Pick a resource type.
Connect a tenant
A READ-ONLY admin API token is all TFsmith needs - it physically cannot write to your tenant. The token is encrypted at rest.
From a Machine-to-Machine application authorized for the Auth0 Management API with read-only scopes. TFsmith mints its own short-lived tokens from these - they are encrypted at rest.
Connecting - validating the token and pulling the first export. This can take a minute on a large tenant.
Settings
▸Tenants
Removing a tenant deletes its stored export. Nothing is ever touched on the provider side - the token is read-only.
▸Users
External users keep password sign-in when SSO is required.
An invite emails a set-your-password link (72 hours). Requires email setup below.
Your license includes a single user. The Business tier has unlimited users - upgrade at tfsmith.com.
▸Security
Single sign-on builds its redirect URI and SAML endpoints from this. Set it before configuring SSO - identity providers compare those addresses exactly, and an internal address derived from request headers will not match.
▸Single sign-on (SSO)
Sign in with your identity provider (Okta, Microsoft Entra, Google, Auth0, Authentik...) over OIDC or SAML. People are matched by email; anyone unknown is created at first sign-in with the default role below. Business plan only.
"Required" needs at least one active admin flagged break-glass WITH MFA enabled - the way back in if your identity provider is down. Break-glass sign-ins are called out in the audit log.
Or import our SP metadata XML at the IdP.
SCIM provisioning
Let your IdP create, update and deactivate TFsmith accounts automatically, and push groups you can map to a role. Deactivating someone in your directory disables them here - it never deletes, so the audit trail survives. Works with either sign-in protocol.
▸Push Groups
Groups your identity provider pushes over SCIM. Names and membership are managed in the IdP, not here. Map a group to a role and its members get that role automatically - someone in several mapped groups gets the highest one, and leaving all mapped groups drops them to the SSO default role.
▸Email (SMTP)
Used for user invites, password-reset links, and license expiry warnings. Your own mail server - TFsmith never sends anything anywhere else.
▸License
▸Audit log
Profile
Your administrator requires MFA on every account - enroll below to continue.
Used for password-reset links (and license expiry warnings if you are an administrator). Leave blank to remove.
Change password
Two-factor authentication (TOTP)
Scan with your authenticator app, or enter the secret manually, then confirm with a current code.
Secret:
No tenants yet
Connect your first tenant with a read-only API token and every object becomes exportable Terraform.
Edit tenant
Rename it, correct the base URL, or rotate the API token. Leave the credential fields blank to keep the current one. The provider cannot be changed - connect a new tenant for a different one.
Saving - revalidating against the provider.
