TrustPortDocs

Turn on a provider

  1. Create an OAuth app with the provider

    In the Google Cloud console or GitHub's developer settings, create an OAuth app (GitHub) or OAuth client (Google). When it asks for a redirect or callback URL, use the one shown in the TrustPort dashboard for that provider. It looks like this:

    Callback URL
    https://id.trustportidentity.com/api/v1/auth/oauth/google/callback
  2. Paste the credentials into TrustPort
    In the dashboardSingle Sign-On & Logins›Providers

    Choose the provider, paste the client ID and client secret, and switch it on. The secret is encrypted as soon as you save it and is never shown again.

  3. Try it

    Open your sign-in page. A Continue with Google or Continue with GitHub button appears for each provider you switched on.

Who can sign in

TrustPort matches the provider's verified email address to a user in your workspace.

SituationWhat happens
A user with that email existsThey are signed in to their existing account.
No user has that email, and self-service sign-up is onTrustPort creates the account using the name from the provider, then signs them in.
No user has that email, and self-service sign-up is offSign-in is refused and the person is told to ask an administrator for an invitation.
The account is deactivated or lockedSign-in is refused.
In the dashboardSingle Sign-On & Logins›Features›Self-service Sign-up

Self-service sign-up is off by default. Leave it off if only invited people should get in; switch it on for a consumer product where anyone may create an account.

Accounts created through Google or GitHub have no usable password. People sign in with the provider, or set a password through Forgot password.

Add social buttons to your own sign-in page

If you built your own sign-in screen, send the browser to TrustPort to start the flow:

Start URL
https://id.trustportidentity.com/api/v1/auth/oauth/google/start
  ?tenant=$TRUSTPORT_WORKSPACE_ID
  &redirect_uri=https://app.example.com/auth/done

After the person approves, TrustPort sends them back to your redirect_uri with a one-time code. Exchange it for tokens within a minute:

Exchange the code
curl -X POST https://id.trustportidentity.com/api/v1/auth/oauth/exchange \
  -H "Content-Type: application/json" \
  -d '{ "code": "<code from the redirect>" }'

Rules for the return address

  • The redirect_uri must be on an approved origin. The TrustPort dashboard is approved already; to use your own app's origin, ask TrustPort support to add it.
  • To show only the buttons that are switched on, list them with GET /api/v1/auth/oauth/providers?tenant=….
  • If sign-in fails or the person cancels, they come back to the same address with error=sign_in_failed and a readable message instead of a code.

Remove a provider

Switch it off to hide the button and refuse new sign-ins through it, or choose Remove credentials to delete the stored secret as well. People who signed up through the provider can still sign in with a password if they set one.

© TrustPort IdentitySomething unclear? Tell us and we'll fix the page.