i've been investigating Zitadel for quite some time and due to backwards compatibility of our product we have to ask Zitadel's API whether data provided by our user in /oauth/token endpoint is correct. Based on that we authenticate user in our product and generate product's token for further purposes.
I've found that there is a Session API that allows me to provide a user name and password when creating a session for that user. However the problem is that it requires IAM user to achieve this. I've tried adjust my yaml file to add "session.write" for ORG_OWNER, but it was not possible to me.
The problem is that IAM user is a global one and we don't want them to see other organizations and my goal would be "only org owner assigned to the specific organization can validate users from this organization only" and I could not find any solution apart from the code change. What are my options here? I can provide local changes that made it work
Continue the conversation
Join the Discord to ask follow-up questions and connect with the community
Z
ZITADEL
ZITADEL - Identity infrastructure, simplified for you.