Apidog Docs
🇺🇸 English
  • 🇺🇸 English
  • 🇯🇵 日本語
  • 🇪🇸 Español
  • 🇰🇷 한국인
  • 🇨🇳 简体中文
  • 🇵🇹 Português (Portugal)
  • 🇮🇩 Bahasa Indonesia
  • 🇧🇷 Português (Brasil)
  • 🇻🇳 Tiếng Việt
  • 🇨🇳 繁體中文
🇺🇸 English
  • 🇺🇸 English
  • 🇯🇵 日本語
  • 🇪🇸 Español
  • 🇰🇷 한국인
  • 🇨🇳 简体中文
  • 🇵🇹 Português (Portugal)
  • 🇮🇩 Bahasa Indonesia
  • 🇧🇷 Português (Brasil)
  • 🇻🇳 Tiếng Việt
  • 🇨🇳 繁體中文
🇺🇸 English
  • 🇺🇸 English
  • 🇯🇵 日本語
  • 🇪🇸 Español
  • 🇰🇷 한국인
  • 🇨🇳 简体中文
  • 🇵🇹 Português (Portugal)
  • 🇮🇩 Bahasa Indonesia
  • 🇧🇷 Português (Brasil)
  • 🇻🇳 Tiếng Việt
  • 🇨🇳 繁體中文
Learning Center
HomeSupport CenterAPI ReferencesDownloadChangelog
Learning Center
HomeSupport CenterAPI ReferencesDownloadChangelog
  1. Enterprise Onboarding
  • Apidog Learning Center
  • Getting Started
    • Introduction to Apidog
    • Basic Concepts in Apidog
    • Navigating Apidog
    • Quick Start
      • Overview
      • Creating an Endpoint
      • Making a Request
      • Adding an Assertion
      • Creating Test Scenarios
      • Sharing API Documentation
      • Explore More
    • Migration to Apidog
      • Overview
      • Manual Import
      • Scheduled Import (Bind Data Sources)
      • Import Options
      • Export Data
      • Import From
        • Import from Postman
        • Import from Stoplight
        • Import OpenAPI Spec
        • Import cURL
        • Import Markdowns
        • Import from Insomnia
        • Import from apiDoc
        • Import .har File
        • Import WSDL
  • Design APIs
    • Overview
    • Create a New API Project
    • Endpoint Basics
    • APl Design Guidelines
    • Module
    • Configure Multiple Request Body Examples
    • Components
    • Common Fields
    • Global Parameters
    • Endpoint Change History
    • Comments
    • Batch Endpoint Management
    • Custom Protocol API
    • Spec-first Mode (Beta)
    • Schemas
      • Overview
      • Create a New Schema
      • Build a Schema
      • Generate Schemas from JSON Etc
      • oneOf, allOf, anyOf
      • Using Discriminator
    • Security Schemes
      • Overview
      • Create a Security Scheme
      • Use the Security Scheme
      • Security Scheme in Online Documentation
    • Advanced Features
      • Custom Endpoint Fields
      • Associated Test Scenarios
      • Endpoint Status
      • Appearance of Parameter Lists
      • Endpoint Unique Identification
  • Develop and Debug APIs
    • Overview
    • Generating Requests
    • Sending Requests
    • Debugging Cases
    • Test Cases
    • Dynamic Values
    • Validating Responses
    • Design-First vs Request-First
    • Generating Code
    • AI Debugging
      • AI Agent Debugger
      • A2A Debugger
    • Environments & Variables
      • Overview
      • Using Variables
      • Environment Management
    • Vault Secrets
      • Overview
      • HashiCorp Vault
      • Azure Key Vault
      • AWS Secrets Manager
    • Pre and Post Processors
      • Overview
      • Assertion
      • Extract Variable
      • Wait
      • Security
      • Database Operations
        • Overview
        • MySQL
        • MongoDB
        • Redis
        • Oracle Client
      • Using Scripts
        • Overview
        • Pre Processor Scripts
        • Post Processor Scripts
        • Script Library
        • Postman Scripts Reference
        • Calling Other Programming Languages
        • Using JS Libraries
        • Visualizing Responses
        • Script Examples
          • Assertion Scripts
          • Using Variables
          • Modifying Requests
          • Other Examples
    • Dynamic Values Modules
  • Mock API Data
    • Overview
    • Smart Mock
    • Custom Mock
    • Mock Priority Sequence
    • Mock Scripts
    • Cloud Mock
    • Self-Hosted Runner Mock
    • Mock Language (Locales)
  • API Testing
    • Overview
    • Test Scenarios
      • Create a Test Scenario
      • Pass Data Between Requests
      • Flow Control Conditions
      • Sync Data from Endpoints and Endpoint Cases
      • Import Endpoints and Endpoint Cases from Other Projects
      • Export Test Scenarios
    • Test Reports
      • Test Reports
    • Run Test Scenarios
      • Run a Test Scenario
      • Run Test Scenarios in Batch
      • Data-Driven Testing
      • Shared Test Data
      • Scheduled Tasks
      • Manage Runtime Environment of APIs from Other Projects
    • Test APIs
      • Integration Testing
      • Performance Testing
      • End-to-End Testing
      • Regression Testing
      • Contract Testing
    • Test Suite
      • Overview
      • Create A Test Suite
      • Orchestrate Test Suite
      • Run Test Suites Locally
      • Scheduled Tasks
  • Apidog CLI
    • Overview
    • Installing and Running Apidog CLI
    • Run Test Suites Via CLI
    • Apidog CLI Commands & Options
    • Use Apidog CLI with an AI Agent
    • CI CD
      • Overview
      • Trigger Test by Git Commit
      • Integrate with Github Actions
      • Integrate with Gitlab
      • Integrate with Jenkins
  • Publish API Docs
    • Overview
    • API Technologies Supported
    • Quick Share
    • Viewing API Documentation
