> For the complete documentation index, see [llms.txt](https://fusionauth.io/docs/llms.txt)

# Search for Tenants

API documentation for the FusionAuth Search for Tenants API.

# Search for Tenants

version

This API has been available since 1.45.0

This API is used to search for Tenants and may be called using the `GET` or `POST` HTTP methods. Examples of each are provided below. The `POST` method is provided to allow for a richer request object without worrying about exceeding the maximum length of a URL. Calling this API with either the `GET` or `POST` HTTP method will provide the same search results given the same query parameters.

**Note:** API key authentication must be made using a global API key. The request may not contain the `X-FusionAuth-TenantId` request header. Requests made using an API key scoped to a specific tenant, or containing the `X-FusionAuth-TenantId` request header will fail with a `401` status code.

## Request

[!Global API Key Authentication](https://fusionauth.io/docs/apis/authentication.md#global-api-key-authentication)

Search for Tenants

GET/api/tenant/search?name={name}

### Request Parameters

`name`Stringoptional

The case-insensitive string to search for in the Tenant name. This can contain wildcards using the asterisk character (`*`). If no wildcards are present, this parameter value will be interpreted as `*value*`.

`numberOfResults`IntegeroptionalDefaults to 25

The number of results to return from the search.

`orderBy`StringoptionalDefaults to name ASC

The database field to order the search results as well as an order direction.

The possible values are:

*   `id` - the unique Id of the Tenant
*   `insertInstant` - the [instant](https://fusionauth.io/docs/reference/data-types.md#instants) when the Tenant was created
*   `name` - the Tenant name

The order direction is optional. Possible values of the order direction are `ASC` or `DESC`. If omitted, the default sort order is `ASC`.

For example, to order the results by the insert instant in a descending order, use `insertInstant DESC`.

`startRow`IntegeroptionalDefaults to 0

The offset into the total results. In order to paginate the results, increment this value by the **numberOfResults** for subsequent requests.

For example, if the total search results are greater than the page size designated by **numberOfResults**, set this value to `25` to retrieve results `26-50`, assuming the default page size.

[!Global API Key Authentication](https://fusionauth.io/docs/apis/authentication.md#global-api-key-authentication)

Search for Tenants

POST/api/tenant/search

OpenAPI Spec

When calling the API using a `POST` request you will send the search criteria in a JSON request body.

### Request Body

`search.name`Stringoptional

The case-insensitive string to search for in the Tenant name. This can contain wildcards using the asterisk character (`*`). If no wildcards are present, this parameter value will be interpreted as `*value*`.

`search.numberOfResults`IntegeroptionalDefaults to 25

The number of results to return from the search.

`search.orderBy`StringoptionalDefaults to name ASC

The database field to order the search results as well as an order direction.

The possible values are:

*   `id` - the unique Id of the Tenant
*   `insertInstant` - the [instant](https://fusionauth.io/docs/reference/data-types.md#instants) when the Tenant was created
*   `name` - the Tenant name

The order direction is optional. Possible values of the order direction are `ASC` or `DESC`. If omitted, the default sort order is `ASC`.

For example, to order the results by the insert instant in a descending order, use `insertInstant DESC`.

`search.startRow`IntegeroptionalDefaults to 0

The offset into the total results. In order to paginate the results, increment this value by the **numberOfResults** for subsequent requests.

For example, if the total search results are greater than the page size designated by **numberOfResults**, set this value to `25` to retrieve results `26-50`, assuming the default page size.

*Example JSON Request*

```json
{
  "search": {
    "name": "Playtronics",
    "numberOfResults": 10,
    "orderBy": "insertInstant",
    "startRow": 0
  }
}
```

## Response

The response for this API contains the Tenants matching the search criteria in paginated format.

*Response Codes*

| Code | Description |
| --- | --- |
| 200 | The request was successful. The response will contain a JSON body. |
| 400 | The request was invalid and/or malformed. The response will contain an [Errors](https://fusionauth.io/docs/apis/errors.md) JSON Object with the specific errors. This status will also be returned if a paid FusionAuth license is required and is not present. |
| 401 | You did not supply a valid Authorization header. The header was omitted, your API key was not valid, your API key is scoped to a single tenant, or the request contains a \`X-FusionAuth-TenantId\` header. The response will be empty. See <a href='/docs/apis/authentication'>Authentication</a>. |
| 500 | There was an internal error. A stack trace is provided and logged in the FusionAuth log files. The response will be empty. |

### Response Body

`tenants`Array

The list of Tenant objects.

`tenants[x].accessControlConfiguration.uiIPAccessControlListId`UUIDAvailable since 1.30.0

The Id of the [IP Access Control List](https://fusionauth.io/docs/apis/ip-acl.md) limiting access to this all applications in this tenant.

`tenants[x].baseURL`StringAvailable since 1.68.0

The default base URL used when rendering links in templates for this Tenant. This value is used when `application.baseURL` is not defined.

`tenants[x].captchaConfiguration.captchaMethod`StringAvailable since 1.30.0

The type of captcha method to use.

`tenants[x].captchaConfiguration.enabled`BooleanAvailable since 1.30.0

Whether captcha configuration is enabled.

`tenants[x].captchaConfiguration.secretKey`StringAvailable since 1.30.0

The secret key for this captcha method.

`tenants[x].captchaConfiguration.siteKey`StringAvailable since 1.30.0

The site key for this captcha method.

`tenants[x].captchaConfiguration.threshold`FloatAvailable since 1.30.0

The numeric threshold which separates a passing score from a failing one. This value only applies if using either the Google v3 or HCaptcha Enterprise method, otherwise this value is ignored.

`tenants[x].configured`Boolean

Indicates the tenant has been configured. It is always `true`, except for default tenant when the setup wizard has not been completed, in which case it is `false`.

`tenants[x].connectorPolicies`ArrayAvailable since 1.18.0

A list of Connector policies. Users will be authenticated against Connectors in order. Each Connector can be included in this list at most once and must exist.

`tenants[x].connectorPolicies[x].connectorId`UUIDAvailable since 1.18.0

The identifier of the Connector to which this policy refers.

`tenants[x].connectorPolicies[x].domains`StringAvailable since 1.18.0

An list of email domains to which this connector should apply.

A value of `["*"]` indicates this connector applies to all users.

`tenants[x].connectorPolicies[x].migrate`BooleanAvailable since 1.18.0

If true, the user's data will be migrated to FusionAuth at first successful authentication; subsequent authentications will occur against the FusionAuth datastore. If false, the Connector's source will be treated as authoritative.

`tenants[x].data`Object

An object that can hold any information about the Tenant that should be persisted.

`tenants[x].emailConfiguration.additionalHeaders`Array<Object>optionalAvailable since 1.32.0

The additional SMTP headers to be added to each outgoing email. Each SMTP header consists of a name and a value.

`tenants[x].emailConfiguration.debug`BooleanoptionalDefaults to falseAvailable since 1.37.0

Determines if debug should be enabled to create an event log to assist in debugging SMTP errors.

`tenants[x].emailConfiguration.defaultFromEmail`StringoptionalAvailable since 1.16.0

The default email address that emails will be sent from when a from address is not provided on an individual email template. This is the address part email address (i.e. Jared Dunn `jared@piedpiper.com`).

`tenants[x].emailConfiguration.defaultFromName`StringoptionalAvailable since 1.16.0

The default From Name used in sending emails when a from name is not provided on an individual email template. This is the display name part of the email address ( i.e. **Jared Dunn** `jared@piedpiper.com`).

`tenants[x].emailConfiguration.emailUpdateEmailTemplateId`UUIDoptionalAvailable since 1.30.0

The Id of the Email Template used to send emails to users when their email address is updated.

`tenants[x].emailConfiguration.emailVerifiedEmailTemplateId`UUIDoptionalAvailable since 1.19.0

The Id of the Email Template used to notify a user that their email address has been verified.

`tenants[x].emailConfiguration.forgotPasswordEmailTemplateId`UUIDoptionalAvailable since 1.19.0

The Id of the Email Template that is used when a user is sent a forgot password email.

`tenants[x].emailConfiguration.host`StringoptionalDefaults to localhostAvailable since 1.8.0

The host name of the SMTP server that FusionAuth will use.

Prior to version `1.28.0` this value was required.

`tenants[x].emailConfiguration.implicitEmailVerificationAllowed`optionalDefaults to trueAvailable since 1.32.0

When set to `true`, this allows email to be verified as a result of completing a similar email based workflow such as change password. When set to `false`, the user must explicitly complete the email verification workflow even if the user has already completed a similar email workflow such as change password.

`tenants[x].emailConfiguration.loginIdInUseOnCreateEmailTemplateId`UUIDoptionalAvailable since 1.30.0

The Id of the Email Template used to send emails to users when another user attempts to create an account with their login Id.

`tenants[x].emailConfiguration.loginIdInUseOnUpdateEmailTemplateId`UUIDoptionalAvailable since 1.30.0

The Id of the Email Template used to send emails to users when another user attempts to update an existing account to use their login Id.

`tenants[x].emailConfiguration.loginNewDeviceEmailTemplateId`UUIDoptionalAvailable since 1.30.0

The Id of the Email Template used to send emails to users when they log in on a new device.

`tenants[x].emailConfiguration.loginSuspiciousEmailTemplateId`UUIDoptionalAvailable since 1.30.0

The Id of the Email Template used to send emails to users when a suspicious login occurs.

`tenants[x].emailConfiguration.passwordlessEmailTemplateId`UUIDoptionalAvailable since 1.19.0

The Id of the Passwordless Email Template, sent to users when they start a passwordless login.

`tenants[x].emailConfiguration.passwordResetSuccessEmailTemplateId`UUIDoptionalAvailable since 1.30.0

The Id of the Email Template used to send emails to users when they have completed a 'forgot password' workflow and their password has been reset.

`tenants[x].emailConfiguration.passwordUpdateEmailTemplateId`UUIDoptionalAvailable since 1.30.0

The Id of the Email Template used to send emails to users when their password has been updated.

`tenants[x].emailConfiguration.port`IntegeroptionalDefaults to 25Available since 1.8.0

The port of the SMTP server that FusionAuth will use.

Prior to version `1.28.0` this value was required.

`tenants[x].emailConfiguration.properties`StringoptionalAvailable since 1.8.0

Custom SMTP configuration properties that may be necessary in some cases. This can contain any Java mail property. It will override anything FusionAuth sets by default.

The following property has a default value:

*   `mail.smtp.ssl.protocols` has a default value of `TLSv1 TLSv1.1 TLSv1.2`.

Since version `1.44.0`, the following two properties have default values:

*   `mail.smtp.timeout` has a default value of `2000`.
*   `mail.smtp.connectiontimeout` has a default value of `2000`.

