Setting up password login to Thredd Portal

Clients who do not have their own Single Sign-On (SSO)-compliant solution (such as Entra, Google, or Okta) can manually add users and set up their password-based access to Thredd Portal and applications.

An Organisation Admin can set up and manage the settings for your organisation's applications, certificates, and users through Thredd Portal. This guidance assumes that you are the Organisation Admin and need to log in to Thredd Portal for the first time. You can manually add users and set up password-based access when Thredd sends an email to the Organisation Admin user notifying them that it is ready for your organisation to do this.

For best practice, Thredd recommends that you first set up your organisation's access in the test (UAT) environment, so that you can verify that your organisation can use Thredd applications and API endpoints successfully. You can review the user access settings later.

About password (non-SSO) user access

Adding new users who will use a password to access the Thredd platform is a manual process. It requires an Organisation Admin to manually create and invite each individual user via Thredd Portal, which sends an email to users inviting them to log in. Offboarding users is also a manual process, requiring an Organisation Admin users to revoke access for an individual user via Thredd Portal.

As an optional alternative, Thredd recommends that you configure Single Sign-On (SSO) access to Thredd. This enables you to automate user onboarding by using Just-in-Time (JIT) provisioning, where your users can visit the Thredd Portal URL and automatically create their account upon their first successful login. This eliminates the need to manually create and invite users.

Prerequisites

  • You must have the Organisation Admin role for your organisation.

  • You must have received confirmation from Thredd that you can start setting up access for you and your organisation's users.

Step 1. Log in to Thredd Portal for the first time

Once Thredd has completed the initial step of registering your organisation and Organisation Admin user in the platform, it sends an email invitation to the Organisation Admin containing a link to log in to Thredd Portal and set up your access as the Organisation Admin.

You need to refer to the email to log in to Thredd Portal for the first time.

  1. Click on the link in the email for Log in to Thredd Portal. This directs you to the initial access screen.

  2. On the next screen, you must create a new password. The password must be at least eight characters in length. Enter and confirm the new password in the separate fields, and then select the Save and Continue to Thredd Portal button.

When you log in to Thredd Portal, you can set up access for your organisation's users when you are ready.

If the link does not work or you need support, use the link at the bottom of the email to contact Thredd. Do not reply to the email. It is system-generated and sent from a notification-only address that cannot accept incoming emails.

Testing API Hub access using the latest Postman Collection

At this point, you can either choose to:

  • Continue with setting up access for your organisation's users (as per step 2 of this guide). After this, test making API calls using the Postman Collection.

  • Test access to the API Hub first. This involves downloading and configuring the latest Postman Collection to make API calls. You can then return to this guide later to set up access for your organisation's users.

For information about connecting to Thredd REST APIs and using the latest Postman Collection, see Connecting to the REST APIs.

Step 2. Check users and configure roles in the Thredd platform

As a first step, an Organisation Admin should ensure users at your organisation are already registered, and add users if necessary. This ensures that they have access to the Thredd platform.

An Organisation Admin can view the users that are registered for their organisation in Thredd Portal, and complete the following tasks:

  • Manage user access, deactivate or reactivate a user's access to the platform.

  • Assign the appropriate roles and permissions to a user.

  • Edit user details, such as the email address that a user logs in with.

  • Resend invitations to users

While you must manually add and invite users who require access, you can complete this task when you are ready to do so. For example, if you want to first test your organisation's connection to the Thredd platform, such as to REST APIs, and then return to this step.

To view and add users:

  1. Navigate to System Admin and select User Management.

  2. The User Management screen appears, and displays a directory of users by default. If you need to add users, you can do so here.

  3. The Users tab displays a summary of information about each user in the following columns:

    • User ID

    • First Name

    • Last Name

    • Email Address

    • Role - displays all roles assigned to a user, which can be more than one role

    • Status - indicates whether a user is Active or Inactive

    • Last logged in

    • IP Address

The Action column contains the action menu for each user, which you can use to edit the role and permissions for a user.

Adding a new user via User Management

An Organisation Admin user can add, edit and remove users. If only an Organisation Admin user exists then first add an additional Admin user if your organisation requires one. You can either add additional users at the same time or add other users later.

To add a new user:

  1. Select the button to create/add a new user.

  2. Enter the user's first and last names, email address, and assign a role. You can view a list of the roles available to a user under Roles.

    The platform assigns all users a Read-Only role by default which allows view-only access to cards and transactions. You can assign a different role to this if required, and you can also assign more than one role to a user.

  3. Select the role that is most appropriate for the user based on the description:

    • Admin Roles: Admin, Sensitive Information Manager

    • Developer Roles: Developer

    • Cards & Transactions Roles: Cards Operations Specialist, Card Config Manager, Card Balance Manager

    • Read-Only Roles: Read-Only

    To learn more, see Understanding Roles.

  4. When you have entered the user details, review the details and select the option to continue.

  5. The Review and Finish screen appears. If all user details are correct, select Confirm and finish and a message appears to confirm that you have saved the details. To make a change before saving, select Previous step to return to the previous screen.

  6. When you return to the User Management screen, you can check if the new user details have been added successfully.

Repeat the process if you want to add additional users.

Users who will use the cards and transaction management functionality can find information in the Thredd Portal: Cards and Transaction Management Guide.

Editing an existing user profile

An Organisation Admin can add, edit and remove users. To edit the details of a user:

  1. Select the action menu (three dots) for an individual user.

  2. Select Edit User.

  3. The Edit User screen appears and displays the user's name, email address, and the role assigned to the user. You can view a list of the roles available to a user under Roles. The platform assigns all users a Read-Only role by default which allows view-only access to cards and transactions. You can assign a different role to this if required, and you can also assign more than one role to a user.

  4. To change the assigned role, select the role that is most appropriate for the user based on its description:

    • Admin Roles: Admin, Sensitive Information Manager

    • Developer Roles: Developer

    • Cards & Transactions Roles: Cards Operations Specialist, Card Config Manager, Card Balance Manager

    • Read-Only Roles: Read-Only

  5. Select Next.

  6. The Review User Details screen appears. If the role is correct, select Save. To make a change before saving, select Back to return to the Edit User screen.

  7. When you are ready to save the user details, select Save. A message appears to confirm that the user details have been updated successfully.

Deactivating a user will revoke their access to the Thredd platform. If you need to restore access, you can reactivate a user.