TrustPortDocs

Base URL

Base URL
https://id.trustportidentity.com

Authentication

Calling asSendUse for
Your backendAuthorization: Bearer sk_live_… (secret API key)Managing your workspace
A signed-in userAuthorization: Bearer <access token>Acting as that person, within their role
Nobody yetX-Tenant-ID: <workspace ID>Sign-in, password reset and other public calls

Responses

Successful responses wrap the result in data. Lists may include meta with a total.

Success
{
  "data": { "id": "…", "email": "ada@example.com" }
}

Errors share one shape. Show message to people; branch on code in your code.

Error
{
  "error": { "code": "FORBIDDEN", "message": "You don't have permission to do this." },
  "meta": { "request_id": "…" }
}

Every response carries an X-Request-ID header. Include it when you contact support.

Error codes

CodeStatusMeaning
BAD_REQUEST400Something in the request is missing or malformed
INVALID_CREDENTIALS401Wrong email or password
UNAUTHORIZED401No valid token or key was sent
INVALID_TOKEN401The token or API key is invalid, expired or revoked
FORBIDDEN403Authenticated, but not allowed: wrong role, or blocked by Radar or an action
ACCOUNT_LOCKED403The account is locked
NOT_FOUND404No such resource in your workspace
CONFLICT409It already exists, e.g. a duplicate email or domain
RATE_LIMITED429Too many requests; slow down and retry
INTERNAL500Something went wrong on our side; retry, then contact support

Pagination

List endpoints accept page (from 1) and per_page. For example GET /api/v1/users?page=2&per_page=50.

Rate limits

CallsLimit
Everything, per IP address1,000 per minute
/api/v1/auth/login10 per minute per IP
/api/v1/auth/password/*10 per minute per IP
/api/v1/auth/oauth/*30 per minute per IP
/api/v1/auth/mfa/verify5 per 5 minutes per user
/oauth/token60 per minute per IP

Resources

Paths below are relative to the base URL. Management endpoints need the owner or admin role, or a secret API key, to make changes; viewers can read.

Sign-in

POST/api/v1/auth/loginSign in with email and password
POST/api/v1/auth/mfa/verifyComplete a two-factor challenge
POST/api/v1/auth/refreshSwap a refresh token for new tokens
POST/api/v1/auth/logoutEnd the current session
POST/api/v1/auth/sessions/revoke-allEnd all of the caller’s sessions
POST/api/v1/auth/password/forgotEmail a password reset link
POST/api/v1/auth/password/resetSet a new password with a reset token
POST/api/v1/auth/password/changeChange the caller’s password
GET/api/v1/auth/oauth/providersList enabled social providers
GET/api/v1/auth/oauth/{provider}/startStart social sign-in
POST/api/v1/auth/oauth/exchangeExchange a social sign-in code for tokens
GET/oauth/authorizeOAuth 2.0 authorization (preview)
POST/oauth/tokenOAuth 2.0 token exchange
GET/.well-known/openid-configurationOIDC discovery
GET/.well-known/jwks.jsonPublic signing keys

Two-factor devices

GET/api/v1/mfa/factorsList the caller’s factors
POST/api/v1/mfa/factors/totpStart enrolling an authenticator app
POST/api/v1/mfa/factors/{id}/verifyConfirm an enrollment
DELETE/api/v1/mfa/factors/{id}Remove a factor

Users and invitations

GET/api/v1/usersList users; filter with q and status
POST/api/v1/usersCreate a user
GET/api/v1/users/{id}Get a user
PATCH/api/v1/users/{id}Update a user
DELETE/api/v1/users/{id}Delete a user
GET/api/v1/users/{id}/rolesList a user’s roles
GET/api/v1/invitationsList invitations
POST/api/v1/invitationsInvite someone by email
POST/api/v1/invitations/{id}/resendResend an invitation
DELETE/api/v1/invitations/{id}Revoke an invitation

Roles and groups

GET/api/v1/rolesList roles
POST/api/v1/rolesCreate a custom role
DELETE/api/v1/roles/{id}Delete a custom role
POST/api/v1/roles/assignGive a user a role, optionally until a date
POST/api/v1/roles/revokeTake a role away
GET/api/v1/groupsList groups
POST/api/v1/groupsCreate a group
DELETE/api/v1/groups/{id}Delete a group

Organizations and SSO

GET/api/v1/organizationsList organizations
POST/api/v1/organizationsCreate an organization
PATCH/api/v1/organizations/{id}Update name, domains or SSO settings
DELETE/api/v1/organizations/{id}Delete an organization
POST/api/v1/organizations/portal-linkCreate an Admin Portal link
GET/api/v1/organizations/{id}/sso-connectionSee submitted SSO details
GET/api/v1/idp-attributesList identity provider attributes
POST/api/v1/idp-attributesCreate a custom attribute
PATCH/api/v1/idp-attributes/{key}Switch an attribute on or off

Applications

GET/api/v1/applicationsList applications
POST/api/v1/applicationsRegister an application
POST/api/v1/applications/{id}/rotate-secretIssue a new client secret
DELETE/api/v1/applications/{id}Delete an application

Access governance

GET/api/v1/iga/entitlementsList entitlements
GET/api/v1/iga/requestsList access requests
POST/api/v1/iga/requests/{id}/approveApprove a request
POST/api/v1/iga/requests/{id}/denyDeny a request
GET/api/v1/iga/reviewsList access reviews
GET/api/v1/iga/reviews/{id}/itemsItems in a review

Security

GET/api/v1/audit/events/List audit events; filter with event_type and outcome
GET/api/v1/threat/statsRadar summary for the last 24 hours
GET/api/v1/threat/scores/recentRecent risk scores
GET/api/v1/vault/objects/List stored secrets
GET/api/v1/vault/objects/{id}/revealRead a secret’s value (admins)

Customization

GET/api/v1/brandingGet branding
GET/api/v1/domainsList custom domains
POST/api/v1/domains/{id}/verifyCheck a domain’s DNS records
GET/api/v1/email-templates/List email templates
PUT/api/v1/email-templates/{key}Update a template

Developers

GET/api/v1/webhooks/List webhook endpoints
POST/api/v1/webhooks/Add an endpoint
GET/api/v1/webhooks/event-typesList subscribable events
POST/api/v1/webhooks/{id}/testSend a test event
GET/api/v1/webhooks/{id}/deliveriesRecent deliveries
POST/api/v1/webhooks/deliveries/{id}/redeliverSend a delivery again
GET/api/v1/actions/List actions
POST/api/v1/actions/{id}/deployDeploy an action
POST/api/v1/actions/{id}/testTest an action
© TrustPort IdentitySomething unclear? Tell us and we'll fix the page.