For AI agents: The complete documentation index is available at
/docs/llms.txt
. A markdown version of this page is available at
/help.md
.
/
Docs
Resources
Docs
Articles
Blog
Release Notes
Install
Light
Dark
System
Log In
Get a demo
Resources
Docs
Articles
Blog
Release Notes
Install
Light
Dark
System
FusionAuth Help
Edit on GitHub
Edit
MD
Copy
Edit on GitHub
Edit
View Markdown
Copy Markdown
Search
⌘
K
Get Started
Overview
Install
Docker
First Time Setup
Upgrade
fusionauth-app
Install a Database
Install a Search Engine
Start & Stop
Development
Access from the Internet
API MCP Server
Docs MCP Server
Kickstart
Kubernetes
Overview
Deploy with k8s
Elastic Kubernetes Service (EKS)
Google Kubernetes Engine (GKE)
Local Cluster with minikube
Microsoft Azure Kubernetes Service (AKS)
Install Reference
Air-gapping
Collected Metrics
Customize Docker Images
Packages
Server Layout
Silent Mode
System Requirements
Product Tour
Step 1 - Install FusionAuth
Step 2 - Login Button
Step 3 - Protected Pages
Step 4 - Role-Based Access Control
Step 5 - Session Management
Step 6 - Logout
Step 7 - Testing
Step 8 - Finished
QuickStarts
Overview
Web
Overview
Express
.NET
Drupal
Golang
Laravel
Next.js
Nuxt
PHP
Python Django
Python Flask
Remix
Ruby on Rails
Rust with Actix
Spring Boot With Thymeleaf
WordPress
Single-page App
Overview
React
Angular
Vue.js
App
Overview
Android Java - AppAuth
Android Kotlin - Fusionauth SDK
Flutter
iOS Swift - AppAuth
iOS Swift - FusionAuth SDK
React Native
API
Overview
.NET API
Golang API
Laravel API
Node.js/Express.js API
Ruby on Rails API
Spring Boot API
Core Concepts
Authentication and Authorization
Identity Providers
Login Pages - Hosted or API
Licensing
Plans and Features
Integration Points
Localization and Internationalization
OAuth Scopes
Types
Overview
Tenants
Applications
Users
Registrations
Roles
Groups
Entity Management
Limitations
Use Cases
Overview
Auth as a Service
App Suite
Business To Business To Consumer
Business To Business To Employee
Machine To Machine Communication
Identity Broker
Authorization Hub
API Consents Platform
Install from a Marketplace
Overview
AWS
DigitalOcean
GitHub Actions
Google Cloud
Render
Customize
Themes
Overview
Customize Advanced Themes
Overview
Upgrade an Advanced Theme
Advanced Theme Upgrade Notes
Theme Examples
Add a Theme to a Kickstart
Tailwind CSS
Theme Template Variables
Themes Helper Macros
Simple Theme Editor
Application-Specific Themes
Client-side Password Rule Validation
Theme Localization
Email & Messages
Overview
Application Email Templates
Add a Custom Generic Messenger
Messengers
Send Messages with Twilio
Configure SMTP
Email Templates
Email Variables
Message Templates
Message Variables
Pre-1.26 2FA
Overview
Twilio Integration
Two-Factor with Google Authenticator
Two-Factor with Twilio Push Notifications
FusionAuth CLI
Operate
Deploy
Overview
FusionAuth and Proxies
FusionAuth And Terraform
FusionAuth Cluster Setup
Upgrade FusionAuth
User Support Guide
Monitor
Overview
CloudWatch
Datadog
Elastic
OpenTelemetry
Prometheus, Loki, And Grafana
Slack
Splunk
Roadmap
Overview
Deprecation Policy
Releases
Secure
Overview
Advanced Threat Detection
Breached Password Detection
Compliance Frameworks
CORS Reference
Key Master
Key Rotation
Networking Configuration
Token Storage
Troubleshooting
Overview
1.69.0 Key Configuration Migration Guide
Technical Support
Extend
Events & Webhooks
Overview
Events
Overview
Audit Log Create
Event Log Create
JWT
Public Key Update
Refresh
Refresh Token Revoke
Kickstart Success
Entity
Create
Create Complete
Delete
Delete Complete
Update
Update Complete
Group
Create
Create Complete
Delete
Delete Complete
Member Add
Member Add Complete
Member Remove
Member Remove Complete
Member Update
Member Update Complete
Update
Update Complete
User
Action
Bulk Create
