# Trivore ID Documentation > Modern solutions for Identity and Access Management This file contains links to documentation sections following the llmstxt.org standard. ## Table of Contents - [How to Use the Change Password Form](https://trivoreid.com/docs/change-password-form.md): Linking to the Change Password form from an external application, and customising its operation and appearance - [Custom Fields (User and Group)](https://trivoreid.com/docs/custom-fields.md): Storing small pieces of application-specific data on User and Group objects, and reading them back via the Management API, filters, or OIDC claims - [UI / OpenID language selection](https://trivoreid.com/docs/language-selection.md): How Trivore ID selects the user interface language during OpenID Connect sign-in - [Locale fields and APIs](https://trivoreid.com/docs/locale-fields.md): Where a user's locale preference is stored, and how it is exposed through OIDC claims and the Management API - [Recommendations for use of ID Service infrastructure in your application stack](https://trivoreid.com/docs/recommendations.md): Recommended ways to use Trivore ID for user registration, sign-in, and backend integration in your application stack - [User Domicile Information](https://trivoreid.com/docs/user-domicile.md): Reading a Finnish user's domicile (home municipality) information via the Management API, UserInfo endpoint, or Management UI - [Developer Guide](https://trivoreid.com/docs/developer-guide.md): Overview of the Developer Guide - the Management API, OpenID Connect, webhooks, and implementation guides for integrating with Trivore ID - [Access Control API](https://trivoreid.com/docs/access-control-api.md): Creating an Access Control object through the Management API and attaching it to an entity that supports it - [API Conventions](https://trivoreid.com/docs/api-conventions.md): Shared Management API conventions - request/response format, pagination, sorting, error responses, and the request logging header - [API documentation](https://trivoreid.com/docs/api-documentation.md): Finding your instance's interactive API documentation and permission and error code references, and authorizing requests in Swagger UI - [Data Storages](https://trivoreid.com/docs/data-storages.md): How Data Storages work, their configuration fields, limitations, and search filter syntax - [File Storage](https://trivoreid.com/docs/file-storage.md): How File Storages work, their access control model, and how to upload and download files through the Management API - [Application Data Persistence and Sharing](https://trivoreid.com/docs/application-data.md): An overview of the ways Trivore ID can store application-specific data, and which method fits which use case - [User Tokens](https://trivoreid.com/docs/user-tokens-api.md): How user tokens work, their limitations, and how to define ACLs to share them between applications - [Authorisations API Usage Examples](https://trivoreid.com/docs/authorisations-api-examples.md): Examples of creating, querying, and managing Authorisation objects through the Management API - [Authorisations](https://trivoreid.com/docs/authorisations.md): How Authorisations model one entity granting another the right to act on its behalf, and how their lifetime and access are controlled - [Suomi.fi Authorisations](https://trivoreid.com/docs/suomifi-authorisations.md): Importing authorisations that users have created in the Suomi.fi service into Trivore ID - [API Client Credentials](https://trivoreid.com/docs/api-client-credentials.md): Registering a Management API client, acquiring and renewing its client ID and secret, and configuring its access - [Client Scopes API](https://trivoreid.com/docs/client-scopes-api.md): Creating custom OIDC scopes and claim mappers through the Management API - [Filtering](https://trivoreid.com/docs/filtering.md): The SCIM-like filter parameter of Management API list endpoints, its operators, and how to find which fields are filterable - [Group Policies API](https://trivoreid.com/docs/group-policies-api.md): Creating and managing Group Policies through the Management API, and how they differ from a namespace's default policy - [Groups API](https://trivoreid.com/docs/groups-api.md): Creating, reading, updating, and deleting Groups through the Management API, including nesting and Group Policy assignment - [Implementing changing of user's email address or mobile number](https://trivoreid.com/docs/change-user-contact-info.md): Implementing a verified change of a user's email address or mobile number with the Management API - [Launch email verification with Management API](https://trivoreid.com/docs/email-verification-with-management-api.md): Sending a user an email verification link through the Management API, optionally using a custom email template - [Generate a Client SDK library for Management API](https://trivoreid.com/docs/generate-client-library.md): Generating a Management API client SDK from its OpenAPI