Service: Identity

Methods provided by authentication modules

Functions

ResultName / ParamsComment
IdentityProviderDescriptionidentity.GetProviderDescriptionReturns a description of the identity provider.
IdentityTokenInfoidentity.IntrospectReturns information about the provided token.
TokenstringThe token to introspect.
voididentity.InvalidateInvalidates the token.
TokenstringThe token to invalidate.

Objects

IdentityProviderDescription

Property Type Description
DisplayName string Provider name to display, e.g., “Microsoft Entra ID”.
IconUrl string URL to an image for usage in the UI.
AuthorizeUrl string URL to the Extension’s authorize endpoint.
TokenUrl string URL to the Extension’s token endpoint.
RevokeUrl ≥identity 0.2.1 string URL to the Extension’s revoke token endpoint.
CheckGrantUrl ≥identity 0.2.1 string URL to the Extension’s check grant endpoint.
PublicKeysUrl ≥identity 0.2.1 string URL to the Extension’s public keys endpoint.
PublicKey <identity 0.2.1 string PEM encoded RSA public key used to verify the signature of JSON Web Tokens issued by the Extension.

IdentityTokenInfo

Property Type Description
IsValid bool Flag indicating whether the token is valid.
Expires time The expiration date of the token.
UserId string The user ID used for login, as specified in the token.
UserCode string The suggested user code, as specified in the token.
UserFirstName string The user’s first name, as specified in the token.
UserLastName string The user’s last name, as specified in the token.
UserName <identity 0.2.0 string The user’s full name, as specified in the token.
UserEmail <identity 0.2.0 string The user’s email, as specified in the token.
UserGroup string The user’s group, as specified in the token.
UserProfiles string[] The user’s profiles, as specified in the token.
ProfileMergeMode ≥identity 0.2.1 string The profile merge mode, as specified in the token. See ProfileMergeMode.

Enums

ProfileMergeMode ≥identity 0.2.1

Name Value Description
Internal internal Only the profiles referenced in the user record are used.
InternalExternal internalexternal Both the profiles referenced in the user record and those referenced by the external identity provider are used.
External external Only profiles referenced by the external identity provider are used.

Tokens

An authentication module issues access tokens as signed JSON Web Tokens and refresh tokens as reference tokens. An access token contains the exp claim with the expiry timestamp and additional claims with user-specific information, which are listed in the following table.

Claim Type Description
id string Mandatory: The unique identifier of the user.
code string Optional: The code of the user.
email <identity 0.2.0 string Optional: The email of the user.
firstname string Optional: The first name of the user.
lastname string Optional: The last name of the user.
name <identity 0.2.0 string Optional: The full name of the user.
group string Optional: The code of the group the user is a member of.
profiles string[] Optional: Array of profile codes the user has.
Last modified September 25, 2026