Skip to main content
GET
Get authentication configuration

Authorizations

x-app-id
string
header
required

App identifier (App.id, sent as the x-app-id header)

Response

200 - application/json

Authentication configuration retrieved

registration_mode
enum<string>
required
Available options:
OPEN,
INVITE_ONLY,
CLOSED
enable_credentials
boolean
required
oauth_providers
string[]
required
show_kerne_branding
boolean
required

Whether the prebuilt @kerne/react components render "Powered by Kerne". Resolved from the owner's platform_kerne_branding entitlement - true when unconfigured.

brand_primary_color
string | null
required

CSS color value the tenant set for the prebuilt components and hosted portal.

brand_logo_url
string | null
required
portal_redirect_url
string | null
required
portal_url
string | null
required

Where to send an unauthenticated user to actually reach the hosted portal (apps/portal). Null when no portal is deployed for this environment.

post_auth_redirect_url
string | null
required

Where apps/portal hands the session back once auth/billing is done - portal_redirect_url if set, else app_url.

user_registration_limit
number | null
required
app_name
string | null
required
onboarding_dismissed_at
string<date-time> | null
required
access_token_ttl_seconds
number | null
required

Access token TTL in seconds (null = default: 3600s / 1h)

refresh_token_ttl_seconds
number | null
required

Refresh token TTL in seconds (null = default: 604800s / 7d)

overview_metrics
string[]
required

Overview tiles the tenant selected, as BillingStatsDto keys. Empty = never customised, so the dashboard applies its own default set. Filtered server-side against the supported keys.

password_policy
object
required

What the server will accept as a password for this tenant. Public so the prebuilt components can state the rules in the form instead of surfacing them through a rejected submit.