Here's an example value which overrides these properties; in this case setting both timeout defaults to 5 seconds.

```plaintext
mail.smtp.timeout=5000\nmail.smtp.connectiontimeout=5000
```

`tenants[x].emailConfiguration.security`StringoptionalDefaults to NONEAvailable since 1.8.0

The type of security protocol FusionAuth will use when connecting to the SMTP server. The possible values are:

*   `NONE` - no security will be used. All communications will be sent plaintext.
*   `SSL` - SSL will be used to connect to the SMTP server. This protocol is not recommended unless it is the only one your SMTP server supports.
*   `TLS` - TLS will be used to connect to the SMTP server. This is the preferred protocol for all SMTP servers.

`tenants[x].emailConfiguration.setPasswordEmailTemplateId`UUIDoptionalAvailable since 1.19.0

The Id of the Email Template that is used when a user had their account created for them and they must set their password manually and they are sent an email to set their password.

`tenants[x].emailConfiguration.twoFactorMethodAddEmailTemplateId`UUIDoptionalAvailable since 1.30.0

The Id of the Email Template used to send emails to users when a MFA method has been added to their account.

`tenants[x].emailConfiguration.adminTwoFactorMethodRemoveEmailTemplateId`UUIDoptionalAvailable since 1.68.0

The Id of the Email Template used to notify a user when an administrator removes one of their MFA methods.

`tenants[x].emailConfiguration.twoFactorMethodRemoveEmailTemplateId`UUIDoptionalAvailable since 1.30.0

The Id of the Email Template used to send emails to users when a MFA method has been removed from their account.

`tenants[x].emailConfiguration.unverified.allowEmailChangeWhenGated`BooleanoptionalDefaults to falseAvailable since 1.27.0

When this value is set to `true`, the user is allowed to change their email address when they are gated because they haven't verified their email address.

`tenants[x].emailConfiguration.unverified.behavior`StringoptionalDefaults to AllowAvailable since 1.27.0

The desired behavior during login for a user that does not have a verified email. The possible values are:

*   `Allow` - the user will be allowed to complete login.
*   `Gated` - verification is required before a user can complete login. The use of this value will require a paid plan.

`tenants[x].emailConfiguration.username`StringoptionalAvailable since 1.8.0

An optional username FusionAuth will to authenticate with the SMTP server.

`tenants[x].emailConfiguration.verificationEmailTemplateId`UUIDoptional

The Id of the Email Template used to send emails to users to verify that their email address is valid. If either the **verifyEmail** or **verifyEmailWhenChanged** fields are `true`, this field is required.

`tenants[x].emailConfiguration.verificationStrategy`StringoptionalAvailable since 1.27.0

The process by which the user will verify their email address. The possible values are:

*   `ClickableLink` - send the user a code with a clickable link.
*   `FormField` - send the user a short code intended to be manually entered into a form field. This is only available when **tenants\[x\].emailConfiguration.unverified.behavior** has the `Gated` value.

`tenants[x].emailConfiguration.verifyEmail`BooleanoptionalDefaults to false

Whether the user's email addresses are verified when the registers with your application.

`tenants[x].emailConfiguration.verifyEmailWhenChanged`BooleanoptionalDefaults to false

Whether the user's email addresses are verified when the user changes them.

`tenants[x].eventConfiguration.events`ObjectAvailable since 1.8.0

A mapping of the configuration for each event type that FusionAuth sends. The event types that are the keys into this Object are:

*   `audit-log.create` - When an audit log is created Available since 1.30.0
*   `event-log.create` - When an event log is created Available since 1.30.0
*   `jwt.public-key.update` - When a JWT signing Public / Private keypair may have been changed
*   `jwt.refresh` - When an access token is refreshed using a refresh token Available since 1.16.0
*   `jwt.refresh-token.revoke` - When a JWT Refresh Token is revoked
*   `kickstart.success` - When kickstart has successfully completed Available since 1.30.0
*   `user.action` - When a user action is triggered
*   `user.bulk.create` - When multiple users are created in bulk (i.e. during an import)
*   `user.create` - When a user is created
*   `user.create.complete` - When a user create transaction has completed Available since 1.30.0
*   `user.deactivate` - When a user is deactivated
*   `user.delete` - When a user is deleted
*   `user.delete.complete` - When a user delete transaction has completed Available since 1.30.0
*   `user.email.update` - When a user updates their email address Available since 1.30.0
*   `user.email.verified` - When a user verifies their email address Available since 1.8.0
*   `user.identity-provider.link` - When a link is created from a user to an Identity Provider Available since 1.36.0
*   `user.identity-provider.unlink` - When an existing Identity Provider link is removed from a User Available since 1.36.0
*   `user.identity.verified` - When a user's identity is verified Available since 1.59.0
*   `user.loginId.duplicate.create` - When a request to create a user with a login Id (email or username) which is already in use has been received Available since 1.30.0
    
    **Note:** To use , you'll need an Enterprise plan.
    
*   `user.loginId.duplicate.update` - When a request to update a user and change their login Id (email or username) to one that is already in use has been received Available since 1.30.0
    
    **Note:** To use , you'll need an Enterprise plan.
    
*   `user.login.failed` - When a user fails a login request Available since 1.6.0
*   `user.login.new-device` - When a user begins a login request with a new device Available since 1.30.0
    
    **Note:** To use , you'll need an Enterprise plan.
    
*   `user.login.success` - When a user completes a login request Available since 1.6.0
*   `user.login.suspicious` - When a user logs in and is considered to be a potential threat (requires an activated Enterprise license) Available since 1.30.0
    
    **Note:** To use , you'll need an Enterprise plan.
    
*   `user.password.breach` - When Reactor detects a user is using a potentially breached password (requires an activated license) Available since 1.15.0
    
    **Note:** To use , you'll need a paid plan.
    
*   `user.password.reset.send` - When a forgot password email has been sent to a user Available since 1.30.0
    
    **Note:** To use , you'll need an Enterprise plan.
    
*   `user.password.reset.start` - When the process to reset a user password has started Available since 1.30.0
    
    **Note:** To use , you'll need an Enterprise plan.
    
*   `user.password.reset.success` - When a user has successfully reset their password Available since 1.30.0
    
    **Note:** To use , you'll need an Enterprise plan.
    
*   `user.password.update` - When a user has updated their password Available since 1.30.0
    
    **Note:** To use , you'll need an Enterprise plan.
    
*   `user.reactivate` - When a user is reactivated
*   `user.registration.create` - When a user registration is created Available since 1.6.0
*   `user.registration.create.complete` - When a user registration create transaction has completed Available since 1.30.0
*   `user.registration.delete` - When a user registration is deleted Available since 1.6.0
*   `user.registration.delete.complete` - When a user registration delete transaction has completed Available since 1.30.0
*   `user.registration.update` - When a user registration is updated Available since 1.6.0
*   `user.registration.update.complete` - When a user registration update transaction has completed Available since 1.30.0
*   `user.registration.verified` - When a user completes registration verification Available since 1.8.0
*   `user.two-factor.challenge` - When a user is presented a two-factor challenge Available since 1.68.0
    
    **Note:** To use , you'll need an Enterprise plan.
    
*   `user.two-factor.failed-attempt` - When a user submits an incorrect answer to a two-factor challenge Available since 1.68.0
    
    **Note:** To use , you'll need an Enterprise plan.
    
*   `user.two-factor.method.add` - When a user has added a two-factor method Available since 1.30.0
    
    **Note:** To use , you'll need an Enterprise plan.
    
*   `user.two-factor.method.remove` - When a user has removed a two-factor method Available since 1.30.0
    
    **Note:** To use , you'll need an Enterprise plan.
    
*   `user.two-factor.success` - When a user submits a correct answer to a two-factor challenge Available since 1.68.0
    
    **Note:** To use , you'll need an Enterprise plan.
    
*   `user.update` - When a user is updated
*   `user.update.complete` - When a user update transaction has completed Available since 1.30.0

`tenants[x].eventConfiguration.events[type].enabled`BooleanAvailable since 1.8.0

Whether or not FusionAuth should send these types of events to any configured Webhooks.

`tenants[x].eventConfiguration.events[type].transactionType`StringAvailable since 1.8.0

The transaction type that FusionAuth uses when sending these types of events to any configured Webhooks. The transaction types are:

*   `None` - No Webhooks are required to succeed for the FusionAuth transaction to be committed.
*   `Any` - Only a single Webhook is required to succeed for the FusionAuth transaction to be committed.
*   `SimpleMajority` - A simple majority (50% or more) of Webhooks are required to succeed for the FusionAuth transaction to be committed.
*   `SuperMajority` - A super majority (2/3 or more) of Webhooks are required to succeed for the FusionAuth transaction to be committed.
*   `AbsoluteMajority` - Every Webhook must succeed for the FusionAuth transaction to be committed.

`tenants[x].externalIdentifierConfiguration.authorizationGrantIdTimeToLiveInSeconds`IntegerAvailable since 1.8.0

The time in seconds until an OAuth authorization code is no longer valid to be exchanged for an access token. This is essentially the time allowed between the start of an Authorization request during the Authorization code grant and when you request an access token using this authorization code on the Token endpoint.

Value must be greater than 0 and less than or equal to 600.

`tenants[x].externalIdentifierConfiguration.changePasswordIdGenerator.length`IntegerAvailable since 1.8.0

The length of the secure generator used for generating the change password Id.

If the **changePasswordIdGenerator.type** is equal to `randomAlpha` then the length must be greater or equal to 4 and less than or equal to 12. If the **changePasswordIdGenerator.type** is equal to `randomAlphaNumeric` then the length must be greater or equal to 4 and less than or equal to 12. If the **changePasswordIdGenerator.type** is equal to `randomBytes` then the length must be greater or equal to 16 and less than or equal to 128. If the **changePasswordIdGenerator.type** is equal to `randomDigits` then the length must be greater or equal to 4 and less than or equal to 12.

`tenants[x].externalIdentifierConfiguration.changePasswordIdGenerator.type`StringAvailable since 1.8.0

The type of the secure generator used for generating the change password Id. Possible values are:

*   `randomAlpha`
*   `randomAlphaNumeric`
*   `randomBytes`
*   `randomDigits`

`tenants[x].externalIdentifierConfiguration.changePasswordIdTimeToLiveInSeconds`IntegerAvailable since 1.8.0

The time in seconds until a change password Id is no longer valid and cannot be used by the Change Password API. Value must be greater than 0.

`tenants[x].externalIdentifierConfiguration.deviceCodeTimeToLiveInSeconds`IntegerAvailable since 1.11.0

The time in seconds until a device code Id is no longer valid and cannot be used by the Token API. Value must be greater than 0.

`tenants[x].externalIdentifierConfiguration.deviceUserCodeIdGenerator.length`IntegerAvailable since 1.11.0

The length of the secure generator used for generating the device code Id.

