Skip to content

Update tenant authentication policy

Updates sign-in methods, password rules, multi-factor requirements, self-registration, guest access, and session limits through the existing audited tenant authentication service. Requires an idempotency key.

Quire permissions

Required capability: auth/configure.

Credential scopes: tenants:write.

The acting subject must also be allowed to perform this action in the organisation.

PUT
https://your-organisation.quirelms.com/api/v1/tenant_auth_settings

Authorisation

  • apiKeyoptionalHTTP
  • oauth2optionalOAuth 2.0

Header parameters

  • Idempotency-Keystringrequired

    A caller-chosen key making this request safe to retry. A replay of a completed request returns the recorded response with Idempotency-Replayed: true. Reusing a key for a different request is refused.

    maxLength: 255
  • Quire-Versionoptionalstring

    The dated API revision to serve this request at. Omitted, the request is served at the revision the credential was issued against. The response echoes the revision actually applied.

    format: date

Request bodyJSONrequired

  • modeoptionalofforoptionalorrequiredorrequired_for_roles
  • required_rolesoptionalarray ofstring
    maxLength: 100, minLength: 1
  • accepted_acr_valuesoptionalarray ofstring
    maxLength: 300, minLength: 1
  • cookie_cache_secondsoptionalinteger
    maximum: 9007199254740991, minimum: -9007199254740991
  • password_min_lengthoptionalinteger
    maximum: 9007199254740991, minimum: -9007199254740991
  • breach_check_enabledoptionalboolean
  • self_registration_enabledoptionalboolean
  • self_registration_domainsoptionalarray ofstring
    maxLength: 253
  • self_registration_requires_approvaloptionalboolean
  • enabled_methodsoptionalarray ofpasswordormagic_linkorpasskeyorsocialorssoorldap
  • mfa_methodsoptionalarray oftotporemail_otporbackup_code
  • password_require_mixed_caseoptionalboolean
  • password_require_digitoptionalboolean
  • password_require_symboloptionalboolean
  • session_idle_minutesoptionalintegerornull
    2 variants

    One of the following:

    • integer
    • null
  • session_absolute_hoursoptionalintegerornull
    2 variants

    One of the following:

    • integer
    • null
  • max_concurrent_sessionsoptionalintegerornull
    2 variants

    One of the following:

    • integer
    • null
  • guest_access_enabledoptionalboolean

Returns

200

Success.

JSON
  • savedbooleanrequired
  • policyobjectrequired
    19 properties
    • modeofforoptionalorrequiredorrequired_for_rolesrequired
    • required_rolesarray ofstringrequired
    • accepted_acr_valuesarray ofstringrequired
    • cookie_cache_secondsnumberrequired
    • password_min_lengthnumberrequired
    • breach_check_enabledbooleanrequired
    • self_registration_enabledbooleanrequired
    • self_registration_domainsarray ofstringrequired
    • self_registration_requires_approvalbooleanrequired
    • enabled_methodsarray ofpasswordormagic_linkorpasskeyorsocialorssoorldaprequired
    • mfa_methodsarray oftotporemail_otporbackup_coderequired
    • password_require_mixed_casebooleanrequired
    • password_require_digitbooleanrequired
    • password_require_symbolbooleanrequired
    • session_idle_minutesnumber | nullrequired
    • session_absolute_hoursnumber | nullrequired
    • max_concurrent_sessionsnumber | nullrequired
    • guest_access_enabledbooleanrequired

401

The credential is missing, malformed, expired or revoked.

JSON
  • typestringrequired
    format: uri
  • titlestringrequired
  • statusintegerrequired
  • codestringrequired
  • categoryvalidationorauthenticationorauthorizationornot_foundorconflictorprecondition+4 morerequired
  • detailstringrequired
  • request_idstringrequired
  • docs_urlstringrequired
    format: uri
  • errorsoptionalarray ofobject
    3 properties
    • pathstringrequired

      RFC 6901 JSON Pointer into the request body.

    • codestringrequired
    • detailstringrequired
  • retry_afteroptionalinteger | null

403

The credential lacks the scope this operation requires, or the acting subject lacks the capability.

JSON
  • typestringrequired
    format: uri
  • titlestringrequired
  • statusintegerrequired
  • codestringrequired
  • categoryvalidationorauthenticationorauthorizationornot_foundorconflictorprecondition+4 morerequired
  • detailstringrequired
  • request_idstringrequired
  • docs_urlstringrequired
    format: uri
  • errorsoptionalarray ofobject
    3 properties
    • pathstringrequired

      RFC 6901 JSON Pointer into the request body.

    • codestringrequired
    • detailstringrequired
  • retry_afteroptionalinteger | null

409

The request conflicts with the current state, with a previous use of the same idempotency key, or with a concurrent write.

JSON
  • typestringrequired
    format: uri
  • titlestringrequired
  • statusintegerrequired
  • codestringrequired
  • categoryvalidationorauthenticationorauthorizationornot_foundorconflictorprecondition+4 morerequired
  • detailstringrequired
  • request_idstringrequired
  • docs_urlstringrequired
    format: uri
  • errorsoptionalarray ofobject
    3 properties
    • pathstringrequired

      RFC 6901 JSON Pointer into the request body.

    • codestringrequired
    • detailstringrequired
  • retry_afteroptionalinteger | null

422

The request was understood and its content is not valid. errors names each field.

JSON
  • typestringrequired
    format: uri
  • titlestringrequired
  • statusintegerrequired
  • codestringrequired
  • categoryvalidationorauthenticationorauthorizationornot_foundorconflictorprecondition+4 morerequired
  • detailstringrequired
  • request_idstringrequired
  • docs_urlstringrequired
    format: uri
  • errorsoptionalarray ofobject
    3 properties
    • pathstringrequired

      RFC 6901 JSON Pointer into the request body.

    • codestringrequired
    • detailstringrequired
  • retry_afteroptionalinteger | null

429

A rate limit or a concurrency cap was reached. Retry-After says when to try again.

JSON
  • typestringrequired
    format: uri
  • titlestringrequired
  • statusintegerrequired
  • codestringrequired
  • categoryvalidationorauthenticationorauthorizationornot_foundorconflictorprecondition+4 morerequired
  • detailstringrequired
  • request_idstringrequired
  • docs_urlstringrequired
    format: uri
  • errorsoptionalarray ofobject
    3 properties
    • pathstringrequired

      RFC 6901 JSON Pointer into the request body.

    • codestringrequired
    • detailstringrequired
  • retry_afteroptionalinteger | null

500

Something failed at our end. Quote request_id when reporting it.

JSON
  • typestringrequired
    format: uri
  • titlestringrequired
  • statusintegerrequired
  • codestringrequired
  • categoryvalidationorauthenticationorauthorizationornot_foundorconflictorprecondition+4 morerequired
  • detailstringrequired
  • request_idstringrequired
  • docs_urlstringrequired
    format: uri
  • errorsoptionalarray ofobject
    3 properties
    • pathstringrequired

      RFC 6901 JSON Pointer into the request body.

    • codestringrequired
    • detailstringrequired
  • retry_afteroptionalinteger | null
Navigation

Type to search…

↑↓ navigate↵ selectEsc close