Z
ZITADEL
Z
ZITADEL
Multi tenant app token introspection
Original message was deleted
ZITADEL
Join
ZITADEL - Identity infrastructure, simplified for you.
4,316
Members
View on Discord
F
FFO
•
12/2/24, 8:10 AM
. I guess this is the case since the api app is located inside a different project and organization
.
Yes that sounds valid
, you can send a scope though to include other clients in the token
.
However
, usually I recommend to have all you components
(web
/api
) in the same project
.
Granting access to a tenant could me made work with project
_grants
(like delegating a role to two orgs
, so that they can access the same data
)
F
FFO
•
12/2/24, 8:11 AM
Or you can set orgMetadata so that you app can check these to see that they belong to the same tenant on your end
F
Felix
Thanks for the quick reply. At the moment we are talking about more than 100 ten...
F
FFO
•
12/6/24, 1:24 PM
When you use opaque tokens we provide the info to what org a user belong and what org the users has access right on the introspect endpoint
.
Meaning you can all Zitadel to give you that answer
.