If the **deviceCodeTimeToLiveInSeconds.type** is equal to `randomAlpha` then the length must be greater or equal to 4 and less than or equal to 12. If the **deviceCodeTimeToLiveInSeconds.type** is equal to `randomAlphaNumeric` then the length must be greater or equal to 4 and less than or equal to 12. If the **deviceCodeTimeToLiveInSeconds.type** is equal to `randomBytes` then the length must be greater or equal to 16 and less than or equal to 128. If the **deviceCodeTimeToLiveInSeconds.type** is equal to `randomDigits` then the length must be greater or equal to 4 and less than or equal to 12.

`tenants[x].externalIdentifierConfiguration.deviceUserCodeIdGenerator.type`StringAvailable since 1.11.0

The type of the secure generator used for generating the device code Id. Possible values are:

*   `randomAlpha`
*   `randomAlphaNumeric`
*   `randomBytes`
*   `randomDigits`

`tenants[x].externalIdentifierConfiguration.emailVerificationIdGenerator.length`IntegerAvailable since 1.8.0

The length of the secure generator used for generating the the email verification Id.

If the **emailVerificationIdGenerator.type** is equal to `randomAlpha` then the length must be greater or equal to 4 and less than or equal to 12. If the **emailVerificationIdGenerator.type** is equal to `randomAlphaNumeric` then the length must be greater or equal to 4 and less than or equal to 12. If the **emailVerificationIdGenerator.type** is equal to `randomBytes` then the length must be greater or equal to 16 and less than or equal to 128. If the **emailVerificationIdGenerator.type** is equal to `randomDigits` then the length must be greater or equal to 4 and less than or equal to 12.

`tenants[x].externalIdentifierConfiguration.emailVerificationIdGenerator.type`StringAvailable since 1.8.0

The type of the secure generator used for generating the email verification Id. Possible values are:

*   `randomAlpha`
*   `randomAlphaNumeric`
*   `randomBytes`
*   `randomDigits`

`tenants[x].externalIdentifierConfiguration.emailVerificationIdTimeToLiveInSeconds`IntegerAvailable since 1.8.0

The time in seconds until an email verification Id is no longer valid and cannot be used by the Verify Email API. Value must be greater than 0.

`tenants[x].externalIdentifierConfiguration.emailVerificationOneTimeCodeGenerator.length`IntegerAvailable since 1.27.0

The length of the secure generator used for generating the email verification one time code.

If the **emailVerificationIdGenerator.type** is equal to `randomAlpha` then the length must be greater or equal to 4 and less than or equal to 12. If the **emailVerificationIdGenerator.type** is equal to `randomAlphaNumeric` then the length must be greater or equal to 4 and less than or equal to 12. If the **emailVerificationIdGenerator.type** is equal to `randomBytes` then the length must be greater or equal to 16 and less than or equal to 128. If the **emailVerificationIdGenerator.type** is equal to `randomDigits` then the length must be greater or equal to 4 and less than or equal to 12.

`tenants[x].externalIdentifierConfiguration.emailVerificationOneTimeCodeGenerator.type`StringAvailable since 1.27.0

The type of the secure generator used for generating the email verification one time code. Possible values are:

*   `randomAlpha`
*   `randomAlphaNumeric`
*   `randomBytes`
*   `randomDigits`

`tenants[x].externalIdentifierConfiguration.externalAuthenticationIdTimeToLiveInSeconds`IntegerAvailable since 1.12.0

The time in seconds until an external authentication Id is no longer valid and cannot be used by the Token API. Value must be greater than 0.

`tenants[x].externalIdentifierConfiguration.identityProviderConnectionTestTimeToLiveInSeconds`IntegerAvailable since 1.65.0

The time in seconds until an identity provider connection test Id is no longer valid and cannot be used by the Identity Provider Test API. Value must be greater than 0.

`tenants[x].externalIdentifierConfiguration.loginIntentTimeToLiveInSeconds`IntegerAvailable since 1.53.0

The time in seconds until a Login Timeout identifier is no longer valid to complete post-authentication steps in the OAuth workflow. Must be greater than 0.

`tenants[x].externalIdentifierConfiguration.oneTimePasswordTimeToLiveInSeconds`IntegerAvailable since 1.8.0

The time in seconds until a One Time Password is no longer valid and cannot be used by the Login API. Value must be greater than 0.

`tenants[x].externalIdentifierConfiguration.passwordlessLoginGenerator.length`IntegerAvailable since 1.8.0

The length of the secure generator used for generating the passwordless login.

If the **passwordlessLoginGenerator.type** is equal to `randomAlpha` then the length must be greater or equal to 4 and less than or equal to 12. If the **passwordlessLoginGenerator.type** is equal to `randomAlphaNumeric` then the length must be greater or equal to 4 and less than or equal to 12. If the **passwordlessLoginGenerator.type** is equal to `randomBytes` then the length must be greater or equal to 16 and less than or equal to 128. If the **passwordlessLoginGenerator.type** is equal to `randomDigits` then the length must be greater or equal to 4 and less than or equal to 12.

`tenants[x].externalIdentifierConfiguration.passwordlessLoginGenerator.type`StringAvailable since 1.8.0

The type of the secure generator used for generating the passwordless login. Possible values are:

*   `randomAlpha`
*   `randomAlphaNumeric`
*   `randomBytes`
*   `randomDigits`

`tenants[x].externalIdentifierConfiguration.passwordlessLoginOneTimeCodeGenerator.length`IntegerAvailable since 1.59.0

The length of the secure generator used for generating the passwordless one-time login.

If the **passwordlessLoginOneTimeCodeGenerator.type** is equal to `randomAlpha` then the length must be greater or equal to 4 and less than or equal to 12. If the **passwordlessLoginOneTimeCodeGenerator.type** is equal to `randomAlphaNumeric` then the length must be greater or equal to 4 and less than or equal to 12. If the **passwordlessLoginOneTimeCodeGenerator.type** is equal to `randomBytes` then the length must be greater or equal to 16 and less than or equal to 128. If the **passwordlessLoginOneTimeCodeGenerator.type** is equal to `randomDigits` then the length must be greater or equal to 4 and less than or equal to 12.

`tenants[x].externalIdentifierConfiguration.passwordlessLoginOneTimeCodeGenerator.type`StringAvailable since 1.59.0

The type of the secure generator used for generating the passwordless one-time login. Possible values are:

*   `randomAlpha`
*   `randomAlphaNumeric`
*   `randomBytes`
*   `randomDigits`

`tenants[x].externalIdentifierConfiguration.passwordlessLoginTimeToLiveInSeconds`IntegerAvailable since 1.8.0

The time in seconds until a passwordless code is no longer valid and cannot be used by the Passwordless API. Value must be greater than 0.

`tenants[x].externalIdentifierConfiguration.pendingAccountLinkTimeToLiveInSeconds`IntegerAvailable since 1.28.0

The number of seconds before the pending account link identifier is no longer valid to complete an account link request.

`tenants[x].externalIdentifierConfiguration.phoneVerificationIdGenerator.length`IntegerAvailable since 1.59.0

The length of the secure generator used for generating the the phone verification Id.

If the **phoneVerificationIdGenerator.type** is equal to `randomAlpha` then the length must be greater or equal to 4 and less than or equal to 12. If the **phoneVerificationIdGenerator.type** is equal to `randomAlphaNumeric` then the length must be greater or equal to 4 and less than or equal to 12. If the **phoneVerificationIdGenerator.type** is equal to `randomBytes` then the length must be greater or equal to 16 and less than or equal to 128. If the **phoneVerificationIdGenerator.type** is equal to `randomDigits` then the length must be greater or equal to 4 and less than or equal to 12.

`tenants[x].externalIdentifierConfiguration.phoneVerificationIdGenerator.type`StringAvailable since 1.59.0

The type of the secure generator used for generating the phone verification Id. Possible values are:

*   `randomAlpha`
*   `randomAlphaNumeric`
*   `randomBytes`
*   `randomDigits`

`tenants[x].externalIdentifierConfiguration.phoneVerificationIdTimeToLiveInSeconds`IntegerAvailable since 1.59.0

The time in seconds until a phone verification Id is no longer valid and cannot be used by the Verify Phone API.

`tenants[x].externalIdentifierConfiguration.phoneVerificationOneTimeCodeGenerator.length`IntegerAvailable since 1.59.0

The length of the secure generator used for generating the phone verification one time code.

If the **phoneVerificationOneTimeCodeGenerator.type** is equal to `randomAlpha` then the length must be greater or equal to 4 and less than or equal to 12. If the **phoneVerificationOneTimeCodeGenerator.type** is equal to `randomAlphaNumeric` then the length must be greater or equal to 4 and less than or equal to 12. If the **phoneVerificationOneTimeCodeGenerator.type** is equal to `randomBytes` then the length must be greater or equal to 16 and less than or equal to 128. If the **phoneVerificationOneTimeCodeGenerator.type** is equal to `randomDigits` then the length must be greater or equal to 4 and less than or equal to 12.

`tenants[x].externalIdentifierConfiguration.phoneVerificationOneTimeCodeGenerator.type`StringAvailable since 1.59.0

The type of the secure generator used for generating the phone verification one time code. Possible values are:

*   `randomAlpha`
*   `randomAlphaNumeric`
*   `randomBytes`
*   `randomDigits`

`tenants[x].externalIdentifierConfiguration.registrationVerificationIdGenerator.length`IntegerAvailable since 1.8.0

The length of the secure generator used for generating the registration verification Id.

If the **registrationVerificationIdGenerator.type** is equal to `randomAlpha` then the length must be greater or equal to 4 and less than or equal to 12. If the **registrationVerificationIdGenerator.type** is equal to `randomAlphaNumeric` then the length must be greater or equal to 4 and less than or equal to 12. If the **registrationVerificationIdGenerator.type** is equal to `randomBytes` then the length must be greater or equal to 16 and less than or equal to 128. If the **registrationVerificationIdGenerator.type** is equal to `randomDigits` then the length must be greater or equal to 4 and less than or equal to 12.

`tenants[x].externalIdentifierConfiguration.registrationVerificationIdGenerator.type`StringAvailable since 1.8.0

The type of the secure generator used for generating the registration verification Id. Possible values are:

*   `randomAlpha`
*   `randomAlphaNumeric`
*   `randomBytes`
*   `randomDigits`

`tenants[x].externalIdentifierConfiguration.registrationVerificationIdTimeToLiveInSeconds`IntegerAvailable since 1.8.0

The time in seconds until a registration verification Id is no longer valid and cannot be used by the Verify Registration API. Value must be greater than 0.

`tenants[x].externalIdentifierConfiguration.registrationVerificationOneTimeCodeGenerator.length`IntegerAvailable since 1.27.0

The length of the secure generator used for generating the registration verification one time code.