    • Markdown Documentation
    • Publishing Documentation Sites
    • Custom Login Page
    • Custom Layouts
    • Custom CSS, JavaScript, HTML
    • Custom Domain
    • AI Features
    • SEO Settings
    • Advanced Settings
      • Documentation Search
      • CORS Proxy
      • Integrating Google Analytics
      • Folder Tree Settings
      • Visibility Settings
      • Embedding Values in Document URLs
    • API Versions
      • Overview
      • Creating API Versions
      • Publishing API Versions
      • Sharing Endpoints with API Versions
  • Send Requests
    • Overview
    • SSE Debugging
    • MCP Client
    • Socket.IO
    • WebSocket
    • Webhook
    • SOAP or WebService
    • GraphQL
    • gRPC
    • Use Request Proxy Agents for Debugging
    • Create Requests
      • Request History
      • Request Basics
      • Parameters and Body
      • Request Headers
      • Request Settings
      • Debug Requests
      • Saving Requests as Endpoints
      • HTTP/2
    • Response and Cookies
      • Viewing API Responses
      • Managing Cookies
      • Overview
    • Authentication and Authorization
      • Overview
      • CA and Client Certificates
      • Authorization Types
      • Digest Auth
      • OAuth 1.0
      • OAuth 2.0
      • Hawk Authentication
      • Kerberos
      • NTLM
      • Akamai EdgeGrid
  • Branches
    • Overview
    • Creating a Sprint Branch
    • Testing APIs in a Branch
    • Designing APIs in a Branch
    • Merging Sprint Branches
    • Managing Sprint Branches
    • AI Branch (Beta)
  • AI Features
    • Overview
    • Enabling AI Features
    • Generating Test Cases
    • Modifying Schemas with AI
    • Endpoint Compliance Check
    • API Documentation Completeness Check
    • AI-Powered Field Naming
    • FAQs
  • Apidog MCP Server
    • Overview
    • Connect Apidog Project to AI
    • Connect Published Documentation to AI
    • Connect OpenAPI Files to AI
  • Best Practices
    • Handling API Signatures
    • Accessing OAuth 2.0 Protected APIs
    • Collaboration Workflow
    • Managing Authentication State
  • Offline Space
    • Overview
  • Administration
    • Basic Concepts
    • Enterprise Onboarding
      • Enterprise Onboarding Journey
      • Set Up Secure Enterprise Access
      • Migrate and Validate Your API Data
      • Establish Your Team’s Apidog Workflow
    • Managing Projects
      • Notification Settings
      • Managing Projects
      • Managing Project Members
      • Project Resources
        • Database Connection
        • Git Connection
    • Managing Teams
      • Managing Teams
      • Managing Team Members
      • Team Roles & Permissions
      • Team Activities
      • Team Resources
        • General Runner
        • Team Variables
        • Request Proxy Agent
      • Real-time Collaborations
        • Team Collaboration
    • Managing Organization
      • Managing Organization
      • Managing Teams in an Organization
      • Organization Role & Permissions
      • Audit Logs
      • Enterprise Policies
      • Single Sign-On (SSO)
        • SSO Overview
        • Configuring Microsoft Entra ID
        • Configuring Okta
        • Configuring SSO for an Organization
        • Managing User Accounts
        • Mapping Groups to Teams
        • Configuring JumpCloud SSO
      • SCIM Provisioning
        • Introduction to SCIM Provisioning
        • Microsoft Entra ID
        • Okta
      • Plans Management
        • Billing Managers in Organizations
      • Organization Resources
        • Self-Hosted Runner
        • GitHub Enterprise Cloud
  • Billing
    • Overview
    • Credits
    • Upgrading Your Plan
    • Alternative Payment Methods
    • Managing Subscriptions
    • Moving Paid Teams to Organizations
  • Data & Security
    • Data Storage and Security
    • User Data Privacy and Security
    • Request Routing and Data Security
    • Secret Scanner
  • Add-ons
    • API Hub
    • Apidog Intellij IDEA Plugin
    • Browser Extension
      • Chrome
      • Microsoft Edge
    • Request Proxy
      • Request Proxy in Web
      • Request Proxy in Shared Docs
      • Request Proxy in Client
  • Account & Preferences
    • Account Settings
    • Generating OpenAPI Access Token
    • Notification
    • Language Settings
    • Hot Keys
    • Network Proxy Configuration
    • Backing Up Data
    • Updating Apidog
    • Deleting Account
    • Experimental Features
  • References
    • API Design-First Approach
    • Apidog OpenAPI Specificaiton Extensions
    • JSONPath
    • XPath
    • Regular Expressions
    • JSON Schema
    • CSV File Format
    • Installing Java Environment
    • Runner Deployment Environment
    • Apidog Markdown Syntax
    • Apidog Swagger Extensions
      • Overview
      • x-apidog-folder
      • x-apidog-status
      • x-apidog-name
      • x-apidog-maintainer
    • Apidog JSON Schema Extensions
      • Overview
      • x-apidog-mock
      • x-apidog-orders
      • x-apidog-enum
  • Apidog Europe
    • Apidog Europe
  • Support Center
  1. Enterprise Onboarding

