Before multi-tenancy
Themis-Trace had individual instances, so a URL, username, and password were enough to identify the caller. Authentication took two steps:
- Get a token. The application sends a
POSTto the Auth Server's/connect/tokenendpoint withgrant_type=password, itsclient_id,scope=ThemisTraceand the user'susernameandpassword. The Auth Server returns anaccess_token. - Call the API. Every API request carries the header
Authorization: Bearer <access_token>. When the token expires, the application repeats step 1.
What changed with multi-tenancy
The token request must now name its tenant. Each tenant has its own users, and the same username can exist in several tenants, so a username and password alone no longer identify the caller.
- Token request: the Auth Server needs the tenant, sent as the
__tenantheader with the tenant's ID. Without it, the Auth Server can't tell which tenant's user is signing in, so it looks for the user outside every tenant and the login fails. - The token: the
access_tokennow carries atenantidclaim for the tenant the user signed in to. - API calls: unchanged. The API reads the tenant from the token's
tenantidclaim, so API requests don't need__tenant.
What your application must change by December 31, 2026
Add the __tenant header, set to the correct tenant ID, to every token request. Nothing else changes.
- Look up the tenant ID. Call
GET /api/abp/multi-tenancy/tenants/by-name/<Tenant Name>on the Auth Server. No sign-in is needed. Send thetenantIdvalue from the response. Look it up by name at startup or keep it in configuration, rather than hard-coding a GUID that differs between environments. - Send it on the token request: add
__tenant: <Tenant ID>to thePOST /connect/tokenrequest, alongside the fields you send today. - Keep API calls as they are. Send
Authorization: Bearer <access_token>as before. API calls don't need__tenant. - Tell us when you're done.
Example lookup, then token request:
# 1. Look up the SCS tenant ID (read tenantId from the JSON response)
curl "https://<auth-server>/api/abp/multi-tenancy/tenants/by-name/<Tenant Name>"
# 2. Request a token for the SCS tenant
curl -X POST "https://<auth-server>/connect/token" \
-H "Content-Type: application/x-www-form-urlencoded" \
-H "__tenant: <Tenant ID>" \
-d "grant_type=password" -d "client_id=<your client id>" -d "scope=ThemisTrace" \
-d "username=<username>" -d "password=<password>"
You can make this change now: a token request that sends its own __tenant already works. After December 31, 2026, token requests without __tenant will fail.
Contact us
For questions or development support, contact us at support@themis-trace.com.