If the **registrationVerificationIdGenerator.type** is equal to `randomAlpha` then the length must be greater or equal to 4 and less than or equal to 12. If the **registrationVerificationIdGenerator.type** is equal to `randomAlphaNumeric` then the length must be greater or equal to 4 and less than or equal to 12. If the **registrationVerificationIdGenerator.type** is equal to `randomBytes` then the length must be greater or equal to 16 and less than or equal to 128. If the **registrationVerificationIdGenerator.type** is equal to `randomDigits` then the length must be greater or equal to 4 and less than or equal to 12.

`tenants[x].externalIdentifierConfiguration.registrationVerificationOneTimeCodeGenerator.type`StringAvailable since 1.27.0

The type of the secure generator used for generating the registration verification one time code. Possible values are:

*   `randomAlpha`
*   `randomAlphaNumeric`
*   `randomBytes`
*   `randomDigits`

`tenants[x].externalIdentifierConfiguration.rememberOAuthScopeConsentChoiceTimeToLiveInSeconds`IntegerAvailable since 1.50.0

The time in seconds until remembered OAuth scope consent choices are no longer valid, and the User will be prompted to consent to requested OAuth scopes even if they have not changed. Applies only when **application.oauthConfiguration.consentMode** is set to `RememberDecision`. Value must be greater than 0.

`tenants[x].externalIdentifierConfiguration.samlv2AuthNRequestIdTimeToLiveInSeconds`IntegerAvailable since 1.19.0

The time in seconds that a SAML AuthN request Id returned by the Start SAML v2 Login Request API will be eligible to be used to complete a SAML v2 Login request.

`tenants[x].externalIdentifierConfiguration.setupPasswordIdGenerator.length`IntegerAvailable since 1.8.0

The length of the secure generator used for generating the setup password Id.

If the **setupPasswordIdGenerator.type** is equal to `randomAlpha` then the length must be greater or equal to 4 and less than or equal to 12. If the **setupPasswordIdGenerator.type** is equal to `randomAlphaNumeric` then the length must be greater or equal to 4 and less than or equal to 12. If the **setupPasswordIdGenerator.type** is equal to `randomBytes` then the length must be greater or equal to 16 and less than or equal to 128. If the **setupPasswordIdGenerator.type** is equal to `randomDigits` then the length must be greater or equal to 4 and less than or equal to 12.

`tenants[x].externalIdentifierConfiguration.setupPasswordIdGenerator.type`StringAvailable since 1.8.0

The type of the secure generator used for generating the setup password Id. Possible values are:

*   `randomAlpha`
*   `randomAlphaNumeric`
*   `randomBytes`
*   `randomDigits`

`tenants[x].externalIdentifierConfiguration.setupPasswordIdTimeToLiveInSeconds`IntegerAvailable since 1.8.0

The time in seconds until a setup password Id is no longer valid and cannot be used by the Change Password API. Value must be greater than 0.

`tenants[x].externalIdentifierConfiguration.trustTokenTimeToLiveInSeconds`IntegerAvailable since 1.33.0

The number of seconds before the Trust Token is no longer valid to complete a request that requires trust. Value must be greater than 0.

`tenants[x].externalIdentifierConfiguration.twoFactorIdTimeToLiveInSeconds`IntegerAvailable since 1.8.0

The time in seconds until a two-factor Id is no longer valid and cannot be used by the Two-Factor Login API. Value must be greater than 0.

`tenants[x].externalIdentifierConfiguration.twoFactorOneTimeCodeIdGenerator.length`IntegerAvailable since 1.8.0

The length of the secure generator used for generating the the two-factor one time code Id.

If the **twoFactorOneTimeCodeIdGenerator.type** is equal to `randomAlpha` then the length must be greater or equal to 4 and less than or equal to 12. If the **twoFactorOneTimeCodeIdGenerator.type** is equal to `randomAlphaNumeric` then the length must be greater or equal to 4 and less than or equal to 12. If the **twoFactorOneTimeCodeIdGenerator.type** is equal to `randomBytes` then the length must be greater or equal to 16 and less than or equal to 128. If the **twoFactorOneTimeCodeIdGenerator.type** is equal to `randomDigits` then the length must be greater or equal to 4 and less than or equal to 12.

`tenants[x].externalIdentifierConfiguration.twoFactorOneTimeCodeIdGenerator.type`StringAvailable since 1.8.0

The type of the secure generator used for generating the two-factor code Id. Possible values are:

*   `randomAlpha`
*   `randomAlphaNumeric`
*   `randomBytes`
*   `randomDigits`

`tenants[x].externalIdentifierConfiguration.twoFactorOneTimeCodeIdTimeToLiveInSeconds`IntegerAvailable since 1.26.0

The number of seconds before the Two-Factor One Time Code used to enable or disable a two-factor method is no longer valid. Must be greater than 0.

`tenants[x].externalIdentifierConfiguration.twoFactorTrustIdTimeToLiveInSeconds`IntegerAvailable since 1.8.0

The time in seconds until an issued Two-Factor trust Id is no longer valid and the User will be required to complete Two-Factor authentication during the next authentication attempt. Value must be greater than 0.

`tenants[x].externalIdentifierConfiguration.webAuthnAuthenticationChallengeTimeToLiveInSeconds`IntegerAvailable since 1.41.0

The time in seconds until a WebAuthn authentication challenge is no longer valid and the User will be required to restart the WebAuthn authentication ceremony by creating a new challenge. This value also controls the timeout for the client-side WebAuthn `navigator.credentials.get` API call. Value must be greater than 0.

`tenants[x].externalIdentifierConfiguration.webAuthnRegistrationChallengeTimeToLiveInSeconds`IntegerAvailable since 1.41.0

The time in seconds until a WebAuthn registration challenge is no longer valid and the User will be required to restart the WebAuthn registration ceremony by creating a new challenge. This value also controls the timeout for the client-side WebAuthn `navigator.credentials.create` API call. Value must be greater than 0.

`tenants[x].failedAuthenticationConfiguration.actionCancelPolicy.onPasswordReset`BooleanAvailable since 1.42.0

Indicates whether you want the user to be able to self-service unlock their account prior to the action duration by completing a password reset workflow.

`tenants[x].failedAuthenticationConfiguration.actionDuration`LongAvailable since 1.8.0

The duration of the User Action. This value along with the `actionDurationUnit` will be used to set the duration of the User Action. Value must be greater than 0.

`tenants[x].failedAuthenticationConfiguration.actionDurationUnit`StringAvailable since 1.8.0

The unit of time associated with a duration. The possible values are:

*   `MINUTES`
*   `HOURS`
*   `DAYS`
*   `WEEKS`
*   `MONTHS`
*   `YEARS`

`tenants[x].failedAuthenticationConfiguration.emailUser`StringoptionalAvailable since 1.42.0

Indicates you would like to email the user when the user's account is locked due to this action being taken. This requires the User Action specified by the **tenant.failedAuthenticationConfiguration.userActionId** to also be configured for email. If the User Action is not configured to be able to email the user, this configuration will be ignored. See **userEmailingEnabled** on the User Action.

`tenants[x].failedAuthenticationConfiguration.resetCountInSeconds`IntegerAvailable since 1.8.0

The length of time in seconds before the failed authentication count will be reset. Value must be greater than 0.

For example, if `tooManyAttempts` is set to `5` and you fail to authenticate `4` times in a row, waiting for the duration specified here will cause your fifth attempt to start back at `1`.

`tenants[x].failedAuthenticationConfiguration.tooManyAttempts`IntegerAvailable since 1.8.0

The number of failed attempts considered to be too many. Once this threshold is reached the specified User Action will be applied to the user for the duration specified. Value must be greater than 0.

`tenants[x].failedAuthenticationConfiguration.userActionId`UUIDAvailable since 1.8.0

The Id of the User Action that is applied when the threshold is reached for too many failed authentication attempts.

`tenants[x].familyConfiguration.allowChildRegistrations`BooleanAvailable since 1.8.0

Whether to allow child registrations.

`tenants[x].familyConfiguration.confirmChildEmailTemplateId`UUIDAvailable since 1.8.0

The unique Id of the email template to use when confirming a child.

`tenants[x].familyConfiguration.deleteOrphanedAccounts`BooleanAvailable since 1.8.0

Indicates that child users without parental verification will be permanently deleted after **tenants\[x\].familyConfiguration.deleteOrphanedAccountsDays** days.

`tenants[x].familyConfiguration.deleteOrphanedAccountsDays`IntegerAvailable since 1.8.0

The number of days from creation child users will be retained before being deleted for not completing parental verification. Value must be greater than 0.

`tenants[x].familyConfiguration.enabled`BooleanAvailable since 1.8.0

Whether family configuration is enabled.

`tenants[x].familyConfiguration.familyRequestEmailTemplateId`UUIDAvailable since 1.8.0

The unique Id of the email template to use when a family request is made.

`tenants[x].familyConfiguration.maximumChildAge`IntegerAvailable since 1.8.0

The maximum age of a child. Value must be greater than 0.

`tenants[x].familyConfiguration.minimumOwnerAge`IntegerAvailable since 1.8.0

The minimum age to be an owner. Value must be greater than 0.

`tenants[x].familyConfiguration.parentEmailRequired`BooleanAvailable since 1.8.0

Whether a parent email is required.

`tenants[x].familyConfiguration.parentRegistrationEmailTemplateId`UUIDAvailable since 1.8.0

The unique Id of the email template to use for parent registration.

`tenants[x].formConfiguration.adminUserFormId`UUIDAvailable since 1.20.0

The unique Id of the form to use for the Add and Edit User form when used in the FusionAuth admin UI.

`tenants[x].httpSessionMaxInactiveInterval`IntegerAvailable since 1.8.0

Time in seconds until an inactive session will be invalidated. Used when creating a new session in the FusionAuth OAuth frontend.

`tenants[x].id`UUID

The unique identifier for this Tenant.

`tenants[x].insertInstant`Long

The [instant](https://fusionauth.io/docs/reference/data-types.md#instants) that the Tenant was added to the FusionAuth database.

`tenants[x].issuer`StringAvailable since 1.8.0

The named issuer used to sign tokens. This is generally your public fully qualified domain with the `https://` protocol prefix. For example, `https://example.com`.

`tenants[x].jwtConfiguration.accessTokenKeyId`UUIDAvailable since 1.8.0

The unique id of the signing key used to sign the access token.

`tenants[x].jwtConfiguration.idTokenKeyId`UUIDAvailable since 1.8.0

The unique id of the signing key used to sign the Id token.

`tenants[x].jwtConfiguration.refreshTokenExpirationPolicy`StringAvailable since 1.17.0

The Refresh Token expiration policy.

