Skip to content

Account Management Overview (1.0)

Frontegg is built with multi-tenancy in mind, allowing the creation and management of multiple accounts (tenants) within an environment. This section provides an overview of relevant API endpoints, organized into Management and Self-Service categories, supporting the creation of accounts, hierarchies, and sub-accounts.

Management Endpoints: Require environment-level authorization and offer full control over resources, including SSO (SAML and OIDC) configurations, account hierarchies, and sub-accounts.

Self-Service Endpoints: Accessible with a user token (JWT), enabling users with the appropriate permissions to create, update, and delete sub-accounts from ah hierarchy.

Languages
Servers
EU Region
https://api.frontegg.com/tenants/
US Region
https://api.us.frontegg.com/tenants/
CA Region
https://api.ca.frontegg.com/tenants/
AU Region
https://api.au.frontegg.com/tenants/
Frontegg sub-domain for use with user tokens
https://{domain}.frontegg.com/tenants/

Accounts

Operations

Lock tenants (batch)

Request

Lock one or more tenants. A vendor token is required for this route, it can be obtained from the vendor authentication route.

Security
bearer
Bodyapplication/jsonrequired
tenantIdsArray of strings<= 100 itemsrequired

Tenant IDs to lock. Maximum 100 per request.

curl -i -X POST \
  https://api.frontegg.com/tenants/resources/tenants/v1/lock \
  -H 'Authorization: Bearer <YOUR_JWT_HERE>' \
  -H 'Content-Type: application/json' \
  -d '{
    "tenantIds": [
      "string"
    ]
  }'

Responses

Unlock tenants (batch)

Request

Unlock one or more tenants. A vendor token is required for this route, it can be obtained from the vendor authentication route.

Security
bearer
Bodyapplication/jsonrequired
tenantIdsArray of strings<= 100 itemsrequired

Tenant IDs to unlock. Maximum 100 per request.

curl -i -X POST \
  https://api.frontegg.com/tenants/resources/tenants/v1/unlock \
  -H 'Authorization: Bearer <YOUR_JWT_HERE>' \
  -H 'Content-Type: application/json' \
  -d '{
    "tenantIds": [
      "string"
    ]
  }'

Responses

Add account (tenant) metadata

Request

Add metadata to an account (tenant).

If a metadata key already exists, its value is overwritten.

Provide the account (tenant) ID as a path parameter and the metadata object in the request body.

An environment token is required for this route and can be obtained from the environment authentication route.

Security
bearer
Path
tenantIdstringrequired
Bodyapplication/jsonrequired
metadataobjectrequired
object
curl -i -X POST \
  'https://api.frontegg.com/tenants/resources/tenants/v1/{tenantId}/metadata' \
  -H 'Authorization: Bearer <YOUR_JWT_HERE>' \
  -H 'Content-Type: application/json' \
  -d '{
    "metadata": {
      "maximumUsers": 50
    }
  }'

Responses

When the given metadata is neither a JSON, nor JSON-string.

Sub-accounts and hierarchy

Operations

Account migration

Operations

Account settings

Operations

Sub-accounts

Operations