Home / Launchpad / Documentation

Portal Setup

After your portal is provisioned, open Configuration in the admin sidebar. Sections appear according to your permissions. This page covers the settings that live there.

Related configuration

Logos and colors are in Branding & Themes. Header links are in Navigation. Portal accounts are in Users (Configuration → Users). Custom profile fields are in Custom User Fields. Apigee connections and workspace display are in Apigee Integration and Multi-Organization. Activity and system logs are in Audit logs (Configuration → Audit logs).

General Settings

Open Configuration → General.

Registration modes

  • Open Registration — Anyone can create an account
  • Invite Only — Self-registration is closed. Create accounts with Add User under Configuration → Users.
  • Domain Restricted — Only emails from the domains you list (comma-separated)
  • SSO only — Developers must sign in with enterprise SSO. Configure the provider under Configuration → SSO Authentication. See Single Sign-On.

Email verification

Under Site Email Address on the same General screen:

  • Site Email Address — Contact address for the portal
  • Verification Required — New users must verify email before signing in
  • Verification Link Expiry (minutes) — How long the link stays valid (1–10080)
  • Resend Limit (per user per day) — Maximum verification emails a user can request

To require a bot challenge on registration, login, or password reset, see CAPTCHA Settings.

Terms and conditions

  • Require agreement on signup — New users must accept before creating an account
  • Title label, Subheading, and Terms body — copy shown on the signup page

Timezone, logo link, and Drupal passwords

  • Portal timezone — IANA timezone for dates shown in the portal. Stored times stay UTC.
  • Logo redirect URL — Where the header logo goes. Blank sends users home. Use a path such as /apps or a full URL.
  • Drupal authentication — When on, sign-in can verify Drupal-compatible password hashes (useful after a Drupal portal migration). The Password hash section in Configuration is a generate/compare utility, not a runtime setting.

CAPTCHA Settings

Protect public forms from bots with Cloudflare Turnstile or Google reCAPTCHA. CAPTCHA is configured once for the portal, then applied to the built-in forms and Form Builder forms you choose.

Open Configuration → Captcha. The section is visible only to users with the Manage Captcha permission (assigned to Administrator by default).

Enable and choose a provider

  1. Turn on Enable CAPTCHA.
  2. Select a provider:
    • Cloudflare Turnstile — default. A privacy-friendly challenge widget.
    • Google reCAPTCHA v2 — the familiar “I’m not a robot” checkbox.
    • Google reCAPTCHA v3 — invisible scoring; visitors do not complete a widget.
  3. Enter the Site key (public) and Secret key (private) from the provider dashboard. Both are required while CAPTCHA is enabled.
  4. Save settings.

Get keys from the Cloudflare Turnstile dashboard or Google reCAPTCHA admin, matching the provider you selected.

Keys must match the provider

Site and secret keys from one provider will not verify against another. Switching providers means issuing a new key pair and updating both fields before saving.

Apply to forms

Enabling CAPTCHA does nothing until you attach it to at least one form. Under Apply to forms, search or filter, then check the forms that should require a challenge:

Built-in forms

  • Login — sign-in at /login
  • Registration — sign-up at /signup
  • Password reset — reset request at /reset-password
  • Email verification — resend verification at /verify-email
  • Change password — change-password forms (including the emailed-token flow)
  • Contact — contact form at /contact

Form Builder forms

Every form created in Form Builder is listed (name, slug, and status). Check a form to require CAPTCHA on submit. If you have no Form Builder forms yet, the list is empty until you create one.

SSO sign-in is not challenged

Enterprise SSO does not use the portal login form, so the Login CAPTCHA does not apply to SSO users. Registration, password reset, and Form Builder forms still can.

How it behaves

  • Selected forms show a widget (Turnstile or reCAPTCHA v2) or run an invisible check (reCAPTCHA v3) before submit.
  • The portal verifies the token with the provider on the server. A missing or failed challenge rejects the request — the form is not processed.
  • CAPTCHA is skipped for a form that is not selected, or when CAPTCHA is turned off, even if keys are saved.
Form Builder also has rate limiting and a honeypot. CAPTCHA is an extra layer you attach per form in this screen — see Form Builder spam protection.

Email

Outbound mail and templates live under Configuration → SMTP Authentication, not a separate Email Templates screen. Configure host, port, credentials, and sender identity, then edit signup, verification, password reset, and apps/teams notification templates. Full steps are in Email Configuration.

Developers search published pages, API specs, and documentation from the header (⌘K / Ctrl+K) or the search icon. After you add or change a lot of content, open Configuration → Search and rebuild the index. Full details are in Search.

Apigee and workspaces

Connect Apigee X from Configuration → Apigee (organization name, GCP service account JSON, test connection) or add further orgs from Manage Workspaces. New connections are Apigee X only.

Display mode (one workspace vs all), workspace labels, and the Plans & Billing nav word are under Manage Workspaces → Display Settings. See Apigee Integration and Multi-Organization.

Service account roles

The GCP service account needs Apigee API Admin, Apigee Analytics Viewer, and Apigee Developer Admin in the Apigee organization.

Sessions

Administrators with Manage User Sessions can open User Sessions (/admin/sessions) to list devices and revoke sessions. Signed-in developers manage their own sessions at /settings/sessions.

Ready to deploy your portal?

Book a 20-minute walkthrough and see Launchpad running with your Apigee environment.