Public Access Controls
By default a public Space does not have any authentication method, but you can choose and set a few:
- Space-wide password;
- Guest Accounts, where you manually create email + password combos and distribute them to your users;
- Magic Links, where you enter specific emails or entire domains, and users will authenticate using a link that we send to their email address;
- Private Accounts, where you add specific domains to let users authenticate/create accounts with their e-mail address
- Private Links, where you can generate private links and share them with your users and teams. Manage access control per user group via links;
- JWT, where your dev team generates a JWT with a secret key you provide in our UI, then pass it back to us as part of a link. This is the easiest to manage, but you will require developer time.
- SAML, when you have an external application that can act as a router to your space domain, so the public portal can be acessed only by members setted in providers like Google, Azure, Okta.
data:image/s3,"s3://crabby-images/e4b78/e4b78bb2900548094d74dfcff470ea4080ca168a" alt="Document image Document image"
The default behaviour is set as None, meaning it is available publicly. You can change to controls to limit the access for readers.
Everyone with the link will be able to read content.
Links are safe to share because they are cryptographically generated and unguessable.
When you want to gate the contents to specific readers, try any of the options below.
data:image/s3,"s3://crabby-images/49731/49731ddb60a791d27e05c7bfac0594dc4e7d40f7" alt="Document image Document image"
Create guest accounts. Everyone with the link and a guest account will be able to read the content. Guest accounts are not charged as seats in Archbee.
data:image/s3,"s3://crabby-images/16fde/16fde93805b7782671ee8def6f8159082c517c40" alt="Document image Document image"
Users will be able to authenticate/create an account in your space with their email address/password if you add their email address or their email domain to the list below.
Everyone with the link and a matched account will be able to read the content. Accounts are not charged as seats in Archbee.
The list of users with active accounts will appear in the 'Active Accounts' window.
data:image/s3,"s3://crabby-images/ff016/ff01653960e776b5a77d91f67a317a1486f8c6ff" alt="Document image Document image"
Users will be able to authenticate to your space with their email address if you add their email address or their email domain to the list below. Everyone with the link and a matched account will be able to read the content. Accounts are not charged as seats in Archbee.
data:image/s3,"s3://crabby-images/f9557/f9557a27281e5e82574aa0b0a36ab8012c5a1969" alt="Document image Document image"
Generate Private links for specific user groups/teams. Each user group/team will have their own link to the same documentation and you can manage access control via this links. You need to cut access for team 1? Delete the private link associated with team 1.
data:image/s3,"s3://crabby-images/65856/65856b4aa62e01f05d65d5d91b0be38bcb5b9052" alt="Public access control - JWT Secret Public access control - JWT Secret"
Go to the Spaces settings, and set a JWT secret key that you generate on your server
data:image/s3,"s3://crabby-images/dc2ec/dc2ec2e9f8f3d54567e8433e5fc6f55fbc86747c" alt="Document image Document image"
Go to the Spaces settings, and set a JSON WEB Key Set URL. A JSON Web Key Set (JWKS) URL is a URL endpoint where a server publishes its public keys in JSON format.
The JWKS URL typically points to a JSON document that contains an array of cryptographic keys used for verifying signatures.
When Archbee receives a JWT, it can retrieve the corresponding public key from the JWKS URL and use it to verify the JWT's signature, ensuring that the token hasn't been tampered with and was indeed issued by a trusted party.
A JWKS URL provides a standardized way for clients to obtain the public keys needed to verify JWT signatures in a secure and scalable manner.
This is a sample jwks.json file:
Use one of the examples below to generate the JWT token.
You also need to replace the URL with the subdomain of your documentation site.
Here is an example to generate a JWT token with .NET: https://github.com/dragosbulugean/archbee-jwt-dotnet
JWT tokens are bypassed on Preview/Staging
data:image/s3,"s3://crabby-images/ebd37/ebd37c20506b28ec003418e874e932c456357dfd" alt="Document image Document image"
SAML can be configured for public space access in the same way as for team integration, see SAML Integration for more detailed steps regarding setting up each provider.
Note that just the metadata URL is needed as input. Also, we assume the space is already hosted on a custom domain.
In this way, the published space link will be routed through the new SAML application; thus, only members set up in the provider application can access the public portal.
Go to Azure Services -> Microsoft Entra ID -> "+Add" -> App registration
Select "Accounts in this organizational directory only -Single tenant" and paste the CallBack URL from Archbee Space Settings ->Public Access Control -> SAML into "Redirect URI" as in the below image, choosing Web auth:
data:image/s3,"s3://crabby-images/88a87/88a87713bff55fd8fd569cc0ee246ba7f3ee5a02" alt="Document image Document image"
Click on "Register"
On the newly created app in Azure, go to "Endpoints" and copy the "Federation metadata document" from the Azure App to the Archbee Space Settings -> Public Access Control -> SAML into the "Set SAML Metatada URL"
data:image/s3,"s3://crabby-images/6b0c3/6b0c3c3d796b5a26e621a5e66bcfbabeb44155e7" alt="Document image Document image"
A unique Entity ID will be generated in Archbee, copy the "api://PUBLISHED..." link in your Azure App - Expose an API -> Add -> Fill Up the URL -> Save it
data:image/s3,"s3://crabby-images/0acd3/0acd31295933e6b90e0ebf9539d56a043b685f6d" alt="Document image Document image"
Go to your Archbee space and re-publish it
Try to access the link and test the SAML authentication