AdminApp configuration workspace
Use the AdminApp to manage ProAuth configuration and User Store data within the permissions assigned to your account. This guide covers deployment settings, common administration tasks, and recovery from errors.
Deploying AdminApp resources
Apply the database migration job before deploying compatible application and resource images. Deploy the AdminApp page definitions and labels together so that forms, actions, and translations match the application version.
The resource deployment job updates the supplied page definitions while preserving independently managed definitions. If the job reports a concurrent change or an uncertain result, review the outcome before retrying. See CLI usage for resource export and replacement commands, and Helm chart configuration for deployment settings.
Reverse-proxy caching
Preserve the cache headers returned by the AdminApp:
- Versioned files under
/assets/use a one-year, public, immutable cache lifetime. Their URLs change with each build. - Application pages and non-versioned static files use
Cache-Control: no-cacheso browsers revalidate them before reuse. - Do not apply the static-asset cache policy to authenticated requests or error responses.
Navigation and scope
Use the sidebar to open a configuration area. On smaller screens, choose Open navigation. Breadcrumbs return to the originating collection.
The Subscription and User Store controls show the current working scope. For User Store pages, select a subscription first, then a User Store. Changing the subscription clears the User Store selection. If only one subscription is available, it may be displayed without a selector. Accessible stores without a subscription appear under Unassigned.
Your role assignments determine the available workspaces and actions. Scope selection filters the data you work with; it does not grant permissions. A selected subscription can therefore contain no records that you are allowed to view. When editing an existing record, its scope remains fixed. A bookmarked scope that is no longer available produces an error instead of silently selecting a different scope. See Role-Based Access Control for permission configuration.
The top-right Settings and sign out menu contains language, appearance, and sign-out controls. Manage Account, when available, opens self-service in a new tab. Appearance supports light, dark, and system settings. Browser preferences are retained, but unsaved configuration changes are not retained after a reload.
Editing configuration
Open a record with its Edit action, by double-clicking its row, or by pressing Enter while the row is focused. Larger forms group settings into tabs. Switching tabs preserves pending changes.
Save saves pending form fields and options across all tabs. Cancel discards those pending changes. Validation messages identify fields that need correction, including fields on other tabs; select a message to move to the field. Leaving a record or changing scope with unsaved changes prompts you to keep editing or discard them.
Changes that take effect immediately
Relationship commands and changes to collections such as metadata, profiles, and redirect URIs take effect when you confirm the corresponding dialog or action. They do not wait for the parent page's Save command, and the parent page's Cancel command does not undo them.
In a relationship dialog, selecting a row only chooses a candidate. Review the record and scope, then choose Link to apply the change. Enter metadata keys as intended, without manually URL-encoding them.
Failed saves and concurrent changes
A save can complete only partially. If a write fails, saving stops and the page identifies changes already accepted and those still pending. Cancel discards remaining drafts; it cannot undo successful writes.
If another administrator has changed a record, compare the original values, your draft, and the current server values. Reapplying your changes prepares a new draft that you must save explicitly. If the outcome of a write is uncertain, check the current server values before retrying to avoid repeating a successful operation.
Bulk actions can also succeed for some records and fail for others. Review the reported outcome before retrying.
Additional actions
More actions contains commands such as password management and Synchronize users or Synchronize groups. Synchronization uses saved configuration and is unavailable while there are pending changes or an active write. Save or discard changes before starting it.
For object-specific settings, see the guides for client applications, User Stores, and SCIM synchronization.
Options and overrides
Tenant, Identity Provider, User Store, and MFA options are grouped by task. Each option distinguishes its default value from an explicit override. Search by group, title, technical key, or description. Overrides shows explicit overrides; Changes shows pending edits.
- Create override sets an explicit value.
- Edit value changes an existing override.
- Reset to inherited removes the override so the default can apply.
These actions stage changes until you choose the page's Save command. Filtering the options does not discard drafts; Save includes pending changes outside the current filter. An empty explicit value may fall back to the default, depending on the option; use Reset to inherited to remove the override.