The possible values are:

*   `Fixed` - the expiration is calculated from the time the token is issued.
*   `SlidingWindow` - the expiration is calculated from the last time the token was used.
*   `SlidingWindowWithMaximumLifetime` - the expiration is calculated from the last time the token was used, or until the **maximumTimeToLiveInMinutes** is reached.   Available since 1.46.0

`tenants[x].jwtConfiguration.refreshTokenOneTimeUseConfiguration.gracePeriodInSeconds`IntegerAvailable since 1.55.1

The length of time specified in seconds that a one-time use token can be reused.

This value must be greater than `0` and less than `86400` which is equal to 24 hours. Setting this value to `0` effectively disables the grace period which means a one-time token may not be reused. For security reasons, you should keep this value as small as possible, and only increase past `0` to improve reliability for an asynchronous or clustered integration that may require a brief grace period.

Note that one-time use tokens refreshed within a grace period are not considered for revocation when **tenant.jwtConfiguration.refreshTokenRevocationPolicy.onOneTimeTokenReuse** is `true`. When a token is reused within the grace period the current token will be returned on the API response and the token will not be rotated.

`tenants[x].jwtConfiguration.refreshTokenRevocationPolicy.onLoginPrevented`BooleanAvailable since 1.17.0

When enabled, all of a user's refresh tokens will be revoked when a user action, such as locking an account based on a number of failed login attempts, prevents user login.

`tenants[x].jwtConfiguration.refreshTokenRevocationPolicy.onMultiFactorEnable`BooleanAvailable since 1.42.0

When enabled, all of a user's refresh tokens will be revoked when the user enables multi-factor authentication for the first time. This policy will not be applied when adding subsequent multi-factor methods to the user.

`tenants[x].jwtConfiguration.refreshTokenRevocationPolicy.onOneTimeTokenReuse`BooleanAvailable since 1.55.1

When enabled, if a one-time use refresh token is reused, the token will be revoked. This does not cause all refresh tokens to be revoked, only the reused token is revoked.

`tenants[x].jwtConfiguration.refreshTokenRevocationPolicy.onPasswordChanged`BooleanAvailable since 1.17.0

When enabled, all of a user's refresh tokens will be revoked when a user changes their password.

`tenants[x].jwtConfiguration.refreshTokenSlidingWindowConfiguration.maximumTimeToLiveInMinutes`IntegerAvailable since 1.46.0

The maximum lifetime of a refresh token when using a **refreshTokenExpirationPolicy** of `SlidingWindowWithMaximumLifetime`.

`tenants[x].jwtConfiguration.refreshTokenTimeToLiveInMinutes`IntegerAvailable since 1.8.0

The length of time in minutes a Refresh Token is valid from the time it was issued. Value must be greater than 0.

`tenants[x].jwtConfiguration.refreshTokenUsagePolicy`StringAvailable since 1.17.0

The refresh token usage policy. The following are valid values:

*   `Reusable` - the token does not change after it was issued.
*   `OneTimeUse` - the token value will be changed each time the token is used to refresh a JWT. The client must store the new value after each usage.

`tenants[x].jwtConfiguration.timeToLiveInSeconds`IntegerAvailable since 1.8.0

The length of time in seconds this JWT is valid from the time it was issued. Value must be greater than 0.

`tenants[x].lambdaConfiguration.loginValidationId`UUIDAvailable since 1.53.0

The Id of the lambda that will be invoked at the end of a successful login request in order to extend custom validation of a login request.

`tenants[x].lambdaConfiguration.multiFactorRequirementId`UUIDoptionalAvailable since 1.62.0

The Id of the lambda that will be invoked during logins, password changes, and MFA Status API calls to perform various validations to decide whether to challenge the user on one of their MFA methods.

`tenants[x].lambdaConfiguration.scimEnterpriseUserRequestConverterId`UUIDAvailable since 1.36.0

The Id of a SCIM User Request Lambda that will be used to convert the SCIM Enterprise User request to a FusionAuth User.

`tenants[x].lambdaConfiguration.scimEnterpriseUserResponseConverterId`UUIDAvailable since 1.36.0

The Id of a SCIM User Response Lambda that will be used to convert a FusionAuth Enterprise User to a SCIM Server response.

`tenants[x].lambdaConfiguration.scimGroupRequestConverterId`UUIDAvailable since 1.36.0

The Id of a SCIM Group Request Lambda that will be used to convert the SCIM Group request to a FusionAuth Group.

`tenants[x].lambdaConfiguration.scimGroupResponseConverterId`UUIDAvailable since 1.36.0

The Id of a SCIM GroupResponse Lambda that will be used to convert a FusionAuth Group to a SCIM Server response.

`tenants[x].lambdaConfiguration.scimUserRequestConverterId`UUIDAvailable since 1.36.0

The Id of a SCIM User Request Lambda that will be used to convert the SCIM User request to a FusionAuth User.

`tenants[x].lambdaConfiguration.scimUserResponseConverterId`UUIDAvailable since 1.36.0

The Id of a SCIM User Response Lambda that will be used to convert a FusionAuth User to a SCIM Server response.

`tenants[x].lastUpdateInstant`Long

The [instant](https://fusionauth.io/docs/reference/data-types.md#instants) that the Tenant was last updated in the FusionAuth database.

`tenants[x].loginConfiguration.requireAuthentication`BooleanAvailable since 1.26.0

Indicates whether to require an API key for the Login API when an `applicationId` is not provided. When an `applicationId` is provided to the Login API call, the application configuration will take precedence.

`tenants[x].logoutURL`StringAvailable since 1.8.0

The logout redirect URL when sending the user's browser to the `/oauth2/logout` URI of the FusionAuth Front End. This value is only used when a logout URL is not defined in your Application.

`tenants[x].maximumPasswordAge.days`IntegerAvailable since 1.8.0

The password maximum age in days. The number of days after which FusionAuth will require a user to change their password. Required when **tenant.maximumPasswordAge.enabled** is set to `true`.

`tenants[x].maximumPasswordAge.enabled`BooleanAvailable since 1.8.0

Indicates that the maximum password age is enabled and being enforced.

`tenants[x].minimumPasswordAge.seconds`IntegerAvailable since 1.8.0

The password minimum age in seconds. When enabled FusionAuth will not allow a password to be changed until it reaches this minimum age. Required when **tenant.minimumPasswordAge.enabled** is set to `true`.

`tenants[x].minimumPasswordAge.enabled`BooleanAvailable since 1.8.0

Indicates that the minimum password age is enabled and being enforced.

`tenants[x].multiFactorConfiguration.authenticator.algorithm`StringAvailable since 1.26.0

The algorithm used by the TOTP authenticator. This value is `HmacSHA1` and read only.

`tenants[x].multiFactorConfiguration.authenticator.codeLength`IntegerAvailable since 1.26.0

The length of the code generated by the TOTP. This value is `6` and read only.

`tenants[x].multiFactorConfiguration.authenticator.enabled`BooleanAvailable since 1.26.0

When enabled, users may utilize an authenticator application to complete a multi-factor authentication request. This method uses TOTP (Time-Based One-Time Password) as defined in [RFC 6238](https://tools.ietf.org/html/rfc6238) and often uses an native mobile app such as Google Authenticator.

`tenants[x].multiFactorConfiguration.authenticator.timeStep`IntegerAvailable since 1.26.0

The time-step size in seconds. This value is `30` and read only.

`tenants[x].multiFactorConfiguration.email.enabled`BooleanAvailable since 1.26.0

When enabled, users may utilize an email address to complete a two-factor authentication request.

`tenants[x].multiFactorConfiguration.email.templateId`UUIDAvailable since 1.26.0

The Id of the email template that is used when notifying a user to complete a two-factor authentication request.

`tenants[x].multiFactorConfiguration.sms.enabled`BooleanAvailable since 1.26.0

When enabled, users may utilize a mobile phone number to complete a two-factor authentication request.

`tenants[x].multiFactorConfiguration.sms.messengerId`UUIDAvailable since 1.26.0

The messenger that is used to deliver a SMS two-factor authentication request.

`tenants[x].multiFactorConfiguration.sms.templateId`UUIDAvailable since 1.26.0

The Id of the SMS template that is used when notifying a user to complete a two-factor authentication request.

`tenants[x].multiFactorConfiguration.voice.enabled`BooleanAvailable since 1.65.0

When enabled, users can receive a spoken multi-factor authentication code over a phone call.

`tenants[x].multiFactorConfiguration.voice.messengerId`UUIDAvailable since 1.65.0

The messenger that is used to deliver a voice two-factor authentication request.

`tenants[x].multiFactorConfiguration.voice.templateId`UUIDAvailable since 1.65.0

The Id of the voice template that is used when notifying a user to complete a two-factor authentication request.

`tenants[x].name`String

The unique name of the Tenant.

`tenants[x].oauthConfiguration.clientCredentialsAccessTokenPopulateLambdaId`UUIDAvailable since 1.26.0

The Id of a lambda that will be called to populate the JWT during a client credentials grant.

`tenants[x].passwordEncryptionConfiguration.encryptionScheme`StringAvailable since 1.8.0

The default method for encrypting the User's password. The following encryptors are provided with FusionAuth:

*   **[salted-md5](https://fusionauth.io/docs/reference/password-hashes.md#salted-md5)**
*   **[salted-sha256](https://fusionauth.io/docs/reference/password-hashes.md#salted-sha-256)**
*   **[salted-hmac-sha256](https://fusionauth.io/docs/reference/password-hashes.md#salted-hmac-sha-256)**
*   **[salted-pbkdf2-hmac-sha256](https://fusionauth.io/docs/reference/password-hashes.md#salted-pbkdf2-hmac-sha-256)**
*   **[salted-pbkdf2-hmac-sha256-512](https://fusionauth.io/docs/reference/password-hashes.md#salted-pbkdf2-hmac-sha-256)**
*   **[salted-pbkdf2-hmac-sha512-512](https://fusionauth.io/docs/reference/password-hashes.md#salted-pbkdf2-hmac-sha-512)**
*   **[bcrypt](https://fusionauth.io/docs/reference/password-hashes.md#salted-bcrypt)**
*   **[phpass-md5](https://fusionauth.io/docs/reference/password-hashes.md#phpass-md5)**
*   **[phpass-sha512](https://fusionauth.io/docs/reference/password-hashes.md#phpass-sha-512)**

`tenants[x].passwordEncryptionConfiguration.encryptionSchemeFactor`IntegerAvailable since 1.8.0

The factor used by the password encryption scheme. If not provided, the `PasswordEncryptor` provides a default value. Generally this will be used as an iteration count to generate the hash. The actual use of this value is up to the `PasswordEncryptor` implementation.

`tenants[x].passwordEncryptionConfiguration.modifyEncryptionSchemeOnLogin`BooleanAvailable since 1.8.0

When enabled a user's hash configuration will be modified to match these configured settings. This can be useful to increase a password hash strength over time or upgrade imported users to a more secure encryption scheme after an initial import.

