Loading…
Velaxe
AccessGuard — Authentication, Customer Identity, Consent, Notifications & App Authorization | Velaxe

AccessGuard

Operate sessions, JWT refresh, introspection, and revocation

Use AccessGuard session APIs and admin tools to control active customer access after authentication.

12 min Intermediate Security Administrator, Application Engineer Updated Aug 23, 2026

Overview

Use AccessGuard session APIs and admin tools to control active customer access after authentication.

Prerequisites

None.

Permissions required

sessions.view sessions.force_logout configure

Steps (4)

Estimated: 12 min
  1. 1

    Review token/session settings

    Security Administrator 3 min Back to top

    Configure access-token, refresh, idle, maximum-session, rotation, and security-notification policy.

    Tips

    —

    Validation

    —

    Success criteria

    —

  2. 2

    Authenticate and refresh

    Application Engineer 3 min Back to top

    Use identity.login followed by identity.token to establish and refresh an AccessGuard-managed session.

    Tips

    —

    Validation

    —

    Success criteria

    —

  3. 3

    Inspect session state

    Security Administrator 3 min Back to top

    Use introspection and the sessions administration screen to inspect current session/account state.

    Tips

    —

    Validation

    —

    Success criteria

    —

  4. 4

    Revoke access

    Security Administrator 3 min Back to top

    Revoke one or multiple sessions and verify subsequent refresh/session use follows the revoked state.

    Tips

    —

    Validation

    —

    Success criteria

    —

About this guide

AccessGuard centralizes workspace authentication and customer identity. External websites can use the signed Bridge v2 proxy and JavaScript SDK for registration, login, verification, recovery, token refresh, profile management, protected media, and notification inbox operations.

Inside the workspace, AccessGuard owns users, sessions, verified identities, customer profiles, communication preferences and consent, approval state, KYC documents, risk flags, notification state, audience segments, application operation grants, delegation policies, and trusted context actions. Canonical capabilities are available through Handler and RCP, with selected operations available through Bridge v2.

Configured providers handle downstream delivery and human work: email, SMS, WhatsApp, voice, push, and case/problem operations can be delegated while AccessGuard preserves the identity, authorization, provenance, and customer-policy record.