PropelAuth Dashboard

The PropelAuth Dashboard is your control center for managing authentication, users, organizations, and settings for your applications. It provides an intuitive interface to configure various aspects of your authentication system without needing to write code.

PropelAuth Projects

In PropelAuth, a Project is the top-level container for your application. You can have multiple projects under your account, each representing a different application or service. Each project will have its own set of environments, users, organizations, settings, login methods, billing, and more.

You can create a new project by clicking on the + button in the top left corner of the dashboard.

Creating a new project

Managing Teammates

Users with the Owner or Admin roles can invite teammates to collaborate on your PropelAuth projects. To add a teammate, click on your avatar in the bottom left corner and click the settings button for your organization.

Accessing Org Settings

Next, click on Invite User and enter the email address of the teammate you want to invite. You can also assign them a role at this time.

User management page

On the same page you can also remove teammates or change their roles.

Managing Teammate Roles

PropelAuth provides several built-in roles to manage teammate permissions within your organization and PropelAuth projects. The available roles are:

  • Owner: Full access
  • Admin: Can do everything the Owner can except access billing information, configure impersonation permissions, and update your team's organization's settings (e.g., name, membership settings, 2FA requirements, etc.)
  • Developer: Can make project level configuration changes such as updating login methods, creating backend API keys, configuring MCP settings, and more. Developers cannot update billing information, create or manage users and organizations, or manage teammates.
  • Customer Management: Can create and manage users and organizations. This includes enabling Enterprise SSO/SCIM for organizations, blocking and unblocking users, inviting/adding users to organizations, and any other customer management tasks. Cannot make project level configuration changes, update billing information, or manage teammates.
  • Member: Members can create users and organizations, manage org membership, and make changes to org and user metadata. Members cannot block/unblock users, manage teammates, update billing information, or make most project level configuration changes.
  • ReadOnly: Read-only access to view users, organizations and settings without making any changes.

See below for a full list of roles and permissions.

User Permissions

Permission
OwnerAdminDeveloperCustomerManagementMemberReadOnly
View Users✅✅✅✅✅✅
View User Audit Logs✅✅✅✅✅✅
Create Users✅✅❌✅✅❌
Update User Properties✅✅❌✅✅❌
Block / Unblock Users✅✅❌✅❌❌
Reset User Password✅✅❌✅❌❌
Logout Users✅✅❌✅❌❌
Delete Users✅✅❌✅❌❌

Organization Permissions

Permission
OwnerAdminDeveloperCustomerManagementMemberReadOnly
View Organizations✅✅✅✅✅✅
View Organization Audit Logs✅✅✅✅✅✅
Create Organizations✅✅❌✅✅❌
Invite Users to Organizations✅✅❌✅✅❌
Add Users to Organizations✅✅❌✅✅❌
Remove Users from Organizations✅✅❌✅✅❌
Update Organization Metadata✅✅❌✅✅❌
Update Organization Membership Settings✅✅❌✅✅❌
Enable / Disable Enterprise SSO for Org✅✅❌✅✅❌
Generate Enterprise SSO Setup Link✅✅❌✅❌❌
Enable / Disable SCIM for Org✅✅❌✅❌❌
Delete Organizations✅✅❌✅❌❌
Convert Org to Isolated✅✅❌✅❌❌

End User API Key Permissions

Permission
OwnerAdminDeveloperCustomerManagementMemberReadOnly
View API Keys✅✅✅✅✅✅
Edit API Key Expiration✅✅❌✅✅❌
Archive API Keys✅✅❌✅❌❌
Delete API Keys✅✅❌✅❌❌

Project Permissions

Permission
OwnerAdminDeveloperCustomerManagementMemberReadOnly
View Project Audit Logs✅✅✅✅✅✅
Configure MCP Settings✅✅✅❌❌❌
Update Billing✅✅❌❌❌❌
Update Project Settings✅✅✅❌❌❌
Update Look & Feel✅✅✅❌✅❌
Update Signup / Login Settings✅✅✅❌❌❌
Update Enterprise SSO Settings✅✅✅❌❌❌
Update Email Settings✅✅✅❌❌❌
Update Organization Settings✅✅✅❌❌❌
Update Roles & Permissions✅✅✅❌❌❌
Update User Properties✅✅✅❌❌❌
Enable / Configure Integrations✅✅✅❌❌❌
Update API Key Settings✅✅✅❌❌❌
Update User Impersonation Permissions✅❌❌❌❌❌
Update Frontend Integration Configuration✅✅✅❌❌❌
Update OAuth Configuration✅✅✅❌❌❌
Generate Backend API Key✅✅✅❌❌❌
Configure Terraform Integration✅✅✅❌❌❌
Set / Update Custom Domain✅✅✅❌❌❌

Teammate Permissions

Permission
OwnerAdminDeveloperCustomerManagementMemberReadOnly
Invite Teammates✅✅❌❌❌❌
Update Teammate Roles✅✅❌❌❌❌
Remove Teammates✅✅❌❌❌❌
Update Membership Settings✅❌❌❌❌❌
Configure Enterprise SSO✅❌❌❌❌❌
Configure SCIM✅❌❌❌❌❌

Project Audit Logs

View project level actions that you and your teammates take on your project - from updating your look & feel to updating who can signup. The project audit logs can be found in the Data page of your PropelAuth Dashboard. For actions taken on or by your users, see the User and Org Audit Logs.

