Skip to main content

19 docs tagged with "rbac"

View all tags

AuthZEN Fine-Grained Authorization

cidaas provides fine-grained authorization beyond OAuth2 scopes and group/role restrictions through the OpenID AuthZEN standard. AuthZEN separates policy administration from policy decision and supports attribute-based policies (Rego/OPA), external data via Policy Information Points (PIP), and Relationship-Based Access Control (ReBAC).

Create User

Learn how to create users in cidaas with admin-set passwords, including role requirements, API integration, user flow, and webhook events.

Delete User

Learn how to delete users in cidaas, including scheduled deletion, immediate deletion, GDPR compliance, webhook events, and API integration.

Event Retention

Configure how long changelog and user-activity events are kept in cidaas before they are removed.

Groups Role Restriction

Group Role Restriction in cidaas — control who can log in by verifying group membership and roles, embed hints in the JWT, and validate access at runtime.

Invite User

Learn how to invite users in cidaas, including email templates, invitation states, API integration, and the complete invitation flow.

LDAP/Active Directory Integration

cidaas supports LDAP (Lightweight Directory Access Protocol) and Active Directory for authentication and user synchronization. You can configure cidaas to act as an Identity Provider (IdP) or as a Service Provider (SP).

Permission Management

Permission management in cidaas — scopes, roles, groups, group/role restrictions, AuthZEN, and group selection, configured in Trustdesk.

Register User

Learn how to implement self-service user registration in cidaas, including webfinger user existence checks, invitation-based registration, and the complete registration flow.

Update User Profile Information

Learn how to update user profile information in cidaas, including field permissions, instant email/mobile changes, and API usage.

User Management Overview

cidaas User Management provides capabilities for creating, managing, and organizing user accounts. This guide introduces core concepts and workflows.

User Roles & Groups

To allow and restrict access to the features of your applications, every user must be assigned permissions based on their role (defines what they can do and not do on your app).

User Setup

Configure registration and login field profiles in cidaas (User Setup), link them to applications via user_setup_id, and manage profiles through Trustdesk or the User Setup API.

User Status Management

Learn how to manage user status in cidaas, including status values, transitions, API usage, email templates, and webhooks.

What is the difference between ID Token and Access Token

After an authentication, cidaas approves the correctness of provided information with a token. OAuth2 and OpenID Connect work with different tokens. Either way, cidaas will provide an access token based on OAuth2 standard. The token is built up as a JWT (JSON Web Token), which is essentially a base64-encoded JSON format. Optionally, in a user authentication, cidaas can also provide an ID token, which is based on OIDC standard and also built up as a JWT.