Beginning in version `1.42.0` when this configuration is enabled, in addition to re-hashing on login, the password will be re-hashed on password change as well.

`tenants[x].passwordValidationRules.breachDetection.enabled`BooleanAvailable since 1.15.0

Whether to enable Reactor breach detection. Requires an activated license.

`tenants[x].passwordValidationRules.breachDetection.matchMode`StringAvailable since 1.15.0

The level of severity where Reactor will consider a breach. The following are valid values:

*   `High` Only requires a password match, this is the most secure and is recommended
*   `Medium` Exact match on username, email address or email sub-address
*   `Low` Exact match on an email or username, or the password is a common breached value

`tenants[x].passwordValidationRules.breachDetection.notifyUserEmailTemplateId`UUIDAvailable since 1.15.0

The Id of the email template to use when notifying a user of a breached password.

`tenants[x].passwordValidationRules.breachDetection.onLogin`StringAvailable since 1.15.0

The behavior when detecting breaches at time of user login. The following are valid values:

*   `Off` Do not perform breach detection at login
*   `RecordOnly` Only record the result, take no action
*   `NotifyUser` Notify the end user via email
*   `RequireChange` Require immediate password change

`tenants[x].passwordValidationRules.maxLength`IntegerAvailable since 1.8.0

The maximum length of a password when a new user is created or a user requests a password change.

`tenants[x].passwordValidationRules.minLength`IntegerAvailable since 1.8.0

The minimum length of a password when a new user is created or a user requests a password change.

`tenants[x].passwordValidationRules.rememberPreviousPasswords.count`IntegerAvailable since 1.8.0

The number of previous passwords to remember. Value must be greater than 0.

`tenants[x].passwordValidationRules.rememberPreviousPasswords.enabled`BooleanAvailable since 1.8.0

Whether to prevent a user from using any of their previous passwords.

`tenants[x].passwordValidationRules.requireMixedCase`BooleanAvailable since 1.8.0

Whether to force the user to use at least one uppercase and one lowercase character.

`tenants[x].passwordValidationRules.requireNonAlpha`BooleanAvailable since 1.8.0

Whether to force the user to use at least one non-alphanumeric character.

`tenants[x].passwordValidationRules.requireNumber`BooleanAvailable since 1.8.0

Whether to force the user to use at least one number.

`tenants[x].passwordValidationRules.validateOnLogin`BooleanAvailable since 1.15.0

When enabled the user's password will be validated during login. If the password does not meet the currently configured validation rules the user will be required to change their password.

`tenants[x].phoneConfiguration.forgotPasswordTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template that is used when sending a user a forgot password message.

`tenants[x].phoneConfiguration.identityUpdateTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template used to send a message to a user when their phone number has been updated. The message will be sent to both their new and old phone numbers.

`tenants[x].phoneConfiguration.implicitPhoneVerificationAllowed`BooleanoptionalDefaults to trueAvailable since 1.59.0

When set to `true`, this allows a phone number to be verified as a result of completing a similar phone based workflow such as change password. When set to `false`, the user must explicitly complete the phone verification workflow even if the user has already completed a similar phone workflow such as change password.

`tenants[x].phoneConfiguration.loginIdInUseOnCreateTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template used to send a message to a user when another user attempts to create an account with their login Id.

`tenants[x].phoneConfiguration.loginIdInUseOnUpdateTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template used to send a message to a user when another user attempts to update an existing account to use their login Id.

`tenants[x].phoneConfiguration.loginNewDeviceTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template used to send a message to a user when they log in on a new device.

`tenants[x].phoneConfiguration.loginSuspiciousTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template used to send a message to a user when a suspicious login using their login Id occurs.

`tenants[x].phoneConfiguration.messengerId`UUIDAvailable since 1.59.0

The messenger that is used to deliver SMS messages for phone number verification and passwordless logins.

`tenants[x].phoneConfiguration.passwordlessTemplateId`UUIDAvailable since 1.59.0

The Id of the Passwordless Message Template, sent to users when they start a passwordless login.

`tenants[x].phoneConfiguration.passwordResetSuccessTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template used to send a message to a user when they have completed a 'forgot password' workflow and their password has been reset.

`tenants[x].phoneConfiguration.passwordUpdateTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template used to send a message to a user when their password has been updated.

`tenants[x].phoneConfiguration.setPasswordTemplateId`UUIDoptionalAvailable since 1.59.0

The Id of the SMS Message Template used when a user must set their password manually after their account was created for them (by an admin, for example).

`tenants[x].phoneConfiguration.adminTwoFactorMethodRemoveTemplateId`UUIDoptionalAvailable since 1.68.0

The Id of the Message Template used to notify a user when an administrator removes one of their MFA methods.

`tenants[x].phoneConfiguration.twoFactorMethodRemoveTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template used to send a message to a user when a MFA method has been removed from their account.

`tenants[x].phoneConfiguration.twoFactorMethodAddTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template used to send a message to a user when a MFA method has been added to their account.

`tenants[x].phoneConfiguration.unverified.allowPhoneNumberChangeWhenGated`BooleanoptionalDefaults to falseAvailable since 1.59.0

When this value is set to `true`, the user is allowed to change their phone number when they are gated because they haven't verified their phone number.

`tenants[x].phoneConfiguration.unverified.behavior`StringAvailable since 1.59.0

The desired behavior during login for a user that does not have a verified phone number. The possible values are:

*   `Allow` - the user will be allowed to complete login.
*   `Gated` - verification is required before a user can complete login. The use of this value will require a paid plan.

`tenants[x].phoneConfiguration.verificationCompleteTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template used to notify a user that their phone number has been verified.

`tenants[x].phoneConfiguration.verificationStrategy`StringAvailable since 1.59.0

The process by which the user will verify their phone number. The possible values are:

*   `ClickableLink` - send the user a code with a clickable link.
*   `FormField` - send the user a short code intended to be manually entered into a form field. This is only available when **tenants\[x\].phoneConfiguration.unverified.behavior** has the `Gated` value.

`tenants[x].phoneConfiguration.verificationTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template used to send SMS messages to users to verify that their phone number is valid.

`tenants[x].phoneConfiguration.verifyPhoneNumber`BooleanAvailable since 1.59.0

Whether a user's phone number is verified when they register with your application.

`tenants[x].rateLimitConfiguration.failedLogin.limit`IntegerAvailable since 1.30.0

The number of times a user can fail to login within the configured **timePeriodInSeconds** duration. If a Failed authentication action has been configured then it will take precedence.

`tenants[x].rateLimitConfiguration.failedLogin.timePeriodInSeconds`IntegerAvailable since 1.30.0

The duration for the number of times a user can fail login before being rate limited.

`tenants[x].rateLimitConfiguration.forgotPassword.limit`IntegerAvailable since 1.30.0

The number of times a user can request a forgot password email within the configured **timePeriodInSeconds** duration.

`tenants[x].rateLimitConfiguration.forgotPassword.timePeriodInSeconds`IntegerAvailable since 1.30.0

The duration for the number of times a user can request a forgot password email before being rate limited.

`tenants[x].rateLimitConfiguration.sendEmailVerification.limit`IntegerAvailable since 1.30.0

The number of times a user can request a verification email within the configured **timePeriodInSeconds** duration.

`tenants[x].rateLimitConfiguration.sendEmailVerification.timePeriodInSeconds`IntegerAvailable since 1.30.0

The duration for the number of times a user can request a verification email before being rate limited.

`tenants[x].rateLimitConfiguration.sendPasswordless.limit`IntegerAvailable since 1.30.0

The number of times a user can request a passwordless login email within the configured **timePeriodInSeconds** duration.

`tenants[x].rateLimitConfiguration.sendPasswordless.timePeriodInSeconds`IntegerAvailable since 1.30.0

The duration for the number of times a user can request a passwordless login email before being rate limited.

`tenants[x].rateLimitConfiguration.sendPasswordlessPhone.limit`IntegerAvailable since 1.59.0

The number of times a user can request a passwordless login SMS message within the configured **timePeriodInSeconds** duration.

`tenants[x].rateLimitConfiguration.sendPasswordlessPhone.timePeriodInSeconds`IntegerAvailable since 1.59.0

The duration for the number of times a user can request a passwordless login SMS message before being rate limited.

`tenants[x].rateLimitConfiguration.sendPhoneVerification.limit`IntegerAvailable since 1.59.0

The number of times a user can request a phone verification message within the configured **timePeriodInSeconds** duration.

`tenants[x].rateLimitConfiguration.sendPhoneVerification.timePeriodInSeconds`IntegerAvailable since 1.59.0

The duration for the number of times a user can request a phone verification message before being rate limited.

`tenants[x].rateLimitConfiguration.sendRegistrationVerification.limit`IntegerAvailable since 1.30.0

The number of times a user can request a registration verification email within the configured **timePeriodInSeconds** duration.

`tenants[x].rateLimitConfiguration.sendRegistrationVerification.timePeriodInSeconds`IntegerAvailable since 1.30.0

The duration for the number of times a user can request a registration verification email before being rate limited.

`tenants[x].rateLimitConfiguration.sendTwoFactor.limit`IntegerAvailable since 1.30.0

The number of times a user can request a two-factor code by email or SMS within the configured **timePeriodInSeconds** duration.

`tenants[x].rateLimitConfiguration.sendTwoFactor.timePeriodInSeconds`IntegerAvailable since 1.30.0

The duration for the number of times a user can request a two-factor code by email or SMS before being rate limited.

`tenants[x].registrationConfiguration.blockedDomains`Array<String>optionalAvailable since 1.30.0

A list of unique domains that are not allowed to register when self service is enabled.

`tenants[x].scimServerConfiguration.clientEntityTypeId`UUIDAvailable since 1.36.0

The Entity Type that will be used to represent SCIM Clients for this tenant.

`tenants[x].scimServerConfiguration.enabled`BooleanAvailable since 1.36.0

Whether or not this tenant has the SCIM endpoints enabled.

`tenants[x].scimServerConfiguration.schemas`MapAvailable since 1.36.0

JSON formatted as a SCIM Schemas endpoint response. Because the SCIM lambdas may modify the JSON response, ensure the Schema's response matches that generated by the response lambdas. [More about Schema definitions.](https://datatracker.ietf.org/doc/html/rfc7643#section-7)

`tenants[x].scimServerConfiguration.serverEntityTypeId`UUIDAvailable since 1.36.0

The Entity Type that will be used to represent SCIM Servers for this tenant.

`tenants[x].ssoConfiguration.deviceTrustTimeToLiveInSeconds`IntegerAvailable since 1.30.2

The number of seconds before a trusted device is reset. When reset, a user is forced to complete captcha during login and complete two-factor authentication if applicable.

