Overview
Use AccessGuard session APIs and admin tools to control active customer access after authentication.
Prerequisites
Permissions required
Steps (4)
-
1
Review token/session settings
Configure access-token, refresh, idle, maximum-session, rotation, and security-notification policy.
Tips
Validation
Success criteria
-
2
Authenticate and refresh
Use identity.login followed by identity.token to establish and refresh an AccessGuard-managed session.
Tips
Validation
Success criteria
-
3
Inspect session state
Use introspection and the sessions administration screen to inspect current session/account state.
Tips
Validation
Success criteria
-
4
Revoke access
Revoke one or multiple sessions and verify subsequent refresh/session use follows the revoked state.
Tips
Validation
Success criteria
About this guide
AccessGuard centralizes workspace authentication and customer identity. External websites can use the signed Bridge v2 proxy and JavaScript SDK for registration, login, verification, recovery, token refresh, profile management, protected media, and notification inbox operations.
Inside the workspace, AccessGuard owns users, sessions, verified identities, customer profiles, communication preferences and consent, approval state, KYC documents, risk flags, notification state, audience segments, application operation grants, delegation policies, and trusted context actions. Canonical capabilities are available through Handler and RCP, with selected operations available through Bridge v2.
Configured providers handle downstream delivery and human work: email, SMS, WhatsApp, voice, push, and case/problem operations can be delegated while AccessGuard preserves the identity, authorization, provenance, and customer-policy record.