Before multi-tenancy

Themis-Trace had individual instances, so a URL, username, and password were enough to identify the caller. Authentication took two steps:

  1. Get a token. The application sends a POST to the Auth Server's /connect/token endpoint with grant_type=password, its client_id, scope=ThemisTrace and the user's username and password. The Auth Server returns an access_token.
  2. Call the API. Every API request carries the header Authorization: Bearer <access_token>. When the token expires, the application repeats step 1.

What changed with multi-tenancy

The token request must now name its tenant. Each tenant has its own users, and the same username can exist in several tenants, so a username and password alone no longer identify the caller.

  • Token request: the Auth Server needs the tenant, sent as the __tenant header with the tenant's ID. Without it, the Auth Server can't tell which tenant's user is signing in, so it looks for the user outside every tenant and the login fails.
  • The token: the access_token now carries a tenantid claim for the tenant the user signed in to.
  • API calls: unchanged. The API reads the tenant from the token's tenantid claim, so API requests don't need __tenant.

What your application must change by December 31, 2026

Add the __tenant header, set to the correct tenant ID, to every token request. Nothing else changes.

  1. Look up the tenant ID. Call GET /api/abp/multi-tenancy/tenants/by-name/<Tenant Name> on the Auth Server. No sign-in is needed. Send the tenantId value from the response. Look it up by name at startup or keep it in configuration, rather than hard-coding a GUID that differs between environments.
  2. Send it on the token request: add __tenant: <Tenant ID> to the POST /connect/token request, alongside the fields you send today.
  3. Keep API calls as they are. Send Authorization: Bearer <access_token> as before. API calls don't need __tenant.
  4. Tell us when you're done.

Example lookup, then token request:

# 1. Look up the SCS tenant ID (read tenantId from the JSON response)
curl "https://<auth-server>/api/abp/multi-tenancy/tenants/by-name/<Tenant Name>"

# 2. Request a token for the SCS tenant
curl -X POST "https://<auth-server>/connect/token" \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -H "__tenant: <Tenant ID>" \
  -d "grant_type=password" -d "client_id=<your client id>" -d "scope=ThemisTrace" \
  -d "username=<username>" -d "password=<password>"

You can make this change now: a token request that sends its own __tenant already works. After December 31, 2026, token requests without __tenant will fail.

Contact us

For questions or development support, contact us at support@themis-trace.com.