Set Up Secure Enterprise Access

Bring a representative group of users into Apidog and verify that each person has access only to the intended Teams and Projects. You can invite users directly or use SSO; both routes finish with the same access-validation checkpoint.
Journey: Enterprise Onboarding Journey → Set Up Secure Enterprise Access → Migrate and Validate Your API Data → Establish Your Team's Apidog Workflow

Prepare the pilot access plan#

Before adding users:
Confirm the Organization Owner and an administrative backup.
Identify the Teams and pilot Project that users need to access.
Select representative Admin, Editor, Read-only, and restricted users.
Record the expected Organization role, Team role, and Project role for each pilot user.
Confirm the customer's deployment using the Enterprise Onboarding Journey. Feature availability and navigation can differ for Apidog On-Premises.
Organization, Team, and Project permissions are separate. An Org Admin can manage the organization's structure and settings but does not automatically receive access to every Project. Review Organization Role & Permissions and Team Roles & Permissions before assigning access.

Choose how users will enter Apidog#

RouteUse whenPrimary owner
Invite users directlyAn Org Admin, Team Admin, or Project Admin will add the initial users at the appropriate level. This is suitable for a small pilot or a manually managed rollout.Org Admin, Team Admin, or Project Admin
Use SSOAn identity provider should authenticate users and, when configured, map groups to Teams.Identity administrator and Org Admin
You can use direct invitations for the pilot and introduce SSO for a later rollout. Complete the same access checks regardless of the route.