document with SwaggerHub or Swagger CodeGen - [Management API](https://trivoreid.com/docs/management-api.md): Overview of the Management API, the credential types it supports, and where to find the current interactive API documentation - [Email and SMS API](https://trivoreid.com/docs/messaging-api.md): Sending free-form and templated email, and SMS messages, through the Management API - [Namespace API](https://trivoreid.com/docs/namespace-api.md): Creating, reading, updating, and deleting namespaces through the Management API - [Simple Usage Examples](https://trivoreid.com/docs/simple-usage-examples.md): Basic Management API usage with curl - Basic authentication, required headers, and reading error responses - [User API](https://trivoreid.com/docs/user-api.md): Overview of the User API's core operations and the related APIs for managing account data, security, and access - [User API Examples](https://trivoreid.com/docs/user-api-examples.md): Examples of listing, creating, updating, and deleting user accounts through the Management API - [User fields](https://trivoreid.com/docs/user-fields.md): Extended information about restrictions, permissions, and usage of commonly used fields in the User document - ['amr' value](https://trivoreid.com/docs/oidc-amr-value.md): The authentication method values Trivore ID returns in the amr claim of the ID token, with examples - [Management of Applications](https://trivoreid.com/docs/oidc-client-management.md): Using the Client Scope Evaluation tool to work out which scopes an OIDC client needs - [Implementing an OIDC Client for authentication](https://trivoreid.com/docs/oidc-client-implementation.md): Choosing an OAuth 2.0 / OpenID Connect flow for your client, and how each supported flow works with Trivore ID - [Resource Owner Password Flow and Introspect API](https://trivoreid.com/docs/oidc-password-grant.md): Authenticating users with the Resource Owner Password flow and verifying the resulting access tokens with the Introspect API - [Client Registration](https://trivoreid.com/docs/oidc-client-registration.md): Configuring an OIDC client's registration details, compatibility modes, authorisation view customisation, and namespace restrictions - [Adding OAuth2 / OpenID Connect sign-in to a mobile app](https://trivoreid.com/docs/oidc-mobile-app-sign-in.md): Implementing OAuth 2.0 / OpenID Connect sign-in in a mobile app, preferably with Authorization Code Flow with PKCE - [How to create an OpenID Connect client that will allow user registration and user will be logged in after registration](https://trivoreid.com/docs/oidc-client-user-registration.md): Configure an OpenID Connect client so that new users can register and are signed in to your application straight after registration - [Embedding OpenID login page](https://trivoreid.com/docs/oidc-embedding-login-page.md): Embed the Trivore ID sign-in page in an iframe, and configure the Content-Security-Policy frame-ancestors setting to allow it - [Using OIDC Client Credentials to generate an Access Token another service can use to verify your Application](https://trivoreid.com/docs/oidc-client-credentials-token.md): Using the Client Credentials flow to get an access token that a third-party service can verify with Trivore ID - [OpenID Connect](https://trivoreid.com/docs/oidc.md): How Trivore ID acts as an OpenID Connect Provider, and an overview of client registration, flows, scopes, claims, and sign-out - [Requiring Re-authentication](https://trivoreid.com/docs/oidc-re-authentication.md): Forcing an already signed-in user to re-authenticate before accessing a sensitive area of your service - [Scopes and Claims](https://trivoreid.com/docs/oidc-scopes-claims.md): Trivore ID's custom OIDC claims, and where to browse the scopes and claims available on your instance - [Sign-out](https://trivoreid.com/docs/oidc-sign-out.md): Signing users out with RP-initiated logout, and single logout with front-channel and back-channel logout - [Webhooks](https://trivoreid.com/docs/webhooks.md): How and when Trivore ID sends webhook calls, and the structure of a webhook request - [Entity Access Control](https://trivoreid.com/docs/entity-access-control.md): How predefined Access Control Lists let a subset of entities restrict access more finely than roles and permissions alone - [Access Management](https://trivoreid.com/docs/access-management-intro.md): How role-based access control, groups, and entity-level access control lists govern who can do what in Trivore ID - [Role-Based Access Control (RBAC)](https://trivoreid.com/docs/role-based-access-control.md): How roles, permissions, and groups combine to control what each user and Management API Client can do - [Frequently Asked Questions](https://trivoreid.com/docs/faq.md): Frequently asked questions, such as whether new User fields can be added and when to use Custom Fields instead - [Trivore ID](https://trivoreid.com/docs.md): What Trivore ID is, the features it gives you