Portal Setup
After your portal is provisioned, open Configuration in the admin sidebar. Sections appear according to your permissions. This page covers the settings that live there.
Related configuration
General Settings
Open Configuration → General.
Registration modes
- Open Registration — Anyone can create an account
- Invite Only — Self-registration is closed. Create accounts with Add User under Configuration → Users.
- Domain Restricted — Only emails from the domains you list (comma-separated)
- SSO only — Developers must sign in with enterprise SSO. Configure the provider under Configuration → SSO Authentication. See Single Sign-On.
Email verification
Under Site Email Address on the same General screen:
- Site Email Address — Contact address for the portal
- Verification Required — New users must verify email before signing in
- Verification Link Expiry (minutes) — How long the link stays valid (1–10080)
- Resend Limit (per user per day) — Maximum verification emails a user can request
To require a bot challenge on registration, login, or password reset, see CAPTCHA Settings.
Terms and conditions
- Require agreement on signup — New users must accept before creating an account
- Title label, Subheading, and Terms body — copy shown on the signup page
Timezone, logo link, and Drupal passwords
- Portal timezone — IANA timezone for dates shown in the portal. Stored times stay UTC.
- Logo redirect URL — Where the header logo goes. Blank sends users home. Use
a path such as
/appsor a full URL. - Drupal authentication — When on, sign-in can verify Drupal-compatible password hashes (useful after a Drupal portal migration). The Password hash section in Configuration is a generate/compare utility, not a runtime setting.
CAPTCHA Settings
Protect public forms from bots with Cloudflare Turnstile or Google reCAPTCHA. CAPTCHA is configured once for the portal, then applied to the built-in forms and Form Builder forms you choose.
Open Configuration → Captcha. The section is visible only to users with the Manage Captcha permission (assigned to Administrator by default).
Enable and choose a provider
- Turn on Enable CAPTCHA.
-
Select a provider:
- Cloudflare Turnstile — default. A privacy-friendly challenge widget.
- Google reCAPTCHA v2 — the familiar “I’m not a robot” checkbox.
- Google reCAPTCHA v3 — invisible scoring; visitors do not complete a widget.
- Enter the Site key (public) and Secret key (private) from the provider dashboard. Both are required while CAPTCHA is enabled.
- Save settings.
Get keys from the Cloudflare Turnstile dashboard or Google reCAPTCHA admin, matching the provider you selected.
Keys must match the provider
Apply to forms
Enabling CAPTCHA does nothing until you attach it to at least one form. Under Apply to forms, search or filter, then check the forms that should require a challenge:
Built-in forms
- Login — sign-in at
/login - Registration — sign-up at
/signup - Password reset — reset request at
/reset-password - Email verification — resend verification at
/verify-email - Change password — change-password forms (including the emailed-token flow)
- Contact — contact form at
/contact
Form Builder forms
Every form created in Form Builder is listed (name, slug, and status). Check a form to require CAPTCHA on submit. If you have no Form Builder forms yet, the list is empty until you create one.
SSO sign-in is not challenged
How it behaves
- Selected forms show a widget (Turnstile or reCAPTCHA v2) or run an invisible check (reCAPTCHA v3) before submit.
- The portal verifies the token with the provider on the server. A missing or failed challenge rejects the request — the form is not processed.
- CAPTCHA is skipped for a form that is not selected, or when CAPTCHA is turned off, even if keys are saved.
Outbound mail and templates live under Configuration → SMTP Authentication, not a separate Email Templates screen. Configure host, port, credentials, and sender identity, then edit signup, verification, password reset, and apps/teams notification templates. Full steps are in Email Configuration.
Search
Developers search published pages, API specs, and documentation from the header
(⌘K / Ctrl+K) or the search icon. After you
add or change a lot of content, open Configuration → Search and rebuild the
index. Full details are in Search.
Apigee and workspaces
Connect Apigee X from Configuration → Apigee (organization name, GCP service account JSON, test connection) or add further orgs from Manage Workspaces. New connections are Apigee X only.
Display mode (one workspace vs all), workspace labels, and the Plans & Billing nav word are under Manage Workspaces → Display Settings. See Apigee Integration and Multi-Organization.
Service account roles
Sessions
Administrators with Manage User Sessions can open
User Sessions (/admin/sessions) to list devices and revoke
sessions.
Signed-in developers manage their own sessions at /settings/sessions.