Auth Configuration

Update auth configuration

Changed on

Updates the project's auth configuration. Only the fields present in the body are changed.

put/projects/{id}/auth/config

Request

  • Base URL: https://api.volcano.dev
  • URL: https://api.volcano.dev/projects/{id}/auth/config
  • Auth: one of:
    • HTTP bearer
    • HTTP bearer

Path parameters

idstring uuid required

Project ID

Request body

access_token_lifetimeinteger
refresh_token_lifetimeinteger
inactivity_timeoutinteger
max_session_durationinteger
min_password_lengthinteger
require_uppercaseboolean
require_lowercaseboolean
require_numbersboolean
require_special_charsboolean
enable_signupboolean

Master switch for signups across ALL providers

enable_email_passwordboolean

Enable/disable email/password provider

rate_limit_signupinteger
rate_limit_signininteger
rate_limit_token_refreshinteger
cors_allow_credentialsboolean
cors_max_ageinteger
enable_anonymous_signinsboolean
allowed_email_domainsstring[]

Replaces the email domain allowlist. Empty array removes the restriction so any domain can sign up. Entries must be bare domains such as domain1.com and are stored normalized (lowercase, no @ prefix); matching is exact, so subdomains need their own entry. At most 100 entries.

Restricting signups is a SUPERAGENT feature to configure and to enforce: a HOBBY project can only remove the restriction and gets 403 for any other change, and the list it keeps is parked until it upgrades.

allowed_email_domains_mode'disabled' | 'signup' | 'signup_and_signin'

How far allowed_email_domains reaches. signup gates account creation only. signup_and_signin also blocks sign-in for accounts outside the list; switching to it, or narrowing the list while in it, deletes the sessions of every account it locks out. disabled keeps the list without enforcing it.

allow_password_resetboolean
password_reset_timeoutinteger
max_password_historyinteger
require_email_confirmationboolean

Require users to confirm email before sign-in. Can only be true when email_enabled is true.

email_confirmation_timeoutinteger

Email confirmation token expiry in seconds.

auto_link_verified_oauthboolean

Link a verified OAuth identity to an existing confirmed account with the same email instead of returning a conflict. Requires require_email_confirmation to be true.

email_enabledboolean

Enable transactional email sending. Cannot be false while require_email_confirmation is true.

email_from_addressstring
email_from_namestring
smtp_hoststring
smtp_portinteger
smtp_usernamestring
smtp_passwordstring password

Replacement SMTP password. Omit this field to preserve the configured password. The value is encrypted at rest and never returned.

smtp_use_tlsboolean
email_confirmation_subjectstring
email_password_reset_subjectstring
email_password_changed_subjectstring
managed_auth_enabledboolean

Enable or disable managed auth hosted pages for the project.

post_auth_redirect_urlstring

Must be included in allowed_redirect_urls when set.

allowed_redirect_urlsstring[]

Redirect allowlist. Every entry must be a valid http/https URL.

post_logout_redirect_urlstring

Must be included in allowed_redirect_urls when set.

device_verification_urlstring

Optional custom device-authorization verification page. Must be a valid http/https URL (not tied to allowed_redirect_urls). When set, device-code logins return this URL (with user_code) instead of the managed device page. Send an empty string to clear the override.

Example request

{
  "allowed_email_domains": [
    "domain1.com",
    "domain2.com"
  ]
}

Response

Configuration updated

project_idstring uuid
access_token_lifetimeinteger

Access token lifetime in seconds

refresh_token_lifetimeinteger

Refresh token lifetime in seconds

inactivity_timeoutinteger

Force re-login after inactivity (seconds, 0=never)

max_session_durationinteger

Force re-login after duration (seconds, 0=never)

min_password_lengthinteger

Configured minimum password length in Unicode characters.

require_uppercaseboolean
require_lowercaseboolean
require_numbersboolean
require_special_charsboolean
enable_signupboolean

Master switch - allow new user signups via ANY provider

enable_email_passwordboolean

Enable email/password authentication as a provider

rate_limit_signupinteger

Signups per hour per IP

rate_limit_signininteger

Signins per hour per IP

rate_limit_token_refreshinteger

Refreshes per hour per IP

cors_enabledboolean
cors_allowed_originsstring[]
enable_anonymous_signinsboolean

Allow creating users without email/password

allowed_email_domainsstring[]

Email domains allowed to create users in this project. Applies to email/password signup, OAuth/SSO signup, anonymous conversion, and email changes. Empty (the default) allows every domain.

Entries are stored normalized (lowercase, no @ prefix) and match the domain part exactly: domain1.com does not cover mail.domain1.com. Signups from other domains are rejected with 403, and allowed_email_domains_mode decides whether sign-in is covered as well.

The allowlist is a SUPERAGENT feature to configure and to enforce. A downgrade parks it: the domains are still returned here and stop being applied until the project is back on SUPERAGENT.

allowed_email_domains_mode'disabled' | 'signup' | 'signup_and_signin'

How far allowed_email_domains reaches. signup only gates account creation, so accounts that predate the list keep signing in. signup_and_signin also refuses to issue a session to an account whose domain is not listed. disabled keeps the list without enforcing it.

platform_token_ttlinteger

TTL in seconds for platform tokens minted via /auth/platform/exchange

allow_password_resetboolean

Enable forgot password flow

password_reset_timeoutinteger

Recovery token expiry in seconds

max_password_historyinteger

Number of previous passwords to remember (0=disabled)

cors_allow_credentialsboolean

Allow credentials in CORS requests

cors_max_ageinteger

CORS preflight cache duration (seconds)

require_email_confirmationboolean

Require users to confirm email before sign-in. Can only be true when email_enabled is true.

email_confirmation_timeoutinteger

Email confirmation token expiry in seconds.

auto_link_verified_oauthboolean

Link a verified OAuth identity to an existing confirmed account with the same email instead of returning a conflict. Requires require_email_confirmation to be true.

email_enabledboolean

Enable transactional email sending (confirmation, reset, change notifications). Must be true when require_email_confirmation is true.

email_from_addressstring
email_from_namestring
smtp_hoststring
smtp_portinteger
smtp_usernamestring
smtp_password_configuredboolean

Whether an SMTP password is configured. The password itself is never returned.

smtp_use_tlsboolean
email_confirmation_subjectstring
email_password_reset_subjectstring
email_password_changed_subjectstring
managed_auth_enabledboolean

Enables project-hosted managed auth pages.

post_auth_redirect_urlstring

Default redirect target after successful hosted auth.

allowed_redirect_urlsstring[]

Redirect allowlist used to validate post_auth_redirect_url and post_logout_redirect_url.

post_logout_redirect_urlstring

Redirect target after logout from hosted pages.

device_verification_urlstring

Optional override for the device-authorization verification page. When set, POST /auth/device/authorize returns this URL (with the user_code) as verification_uri/verification_uri_complete instead of the built-in managed device page. Lets a CLI surface the project's own RFC 8628 approval page. Empty falls back to the managed page.

Example response

{
  "cors_allowed_origins": [
    "https://myapp.com",
    "http://localhost:3000"
  ],
  "allowed_email_domains": [
    "domain1.com",
    "domain2.com"
  ],
  "device_verification_url": "https://app.acme.com/device"
}

Changes

    • ○

      the endpoint scheme security ProjectAccessToken was added to the API

    • ▲

      added the new path request parameter id

    • ▲

      the request's body type changed from no type to object

    • ▲

      the response's body type changed from no type to object for status

    • ▲

      the response's body type changed from no type to object for status

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the new optional request property

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the required property to the response with the status

    • ○

      added the required property to the response with the status