Installation & Administration

CardIQ Identity Configuration Guide

Configure CardIQ Identity core settings, SMTP, companies, roles, lifecycle, integrations, Wallet and supported billing safely.

Core and email settings

Core and email settings

Configure database access, APP_URL, APP_SECRET, storage paths, support address, production error hiding, HTTPS enforcement and optional SMTP settings in the hosting-only configuration. SMTP is not automatic: configure the approved transport and validate invitations, verification, password setup and notifications using safe diagnostics and private logs.

Company, roles and lifecycle

Company, roles and lifecycle

Super Admin manages companies, plans and company administrators. Company Admin manages its employees, cards and entitled modules; Employee access is scoped to employee workflows. Configure company identity, branding, slug, verified domain, Trusted Domains, public profile and directory. Lifecycle controls must remain tenant-scoped and auditable.

Enterprise identity integrations

Enterprise identity integrations

Microsoft Entra integration supports scoped directory preview, controlled employee synchronization and lifecycle reconciliation where configured. Entra-based enterprise sign-in is supported where configured. SCIM 2.0 Users provisioning is implemented in the current application build but still requires tenant configuration and environment interoperability validation before production enablement; SCIM Groups and Bulk are not supported. SAML login and JIT user creation are not currently represented as supported production capabilities.

API, webhooks and Wallet

API, webhooks and Wallet

Create company-scoped API keys only for authorized integrations and configure HTTPS webhook destinations and signing material without exposing secret values. Google Wallet and Apple Wallet require their own provider credentials/certificates and valid public HTTPS URLs. Keep credential material outside source control and validate lifecycle eligibility before issuance.

Security and version awareness

Security and version awareness

Restrict privileged interfaces, protect secrets, validate audit logging and review the documentation associated with the deployed release before changing identity, integration, billing or deployment settings. Implementation in source control does not by itself mean a capability has been deployed or enabled in production.

Control how employees represent your company externally

Explore the CardIQ Identity platform or review the workflow from verification through identity deactivation.

See how CardIQ Identity works View pricing