`tenants[x].ssoConfiguration.allowAccessTokenBootstrap`BooleanAvailable since 1.56.0

When enabled, an SSO session can be created after login by providing an access token as a bearer token in a request to the OAuth2 Authorize endpoint.

`tenants[x].state`StringAvailable since 1.22.0

The current state of the tenant. The following are valid values:

*   `Active` - The tenant is active.
*   `PendingDelete` - A delete request has been requested and is being processed.

`tenants[x].themeId`UUIDAvailable since 1.8.0

The unique Id of the theme to be used to style the login page and other end user templates.

`tenants[x].userDeletePolicy.unverified.enabled`BooleanAvailable since 1.13.0

Indicates that users without a verified email address will be permanently deleted after **tenants\[x\].userDeletePolicy.unverified.numberOfDaysToRetain** days.

`tenants[x].userDeletePolicy.unverified.enabledInstant`LongAvailable since 1.48.0

The [instant](https://fusionauth.io/docs/reference/data-types.md#instants) that this policy was enabled.

Users created before this time will not be eligible to be deleted. This means that you can safely enable this feature and the policy will only be enforced for users created after this policy was enabled. If you would like to delete users created prior to this policy being enabled that have an unverified email address, you can use the User Search API or User Bulk Delete API to search on the `insertInstant` and **verified** fields to identify users that you would like to delete.

For example, the following query string will return users that were created at least 7 days ago that have not verified their email address.

```plaintext
insertInstant:<now-7d AND verified:false
```

Please note that prior to version `1.48.0`, when enabling this policy all user's with an unverified email were eligible for deletion.

`tenants[x].userDeletePolicy.unverified.numberOfDaysToRetain`IntegerAvailable since 1.13.0

The number of days from creation users will be retained before being deleted for not completing email verification. Value must be greater than 0.

`tenants[x].usernameConfiguration.unique.enabled`BooleanAvailable since 1.27.0

When `true`, FusionAuth will handle username collisions by generating a random suffix. Users with colliding usernames will be able to use the same one, but in the admin and API interfaces, a unique username will be displayed.

`tenants[x].usernameConfiguration.unique.numberOfDigits`IntegerAvailable since 1.27.0

The maximum number of digits to use when building a unique suffix for a username. A number will be randomly selected and will be 1 or more digits up to this configured value in length. For example, if this value is `5`, the suffix will be a number between `00001` and `99999`, inclusive.

`tenants[x].usernameConfiguration.unique.separator`StringAvailable since 1.27.0

A single character to use as a separator from the requested username and a unique suffix that is added when a duplicate username is detected. This value can be a single non alphanumeric ASCII character.

`tenants[x].usernameConfiguration.unique.strategy`StringAvailable since 1.29.0

This strategy instructions FusionAuth when to append a unique suffix to the username. The possible values are:

*   `Always` - Always append a unique suffix even when the requested username is not in use.
*   `OnCollision` - Only append a unique suffix when the requested username is in use.

`tenants[x].webAuthnConfiguration.bootstrapWorkflow.authenticatorAttachmentPreference`StringAvailable since 1.41.0

The authenticator attachment requirement for WebAuthn passkey registration when using the bootstrap workflow. The possible values are:

*   `any` - An authenticator with any attachment modality will be allowed during registration.
*   `crossPlatform` - Only authenticators with the `cross-platform` attachment modality will be allowed during registration. These are also referred to as "roaming" authenticators.
*   `platform` - Only authenticators with the `platform` attachment modality will be allowed during registration.

`tenants[x].webAuthnConfiguration.bootstrapWorkflow.enabled`BooleanAvailable since 1.41.0

Whether the WebAuthn bootstrap workflow is enabled.

`tenants[x].webAuthnConfiguration.bootstrapWorkflow.userVerificationRequirement`StringAvailable since 1.41.0

The user verification requirement for WebAuthn passkey registration and authentication when using the bootstrap workflow. The possible values are:

*   `discouraged` - If possible, do not require user verification during registration and authentication.
*   `preferred` - Prefer authenticators that support user verification during registration and authentication but allow others.
*   `required` - Only authenticators that support user verification will be allowed.

`tenants[x].webAuthnConfiguration.debug`BooleanAvailable since 1.41.0

Whether debug event log output is enabled for WebAuthn.

`tenants[x].webAuthnConfiguration.enabled`BooleanAvailable since 1.41.0

Whether WebAuthn configuration is enabled.

`tenants[x].webAuthnConfiguration.reauthenticationWorkflow.authenticatorAttachmentPreference`StringAvailable since 1.41.0

The authenticator attachment requirement for WebAuthn passkey registration when using the reauthentication workflow. The possible values are:

*   `any` - An authenticator with any attachment modality will be allowed during registration.
*   `crossPlatform` - Only authenticators with the `cross-platform` attachment modality will be allowed during registration. These are also referred to as "roaming" authenticators.
*   `platform` - Only authenticators with the `platform` attachment modality will be allowed during registration.

`tenants[x].webAuthnConfiguration.reauthenticationWorkflow.enabled`BooleanAvailable since 1.41.0

Whether the WebAuthn reauthentication workflow is enabled.

`tenants[x].webAuthnConfiguration.reauthenticationWorkflow.userVerificationRequirement`StringAvailable since 1.41.0

The user verification requirement for WebAuthn passkey registration and authentication when using the reauthentication workflow. The possible values are:

*   `discouraged` - If possible, do not require user verification during registration and authentication.
*   `preferred` - Prefer authenticators that support user verification during registration and authentication but allow others.
*   `required` - Only authenticators that support user verification will be allowed.

`tenants[x].webAuthnConfiguration.relyingPartyId`StringAvailable since 1.41.0

The Relying Party Id the tenant will use in WebAuthn ceremonies. Passkeys can only be used to authenticate on sites using the same Relying Party Id they were registered with.

The default value is `null`, which instructs the [WebAuthn JavaScript API](https://developer.mozilla.org/en-US/docs/Web/API/Web_Authentication_API) to use the browser origin.

`tenants[x].webAuthnConfiguration.relyingPartyName`StringAvailable since 1.41.0

The Relying Party name the tenant will use in WebAuthn ceremonies. This value is used only for display and may be shown by browser or OS dialogs during WebAuthn ceremonies.

If no value is configured, the **tenant.issuer** value will be used.

`total`Integer

The total number of Tenants matching the search criteria. Use this value along with the **numberOfResults** and **startRow** in the Search request to perform pagination.

