]- Description
The members who couldn't be added. The
codeisresource_not_foundwhen the user isn't a member of the Organization, andsso_bypass_domain_not_servedwhen the member has no verified email address on a domain served by one of the Organization's enterprise connections.
An error for one member doesn't prevent other members from being added.
removeUser()
Removes an Organization member from the allowlist. Entries on enterprise connections outside the Organization aren't affected. Returns a DeletedObjectResource object.
function removeUser(userId: string): Promise<DeletedObjectResource>- Name
userId- Type
string- Description
The ID of the Organization member to remove.
SSOBypassAllowlistUserResource
An Organization member's entry on the SSO bypass allowlist.
- Name
createdAt- Type
Date- Description
The date when the member was added to the allowlist.
- Name
id- Type
string- Description
The unique identifier for the entry. Same as
userId.
- Name
publicUserData- Type
- PublicUserData
- Description
Information about the member that's publicly available.
- Name
updatedAt- Type
Date- Description
The date when the entry was last updated.
- Name
userId- Type
string- Description
The ID of the member.
Feedback
Last updated on