Developers
API reference
Everything you can do in the dashboard, you can do with the API. Requests and responses are JSON, and every call goes to one base URL.
Base URL
https://id.trustportidentity.comAuthentication
| Calling as | Send | Use for |
|---|---|---|
| Your backend | Authorization: Bearer sk_live_… (secret API key) | Managing your workspace |
| A signed-in user | Authorization: Bearer <access token> | Acting as that person, within their role |
| Nobody yet | X-Tenant-ID: <workspace ID> | Sign-in, password reset and other public calls |
Responses
Successful responses wrap the result in data. Lists may include meta with a total.
{
"data": { "id": "…", "email": "ada@example.com" }
}Errors share one shape. Show message to people; branch on code in your code.
{
"error": { "code": "FORBIDDEN", "message": "You don't have permission to do this." },
"meta": { "request_id": "…" }
}Every response carries an X-Request-ID header. Include it when you contact support.
Error codes
| Code | Status | Meaning |
|---|---|---|
BAD_REQUEST | 400 | Something in the request is missing or malformed |
INVALID_CREDENTIALS | 401 | Wrong email or password |
UNAUTHORIZED | 401 | No valid token or key was sent |
INVALID_TOKEN | 401 | The token or API key is invalid, expired or revoked |
FORBIDDEN | 403 | Authenticated, but not allowed: wrong role, or blocked by Radar or an action |
ACCOUNT_LOCKED | 403 | The account is locked |
NOT_FOUND | 404 | No such resource in your workspace |
CONFLICT | 409 | It already exists, e.g. a duplicate email or domain |
RATE_LIMITED | 429 | Too many requests; slow down and retry |
INTERNAL | 500 | Something went wrong on our side; retry, then contact support |
Pagination
List endpoints accept page (from 1) and per_page. For example GET /api/v1/users?page=2&per_page=50.
Rate limits
| Calls | Limit |
|---|---|
| Everything, per IP address | 1,000 per minute |
/api/v1/auth/login | 10 per minute per IP |
/api/v1/auth/password/* | 10 per minute per IP |
/api/v1/auth/oauth/* | 30 per minute per IP |
/api/v1/auth/mfa/verify | 5 per 5 minutes per user |
/oauth/token | 60 per minute per IP |
Resources
Paths below are relative to the base URL. Management endpoints need the owner or admin role, or a secret API key, to make changes; viewers can read.
Sign-in
POST
/api/v1/auth/loginSign in with email and passwordPOST
/api/v1/auth/mfa/verifyComplete a two-factor challengePOST
/api/v1/auth/refreshSwap a refresh token for new tokensPOST
/api/v1/auth/logoutEnd the current sessionPOST
/api/v1/auth/sessions/revoke-allEnd all of the caller’s sessionsPOST
/api/v1/auth/password/forgotEmail a password reset linkPOST
/api/v1/auth/password/resetSet a new password with a reset tokenPOST
/api/v1/auth/password/changeChange the caller’s passwordGET
/api/v1/auth/oauth/providersList enabled social providersGET
/api/v1/auth/oauth/{provider}/startStart social sign-inPOST
/api/v1/auth/oauth/exchangeExchange a social sign-in code for tokensGET
/oauth/authorizeOAuth 2.0 authorization (preview)POST
/oauth/tokenOAuth 2.0 token exchangeGET
/.well-known/openid-configurationOIDC discoveryGET
/.well-known/jwks.jsonPublic signing keysTwo-factor devices
GET
/api/v1/mfa/factorsList the caller’s factorsPOST
/api/v1/mfa/factors/totpStart enrolling an authenticator appPOST
/api/v1/mfa/factors/{id}/verifyConfirm an enrollmentDELETE
/api/v1/mfa/factors/{id}Remove a factorUsers and invitations
GET
/api/v1/usersList users; filter with q and statusPOST
/api/v1/usersCreate a userGET
/api/v1/users/{id}Get a userPATCH
/api/v1/users/{id}Update a userDELETE
/api/v1/users/{id}Delete a userGET
/api/v1/users/{id}/rolesList a user’s rolesGET
/api/v1/invitationsList invitationsPOST
/api/v1/invitationsInvite someone by emailPOST
/api/v1/invitations/{id}/resendResend an invitationDELETE
/api/v1/invitations/{id}Revoke an invitationRoles and groups
GET
/api/v1/rolesList rolesPOST
/api/v1/rolesCreate a custom roleDELETE
/api/v1/roles/{id}Delete a custom rolePOST
/api/v1/roles/assignGive a user a role, optionally until a datePOST
/api/v1/roles/revokeTake a role awayGET
/api/v1/groupsList groupsPOST
/api/v1/groupsCreate a groupDELETE
/api/v1/groups/{id}Delete a groupOrganizations and SSO
GET
/api/v1/organizationsList organizationsPOST
/api/v1/organizationsCreate an organizationPATCH
/api/v1/organizations/{id}Update name, domains or SSO settingsDELETE
/api/v1/organizations/{id}Delete an organizationPOST
/api/v1/organizations/portal-linkCreate an Admin Portal linkGET
/api/v1/organizations/{id}/sso-connectionSee submitted SSO detailsGET
/api/v1/idp-attributesList identity provider attributesPOST
/api/v1/idp-attributesCreate a custom attributePATCH
/api/v1/idp-attributes/{key}Switch an attribute on or offApplications
GET
/api/v1/applicationsList applicationsPOST
/api/v1/applicationsRegister an applicationPOST
/api/v1/applications/{id}/rotate-secretIssue a new client secretDELETE
/api/v1/applications/{id}Delete an applicationAccess governance
GET
/api/v1/iga/entitlementsList entitlementsGET
/api/v1/iga/requestsList access requestsPOST
/api/v1/iga/requests/{id}/approveApprove a requestPOST
/api/v1/iga/requests/{id}/denyDeny a requestGET
/api/v1/iga/reviewsList access reviewsGET
/api/v1/iga/reviews/{id}/itemsItems in a reviewSecurity
GET
/api/v1/audit/events/List audit events; filter with event_type and outcomeGET
/api/v1/threat/statsRadar summary for the last 24 hoursGET
/api/v1/threat/scores/recentRecent risk scoresGET
/api/v1/vault/objects/List stored secretsGET
/api/v1/vault/objects/{id}/revealRead a secret’s value (admins)Customization
GET
/api/v1/brandingGet brandingGET
/api/v1/domainsList custom domainsPOST
/api/v1/domains/{id}/verifyCheck a domain’s DNS recordsGET
/api/v1/email-templates/List email templatesPUT
/api/v1/email-templates/{key}Update a templateDevelopers
GET
/api/v1/webhooks/List webhook endpointsPOST
/api/v1/webhooks/Add an endpointGET
/api/v1/webhooks/event-typesList subscribable eventsPOST
/api/v1/webhooks/{id}/testSend a test eventGET
/api/v1/webhooks/{id}/deliveriesRecent deliveriesPOST
/api/v1/webhooks/deliveries/{id}/redeliverSend a delivery againGET
/api/v1/actions/List actionsPOST
/api/v1/actions/{id}/deployDeploy an actionPOST
/api/v1/actions/{id}/testTest an action