SSO Manager
  • Catalog
  • Users
  • Groups
  • Configuration
  • Directory
  • Plugins
  • Vault
  • Overview
Login
Profile:

Name: {{givenName}} {{sn}}

Email: {{mail}} {{#emailVerified}} Verified{{/emailVerified}}

Phone: {{mobile}} {{#phoneVerified}} Verified{{/phoneVerified}}

Location (Site): {{location}}

LDAP DN: {{dn}}

Home Directory: {{homeDirectory}}

Login Shell: {{loginShell}}

Manager(s): {{#managerUids}}{{.}}{{/managerUids}}

Status: {{#isActive}}Active{{/isActive}} {{#isInactive}}Inactive{{/isInactive}}

Date of Birth: {{dateOfBirth}}

TOS: {{#tosAccepted}}Accepted{{/tosAccepted}} {{#tosNotAccepted}}Pending{{/tosNotAccepted}}

SSH Public Key: {{sshPublicKey}}

Unix User ID: {{uidNumber}}

Unix Group ID: {{gidNumber}}

{{#description}}

Description:
{{description}}

{{/description}}

Joined: {{createTimestamp}} | Edited: {{modifyTimestamp}}

Admin Actions
{{#isActive}} {{/isActive}} {{#isInactive}} {{/isInactive}}
Name Description Actions
{{cn}} {{description}}
Name Address / IP Description Kind
{{name}} ({{slug}}) {{resolvedAddress}} {{description}} {{#metadata.isProduction}}Prod
{{/metadata.isProduction}} {{kind}}{{#metadata.subType}} ({{metadata.subType}}){{/metadata.subType}}
Top Services Used (Last 7 Days)
  • Loading...

Every account gets a personal Unix group (its primary GID) — add other accounts here as supplementary members.

Username Actions
{{uid}}
Edit Profile

Editing {{uid}}

API Tokens

A personal access token lets scripts and services call the SSO management API as you, with your permissions. Treat it like a password.

No API tokens.

{{ name }}
{{ id_short }}
{{ #description }}

{{ description }}

{{ /description }}
Token ID
{{ id_short }}
Created
{{{ created_display }}}
Last used
{{{ last_used_display }}}
Expires
{{{ expires_display }}}
Impersonating
The real password is unchanged. This temporary credential expires automatically.

Expires at — works for any LDAP-backed service.

© 2026 theta42 · MIT License Docs GitHub Terms of Service v1.19.6 (ef2207e)