Skip to content

General

In the console: Settings › Authentication › General

Where accounts and passwords come from, the rules for passwords, and what new accounts may do.

Directory

Authentication Directory

External directory used for authentication, or null to use the internal directory.

One of your Directories, chosen from a list. Name in the API: directoryId.

Password Policy

Hash Algorithm

Password hashing algorithm to use for storing user passwords in the internal directory.

One of: Argon2id (argon2id), Bcrypt (bcrypt), Scrypt (scrypt), Pbkdf2 (pbkdf2). Default: Argon2id. Name in the API: passwordHashAlgorithm.

Min Length

Minimum length for user passwords in the internal directory.

A number. Default: 8. Name in the API: passwordMinLength.

Max Length

Maximum length for user passwords in the internal directory.

A number. Default: 128. Name in the API: passwordMaxLength.

Min Strength

Minimum strength for user passwords in the internal directory, calculated using the zxcvbn algorithm.

One of: Too guessable: risky password. (guesses < 10^3) (zero), Very guessable: protection from throttled online attacks. (guesses < 10^6) (one), Somewhat guessable: protection from unthrottled online attacks. (guesses < 10^8) (two), Safely unguessable: moderate protection from offline slow-hash scenario. (guesses < 10^10) (three), Very unguessable: strong protection from offline slow-hash scenario. (guesses >= 10^10) (four). Default: Safely unguessable: moderate protection from offline slow-hash scenario. (guesses < 10^10). Name in the API: passwordMinStrength.

Default Expiry

Default expiration time for user passwords in the internal directory, after which the user will be required to change their password.

A length of time. Name in the API: passwordDefaultExpiry.

Default Roles

User Roles

Default roles to assign for accounts.

A list. Each one: one of your Roles, chosen from a list. Name in the API: defaultUserRoleIds.

Group Roles

Default roles to assign for groups.

A list. Each one: one of your Roles, chosen from a list. Name in the API: defaultGroupRoleIds.

Admin Roles

Default roles to assign for administrators.

A list. Each one: one of your Roles, chosen from a list. Name in the API: defaultAdminRoleIds.

Tenant Roles

Default roles to assign for tenants in multi-tenant environments.

A list. Each one: one of your Roles, chosen from a list. Name in the API: defaultTenantRoleIds.

App Passwords

Max App Passwords

The default maximum number of app passwords a user can create.

A number. Default: 5. Name in the API: maxAppPasswords.

Max API Keys

The default maximum number of API keys a user can create.

A number. Default: 5. Name in the API: maxApiKeys.