out of the box, and where to find the rest of the documentation - [OpenID Connect](https://trivoreid.com/docs/openid-connect-intro.md): Trivore ID as an OpenID Connect provider - sign-in, single sign-on, self-service registration, and identity verification for your apps - [DVV Muutostietopalvelu Support Module](https://trivoreid.com/docs/dvv-muutostietopalvelu.md): How the optional DVV Muutostietopalvelu module keeps User LegalInfo data in sync with Finland's population register - [MyData Solution](https://trivoreid.com/docs/mydata-solution.md): How the optional MyData Solution integrates personal data from an organisation's back-end systems into Trivore ID's self-service data access - [Trivore ID 5 changelog](https://trivoreid.com/docs/release-notes-5.md): Changelog for all Trivore ID 5.x releases - [Trivore ID 6 changelog](https://trivoreid.com/docs/release-notes-6.md): Changelog for Trivore ID 6.x releases, the current production-ready major version - [Release notes](https://trivoreid.com/docs/release-notes.md): Where to find release notes for current and archived Trivore ID versions - [Important Upgrade Notes](https://trivoreid.com/docs/upgrade-notes.md): Version-specific instructions and breaking changes to review before upgrading a Trivore ID installation - [Groups and Group Policies](https://trivoreid.com/docs/groups-intro.md): How Groups, Group Policies, and the namespace default policy work together to manage user accounts in bulk - [User Management](https://trivoreid.com/docs/user-management-intro.md): An overview of user accounts in Trivore ID — account types, their lifecycle, and how groups, policies, and identification tie into them - [Invite User Accounts via Email](https://trivoreid.com/docs/invites.md): How to invite new user accounts by email, via the Management API or the Management UI - [Strong Identification Explained](https://trivoreid.com/docs/strong-identification.md): The strong identification methods Trivore ID supports, the Level of Assurance concept, and the API resources for querying identification data - [Initiating Interactive Strong Identification (suomi.fi-tunnistus)](https://trivoreid.com/docs/strong-identification-initiating.md): How to generate and use an interactive strong identification URL for suomi.fi-tunnistus - [Dashboard](https://trivoreid.com/docs/dashboard.md): The Dashboard main menu item, an overview of system state and a hub of self-service shortcuts - [Getting Started](https://trivoreid.com/docs/getting-started.md): Orientation for the Trivore ID Management UI — screen layout, the Dashboard, and a reference for menu items not covered elsewhere - [Navigating the UI](https://trivoreid.com/docs/navigating-the-ui.md): An overview of the Trivore ID Management UI screen layout — Top Bar, Main Menu, Personal Menu, and Main Pane - [Other Main Menu Items](https://trivoreid.com/docs/other-menu-items.md): Reference for the Main Menu items not covered by their own dedicated page - [Management](https://trivoreid.com/docs/management.md): Overview of administering Trivore ID - navigating the UI, system configuration, user directories, and other management topics - [Custom OIDC Scopes](https://trivoreid.com/docs/custom-oidc-scopes.md): How to create custom OIDC client scopes and mappers, and enable them on an OIDC client - [Email templates](https://trivoreid.com/docs/email-templates.md): Reusable, localised email messages with dynamic content, editable in the Management UI or managed as JSON - [External Permissions](https://trivoreid.com/docs/external-permissions.md): How External Permissions work, how to define and organise them, and how to grant, revoke, and query them via the console and the Management API - [Integrations](https://trivoreid.com/docs/integrations.md): Ways external systems connect to and integrate with Trivore ID — federated sign-in, SSO, custom OIDC scopes, external permissions, and LDAP - [LDAP Server](https://trivoreid.com/docs/ldap-server.md): How to enable and configure the built-in read-only LDAP server, including per-namespace scoping and the Cisco LDAP extension - [Creating SSO targets](https://trivoreid.com/docs/sso-targets.md): Configuring SSO targets in the Management UI - [Example source code](https://trivoreid.com/docs/sso-example-code.md): Reference Java implementations for both SSO mechanisms - [Distributed Single Sign-On and Single Sign-Out](https://trivoreid.com/docs/single-sign-on.md): How distributed Single sign-on (SSO) and Single sign-out work in Trivore ID, and where to find the setup guides for each SSO mechanism - [Management API mechanism](https://trivoreid.com/docs/sso-via-management-api.md): How an SSO target consumes an sso-token via the Management API, with an example request and response - [OpenID Connect mechanism for SSO](https://trivoreid.com/docs/sso-via-oidc.md): How an SSO target consumes an sso-token via OpenID Connect, with a full walkthrough between two example client sites - [Suomi.fi-tunnistus IdP SAML