Airlock as a Service Knowledge Base

Configure your first tenant IAM

The Getting started configuration lets you configure a tenant IAM using predefined template options. This allows you to quickly try different flows and styling options, and to integrate with your application. At any time, you can activate the configuration and test it to get feedback quickly.

Recommendation
We recommend an iterative approach:
For your first tenant IAM, activate the configuration as provided. This allows you to deploy and access a tenant IAM within minutes. Then enhance the configuration step by step, as outlined below.


Integrate with your application

You can connect your tenant IAM to your application using OIDC. To do so, you need the following information:

  • Redirect URI – the URI that users are redirected to after login, whether the login succeeds or fails

  • CORS allowed origins – one or more origins that are allowed to access the tenant IAM from a browser c

  • Client ID – the client ID of your application

  • Client Secret - the client secret used by your application for OIDC authentication

In return, we provide all necessary OIDC credentials and endpoints for the integration into your application code.

Notice
An overview on how OIDC works in general can be found here.


Choose an authentication flow

There are several authentication flows available for your configuration.

Recommendation
We strongly recommend choosing a secure option such as Passkey.

Depending on the selected flow, additional options are available (e.g., the password policy or the email text for an email OTP).


Define how users can onboard or register

You can define whether users can self-register or whether user registration is managed by you in the tenant IAM Adminapp.


Style the tenant IAM Loginapp

The Getting Started configuration lets you apply basic styling to the tenant IAM Loginapp. You can define the supported languages and tone of voice, and configure the logo, favicon, and colors.


Further enhancing your configuration

For more advanced configurations, contact your partner to fine-tune the configuration and add additional flows, styling options, and integrations with other applications and technical clients.