Skip to main content

Authentication

Authentication for the user interface is managed using a Keycloak instance. Users are either managed directly in this instance, or using an external identity provider using OpenID Connect or SAML 2.0 (e.g. AzureAD).

The table below lists the available roles and their associated permissions.

RoleDashboardSpaces creationSpace configurationSubmitReviewConfigure org endpoints
super-admin
<org_id>-admin
<org_id>-user
space admin
space submitter
space reviewer
space anonymous submitter