AAC Docs

aac sso register-idp

AAC CLI 0.2.8MarkdownDocs 6b7d8268ba78

Register a tenant↔IdP connection.

Registers one tenant↔IdP trust relationship on the control plane: issuer, audience, the three-layer claims mapping, and optional session-TTL overrides. Production registrations trigger server-side OIDC discovery on the issuer; a jwks_static member in the file skips discovery (dev/compose stacks only).

Synopsis

aac sso register-idp
  [-h]
  [--profile PROFILE]
  [--admin-url ADMIN_URL]
  [--data-plane-url DATA_PLANE_URL]
  [--output {json,table}]
  [--tenant-id TENANT_ID]
  --file FILE
  [--bootstrap-token BOOTSTRAP_TOKEN]
  [--shared]

Arguments

Argument Type Required Default Description
-h, --help flag no — show this help message and exit
--profile value no — Profile to run under (selection: --profile > AAC_PROFILE > reserved baseline main). aac profile list shows what exists.
--admin-url value no — Admin-surface base URL (overrides profile).
--data-plane-url value no — Data-plane-surface base URL (overrides profile).
--output json | table no json Output mode: json (the default) or table.
--tenant-id value no — Tenant to register the connection FOR (default: profile/env tenant).
--file value yes — Connection config JSON file (aws --cli-input-json idiom; see epilog).
--bootstrap-token value no empty Ceremony bootstrap token for the X-AAC-Bootstrap-Token header (first-IdP onboarding; falls back to $AAC_BOOTSTRAP_TOKEN).
--shared flag no — Register a SHARED developer-tier connection (github/google) owned by the platform, not a tenant — a platform operator ceremony (--bootstrap-token required; --tenant-id ignored). The connection file omits binding_claims/groups_claim/role_map (roles come from principal→tenant bindings) and may carry public_client_secret (Google) or jwks_static {"keys": []} + explicit endpoints (GitHub).

Output

--output json (the default) prints one JSON document to standard output; --output table prints a readable table instead. Progress notes and diagnostics go to standard error, so the JSON stays parseable.

Exit codes

Code Meaning
0 Success.
1 The control plane or the identity provider rejected the request.
2 Usage error: an invalid flag, value or flag combination.
3 A local configuration or state problem: profile, credential file, cached session or agent.
4 Transport failure: an endpoint could not be reached.

Notes

example connection.json (Entra):
  {
    "issuer": "https://login.microsoftonline.com/<tid>/v2.0",
    "family": "entra",
    "expected_audience": "<Application (client) ID — the GUID, not the app name>",
    "binding_claims": {"tid": "<tid>"},
    "groups_claim": "groups",
    "role_map": {"<group-object-id>": ["tenant-admin"]}
  }

First-IdP onboarding runs under the ops ceremony (--bootstrap-token / $AAC_BOOTSTRAP_TOKEN); adding further IdPs self-serve uses your session (aac sso login).