Application signup & auth (TenancyEngine)
Configure how end users sign up, authenticate, and enroll MFA for your SaaS product.
Console: Application workspace → Signup (/applications/:id/signup)
Requires Applications configure to change policies. Read-only users can review current settings.
Auth methods
Choose which sign-in methods tenants may use — email/password, SSO/OIDC, magic links, and passkeys where enabled. Disabled methods are hidden from your product portal and console login surfaces.
Coordinate OIDC client settings on the Settings and Environments tabs before enabling SSO.
MFA policy
Set organization-wide MFA requirements for tenant users — optional, required for admins, or required for all members. Changes apply to new sessions; existing sessions may continue until refresh depending on your product integration.
SMS subaccount
When SMS OTP or notifications are enabled, link a Twilio subaccount scoped to this application. The panel shows provisioning status and test-send guidance.
Self-registration
Control whether new organizations can sign up without an invite:
- Allow self-registration — public signup flows create a tenant under this application.
- Require invite — only invited emails can join; blocks duplicate org creation at signup.
- Signup URL — copy the hosted signup link for marketing pages or onboarding emails.
Self-registration respects platform plan limits (max tenants, apps) for the vendor organization.
Related
- Application settings — OAuth client and redirect URIs
- Application environments — per-stage OIDC endpoints
- Security settings — your operator account MFA