Authorization servers: Identities
The Identities tab manages local login identities for one hosted authorization-server UUID. External resources do not own local identities and do not show this tab.
Open the tab
| Navigation | Protocols, Authorization Servers, select a hosted resource, Identities |
| Resource link | #tenant={tenantId}&surface=as&instance={authorizationServerId}&tab=users |
| Scope | Customer tenant and selected hosted resource |
Create an identity
Choose Add identity and enter the stable subject plus its identifiers. Email identifiers can be marked primary only when their format is valid. The same provider-qualified identifier cannot identify two live accounts in the authorization server.
Choose an initial credential flow:
- Send activation creates the identity in its pending state and sends the governed account-action email.
- Create manual activation link returns a short-lived link only to an authorized operator. Use this for controlled support flows, not routine onboarding.
- Write a password credential accepts a password once and immediately stores it through the credential or secret authority. Read responses never return the password or its stored representation.
The interface does not place passwords, activation tokens, or secret references into list rows, browser URLs, logs, or audit messages.
Identity state
An identity can be pending, active, suspended, or disabled according to the hosted identity lifecycle. Suspending an identity stops new authentication while retaining its identifiers and audit history. Reactivation is a separate operation and does not silently reset credentials.
Account actions
The row menu exposes actions valid for the current identity state:
- Send or resend activation to a verified primary email.
- Create a manual activation link when the operator has the required permission.
- Send a password-change email to a verified primary email.
- Create a manual password-change link for a controlled support flow.
- Update identifiers and display metadata with revision conflict protection.
- Suspend, reactivate, or delete when dependency and policy checks allow it.
Email operations report delivery state. They do not return the action token. Manual-link operations show the value once and require explicit confirmation because the operator becomes responsible for secure delivery.
Hosted authentication mode
Local identities can authenticate only when the hosted resource uses Local only or Hybrid authentication. Switching to Federated only does not delete identities, but it removes the local route from new authorization transactions. Existing sessions remain subject to normal prompt, maximum-age, client, issuer, and account-state checks.
REST operations
Identity operations are nested below the stable authorization-server UUID:
GET /api/platform/config/v1/tenants/{tenantId}/authorization-servers/{authorizationServerId}/identities
POST /api/platform/config/v1/tenants/{tenantId}/authorization-servers/{authorizationServerId}/identities
GET /api/platform/config/v1/tenants/{tenantId}/authorization-servers/{authorizationServerId}/identities/{identityId}
PATCH /api/platform/config/v1/tenants/{tenantId}/authorization-servers/{authorizationServerId}/identities/{identityId}
DELETE /api/platform/config/v1/tenants/{tenantId}/authorization-servers/{authorizationServerId}/identities/{identityId}
Activation and password-change operations use dedicated subresources. See the Platform Config REST reference for their exact request, response, and permission contracts.