*Example Response JSON for Tenant Search*

```json
{
  "tenants": [
    {
      "accessControlConfiguration": {
        "uiIPAccessControlListId": "11d49de7-69f6-46fc-8270-0b3aa626327a"
      },
      "configured": true,
      "captchaConfiguration": {
        "captchaMethod": "GoogleRecaptchaV3",
        "enabled": false,
        "threshold": 0.5
      },
      "connectorPolicies": [
        {
          "connectorId": "e3306678-a53a-4964-9040-1c96f36dda72",
          "domains": [
            "*"
          ],
          "migrate": false
        },
        {
          "connectorId": "27f22280-7e55-4d1c-b9f8-239bf9cc1a5e",
          "domains": [
            "*"
          ],
          "migrate": true
        }
      ],
      "data": {
        "description": "No more secrets, Marty."
      },
      "emailConfiguration": {
        "additionalHeaders": [
          {
            "name": "X-SES-CONFIGURATION-SET",
            "value": "example_configuration_set_name"
          }
        ],
        "defaultFromEmail": "jared@piedpiper.com",
        "defaultFromName": "Jared Dunn",
        "emailUpdateEmailTemplateId": "ec3045c7-97d8-47f8-8725-61b93deacf5d",
        "emailVerifiedEmailTemplateId": "1c3045c7-97d8-47f8-8725-61b93deacf5d",
        "forgotPasswordEmailTemplateId": "49aba1de-0225-45d7-a2b1-f9fe46b0242c",
        "host": "smtp.sendgrid.net",
        "implicitEmailVerificationAllowed": true,
        "loginIdInUseOnCreateEmailTemplateId": "1c3045c7-97d8-47f8-8725-61b93deacf5d",
        "loginIdInUseOnUpdateEmailTemplateId": "2c3045c7-97d8-47f8-8725-61b93deacf5d",
        "loginNewDeviceEmailTemplateId": "3c3045c7-97d8-47f8-8725-61b93deacf5d",
        "loginSuspiciousEmailTemplateId": "4c3045c7-97d8-47f8-8725-61b93deacf5d",
        "password": "password",
        "passwordlessEmailTemplateId": "a917e23a-da58-4cda-be01-90f542f8c343",
        "passwordResetSuccessEmailTemplateId": "5c3045c7-97d8-47f8-8725-61b93deacf5d",
        "passwordUpdateEmailTemplateId": "6c3045c7-97d8-47f8-8725-61b93deacf5d",
        "port": 587,
        "properties": {
          "key": "value"
        },
        "security": "TLS",
        "setPasswordEmailTemplateId": "a9aba13e-0125-4fd7-a2b1-aaa146b02423",
        "twoFactorMethodAddEmailTemplateId": "7c3045c7-97d8-47f8-8725-61b93deacf5d",
        "twoFactorMethodRemoveEmailTemplateId": "8c3045c7-97d8-47f8-8725-61b93deacf5d",
        "unverified": {
          "allowEmailChangeWhenGated": false,
          "behavior": "Allow"
        },
        "username": "username",
        "verificationEmailTemplateId": "8da42c09-461c-45f3-b931-6e9f63b87ab5",
        "verificationStrategy": "FormField",
        "verifyEmail": true,
        "verifyEmailWhenChanged": true
      },
      "eventConfiguration": {
        "events": {
          "user.delete": {
            "enabled": true,
            "transactionType": "None"
          },
          "user.create": {
            "enabled": true,
            "transactionType": "None"
          },
          "user.update": {
            "enabled": true,
            "transactionType": "None"
          },
          "user.deactivate": {
            "enabled": true,
            "transactionType": "None"
          },
          "user.bulk.create": {
            "enabled": true,
            "transactionType": "None"
          },
          "user.reactivate": {
            "enabled": true,
            "transactionType": "None"
          },
          "jwt.refresh": {
            "enabled": true,
            "transactionType": "None"
          },
          "jwt.refresh-token.revoke": {
            "enabled": true,
            "transactionType": "None"
          },
          "jwt.public-key.update": {
            "enabled": true,
            "transactionType": "None"
          },
          "user.login.success": {
            "enabled": true,
            "transactionType": "None"
          },
          "user.login.failed": {
            "enabled": true,
            "transactionType": "None"
          },
          "user.password.breach": {
            "enabled": true,
            "transactionType": "None"
          },
          "user.registration.create": {
            "enabled": true,
            "transactionType": "None"
          },
          "user.registration.update": {
            "enabled": true,
            "transactionType": "None"
          },
          "user.registration.delete": {
            "enabled": true,
            "transactionType": "None"
          },
          "user.registration.verified": {
            "enabled": true,
            "transactionType": "None"
          },
          "user.email.verified": {
            "enabled": true,
            "transactionType": "None"
          }
        }
      },
      "externalIdentifierConfiguration": {
        "authorizationGrantIdTimeToLiveInSeconds": 30,
        "changePasswordIdGenerator": {
          "length": 32,
          "type": "randomBytes"
        },
        "changePasswordIdTimeToLiveInSeconds": 600,
        "deviceCodeTimeToLiveInSeconds": 1800,
        "deviceUserCodeIdGenerator": {
          "length": 6,
          "type": "randomAlphaNumeric"
        },
        "emailVerificationIdGenerator": {
          "length": 32,
          "type": "randomBytes"
        },
        "emailVerificationIdTimeToLiveInSeconds": 86400,
        "emailVerificationOneTimeCodeGenerator": {
          "length": 6,
          "type": "randomAlphaNumeric"
        },
        "externalAuthenticationIdTimeToLiveInSeconds": 300,
        "loginIntentTimeToLiveInSeconds": 1800,
        "oneTimePasswordTimeToLiveInSeconds": 60,
        "passwordlessLoginGenerator": {
          "length": 32,
          "type": "randomBytes"
        },
        "passwordlessLoginTimeToLiveInSeconds": 180,
        "pendingAccountLinkTimeToLiveInSeconds": 3600,
        "phoneVerificationIdGenerator": {
          "length": 32,
          "type": "randomBytes"
        },
        "phoneVerificationIdTimeToLiveInSeconds": 86400,
        "phoneVerificationOneTimeCodeGenerator": {
          "length": 6,
          "type": "randomAlphaNumeric"
        },
        "registrationVerificationIdGenerator": {
          "length": 32,
          "type": "randomBytes"
        },
        "registrationVerificationIdTimeToLiveInSeconds": 86400,
        "registrationVerificationOneTimeCodeGenerator": {
          "length": 6,
          "type": "randomAlphaNumeric"
        },
        "rememberOAuthScopeConsentChoiceTimeToLiveInSeconds": 2592000,
        "samlv2AuthNRequestIdTimeToLiveInSeconds": 300,
        "setupPasswordIdGenerator": {
          "length": 32,
          "type": "randomBytes"
        },
        "setupPasswordIdTimeToLiveInSeconds": 86400,
        "twoFactorIdTimeToLiveInSeconds": 300,
        "twoFactorOneTimeCodeIdGenerator": {
          "length": 6,
          "type": "randomDigits"
        },
        "twoFactorOneTimeCodeIdTimeToLiveInSeconds": 60,
        "twoFactorTrustIdTimeToLiveInSeconds": 2592000,
        "webAuthnAuthenticationChallengeTimeToLiveInSeconds": 180,
        "webAuthnRegistrationChallengeTimeToLiveInSeconds": 180
      },
      "failedAuthenticationConfiguration": {
        "actionDuration": 3,
        "actionDurationUnit": "MINUTES",
        "resetCountInSeconds": 60,
        "tooManyAttempts": 5,
        "userActionId": "16cfc707-268c-4c5b-8989-f71f3ee156d4"
      },
      "familyConfiguration": {
        "allowChildRegistrations": true,
        "confirmChildEmailTemplateId": "87654321-4321-8765-ba09-ba0987654321",
        "deleteOrphanedAccounts": false,
        "deleteOrphanedAccountsDays": 30,
        "enabled": true,
        "familyRequestEmailTemplateId": "57462514-a73b-cd76-0001-b8a65cd61230",
        "maximumChildAge": 12,
        "minimumOwnerAge": 21,
        "parentEmailRequired": false,
        "parentRegistrationEmailTemplateId": "12345678-1234-5678-90ab-1234567890ab"
      },
      "formConfiguration": {
        "adminUserFormId": "e92751a5-25f4-4bca-ad91-66cdf67725d2"
      },
      "httpSessionMaxInactiveInterval": 3600,
      "id": "32306536-3036-6431-3865-646430303332",
      "insertInstant": 1572469040579,
      "issuer": "https://example.com",
      "jwtConfiguration": {
        "accessTokenKeyId": "025233ca-d4f3-2aa4-eca9-7e4200e9b472",
        "enabled": true,
        "idTokenKeyId": "092dbedc-30af-4149-9c61-b578f2c72f59",
        "refreshTokenExpirationPolicy": "Fixed",
        "refreshTokenRevocationPolicy": {
          "onLoginPrevented": true,
          "onPasswordChanged": true
        },
        "refreshTokenTimeToLiveInMinutes": 43200,
        "refreshTokenUsagePolicy": "Reusable",
        "timeToLiveInSeconds": 3600
      },
      "lambdaConfiguration": {
        "loginValidationId": "c0dd79db-38dd-424b-b77a-4dccaad71052",
        "scimEnterpriseUserRequestConverterId": "c2e70f8d-19bb-4df7-848a-33a9a1e26b84",
        "scimEnterpriseUserResponseConverterId": "44fc9553-8a2e-408f-8aa2-fa65b70b55e2",
        "scimGroupRequestConverterId": "66d65de0-1819-42f8-86ed-7daaa4e155dc",
        "scimGroupResponseConverterId": "79812ede-432f-4375-9b43-23c0fe996fef",
        "scimUserRequestConverterId": "8a51d7a1-5e3e-442a-b96a-0c31379bb3d4",
        "scimUserResponseConverterId": "c8720843-dc4f-4e6c-b6ca-500e9c44695f"
      },
      "lastUpdateInstant": 1595361143101,
      "loginConfiguration": {
        "requireAuthentication": true
      },
      "logoutURL": "http://example.com/logout",
      "maximumPasswordAge": {
        "days": 180,
        "enabled": false
      },
      "minimumPasswordAge": {
        "enabled": false,
        "seconds": 30
      },
      "multiFactorConfiguration": {
        "authenticator": {
          "algorithm": "HmacSHA1",
          "codeLength": 6,
          "enabled": true,
          "timeStep": 30
        },
        "email": {
          "enabled": true,
          "templateId": "d312fb71-d7d8-4b75-a497-6096a07220b3"
        },
        "sms": {
          "enabled": true,
          "messengerId": "0a4bae38-ffef-4c33-b74c-1d50c796f600",
          "templateId": "f35e04e6-72ec-4f52-b552-29cf950a4ed6"
        }
      },
      "name": "Playtronics Co.",
      "oauthConfiguration": {
        "clientCredentialsAccessTokenPopulateLambdaId": "46e120c1-4c22-473f-95b4-e2c187cd20c2"
      },
      "passwordEncryptionConfiguration": {
        "encryptionScheme": "salted-pbkdf2-hmac-sha256",
        "encryptionSchemeFactor": 24000,
        "modifyEncryptionSchemeOnLogin": false
      },
      "passwordValidationRules": {
        "breachDetection": {
          "enabled": true,
          "notifyUserEmailTemplateId": "e6c74b53-d43d-471e-ae7e-906456d0f341",
          "matchMode": "High",
          "onLogin": "Off"
        },
        "maxLength": 256,
        "minLength": 8,
        "rememberPreviousPasswords": {
          "count": 2,
          "enabled": true
        },
        "requireMixedCase": true,
        "requireNonAlpha": true,
        "requireNumber": true,
        "validateOnLogin": false
      },
      "phoneConfiguration": {
        "forgotPasswordTemplateId": "f90c8a8f-db77-4f2f-a3dd-5f692faf5d55",
        "identityUpdateTemplateId": "77df7e94-2dbf-44ab-b58c-06ac4224c449",
        "implicitPhoneVerificationAllowed": false,
        "loginIdInUseOnCreateTemplateId": "7880dac6-809b-489e-8a69-363b043dd0f4",
        "loginIdInUseOnUpdateTemplateId": "de14b495-a358-4941-bb6b-0ddce04370ef",
        "loginNewDeviceTemplateId": "d77ac611-ddff-4a06-903c-fafe5c1f9f7a",
        "loginSuspiciousTemplateId": "73a8408a-e857-4ce2-82bb-d15b94d7c709",
        "messengerId": "22a2ec45-39de-439a-a41c-eb7666b3b051",
        "passwordResetSuccessTemplateId": "6a0f3a7a-3511-4936-a546-3bd8f68dbdd3",
        "passwordUpdateTemplateId": "3ca81208-5678-434f-92b8-7fcc3b62bc7a",
        "passwordlessTemplateId": "e8449783-60a7-483f-8c66-bcdf0d05705f",
        "setPasswordTemplateId": "a6655c95-d94c-4dea-8191-0190f562bc39",
        "twoFactorMethodAddTemplateId": "c450521d-7f39-4a21-ba02-ced83225efcc",
        "twoFactorMethodRemoveTemplateId": "fba4fe64-3a29-45f8-895f-520d73d93659",
        "unverified": {
          "allowPhoneNumberChangeWhenGated": false,
          "behavior": "Allow"
        },
        "verificationCompleteTemplateId": "7b6b80bd-e3a5-42ff-b333-93ef37c192df",
        "verificationStrategy": "ClickableLink",
        "verificationTemplateId": "c96ed02d-fbc6-4b27-9e74-54444747d18a",
        "verifyPhoneNumber": true
      },
      "scimServerConfiguration": {
        "clientEntityTypeId": "d9ed49f7-1106-4b20-acdb-5cbda76ae77e",
        "enabled": true,
        "serverEntityTypeId": "919e0ac5-1cf0-4fcf-a8fc-29d77a0d1d8f",
        "schemas": {}
      },
      "ssoConfiguration": {
        "allowAccessTokenBootstrap": false,
        "deviceTrustTimeToLiveInSeconds": 31536000
      },
      "state": "Active",
      "themeId": "c6ad3fac-6f32-4db7-91a4-061ff035e871",
      "userDeletePolicy": {
        "unverified": {
          "enabled": true,
          "enabledInstant": 1698772159415,
          "numberOfDaysToRetain": 30
        }
      },
      "usernameConfiguration": {
        "unique": {
          "enabled": false,
          "numberOfDigits": 5,
          "separator": "#",
          "strategy": "OnCollision"
        }
      },
      "webAuthnConfiguration": {
        "enabled": true,
        "bootstrapWorkflow": {
          "authenticatorAttachmentPreference": "crossPlatform",
          "enabled": true,
          "userVerificationRequirement": "required"
        },
        "debug": false,
        "reauthenticationWorkflow": {
          "authenticatorAttachmentPreference": "platform",
          "enabled": true,
          "userVerificationRequirement": "required"
        },
        "relyingPartyId": "piedpiper.com",
        "relyingPartyName": "Pied Piper"
      }
    }
  ],
  "total": 1
}
```