Project Audit Logs

Here is a full list of actions:

Pricing Plan UpdatedData Enrichment AddedSubscribed To Api Keys Add OnUnsubscribed To Api Keys Add On
Theme UpdatedPersonal Api Keys Enabled/DisabledOrg Api Keys Enabled/DisabledInvalidate Org Api Key Upon User Removal Enabled/Disabled
Api Key Config UpdatedHas Orgs Enabled/DisabledOrgs Metaname UpdatedUsers Can Create Orgs Enabled/Disabled
Users Can Delete Their Own Orgs Enabled/DisabledUsers Must Be In An Organization Enabled/DisabledOrgs Can Require 2fa Enabled/DisabledRequire Password For Email Confirmation Enabled/Disabled
Phone Mfa Enabled/DisabledAll Users Must Setup 2fa Enabled/DisabledMax Num Orgs Users Can Be In UpdatedEmail Integration Updated
Custom Email Configuration UpdatedAllow Public Signups Enabled/DisabledAllow Autojoin By Domain Enabled/DisabledAllow Personal Email Signups Enabled/Disabled
Allow Disposable Email Signups Enabled/DisabledInclude Login Method Enabled/DisabledWaitlist Users Enabled/DisabledWaitlist Users Require Email Confirmation Enabled/Disabled
Require Email Confirmation Enabled/DisabledUser Autologout Type/Seconds UpdatedPassword Login Enabled/DisabledPasswordless Login Enabled/Disabled
Orgs Can Setup Saml Enabled/DisabledOrgs Can View Org Audit Log Enabled/DisabledAll Orgs Can View Org Audit Log Enabled/DisabledOrg Audit Log Includes Api Keys Enabled/Disabled
Org Audit Log Includes Impersonation Enabled/DisabledOrg Audit Log Includes Employees Enabled/DisabledUsers Can View Personal Audit Log Enabled/DisabledPersonal Audit Log Includes Impersonation Enabled/Disabled
Personal Audit Log Includes Api Keys Enabled/DisabledPersonal Audit Log Includes Employees Enabled/DisabledSkip Saml Role Mappings Enabled/DisabledDefault To Saml Login Enabled/Disabled
Use Org Name For Saml Enabled/DisabledSocial Provider Enabled/DisabledUser Impersonation Enabled/DisabledProject Name Updated
Project DeletedProject Email Template Version UpdatedUsers Can Delete Own Account Enabled/DisabledScim Enabled/Disabled
Users Can Change Email Enabled/DisabledUser Impersonation Settings UpdatedPassword Requirements ChangedHosted Pages Overrides Changed
Require 2fa By Default Enabled/DisabledSignup Domain Allowlist Enabled/DisabledSignup Domain Blocklist Enabled/DisabledAccount Linking Enabled/Disabled
Disable Mfa Requires Mfa Enabled/DisabledSpam Ip Blocking Enabled/DisabledSignup Domain Allowlist/Blocklist UpdatedSignup Tld Blocklist Updated
User Export InitiatedPersonal/Org Api Key Rate Limit UpdatedEmail Confirmation Expires In SetOrg Invitation Expires In Set
Waitlist Expires In SetPasswordless Expires In SetSso Account Age Requirement SetUser Properties Settings Changed
Be Integration Key Created/DeletedOauth Client Created/DeletedOauth Client Secret RegeneratedOauth Client Redirect Uri Added/Removed
Update Fe Integration InfoSet Allowed UrlsSet External Integration ConfigGeneric Api Key Created/Updated/Deleted
Role Permission Mapping Created/Edited/DeletedSet Role Permission Mapping To DefaultRole Added/Edited/DeletedPermission Added/Edited/Deleted
Removed/Revoke Permission From RolesSet Default RoleMagic Link Interstitial Page Enabled/DisabledMagic Link Expires After First Use Enabled/Disabled
Custom Domain VerifiedMcp Enabled/DisabledMcp Enabled/Disabled For RealmMcp Dcr Enabled/Disabled
Can Users Create Mcp Clients Enabled/DisabledMcp Config SetMcp Server Created/DeletedMcp Clients Garbage Collected
Api Key Expiration Alerting Set/DisabledIac Api Key Created/Updated/DeletedMigrated To Multi RoleRole Hierarchy Changed