Route A: Invite users directly#

Choose the invitation level based on the access each person needs.
Invite fromUse whenConfirm
OrganizationAdministrators are creating the enterprise member pool and assigning users to one or more Teams.Organization role, Team assignments, Team roles, and resulting Project access.
TeamInternal users need access to several Projects within one Team.Team role and the role for each relevant Project.
ProjectA user should access one Project, such as an external or cross-functional collaborator.Current Project role, resulting Team role, and access to other Projects.

Invite the pilot users#

1.
If inviting at the Organization level, confirm that the Organization has at least one Team.
2.
Invite each user from the Organization, Team, or Project level that matches the required access.
3.
Assign the intended Organization and Team roles where those settings apply.
4.
Assign the required Project role: Admin, Editor, Read-only, Forbidden, or an approved custom Project role.
5.
Review access to the other Projects in the Team, especially for external collaborators.
6.
Test the representative users before inviting the remaining population.
Use the dedicated guides while completing this route:
Managing Organization
Managing Team Members
Managing Project Members
Team Roles & Permissions

Route B: Connect SSO#

Use SSO when authentication and Team assignment should follow the organization's identity process. Keep SSO, SAML Group Mapping, and SCIM responsibilities distinct.
CapabilityWhat it doesImportant boundary
SAML SSOAuthenticates users and can add them to the Organization.Users are not assigned to Teams by default unless SAML Group Mapping is configured.
SAML Group MappingMaps identity-provider groups to Apidog Teams and grants initial Project permissions.The initial Project role depends on the mapped Team role. Group Mapping does not provide a separate role setting for each Project.
SCIMAutomates supported user provisioning and removal.SCIM does not manage groups. Use SAML Group Mapping for identity-provider group-to-Team mapping.

Configure the pilot SSO flow#

1.
Confirm that the Organization uses an Apidog Enterprise plan and that the identity provider supports SAML 2.0.
2.
Configure the identity provider using the appropriate guide:
Configuring Microsoft Entra ID
Configuring Okta
Configuring JumpCloud SSO
3.
Complete and test the Apidog-side setup using Configuring SSO for an Organization.
4.
If Teams should be assigned from identity-provider groups, configure Mapping Groups to Teams. Review the initial Project permissions produced by each mapped Team role.
5.
Add SCIM Provisioning only when supported user provisioning and removal are required.
6.
Sign in with a representative user from each mapped group.
7.
Review each user's Organization membership, Team assignments, and Project roles. Adjust Project-specific roles where the initial role is not sufficient.
8.
Test a user without the intended group mapping and verify that the user does not receive unauthorized Team or Project access. If SCIM is enabled, also test its supported add and remove behavior.
For an overview of the SSO flow and user membership behavior, see SSO Overview and Managing User Accounts.

Validate access for both routes#

Test the same representative access set whether users were invited directly or entered through SSO.
Representative userExpected accessValidation
Admin userProject AdminCan manage the pilot Project and its members.
Editor userProject EditorCan create and modify the intended Project content.
Read-only userProject Read-onlyCan view and run permitted content but cannot edit it.
Restricted userProject Forbidden or no Project membershipCannot open the pilot Project.
Record the expected result, actual result, and owner of any exception. Correct access issues before adding more users.

Complete the access phase#

The selected invitation or SSO route works for the pilot users.
Every representative user has the intended Organization and Team membership.
Each pilot user's Project role matches the access plan.
Admin, Editor, and Read-only behaviors match the expected permissions.
The restricted user cannot access the pilot Project.
SAML Group Mapping produces the intended initial Project access, if configured.
Supported SCIM add and remove behavior works as expected, if configured.
Identity or access exceptions have named owners.
This phase is complete when representative users have only the intended access and the organization can repeat the selected route for the next group.
Modified at 2026-08-20 10:34:39
Previous
Enterprise Onboarding Journey
Next
Migrate and Validate Your API Data
Built with