Thredd Portal overview
Thredd Portal is the main entry point to Thredd services and is the main component that is related to the API Hub; before you can use the API Hub, your organisation must be set up on Thredd Portal and Thredd Secure Framework. These combine several components that enable secure access to Thredd’s resources, using a common identity store.
Thredd Portal provides a number of features, including:
-
Organisation and application management — Organisation Admin users. Manage access for your organisation's applications, edit/add SSO details, create and manage certificates, generate and validate access tokens and certificates, and more.
-
User management — Organisation Admin users. Invite users to onboard to Thredd and manage user roles, permissions, and access, including the option to deactivate and reactivate users.
-
Access to Webhook management in Thredd Portal — for users with the Developer role.
-
Cards and transaction management, and other related functionality — for users with the appropriate roles.
If you currently use Smart Client to manage cards and transactions, then you can continue to use it for these purposes after migrating your organisation and user access management to Thredd Portal.
Identity and Access Management
Thredd Portal provides identity and access management functionality at an organisation, application, and user level. Thredd Portal functions as a Confidential Client, where Thredd's own application infrastructure undertakes authentication and authorisation activity on behalf of the user.
Once a user is registered and has logged in to Thredd Portal, they can access other Thredd services. Thredd Portal also operates behind-the-scenes as an authentication server, enabling a single sign-on journey and access to Thredd's REST APIs.
Thredd Portal also provides access to Thredd's Certificate Authority for setting up and managing certificates to connect to Thredd services, including the REST APIs via API Hub.
To learn more, see Thredd Secure Framework.
Connecting to Thredd Portal
Thredd Portal provides support for multiple roles, with Admin access available to an Organisation Admin. An Organisation Admin user can manage the settings for your organisation's applications, certificates, SSO configuration, and users through Thredd Portal.
This guidance focuses on an Organisation Admin completing the migration to Thredd Portal, and checking the settings for your organisation and users.
Thredd Portal supports the following methods for users to log in to Thredd services:
-
Single Sign-On (SSO) — if your organisation already uses SSO, then Thredd migrates your settings to Thredd Portal.
-
Email address and password — this involves manually adding details for each user in Thredd Portal and sending an invite using its built-in invitation feature.
About Single Sign-On access (optional)
SSO configurations and users and will not be automatically migrated over as part of the migration process. SSO configurations and users will need to be re-added.
Thredd's Secure Framework allows you to optionally use SSO, using SAML (Security Assertion Markup Language) or OIDC (OpenID Connect), to access Thredd services, for example Thredd Portal. This not mandatory but Thredd recommends that your users log in using SSO instead of using a password because it offers the following benefits:
-
An enhanced user experience for users as it removes the hassle of remembering passwords.
-
Companies to save time on maintenance.
-
Reductions in overheads when managing accounts.
-
Enables you to automate user onboarding, where your users can visit the Thredd Portal URL and automatically create their account upon their first successful login.
This enables a Single Sign-On journey by linking your IdP with Thredd's own provision. If you do not use an IdP, Thredd can act as the IdP.
This Single Sign-On journey is involved with:
-
Accessing the organisation and user management features of Thredd Portal for Organisation Admin users, such as creating certificates with Thredd's CA, and the user management functionality to set up access for other users.
-
Accessing the card and transaction management features of Thredd Portal.
-
Managing access behind-the-scenes to the REST API.
Setting up access to Thredd Portal
An Organisation Admin user at your organisation must first register and log in to Thredd Portal before other users within your organisation can access Thredd Portal and other services.
The set up guidance outlines the full process of setting up the Organisation Admin for the first time and setting up additional users. However, an Organisation Admin does not have to invite/add users to register with Thredd Portal straight away. Instead, the Admin can choose to first check the organisation's SSO details (if using SSO), check or create credentials for your client applications, and test access to Thredd REST APIs and API Hub. An Organisation Admin can later return to this step to check access for the organisation's users.
Summary of the steps
The following is a summary of tasks that Thredd completes:
-
Thredd registers your organisation.
-
Thredd registers an Organisation Admin user for your organisation and sends an email inviting them to log in to Thredd Portal.
Thredd registers an Organisation Admin user for your organisation and sends an email inviting them to log in to Thredd Portal.
-
Organisation Admin recreates required SSO configuration settings in the Thredd Portal.
-
Organisation Admin recreates required application and OAuth Client settings in the Thredd Portal.
An Organisation Admin user at your organisation can then complete the following tasks:
-
Log in to Thredd Portal.
-
Manage the SSO settings for your organisation (necessary only if your organisation uses SSO to log in to Thredd services).
-
Manage user access:
-
If using SSO — invite users via your SSO/identity provider to sign in to Thredd Portal.
-
If not using SSO — manually invite users to sign in using the Invite User feature in Thredd Portal via System Admin > User Management.
-
-
Check the roles assigned to users within Thredd Portal, making any changes if necessary.
Set up guides
To learn more about configuring access for your organisation, applications and users in Thredd Portal, see:
- Migrating Single Sign-On access and users to the Thredd platform
- Setting up password login to Thredd Portal
- Understanding Roles
- Understanding Scopes
If your organisation will use Single Sign-On to access Thredd services, make sure that you check your SSO provider settings and make any changes as required.
You can learn more about the cards and transaction management features of Thredd Portal in Thredd Portal Guide: Getting Started.