TrustPortDocs

Workspace

Your workspace is your own private TrustPort: its users, settings, keys and logs are kept apart from every other customer's. Everything in these guides happens inside one workspace.

Each workspace has an ID. Public calls that happen before anyone is signed in, like sign-in or a password reset, send it in the X-Tenant-ID header so TrustPort knows which workspace the person belongs to. Signed-in calls and API-key calls don't need it; the workspace comes from the token.

Users

A user is a person who can sign in: one of your teammates, or one of your own customers' users. Users have a profile (name, email, username), a status (active or deactivated), their sign-in factors and their roles. See Users and invitations.

Roles and groups

A role describes what someone can do. Three built-in roles control the TrustPort dashboard itself: owner, admin and viewer. You can add your own roles for your product; they are included in each user's sign-in token so your app can act on them. A group collects users so you can manage them together. See Roles and groups.

Organizations

An organization is one of your business customers, such as Acme Corp. It owns one or more email domains (acme.com) and holds that customer's single sign-on connection. Organizations are how you sell to enterprises without building a separate login for each one. See Set up an enterprise customer.

Applications

An application is a product of yours that signs users in through TrustPort, such as your web app or mobile app. Each one gets a client ID, a client secret and a list of approved redirect URIs. See Add sign-in to your app.

Sessions and tokens

When someone signs in, TrustPort starts a session and gives your app two tokens: a short-lived access token that proves who the user is, and a refresh token that gets a new access token without asking for the password again. See Sessions and tokens.

Events

Everything that happens, from a sign-in to a role change, is recorded as an event. Events appear in your audit log and can be sent to your servers as webhooks.

How they fit together

ThingBelongs toExample
WorkspaceYouYour company’s TrustPort
ApplicationWorkspaceYour web app, your admin tool
OrganizationWorkspaceAcme Corp, a customer of yours
DomainOrganizationacme.com
UserWorkspaceada@acme.com
RoleWorkspace, assigned to usersadmin, billing_manager
EventWorkspaceLoginSuccess for ada@acme.com
Not sure whether something is a user problem or an organization problem? If it is about one person, start with Users. If it is about everyone at a customer, start with Organizations.
© TrustPort IdentitySomething unclear? Tell us and we'll fix the page.