> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getprimo.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Link SaaS identities to the employees who own them

> Link existing SaaS identities (accounts already on an application) to the employees who own them, up to 100 identity → employee pairs per call. Primo links an account to an employee by itself only when the account email equals the employee email; this links the accounts it could not match, such as an alias (`firstname.lastname@`) of an employee whose HR email is `flastname@`.

The account keeps its own email, becomes an employee account and leaves the "To link" list. An identity already linked to another employee moves to the one given. A later integration sync keeps the link. Nothing changes in the application itself.

Read the identities to link from `getUnlinkedSaasIdentities` (its `id`) and the employees from `getEmployees` (its `id`). To record an account Primo does not know yet, use `createSaasIdentity` instead; to have an admin create a new account, use `provisionSaasIdentity`.

Writes are independent and best-effort: the call returns 200 with a `results` manifest reporting `ok` / `error` per item — always inspect `results` rather than relying on the HTTP status to detect partial failures.

<span className="badge-write">Key: Write</span><span className="badge-company">Scope: Company</span>


## OpenAPI

````yaml https://api.getprimo.com/openapi.json post /saas-identities/batch-link
openapi: 3.1.1
info:
  title: Public API - BETA
  description: Read docs on https://docs.getprimo.com/
  version: '1.0'
  contact: {}
servers:
  - url: https://api.getprimo.com
security:
  - apikey: []
tags: []
paths:
  /saas-identities/batch-link:
    post:
      tags:
        - Saas
      summary: Link SaaS identities to the employees who own them
      description: >-
        Link existing SaaS identities (accounts already on an application) to
        the employees who own them, up to 100 identity → employee pairs per
        call. Primo links an account to an employee by itself only when the
        account email equals the employee email; this links the accounts it
        could not match, such as an alias (`firstname.lastname@`) of an employee
        whose HR email is `flastname@`.


        The account keeps its own email, becomes an employee account and leaves
        the "To link" list. An identity already linked to another employee moves
        to the one given. A later integration sync keeps the link. Nothing
        changes in the application itself.


        Read the identities to link from `getUnlinkedSaasIdentities` (its `id`)
        and the employees from `getEmployees` (its `id`). To record an account
        Primo does not know yet, use `createSaasIdentity` instead; to have an
        admin create a new account, use `provisionSaasIdentity`.


        Writes are independent and best-effort: the call returns 200 with a
        `results` manifest reporting `ok` / `error` per item — always inspect
        `results` rather than relying on the HTTP status to detect partial
        failures.
      operationId: linkSaasIdentities
      parameters: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/LinkSaasIdentitiesBody'
      responses:
        default:
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/LinkSaasIdentitiesResult_Output'
components:
  schemas:
    LinkSaasIdentitiesBody:
      type: object
      properties:
        links:
          description: >-
            The identity → employee pairs to link. Each identity may appear at
            most once and up to 100 pairs per call. Writes are best-effort:
            inspect the per-item `results` to learn which succeeded — the HTTP
            status is 200 even when some items fail.
          minItems: 1
          maxItems: 100
          type: array
          items:
            type: object
            properties:
              saasApplicationUserId:
                description: >-
                  The SaaS identity ID, as returned by
                  `getUnlinkedSaasIdentities` → `id` or `getSaasById` →
                  `identities[].id`.
                type: string
                pattern: ^[a-f\d]{24}$
              employeeId:
                description: >-
                  The employee who owns the account, as returned by
                  `getEmployees` → `id`.
                type: string
                pattern: ^[a-f\d]{24}$
            required:
              - saasApplicationUserId
              - employeeId
      required:
        - links
    LinkSaasIdentitiesResult_Output:
      type: object
      properties:
        successCount:
          type: integer
          description: Number of identities linked successfully.
          minimum: -9007199254740991
          maximum: 9007199254740991
        failureCount:
          type: integer
          description: Number of identities that failed.
          minimum: -9007199254740991
          maximum: 9007199254740991
        results:
          type: array
          description: Per-item outcome, in the same order as the input `links`.
          items:
            type: object
            properties:
              status:
                type: string
                enum:
                  - ok
                  - error
              errorCode:
                description: Machine-readable error code when status is "error".
                anyOf:
                  - type: string
                  - type: 'null'
              message:
                description: Human-readable error detail when status is "error".
                anyOf:
                  - type: string
                  - type: 'null'
              saasApplicationUserId:
                type: string
              employeeId:
                description: The employee the item targeted, echoed from the input.
                type: string
            required:
              - status
              - saasApplicationUserId
              - employeeId
            additionalProperties: false
      required:
        - successCount
        - failureCount
        - results
      additionalProperties: false
  securitySchemes:
    apikey:
      scheme: bearer
      bearerFormat: API key
      type: http
      description: >-
        Use your Primo API key in the Authorization header as `Bearer
        <API_KEY>`.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.