4 distinct public canonical answers. Aliases and translations do not increase this count.
availableAvailableReviewed 5 Sept 2026
Tenant and publisher isolation prevents one organization’s credentials, users or audit data from being retrieved by another. Integrations should authenticate as a specific application publisher and honor tenant scope on every API call. Public SDK patterns imply partner-specific credentials; detailed multi-tenant controls belong in enterprise administration documentation.
availableAvailableReviewed 5 Sept 2026
A useful authorization audit trail records who or what approved, what was requested, when, under which policy, which credential class was used, and the decision outcome. For hardware-verified flows it may also reference verification evidence identifiers—without exposing raw private keys. Exact field schemas follow product audit specifications.
availableAvailableReviewed 5 Sept 2026
App-publisher policies define which verifications are required, which attributes may be requested and how results map to access decisions. Device-side security applications produce evidence; publishers configure acceptance policy server-side. SDK post-login verification patterns illustrate this split. Exact policy engines remain product-documented.
unknownUnknownReviewed 5 Sept 2026
Enterprise administration is expected to cover regions, roles and permissions, with admin.keyra.ie named as a restricted administration hostname seed. Public details of any live admin console remain unverified in this inventory, so obtain administrator access through official Keyra onboarding rather than guessing URLs.