TrustPortDocs

Password rules

RuleValue
Length8 to 128 characters
StorageHashed with Argon2id, never stored or logged in plain text
Wrong password or unknown emailSame message for both: “the provided credentials are incorrect”
Deactivated or locked accountSign-in is refused once the password is confirmed
Encourage long passphrases rather than complex short passwords. Then add a second factor; see Two-factor authentication.

When someone forgets their password

People reset their own password from the sign-in page. You don't need to do anything.

  1. They choose “Forgot password”

    They enter their email address. The page always confirms that an email is on its way, whether or not the account exists, so the form can't be used to check who has an account.

  2. They open the reset email

    The link is valid for 30 minutes and works once. To stop the form being used to flood someone's inbox, TrustPort sends at most one reset email per address per minute.

  3. They choose a new password

    Once it's saved, TrustPort signs them out of every other device. Anyone who had their old password loses access straight away.

You can change the wording of the reset email under Emails; see Email templates.

From your own app

If your app has its own sign-in screen, call the same two endpoints:

Request a reset email
curl -X POST https://id.trustportidentity.com/api/v1/auth/password/forgot \
  -H "Content-Type: application/json" \
  -H "X-Tenant-ID: $TRUSTPORT_WORKSPACE_ID" \
  -d '{ "email": "ada@example.com" }'
Set the new password with the token from the link
curl -X POST https://id.trustportidentity.com/api/v1/auth/password/reset \
  -H "Content-Type: application/json" \
  -d '{ "token": "<token from the email link>", "password": "a-new-long-passphrase" }'

Changing a password

In the dashboardAccount & Security›Change password

Signed-in users can change their password by entering the current one and the new one. Like a reset, this signs them out of their other sessions.

Setting a password for someone else

When you create a user directly, you choose their initial password. For teammates, sending an invitation is better: they pick their own password and you never know it.

© TrustPort IdentitySomething unclear? Tell us and we'll fix the page.