Identity provider attributes
When a customer connects their identity provider, their IT team maps fields from their directory to yours. This page decides which fields are on that list.
Three kinds of attribute
| Kind | What it is | Where the value appears |
|---|---|---|
| Standard | Core identity fields every connection provides | At the top level of the user profile |
| Predefined | Common HR and directory fields, off until you switch them on | custom_attributes |
| Custom | Fields you invent for your product | custom_attributes |
Standard attributes
| Attribute | Description | Required |
|---|---|---|
idp_id | Unique user ID from the identity provider | Always |
email | The user’s email address | Always |
first_name | First name | Yes |
last_name | Last name | Yes |
name | Full name | Optional, off by default |
idp_id and email are locked on; they are how TrustPort recognises a person.
Predefined attributes
Switch on the ones your product uses, so IT admins know to map them:
addresses, cost_center_name, department_name, display_name, division_name, emails, employee_number, employee_type, employment_start_date, job_title, manager_email, manager_id, manager_name, organization, phone_numbers, username.
Create a custom attribute
- Choose a key
Lowercase letters, digits and underscores, starting with a letter:
security_clearance_level. The key is what your code reads, so pick something you're happy to keep. - Describe it
IT admins see the description while mapping, so say what belongs there and in what format.
What your app receives
The dashboard previews the profile shape for the attributes you have switched on. For example:
{
"idp_id": "00u1a2b3c4",
"email": "ada@acme.com",
"first_name": "Ada",
"last_name": "Obi",
"custom_attributes": {
"department_name": "Engineering",
"job_title": "Staff Engineer",
"security_clearance_level": "2"
}
}