Use field help for accepted values, units, and formats. Existing values outside suggested choices remain visible for review. Inherit differs from explicitly choosing None, Enabled, or Disabled. Tenant security requirements can take precedence over client choices; see FAPI 2.0 security profiles and token encryption.
Sensitive values remain masked until you choose Reveal value. Opening an editor without changing a stored secret does not replace it. Locked options cannot be edited. Viewing, creating, changing, and removing overrides may require different permissions; permission to edit options does not necessarily allow changes to the owning record's other fields.
Field help and language
Use a field's help button for explanations without leaving the form or losing pending changes. Choose Close or press Escape to dismiss help.
The interface supports English, German, French, Italian, and Dutch. Some option descriptions and help are available only in English and German; missing translations fall back to English when available.
Finding and filtering records
Use Search to find records. Paste a complete GUID to search for an exact identifier. Select an identifier in a table to inspect or copy its full value. Use column settings to show an identifier column that you previously hid.
Open Filters to select criteria, then choose Apply filters. Canceling or dismissing the panel leaves the current results unchanged. Multiple values within one criterion are combined with OR; different criteria are combined with AND. A collection's subscription filter further narrows the global scope.
Applied filters appear above the results and can be removed individually. Clearing field filters preserves search, sorting, and global scope. Search, applied filters, sorting, and paging can be bookmarked.
On Identity Provider and MFA lists, Configuration Errors filters by the recorded configuration error: True selects records with an error; False selects records without one.
Personal grid settings
Column visibility, order, width, pinning, and identifier display are saved for your account in the current browser. These preferences do not synchronize across browsers or devices.
Saved filters store applied search, field filters, and sorting. They do not store column settings or the current subscription or parent-record scope. Apply staged filters before saving them. Resetting column settings preserves saved filters.
Audit entry details
Audit entries are read-only and, where applicable, use the selected User Store scope. See Auditing for audit configuration.
Audit timestamp filters use UTC, matching the displayed timestamps. From and To accept a date and time including seconds; either bound may be omitted. Bounds are inclusive at the specified instant: 18:31:00 means that exact time, not the whole minute. The start must not be later than the end.
Permissions and capability caching
The AdminApp checks permissions to determine which navigation items and controls are available. Every operation is also authorized by the server. Pending or failed permission checks keep dependent actions unavailable.
Permission results used by the interface are cached for five minutes by default. This is a reuse period, not an automatic refresh interval. Changing another user's roles does not immediately refresh their open AdminApp. Reloading the page starts fresh permission checks; save or discard pending changes first. Server-side authorization still applies regardless of the controls currently displayed.
Configure the following settings on the AdminApp server:
| Setting | Default | Purpose |
|---|---|---|
AdminApp:Capabilities:CacheTtlSeconds | 300 | How long the interface reuses permission results, in whole seconds. Accepts 0 to 86400; 0 disables caching. |
AdminApp:Capabilities:StartupBatching | true | Checks permissions for the supplied pages together during startup. When false, checks run as needed. Skipped when caching is disabled. |
The equivalent environment variables are AdminApp__Capabilities__CacheTtlSeconds and AdminApp__Capabilities__StartupBatching. For example, the following configuration uses a ten-minute reuse period:
{
"AdminApp": {
"Capabilities": {
"CacheTtlSeconds": 600,
"StartupBatching": true
}
}
}Apply changes through your normal deployment and restart process, then reload open AdminApp pages. Invalid values prevent server startup. These settings affect interface permission checks; they do not configure the server-side RBAC cache.
Startup and error recovery
| Symptom | Action |
|---|---|
| Sign-in or session failure | Choose Sign in to establish a new session. |
| Workspace cannot finish starting | Check service availability and that the application and resource deployment succeeded, then choose Retry. |
| A page or table reports an authorization error | Verify the account's permissions and selected scope, then choose Retry. |
A path such as /adminapp/clientappedit/section/flows appears instead of a label | Check that the matching label resources were imported for the intended language and that the application can load them. Deploy page definitions and labels together. |
| A server error page appears | Use the link back to administration. If the problem persists, use the displayed reference to locate the corresponding server trace or include it in a support request. |
Error pages omit exception details. Use server logs and traces for diagnosis; see Monitoring.