Metadata Change](https://trivoreid.com/docs/suomifi-tunnistus-metadata-change.md): Updating a Suomi.fi-tunnistus user directory's IdP SAML metadata when DVV rotates its certificates - [Configure AD FS User Directory](https://trivoreid.com/docs/user-directory-adfs.md): How to configure an Active Directory Federation Services (AD FS) user directory - [Advanced Features](https://trivoreid.com/docs/user-directories-advanced.md): Linking multiple user directories to one account, on-demand account creation via suomi.fi-tunnistus, and direct-to-directory redirects - [Configure Azure AD User Directory](https://trivoreid.com/docs/user-directory-azure-ad.md): How to configure an Azure AD / Entra ID user directory, including group import - [Common User Directory Settings](https://trivoreid.com/docs/user-directory-common-settings.md): Settings shared by every user directory type — display options, login translations, user and group attribute mapping - [How-to: Entra ID](https://trivoreid.com/docs/entra-id-howto.md): Step-by-step guide to registering an application in Azure / Entra ID for Trivore ID authentication - [How-to: Multi-Tenant Entra ID](https://trivoreid.com/docs/entra-id-multitenant-howto.md): How to configure multi-tenant Entra ID authentication so users from multiple external tenants can sign in through a single Trivore ID user directory - [How-to: Smartcard](https://trivoreid.com/docs/smartcard-howto.md): How to configure smart card (mTLS client certificate) based authentication for Trivore ID - [How-to: Suomi.fi](https://trivoreid.com/docs/suomi-fi-directory-howto.md): Step-by-step guide to configuring Suomi.fi-tunnistus authentication in Trivore ID and registering the e-service with Suomi.fi - [User Directories](https://trivoreid.com/docs/user-directories.md): How external user directories work in Trivore ID, which types are supported, and where to find settings shared across all of them - [User Directory Login Requirements](https://trivoreid.com/docs/user-directory-login-requirements.md): Restricting sign-in via a user directory based on attribute values, such as group membership - [Configure MPASSid User Directory](https://trivoreid.com/docs/user-directory-mpassid.md): How to configure an MPASSid user directory for the Finnish education sector - [Configure OP Identity Service Broker User Directory](https://trivoreid.com/docs/user-directory-op.md): How to configure an OP Identity Service Broker user directory, including the technical information OP requires - [Common SAML User Directory Settings](https://trivoreid.com/docs/user-directory-saml.md): Settings shared by all SAML-based user directories — AD FS, generic SAML, and Suomi.fi - [Configure Suomi.fi User Directory (Finland only)](https://trivoreid.com/docs/user-directory-suomi-fi.md): How to configure the Suomi.fi-tunnistus user directory for Finnish governmental strong identification and sign-in - [Configure Trivore ID User Directory](https://trivoreid.com/docs/user-directory-trivore-id.md): How to configure a Trivore ID user directory that federates sign-in from another Trivore ID instance - [Hiding Namespace Info from Password Reset](https://trivoreid.com/docs/hiding-namespace-info-from-password-reset.md): Hide the namespace name from the /resetPassword new-password entry view via a Group Policy setting - [Namespace Management](https://trivoreid.com/docs/namespace-management.md): Managing namespaces (tenants) — configuration, initial setup, and namespace-level policies - [Namespaces](https://trivoreid.com/docs/namespaces.md): Managing tenants (namespaces) and their configuration - [Setup Tasks for a New Namespace](https://trivoreid.com/docs/namespace-setup-checklist.md): Recommended initial configuration steps for a new namespace - [Base Settings](https://trivoreid.com/docs/base-settings.md): Core platform settings — service address, sign-in and sign-out behavior, CORS, and the strong identification and account-linking endpoints - [Branding](https://trivoreid.com/docs/branding.md): Software, licensee, and logo branding, message template wrappers, and redirect page styling - [Email](https://trivoreid.com/docs/email-settings.md): Configuring email gateways for outgoing messages - [Event Log Item Expiration Example](https://trivoreid.com/docs/event-log-expiration-example.md): A worked example of how Event Log life-time classes determine when entries expire - [Event Log](https://trivoreid.com/docs/event-log.md): How Event Log (audit trail) works in Trivore ID — retention settings, severity levels, and where to view and export log entries - [Event Log Item Life-Time Base-Line Usage Guidelines](https://trivoreid.com/docs/event-log-lifetime-usage.md): Recommended Event Log retention periods by industry — enterprise, governmental, healthcare, and finance/insurance use - [System Management](https://trivoreid.com/docs/system-management.md): System-wide settings affecting all namespaces — platform configuration, branding, communication, maintenance, and