# Is it possible to create a SAML external role using the REST API?

**URL:** <https://community.sonatype.com/t/is-it-possible-to-create-a-saml-external-role-using-the-rest-api/9132>\
**Category:** Sonatype Nexus Repository\
**Created:** [August 16, 2022, 3:59pm UTC](https://community.sonatype.com/t/is-it-possible-to-create-a-saml-external-role-using-the-rest-api/9132 "2022-08-16T15:59:38Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![anders.e.stenman](https://avatars.discourse-cdn.com/v4/letter/a/df788c/32.png) [@anders.e.stenman](https://community.sonatype.com/u/anders.e.stenman)\
**Post date:** [August 16, 2022, 3:59pm UTC](https://community.sonatype.com/t/is-it-possible-to-create-a-saml-external-role-using-the-rest-api/9132/1 "2022-08-16T15:59:39Z")

</div>

Is it possible to create a SAML external role mapping using the REST API? We are using Nexus Repository Manager PRO 3.41.0-01.

---

<div class="post-metadata">

**Author:** ![anders.e.stenman](https://avatars.discourse-cdn.com/v4/letter/a/df788c/32.png) [@anders.e.stenman](https://community.sonatype.com/u/anders.e.stenman)\
**Post date:** [August 17, 2022, 1:40pm UTC](https://community.sonatype.com/t/is-it-possible-to-create-a-saml-external-role-using-the-rest-api/9132/2 "2022-08-17T13:40:36Z")

</div>

In the web interface it is possible to specify external role mapping and SAML

 ![image](https://canada1.discourse-cdn.com/flex047/uploads/communitysonatype/original/2X/f/faff2165b9f8d1162715ffe955fce91d3d751953.png)

---

<div class="post-metadata">

**Author:** ![mmartz](https://avatars.discourse-cdn.com/v4/letter/m/e9bcb4/32.png) [@mmartz](https://community.sonatype.com/u/mmartz)\
**Post date:** [August 17, 2022, 2:05pm UTC](https://community.sonatype.com/t/is-it-possible-to-create-a-saml-external-role-using-the-rest-api/9132/3 "2022-08-17T14:05:31Z")

</div>

I don’t remember exactly how it works off the top of my head, but you can fetch the role configuration via the API to see how to map external roles. The REST API will work just fine for creating external roles, it’s just not obvious how and I don’t think we’ve documented anywhere how it works.

---

<div class="post-metadata">

**Author:** ![mmartz](https://avatars.discourse-cdn.com/v4/letter/m/e9bcb4/32.png) [@mmartz](https://community.sonatype.com/u/mmartz)\
**Post date:** [August 17, 2022, 6:39pm UTC](https://community.sonatype.com/t/is-it-possible-to-create-a-saml-external-role-using-the-rest-api/9132/4 "2022-08-17T18:39:56Z")

</div>

Just did a quick test and it looks like you can do a normal POST to the roles rest api with something like this to create a new externally-mapped role. The id is the name of the role from SAML and the name is just the name to use in nxrm.

```auto
{
  "id": "saml-mapped-role",
  "source": "default",
  "name": "saml-mapped-role-name",
  "description": "saml-mapped-role-description",
  "readOnly": false,
  "privileges": [
    "nx-all"
  ],
  "roles": [
    "nx-admin"
  ]
}

```

---

<div class="post-metadata">

**Author:** ![anders.e.stenman](https://avatars.discourse-cdn.com/v4/letter/a/df788c/32.png) [@anders.e.stenman](https://community.sonatype.com/u/anders.e.stenman)\
**Post date:** [August 17, 2022, 7:24pm UTC](https://community.sonatype.com/t/is-it-possible-to-create-a-saml-external-role-using-the-rest-api/9132/5 "2022-08-17T19:24:02Z")

</div>

Great!

I will test tomorrow. Thank you!
