Validate OIDC discovery and issuer metadata

POST/v1/identity-connections/{connectionId}/validate

Performs bounded, SSRF-protected discovery and verifies issuer and authorization-code compatibility.

How to call this endpoint

Every ACP API request uses bearer authentication. The examples here show the actual request path, auth header, and body shape that the platform expects.

Path, query, and header parameters

These parameters control which ACP object the endpoint acts on and how the request is processed.

Path parameters
NameLocationTypeRequiredDescription
connectionIdpathstringYesOrganization identity connection ID
Query parameters
None.
Header parameters
NameLocationTypeRequiredDescription
X-Computer-Agents-OrganizationheaderstringNoActive organization context. If omitted, the authenticated user's personal organization is used.

Body schema

This endpoint does not require a request body.

None.

What the API returns

Each response code below includes the documented payload shape for the ACP API.

200Validated provider metadataapplication/json
FieldTypeRequiredDescription
dataobjectYes
400Provider metadata is invalid or unsafe
None.
Validate OIDC discovery and issuer metadata
Loading...
Response 200
Loading...
See the ACP quickstart and SDK flow