Skip to main content
This feature is available only in Staging for testing and is not yet available in Production.
This guide shows how to manage partners from the Console. You create the partner, issue its credentials, and change or end its access later.

Before you start


You need the partners permission with the get action to open the page. To create a partner’s credentials, you also need the applications permission with the post action. Collect this information before you start:
  • The products the partner needs, and what it may do in each one.
  • The IDs of the items the partner may reach: for Midaz, at least the organization ID. Copy the IDs from the product’s own API or Console. The Console does not check that they exist.
  • The network addresses the partner calls from, if you want to restrict them.
  • The start and end dates of its access, if it has a time limit.

Open the Partners page


1

Open Settings

Click the gear icon () in the top navigation bar.
2

Select Partners

Select Partners in the Settings sidebar. The subtitle reads “Give each customer its own credentials and limit what it can reach.”
The page lists your partners. A partner that is not working shows a status badge: Suspended, Expired, or Not yet valid. With no partners yet, the page reads “You haven’t registered any partners yet”.

Create a partner


Click New partner. A wizard opens with five steps: Details, Products, Scope, Permissions, and Review. Next opens only when the current step is complete. Back keeps what you entered.
1

Details

Type the partner’s Name. Only your team sees this name, and it must be unique in your tenant.Under Validity window, fill in Valid from and Valid until if the access has a time limit. Leave Valid from empty to start now. Leave Valid until empty so it never expires.Under Where it calls from, choose one option:
  • Use your organization’s IP list: the partner uses your tenant’s IP allowlist.
  • Give it its own list: type the partner’s addresses or CIDR ranges. Its own list replaces your tenant’s list. An address that is only on your tenant’s list does not work for this partner.
2

Products

Choose the products the partner can use. The list shows only what your tenant has.A product that cannot take partners yet is greyed out with the message “This product isn’t ready for partners yet.” You cannot select it.
3

Scope

Say where the partner can act in each product. A restriction that the product requires is already open. For Midaz, that is the organization.To narrow the access, click Add restriction and choose the item under Restrict by, for example a ledger or an account. Type one ID, or several IDs separated by commas.Once you restrict a type by ID, the partner cannot list or create items of that type.
4

Permissions

Check the resources and the actions the partner can call on each product. To give a different set of actions on other resources, add a line with the product’s button, for example Add another line on Midaz.The Console offers only what your tenant can give. A line that cannot be saved shows its reason:
  • Not allowed: your tenant does not hold this permission.
  • Outside the scope: the write acts above the partner’s scope. For example, creating ledgers acts on the whole organization, so a partner restricted to one ledger cannot get it.
  • Granted twice: another line already grants the same action on the same resource.
5

Review

Under “Check what this partner can and can’t do”, read the summary. It can lists the actions, the items, and the IP list. It can’t lists what stays outside.Click Save. The Console creates the partner with no credentials. You issue them on its Applications tab.
If Access Manager refuses the partner, the Console shows “The Access Manager refused this change” and opens the step that holds the field to fix.

Issue the partner’s credentials


A partner without an application cannot call anything. Create one application per product.
1

Open the Applications tab

In the partner list, click the partner. Select the Applications tab.
2

Create the application

Click New Application. In the New application side sheet, choose the Product. Only products that the partner has permissions on are offered. Fill in Description and click Create application.
3

Copy the credentials

The dialog “Save the credentials” shows the client ID and the client secret. Copy both now. The client secret is shown only once. Click I’ve saved them to close the dialog.
4

Send the credentials to the partner

Send the client ID and the client secret to the partner through a secure channel. The partner’s system uses them to request access tokens.
Partner applications do not appear in Settings → Applications. They follow the partner’s permissions, scope, validity window, and IP list. If a client secret is lost, delete that application and create a new one. A new application comes with a new secret. When you delete an application, the partner’s program that uses it stops working at once.

Change a partner


Open the partner from the list. The detail page has five tabs: Saving on Permissions or Scope replaces the permissions and the scope together. A change applies from the partner’s next request.

Suspend or reactivate a partner


On the Overview tab, click Suspend and confirm. Every credential of the partner is refused from its next request, including tokens it already holds. Nothing is deleted. To give the access back, click Reactivate and confirm. The partner’s credentials work again from its next request. They are the same credentials as before.

Delete a partner


You can delete only a partner without applications.
1

Delete its applications

On the Applications tab, delete each application of the partner.
2

Delete the partner

On the Overview tab, click Delete partner and confirm. The partner loses access at once. Its permissions, scope, and IP list are deleted too. You cannot undo this.
If the partner still has applications, the Console lists them and offers Go to Applications.

Partners that use your tenant’s IP list


On Settings → Security, the IP allowlist tab shows how many partners use your tenant’s list. A change to that list also applies to those partners, from their next request. To make a partner independent of that list, give it its own list on its IPs tab.