Maps a raw IdP group to an ANKASecure role for this tenant (the deny-by-default admission input). The mapped role is checked at declaration time so the mapping cannot be created in a state the federated login path is unable to consume: an unknown role, or a custom role owned by another tenant, is refused 404 (both causes are collapsed into one oracle-safe body); a service-to-service-only role is refused 400; and a role that is not assignable inside a tenant of this type — a PLATFORM_* composite, for instance — is refused 422 federated-role-not-assignable. Cross-surface divergence, deliberate: the SAME (role, tenant type) matrix answers 400 invalid-input on assignUserRoles and 422 here. The user-assignment surface rejects a malformed assignment request, whereas this surface accepts a well-formed declaration whose semantics cannot be satisfied — which is what 422 means. Required scope: admin.tenant.idp.mapping.manage.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||