Create
Create Complete
Deactivate
Delete
Delete Complete
Email Update
Email Verified
Identity Provider Link
Identity Provider Unlink
Identity Verified
Reactivate
Two-factor Challenge
Two-factor Failed Attempt
Two-factor Method Add
Two-factor Method Remove
Two-Factor Success
Update
Update Complete
Login
Failed
Id Duplicate Create
Id Duplicate Update
New Device
Success
Suspicious
Password
Breach
Reset Send
Reset Start
Reset Success
Update
Registration
Create
Create Complete
Delete
Delete Complete
Update
Update Complete
Verified
Kafka Integration
Overview
Secure Webhooks
Sign Webhooks
Webhook Event Log
Write a Webhook
Fine-Grained Authorization
Code
Lambdas
Overview
Call an API from a Lambda
Test Lambdas
Client Credentials JWT Populate Lambda
JWT Populate Lambda
Login Validation Lambda
MFA Requirement Lambda
SAML v2 Populate Lambda
SCIM Group Request Converter Lambda
SCIM Group Response Converter Lambda
SCIM User Request Converter Lambda
SCIM User Response Converter Lambda
Self-Service Registration Validation Lambda
UserInfo Populate Lambda
Reconcile
Apple Reconcile Lambda
Epic Games Reconcile Lambda
External JWT Reconcile Lambda
Facebook Reconcile Lambda
Google Reconcile Lambda
HYPR Reconcile Lambda
LDAP Connector Reconcile Lambda
LinkedIn Reconcile Lambda
Nintendo Reconcile Lambda
OpenID Connect Reconcile Lambda
SAML v2 Reconcile Lambda
Sony PlayStation Network Reconcile Lambda
Steam Reconcile Lambda
Twitch Reconcile Lambda
Twitter Reconcile Lambda
Xbox Reconcile Lambda
Plugins
Overview
Custom Password Hashing
Writing a Plugin
Examples
5 Minute Intro
Overview
Docker Install
Fast Path Install
Sandbox
API Gateways
Overview
Amazon API Gateway
Cloudflare Worker Functions (API Gateway)
HAProxy API Gateway
Kong Gateway
ngrok Cloud Edge
Securing your APIs with FusionAuth
Control MCP Server Access
Device Limiting
Example Applications
Modeling Hierarchies
Modeling Organizations
Multi-Application Dashboard
Multi-tenancy
Twilio Segment
Lifecycle
Overview
Migrate Users
Overview
Connectors
Overview
FusionAuth Connector
Generic Connector
LDAP Connector
Export from FusionAuth
Generic Migration Tutorial
SCIM
Overview
Azure AD SCIM Client
Okta SCIM Client
SCIM-SDK
Framework Specific
Migrate From Passport
Migrate From Rails
Provider Specific
Migrate From Akamai
Migrate From Amazon Cognito
Migrate From Auth0
Migrate From Duende IdentityServer
Migrate From Firebase
Migrate From Forgerock
Migrate From Frontegg
Migrate From Keycloak
Migrate From Microsoft Azure AD B2C
Migrate From Ping Identity
Migrate From Stytch
Migrate From Supabase
Migrate From Userfront
Migrate From WordPress
Register Users
Overview
Advanced Registration Forms
Anonymous Users
Complete Registration
Register A User And Login
Self-service Registration
Authenticate Users
Add an Identity Provider (IdP)
Overview
Add an OpenID Connect IdP
Add an External SAML v2 IdP
Add an External JWT IdP
Overview
External JWT IdP Example Usage
Enterprise
Add a HYPR IdP
Add a OpenID Connect with Cognito IdP
Add a SAML v2 IdP-Initiated IdP
Add a SAML v2 IdP-Initiated with Okta IdP
Add a SAML v2 with ADFS IdP
Add a SAML v2 with Azure AD IdP
Add a SAML v2 with Okta IdP
Add an OpenID Connect with Azure AD IdP
Add an OpenID Connect with Okta IdP
Gaming
Add a Nintendo IdP
Add a Sony PlayStation Network IdP
Add a Steam IdP
Add a Twitch IdP
Add an Epic Games IdP
Add an OpenID Connect with Discord IdP
Add an Xbox IdP
Social
Add a Facebook IdP
Add a Github IdP
Add a Google IdP
Add a LinkedIn IdP
Add a Twitter/X IdP
Add an Apple IdP
Build a Login Page with the Login API
Overview
JSON Web Tokens
OAuth
Overview
Access Control with OAuth Scopes
Manage Software Tokens
Modes
OAuth DPoP
OAuth Issuer Validation
OAuth Response Modes
OIDC Prompt
URL Validation
One-Time Passwords
Overview
Configure
Customize
