General¶
In the console: Settings › Authentication › General
Where accounts and passwords come from, the rules for passwords, and what new accounts may do.
Directory¶
Authentication Directory¶
External directory used for authentication, or null to use the internal directory.
One of your Directories, chosen from a list. Name in the API: directoryId.
Password Policy¶
Hash Algorithm¶
Password hashing algorithm to use for storing user passwords in the internal directory.
One of: Argon2id (argon2id), Bcrypt (bcrypt), Scrypt (scrypt), Pbkdf2 (pbkdf2). Default: Argon2id. Name in the API: passwordHashAlgorithm.
Min Length¶
Minimum length for user passwords in the internal directory.
A number. Default: 8. Name in the API: passwordMinLength.
Max Length¶
Maximum length for user passwords in the internal directory.
A number. Default: 128. Name in the API: passwordMaxLength.
Min Strength¶
Minimum strength for user passwords in the internal directory, calculated using the zxcvbn algorithm.
One of: Too guessable: risky password. (guesses < 10^3) (zero), Very guessable: protection from throttled online attacks. (guesses < 10^6) (one), Somewhat guessable: protection from unthrottled online attacks. (guesses < 10^8) (two), Safely unguessable: moderate protection from offline slow-hash scenario. (guesses < 10^10) (three), Very unguessable: strong protection from offline slow-hash scenario. (guesses >= 10^10) (four). Default: Safely unguessable: moderate protection from offline slow-hash scenario. (guesses < 10^10). Name in the API: passwordMinStrength.
Default Expiry¶
Default expiration time for user passwords in the internal directory, after which the user will be required to change their password.
A length of time. Name in the API: passwordDefaultExpiry.
Default Roles¶
User Roles¶
Default roles to assign for accounts.
A list. Each one: one of your Roles, chosen from a list. Name in the API: defaultUserRoleIds.
Group Roles¶
Default roles to assign for groups.
A list. Each one: one of your Roles, chosen from a list. Name in the API: defaultGroupRoleIds.
Admin Roles¶
Default roles to assign for administrators.
A list. Each one: one of your Roles, chosen from a list. Name in the API: defaultAdminRoleIds.
Tenant Roles¶
Default roles to assign for tenants in multi-tenant environments.
A list. Each one: one of your Roles, chosen from a list. Name in the API: defaultTenantRoleIds.
App Passwords¶
Max App Passwords¶
The default maximum number of app passwords a user can create.
A number. Default: 5. Name in the API: maxAppPasswords.
Max API Keys¶
The default maximum number of API keys a user can create.
A number. Default: 5. Name in the API: maxApiKeys.