Apiable

API Portal

Portal security and MFA

Put a username and password prompt in front of your whole API Portal while you build it, and set multi-factor authentication for developers to ON, OPTIONAL, or OFF. Covers what each control does and does not protect, and how changes are applied.

Your API Portal has two separate access settings. Restricted portal access puts a username and password prompt in front of the whole site, for a portal that is not ready to be seen. Multi-factor Authentication adds a second factor to each developer's own sign-in. You set both under Settings, Portal settings, Security.

How do you put the whole portal behind a password prompt?

Open Settings, Portal settings, Security. Under Restricted portal access, turn on Password protection and choose Save Changes. Visitors then have to enter the username and password shown in that section before the portal loads.

  1. Open Settings at the bottom of the dashboard sidebar, then Portal settings, then Security.
  2. Turn on Password protection.
  3. Choose Save Changes.
  4. Share the Username and Password shown below the toggle with the people who need to see the portal. Use the eye icon to show the password.

To remove the prompt, turn Password protection off and choose Save Changes. Either change takes a few minutes to apply, and while it is being applied the toggle shows off.

What does restricted portal access protect?

It asks every visitor for a username and password before the portal loads, which keeps an unfinished portal out of search results and casual view. It is not a way to keep content confidential or to identify developers, and it does not replace developer sign-in.

What multi-factor options does the portal support?

Three: ON, OPTIONAL, and OFF. You choose one in the Multi-factor Authentication block and save it. The setting applies to developers who sign in with an email address and password.

SettingWhat it means for developers
ONA second factor, beyond username and password, is required every time they sign in.
OPTIONALEach developer can turn on a second factor for their account, or leave it off.
OFFSign-in needs only a username and password.

Developers who sign in through a connected identity provider authenticate at that provider, so the provider's own MFA applies to them, not this setting. See Identity Providers.

How do developers set up MFA?

From My Profile in the portal's account menu, under Two-factor authentication. They choose Set up authenticator app, scan the QR code, and enter the code the app shows. When MFA is ON, a developer without an authenticator is asked to set one up at sign-in.

With OPTIONAL, developers can also turn the second factor off again from My Profile. With ON, they can reconfigure it but not turn it off.

How do you change the MFA setting?

Select ON, OPTIONAL, or OFF, then choose Save Changes. Saving sends your choice to Apiable, who apply it to your portal. Until the new setting is live, the buttons are locked and a message says the MFA system is being updated.

  1. In Multi-factor Authentication, select the option you want.
  2. Choose Save Changes.
  3. The buttons lock while Apiable applies the change.
  4. When the change is live, the buttons unlock and show the new setting.

The block always shows the setting that is in force on your portal, not just the one you asked for.

Troubleshooting

Match what you see to the fix.

What you seeWhat to do
The toggle, the MFA buttons and Save Changes are disabledYour role cannot manage portals. Ask your Organisation Owner or an Organisation Admin.
Password protection shows off right after you turned it onThe change is still being applied. Reload the page after a few minutes.
There is no Multi-factor Authentication blockYour portal's current MFA setting is not known yet. Contact Apiable.
The MFA buttons are locked with an update messageApiable is applying your last change. Wait for it to go live.
Developers who use single sign-on are not asked for a second factorThey sign in at your identity provider. Turn on MFA there.

Where to next