Sign-in
How sign-in works
Every sign-in passes through the same set of checks, whichever method a person uses. Knowing the order helps you decide where to add your own rules.
The journey
1IdentifyEmail and password, or a social provider
2Your rulesPre-authentication actions run
3VerifyPassword checked, account must be active
4Assess riskRadar scores the attempt
5Second factorAuthenticator code, if required
6SessionTokens issued, event recorded
In more detail:
- Identify. The person enters their email and password, or picks Google or GitHub.
- Your rules. Any pre-authentication actions you have deployed run first and can turn the attempt away.
- Verify. TrustPort checks the password. A wrong password and an unknown email give the same message, so nobody can use your sign-in page to find out who has an account. Deactivated or locked accounts stop here.
- Assess risk. Radar compares the attempt with the person's usual behaviour. A critical score blocks the sign-in even when the password is right.
- Second factor. If the person has an authenticator app enrolled, or one of your actions requires it, they must enter a code.
- Session. TrustPort runs your post-login actions, issues tokens and records the sign-in in your audit log.
Sign-in methods
| Method | Availability | Set up in |
|---|---|---|
| Email and password | Available | Always on |
| Google and GitHub | Available | Single Sign-On & Logins › Providers |
| Authenticator app (TOTP) | Available | Each user, under Account & Security |
| Enterprise SSO (SAML, OIDC) | Preview | Organizations |
| Passkeys | Coming soon | — |
| Email one-time codes (magic links) | Coming soon | — |
What your app receives
A successful sign-in returns an access token, valid for 15 minutes, and a refresh token, valid for 30 days. The access token names the user, your workspace, the session and the user's roles, plus any claims your actions added. Read Sessions and tokens for how to use them.
See it live
The Authentication page in the dashboard shows sign-in counts, failures and blocks from the last day, straight from your audit log and Radar.