Passkeys
Overview
Configure
Customize
Application Authentication Tokens
Contextual Multi-Factor Authentication (MFA)
Host a SAML v2 Identity Provider
Implementing Single Sign-on
Logout And Session Management
Multi-Factor Authentication (MFA)
Risk Signals
Setting Up User Account Lockout
Integrations
OpenID Connect Integrations
Overview
OIDC & CockroachDB
OIDC & Salesforce
OIDC & Tableau Cloud
SAML
Overview
SAML v2 & Aiven
SAML v2 & Google
SAML v2 & PagerDuty
SAML v2 & SendGrid
SAML v2 & Tableau Cloud
SAML v2 & Zendesk
Manage Users
Self-Service Account Management
Overview
Account Troubleshooting
Add Authenticator as a second factor
Add Email as a second factor
Add Phone as a second factor
Add WebAuthn Passkey
Bootstrapping Login For Self-Service Account Management
Customizing Self-Service Account Management
Update User Profiles and Passwords
Tenant Manager App
CleanSpeak Integration
Custom Admin Forms
How To Use User Actions
Search
Overview
Searching Users With Elasticsearch or OpenSearch
Switching Search Engines
Verification
Gate Users Application Registration
Gate Users Until They Verify Their Email
Gate Users Until They Verify Their Phone
Identity Pre-Verification Using Email Verification Form
Identity Pre-Verification Using Phone Verification Form
Identity Pre-Verification Via API
Registration-based Email Verification
Client Libraries and SDKs
Overview
Example Apps
Overview
.NET Core Example Apps
Go Example Apps
Java Example Apps
PHP Example Apps
Python Example Apps
Ruby Example Apps
Typescript, Node and JavaScript Example Apps
OpenAPI Specification
React SDK
Vue SDK
Angular SDK
Kotlin SDK for Android
Swift SDK for iOS
.NET Core Client Library
Go Client Library
Java Client Library
PHP Client Library
Python Client Library
Ruby Client Library
TypeScript Client Library
Reference
API Endpoints Guarded by API Keys
Authentication Types
Configuration Reference
Data Types
GDPR Compliance
Indexed Entity Fields
Indexed User Fields
Login Page Cookies
Password-Hashing Algorithms
Required Network Hostname Access
APIs
Overview
Authenticate with our APIs
Configure CORS
Error Responses
Identity Provider
Overview
Apple
Epic Games
External JWT
Facebook
Google
HYPR
LinkedIn
Links
Nintendo
OpenID Connect
SAML v2
SAML v2 IdP Initiated
Sony PlayStation Network
Steam
Test
Twitch
Twitter/X
Xbox
Messenger
Overview
Generic Messenger
Twilio Messenger
SCIM
Overview
EnterpriseUser
Group
Service Provider
User
Connector
Overview
Generic Connector
LDAP Connector
Custom Form
Form
Form Field
Entity
Overview
Entity
Entity Type
Grant
Theme
Advanced Themes
Simple Themes
API Keys
Overview
Create an API Key
Retrieve an API Key
Update an API Key
Delete an API Key
Application
Overview
Create an Application
Retrieve an Application
Update an Application
Search for Applications
Delete an Application
Reactivate an Application
Create an Application Role
Update an Application Role
Delete an Application Role
Retrieve OAuth Configuration
Audit Log
Overview
Search the Audit Log
Add an Entry to the Audit Log
Retrieve an Audit Log
Export Audit Logs
Consent
Overview
Create a Consent
Retrieve a Consent
Update a Consent
Delete a Consent
Search for Consents
Grant a User Consent
Retrieve a User Consent
Update a User Consent
Revoke a User Consent
Email
Overview
Create an Email Template
Retrieve an Email Template
Search for Email Templates
Update an Email Template
Delete an Email Template
Preview an Email Template
Send an Email
Event Log
Family
Overview
Add a User to a Family
Retrieve a Family
Update a Family
Remove a User from a Family
Retrieve Pending Family Members
Request Parental Approval
Group
Overview
Create a Group
Retrieve a Group
Update a Group
Delete a Group
Search for Groups
Add Users to a Group
Update Users in a Group
Remove Users from a Group
Search for Group Members
