Overview
Use AccessGuard profile media APIs backed by Core secure ingress/download services.
Prerequisites
Permissions required
Steps (4)
-
1
Choose the profile
Resolve the AccessGuard profile that owns the media.
Tips
Validation
Success criteria
-
2
Upload through the secure endpoint
Use profile.upload/profile media APIs so Core SecureUploadService handles file ingress and AccessGuard stores profile/photo metadata.
Tips
Validation
Success criteria
-
3
Set avatar when required
Mark the authorized photo as the profile avatar using the profile media API.
Tips
Validation
Success criteria
-
4
Retrieve protected content
Fetch profile.media/content through the authenticated API/Bridge path backed by SafeDownloadService.
Tips
Validation
Success criteria
About this guide
AccessGuard centralizes workspace authentication and customer identity. External websites can use the signed Bridge v2 proxy and JavaScript SDK for registration, login, verification, recovery, token refresh, profile management, protected media, and notification inbox operations.
Inside the workspace, AccessGuard owns users, sessions, verified identities, customer profiles, communication preferences and consent, approval state, KYC documents, risk flags, notification state, audience segments, application operation grants, delegation policies, and trusted context actions. Canonical capabilities are available through Handler and RCP, with selected operations available through Bridge v2.
Configured providers handle downstream delivery and human work: email, SMS, WhatsApp, voice, push, and case/problem operations can be delegated while AccessGuard preserves the identity, authorization, provenance, and customer-policy record.