other system-wide management tasks - [Longer data retention in InfluxDB 1.8, Grafana](https://trivoreid.com/docs/influxdb-data-retention.md): Configuring longer InfluxDB data retention and Continuous Queries, and updating Grafana panels to use them - [Maintenance](https://trivoreid.com/docs/maintenance-settings.md): Maintenance mode, database and metrics tooling, log viewing, JVM diagnostics, and post-update tools - [New Namespace Defaults](https://trivoreid.com/docs/new-namespace-defaults.md): Default settings and Group Policies applied to newly created namespaces - [Scheduled Tasks](https://trivoreid.com/docs/scheduled-tasks.md): Viewing, scheduling, manually running, and checking the logs of Trivore ID's automatic maintenance tasks - [SMS](https://trivoreid.com/docs/sms-settings.md): Configuring SMS sending for the platform — gateways, routing plans, and namespace-level settings - [Support](https://trivoreid.com/docs/support-settings.md): Automated uptime, health, and problem report configuration, a password hash generator, and the Event Log event type reference - [Translating Content](https://trivoreid.com/docs/translating-content.md): How to customise system-wide UI text strings using the Translations main menu item - [Web Themes](https://trivoreid.com/docs/web-themes.md): Customising the layout and styling of end-user-facing pages with Web Themes, distinct from simple CSS-only Branding Styles - [User-interface styling](https://trivoreid.com/docs/web-themes-ui-styling.md): Customising end-user-facing pages with CSS stylesheets — managing them, available CSS classes, and migrating from Trivore ID 5 to 6 - [Accounts](https://trivoreid.com/docs/accounts.md): Managing user accounts — creating, editing, filtering, and the bulk actions available for them - [Email Address and Mobile Number Verification During Authentication](https://trivoreid.com/docs/email-verification-during-auth.md): Requiring or suggesting that a user verify their email address or mobile number before or during OpenID Connect sign-in - [GDPR](https://trivoreid.com/docs/gdpr.md): How GDPR personal data requests (data retrieval, correction, erasure, and processing restriction) work in Trivore ID - [Group Policies](https://trivoreid.com/docs/group-policies.md): How the namespace default policy and Group Policies control account-level settings such as MFA requirements, session timeouts, and UI language - [Groups](https://trivoreid.com/docs/groups.md): Managing groups, group membership, and the settings available in the Group editor - [User Management](https://trivoreid.com/docs/user-management.md): Managing user accounts — access control building blocks, authentication, account lifecycle, and consent/compliance - [Last Activity](https://trivoreid.com/docs/last-activity.md): How Trivore ID tracks each account's last-activity time, where to view it, and how to read or update it via the REST API - [Locking User Accounts](https://trivoreid.com/docs/account-locking.md): Why and how user accounts get locked, and how administrators can lock, unlock, and inspect locks via the Management UI or REST API - [Multi-Factor Authentication (MFA)](https://trivoreid.com/docs/mfa.md): How MFA works in Trivore ID, and configuring required or allowed methods with the default policy and Group Policies - [Native App Associations](https://trivoreid.com/docs/passkey-native-apps.md): How to configure Trivore ID to host the Digital Asset Links and Apple App Site Association files required by a native Android or iOS authenticator app - [Passkey Configuration](https://trivoreid.com/docs/passkey-authentication.md): How to configure Passkey (WebAuthn) authentication in Trivore ID - [Password Reset](https://trivoreid.com/docs/password-reset.md): How the self-service password reset form works, how to link to it directly, and where its behavior is configured - [Password Tasks](https://trivoreid.com/docs/password-tasks.md): Password-related tasks that aren't part of daily routine, such as password change and recovery via direct URL, and password expiration behavior - [Import and Create Prepared User Accounts](https://trivoreid.com/docs/prepared-user-accounts.md): Pre-creating partially-known user accounts by importing them from an external system before the user's first sign-in - [Roles](https://trivoreid.com/docs/roles.md): Managing Custom Roles and the permissions they grant, and how System Roles differ from them - [Tags](https://trivoreid.com/docs/account-tags.md): How to tag user accounts for lightweight grouping, and manage tags via the Management UI or REST API - [User agreements](https://trivoreid.com/docs/user-agreements.md): Defining Terms and Conditions, Privacy Policy, and other agreements users must accept, customisable per namespace - [User Registration](https://trivoreid.com/docs/user-registration.md): How new users can create their own account from the OpenID Connect sign-in view, via an integrated or an external registration form