Hosted Backend
Identity Verify
Integration
IP Access Control List
Overview
Create an IP ACL
Retrieve an IP ACL
Search for IP ACLs
Update an IP ACL
Delete an IP ACL
JWTs & Refresh Token
Overview
Issue a JWT
Reconcile a JWT Using the External JWT Provider
Retrieve Public Keys
Refresh a JWT
Retrieve Refresh Tokens
Revoke Refresh Tokens
Validate a JWT
Vend a JWT
Key
Overview
Retrieve a Key
Update a Key
Delete a Key
Search for Keys
Generate a Key
Import a Key
Lambda
Overview
Create a Lambda
Retrieve a Lambda
Search for Lambdas
Update a Lambda
Delete a Lambda
Login
Overview
Authenticate a User
Authenticate a User with a One Time Password
Complete Multi-Factor Authentication
Update Login Instant
Logout a User
Search Login Records
Export Login Records
Manage User Action
Overview
Create a User Action
Retrieve a User Action
Update a User Action
Delete a User Action
Reactivate a User Action
Message Template
Multi-Factor
Overview
Enable Multi-Factor
Disable Multi-Factor
Update Multi-Factor Method
Generate a Secret
Start Multi-Factor
Retrieve Multi-Factor Status
Send a Multi-Factor Code During Login or Step Up
Send a Multi-Factor Code When Enabling MFA
Send a Multi-Factor Code When Disabling MFA
Generate Recovery Codes
Retrieve Recovery Codes
OAuth Scopes
OAuth2
Overview
Authorize
Logout
Token
Device
Introspect
UserInfo
JSON Web Key Set (JWKS)
OpenID Configuration
OAuth Error Reference
Client Secret Reference
Passwordless
Overview
Start Passwordless Login
Send Passwordless Login
Complete a Passwordless Login
Reactor
Report
Overview
Retrieve Totals Report
Retrieve Daily Active Users Report
Retrieve Login Report
Retrieve Monthly Active Users Report
Retrieve Registration Report
System
Overview
Retrieve the System Configuration
Update the System Configuration
Export System Logs
Retrieve the Logging Level
Update the Logging Level
Rebuild the Elasticsearch index
Retrieve the status of an index rebuild
Retrieve System Status
Retrieve System Health
Retrieve System Version
Retrieve System Metrics Using Prometheus
Tenant Manager
Tenants
Overview
Create a Tenant
Retrieve a Tenant
Search for Tenants
Update a Tenant
Delete a Tenant
Retrieve the Password Validation Rules
User
Overview
Create a User
Retrieve a User
Update a User
Delete a User
Bulk Delete Users
Reactivate a User
Import Users
Import Refresh Tokens
Search for Users
Flush the Search Engine
Retrieve Recent Logins
Verify a User's Email
Resend Verification Email
Start Forgot Password Workflow
Validate a Password Change
Change a User's Password
User Action
User Action Reason
User Comment
Overview
Add a Comment to a User
Retrieve a User's Comments
Search for User Comments
User Registration
Overview
Create a User Registration (for an existing user)
Create a User and Registration (combined)
Retrieve a User Registration
Update a User Registration
Delete a User Registration
Verify a User Registration
Resend a User Registration Verification Email
WebAuthn
Overview
Retrieve a Passkey
Delete a Passkey
Import Passkeys
Start a WebAuthn Passkey Registration
Complete a WebAuthn Passkey Registration
Start a WebAuthn Passkey Assertion or Authentication
Complete a WebAuthn Passkey Authentication
Complete a WebAuthn Passkey Assertion
Webhook
Overview
Create a Webhook
Retrieve a Webhook
Update a Webhook
Delete a Webhook
Search for Webhooks
Webhook Event Log
Cloud
Overview
Account
Overview
Create
Delete
Create a Deployment
Upgrade a Deployment
Delete a Deployment
Operate
Custom Domains
Alter a Deployment
Proxy
Load Test
Migrate
Emigrate
Security
Test
Cloud vs Self-Hosted
Reference
FusionAuth Cloud Limits
Regions
Instance IP Addresses
SLA
Disaster Recovery
User Data
Support
Developer Tools
Overview
Base64 Encoder/Decoder
Epoch/Unix Time Converter
JWT Decoder
URL Encoder/Decoder
UUID Generator
Release Notes