lbcli get idp-client-configuration
Gets an IdP client configuration.
Synopsis
Gets an IdP client configuration.
Examples:
Flag | Short | Type | Default | Description |
|---|---|---|---|---|
--help | -h | bool | Help for idp-client-configuration. | |
--name | string | The IdP client configuration name (required). |
This command returns the following fields for each snapshot. The default output format is human-readable. The human-readable output only shows some of these fields. The json/yaml output format is also supported and includes additional fields.
Field | Type | Description |
|---|---|---|
object | object | idp-client-configuration represents a configuration of a client-specific IdP entry in the Lightbits cluster. The Lightbits cluster supports IdP client configurations with three types of authorization modes: App, User, and Converge. App authorization mode should be used when Lightbits should map a specific client to a scope and role. User authorization mode should be used when Lightbits should map according to both the client ID and a specific claim in the JWT. Converge mode is used when Lightbits should map only according to the claim in the JWT. In this mode the client ID is ignored. Only a single such entry can be created for each IdP configuration. The Lightbits API service will first attempt to check for a dedicated IdP client configuration using this client ID, falling back to to an optional converge entry only if no direct client specific entry is found. |
UUID | string | The UUID of the idp-client-config entry. |
name | string | A unique name of the idp-client-config. |
clientId | string | A unique client ID identifier registered in the IdP to identify a specific application (or a client) that wants to access resources from a Lightbits cluster. When using converge authorization mode, this field must be configured to: NOT_APPLICABLE. |
idpConfigurationName | string | A reference to the IdP configuration that will use this client configuration. |
claimName | string | When working in user authorization/converge mode, the claim name specifies the name of the field in JWT claim from which to extract the identifier value. Note that this field is only required when authzMode is user or converge. |
authzMode | string | The authorization mode will determine what information from access JWT will be mapped to a matching scope/role in the Lightbits cluster. The authorization mode can be one of the following: user, app, converge. Enum: Default: UnknownAuthzMode |
© 2026 Lightbits Labs™