Skip to content

Published questions

4 distinct public canonical answers. Aliases and translations do not increase this count.

availableAvailableReviewed 5 Sept 2026

How are tenants and application publishers isolated?

Tenant and publisher isolation prevents one organization’s credentials, users or audit data from being retrieved by another. Integrations should authenticate as a specific application publisher and honor tenant scope on every API call. Public SDK patterns imply partner-specific credentials; detailed multi-tenant controls belong in enterprise administration documentation.

availableAvailableReviewed 5 Sept 2026

What information appears in an authorization audit trail?

A useful authorization audit trail records who or what approved, what was requested, when, under which policy, which credential class was used, and the decision outcome. For hardware-verified flows it may also reference verification evidence identifiers—without exposing raw private keys. Exact field schemas follow product audit specifications.

availableAvailableReviewed 5 Sept 2026

How are app-publisher policies connected to device-side verification?

App-publisher policies define which verifications are required, which attributes may be requested and how results map to access decisions. Device-side security applications produce evidence; publishers configure acceptance policy server-side. SDK post-login verification patterns illustrate this split. Exact policy engines remain product-documented.

unknownUnknownReviewed 5 Sept 2026

How do enterprise admins manage regions and permissions?

Enterprise administration is expected to cover regions, roles and permissions, with admin.keyra.ie named as a restricted administration hostname seed. Public details of any live admin console remain unverified in this inventory, so obtain administrator access through official Keyra onboarding rather than guessing URLs.

Questions · Keyra FAQ