Service: Identity
Methods provided by authentication modules
Functions
Objects
IdentityProviderDescription
| Property |
Type |
Description |
| DisplayName |
string |
Provider name to display, e.g., “Microsoft Entra ID”. |
| IconUrl |
string |
URL to an image for usage in the UI. |
| AuthorizeUrl |
string |
URL to the Extension’s authorize endpoint. |
| TokenUrl |
string |
URL to the Extension’s token endpoint. |
| RevokeUrl ≥identity 0.2.1 |
string |
URL to the Extension’s revoke token endpoint. |
| CheckGrantUrl ≥identity 0.2.1 |
string |
URL to the Extension’s check grant endpoint. |
| PublicKeysUrl ≥identity 0.2.1 |
string |
URL to the Extension’s public keys endpoint. |
| PublicKey <identity 0.2.1 |
string |
PEM encoded RSA public key used to verify the signature of JSON Web Tokens issued by the Extension. |
IdentityTokenInfo
| Property |
Type |
Description |
| IsValid |
bool |
Flag indicating whether the token is valid. |
| Expires |
time |
The expiration date of the token. |
| UserId |
string |
The user ID used for login, as specified in the token. |
| UserCode |
string |
The suggested user code, as specified in the token. |
| UserFirstName |
string |
The user’s first name, as specified in the token. |
| UserLastName |
string |
The user’s last name, as specified in the token. |
| UserName <identity 0.2.0 |
string |
The user’s full name, as specified in the token. |
| UserEmail <identity 0.2.0 |
string |
The user’s email, as specified in the token. |
| UserGroup |
string |
The user’s group, as specified in the token. |
| UserProfiles |
string[] |
The user’s profiles, as specified in the token. |
| ProfileMergeMode ≥identity 0.2.1 |
string |
The profile merge mode, as specified in the token. See ProfileMergeMode. |
Enums
ProfileMergeMode ≥identity 0.2.1
| Name |
Value |
Description |
| Internal |
internal |
Only the profiles referenced in the user record are used. |
| InternalExternal |
internalexternal |
Both the profiles referenced in the user record and those referenced by the external identity provider are used. |
| External |
external |
Only profiles referenced by the external identity provider are used. |
Tokens
An authentication module issues access tokens as signed JSON Web Tokens and refresh tokens as reference tokens.
An access token contains the exp claim with the expiry timestamp and additional claims with user-specific information, which are listed in the following table.
| Claim |
Type |
Description |
| id |
string |
Mandatory: The unique identifier of the user. |
| code |
string |
Optional: The code of the user. |
| email <identity 0.2.0 |
string |
Optional: The email of the user. |
| firstname |
string |
Optional: The first name of the user. |
| lastname |
string |
Optional: The last name of the user. |
| name <identity 0.2.0 |
string |
Optional: The full name of the user. |
| group |
string |
Optional: The code of the group the user is a member of. |
| profiles |
string[] |
Optional: Array of profile codes the user has. |
Last modified September 25, 2026