Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Is there a way not to have email verification? #367

Open
sosoxuc opened this issue Sep 13, 2024 · 1 comment
Open

Is there a way not to have email verification? #367

sosoxuc opened this issue Sep 13, 2024 · 1 comment

Comments

@sosoxuc
Copy link

sosoxuc commented Sep 13, 2024

Credential Bundle is handed over email, is there any other way?

@r-n-o
Copy link
Contributor

r-n-o commented Sep 16, 2024

@sosoxuc in the case of email auth, email verification is a critical part of the security of this flow (this ensures the end-user receives the bundle and nobody else, to prevent MITM-type attacks)

What kind of flow are you trying to implement? There are other options to add credentials to a user: you can add a programmatic user to a sub-org with a policy which lets it add credentials directly, you can also have users add browser-created creds to their sub-orgs directly, we also recently implemented OAuth which also works with bundles. Turnkey is pretty flexible; the options available really depend on your use case and security profile.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants