SSO and SCIM
Plan SAML or OIDC identity, attribute mapping, provisioning, deprovisioning, enforcement, recovery, and audit.
Explore capabilityReview conceptual API, webhook, authentication, import, export, SSO, SCIM, and automation patterns for the SierraTec Survey product. The downloadable files are implementation examples, not a live production API contract.
curl --request POST \
--url https://api.example.survey.sierratecsecure.com/v1/surveys \
--header 'Authorization: Bearer $SIERRATEC_API_TOKEN' \
--header 'Content-Type: application/json' \
--header 'Idempotency-Key: 8f6b2d6e-...' \
--data '{
"title": "Customer onboarding feedback",
"workspace_id": "ws_demo_001"
}'Separate environments, restrict access, rotate secrets, and never place private tokens in browser code.
Use stable event IDs and idempotency keys so retries do not create unintended duplicate effects.
Respect rate headers, back off with jitter, persist cursors, and resume safely after partial failure.
Log correlation IDs, monitor delivery, protect sensitive data, and maintain clear support runbooks.
A production contract should be versioned, documented in OpenAPI, tested for backward compatibility, and governed by plan entitlements.
| Method | Endpoint | Purpose | Typical scope |
|---|---|---|---|
| GET | /v1/surveys | List surveys with cursor pagination and updated-since filters. | surveys:read |
| POST | /v1/surveys | Create a draft survey under a workspace. | surveys:write |
| POST | /v1/surveys/{id}/publish | Publish an approved survey version. | surveys:publish |
| GET | /v1/surveys/{id}/responses | Read responses under authorized filters and field controls. | responses:read |
| POST | /v1/exports | Queue an asynchronous, permission-checked export job. | exports:create |
| GET | /v1/jobs/{id} | Read import, export, delivery, or analysis job status. | jobs:read |
| POST | /v1/webhooks | Register a signed event destination. | webhooks:manage |
A production webhook should include a unique event ID, timestamp, type, workspace context, versioned payload, and signature. Consumers should reject stale or invalid signatures and deduplicate before applying changes.
{
"id": "evt_demo_01H...",
"type": "response.completed",
"created_at": "2026-08-05T14:42:18Z",
"workspace_id": "ws_demo_001",
"data": {
"survey_id": "sv_demo_123",
"response_id": "rsp_demo_456",
"status": "completed"
}
}Plan SAML or OIDC identity, attribute mapping, provisioning, deprovisioning, enforcement, recovery, and audit.
Explore capabilityUse schemas, validation, previews, error files, idempotency, versioning, and governed commit steps.
Explore capabilityQueue permission-checked jobs, protect downloads, expire links, and record requester, filters, fields, and purpose.
Explore capabilityEnter your work email or organization domain. You will be routed to your organization's identity provider.
Continue to sign in