Projects and access

How projects group your resources in Affinidi Portal, who can access them, and how you and your systems are identified.

When one developer account builds several applications, their login configurations, wallets, and appliances can get mixed up, and it becomes hard to share one application’s setup with a teammate without exposing everything else.

Affinidi Portal groups resources into projects: each project has its own resources, plan, usage, and list of people and tokens that can reach it.

You can keep each application separate and give your team access to exactly the project they work on. Work with projects →

How the active project scopes what you see

At any moment one project is your active project, and the project switcher in the top bar shows its name. Every product page in the sidebar lists only the active project’s resources, and every resource you create belongs to it.

Switching project changes what each product page shows. A login configuration you created in one project appears only while that project is active, and it’s still there when you switch back.

Plans, Affinidi Credits, and usage are also counted per project, so one project running out of credits leaves your other projects unaffected. See Plans, credits, and limits.

How a project starts and how many you can have

The first time you sign in, Affinidi Portal creates a project named Default project and makes it active, so you can configure a product straight away. You can create more projects as you need them, and own up to 5 per account. The limit covers only the projects you own, so projects other owners share with you are on top of it. The Dashboard’s Total Projects counts every project in your list, shared ones included.

Who can open and change a project

Each project has one owner: the account that created it. The All projects page lists the projects you own under Created by you and the projects other owners have shared with you under Shared with you.

  • Owner: can edit the project’s name and description. The Edit button and the Actions menu on the project page appear only to the owner.
  • Collaborator: another developer the owner has given access to. What a collaborator can do with the project’s resources depends on the policy the owner defines for them, for example read-only access to Affinidi Iota Framework configurations.

Policies are defined with Affinidi CLI, and the project page’s Collaborators table shows the result, with a View Policy link for each person. See Give a team member access.

How Affinidi Portal identifies you

You have two identifiers:

  • User Principal ID: your identity as a developer in Affinidi Portal. Owners use it to grant you access to their projects, and it appears in their Collaborators table. Find it under Account > Account Info.
  • Vault DID: the decentralised identifier (DID) of your Affinidi Vault. It identifies you as a holder of credentials, while your User Principal ID identifies you as a developer. You need it to test Credential Issuance and Affinidi Iota Framework configurations from Affinidi Portal.

See Account Info for where to find each one.

You can sign in with Affinidi Login, Apple, Google, GitHub, Microsoft, or a passkey. Each method you link on the Authentication methods page signs you in to the same account, so your User Principal ID and projects stay the same whichever method you use. Affinidi Portal identifies accounts by sign-in method rather than email address, so a method you haven’t linked signs you in to a separate account with its own User Principal ID. Affinidi CLI signs you in with Affinidi Login. See Manage your sign-in methods.

Affinidi Portal reads your Vault DID when you sign in with Affinidi Login. When you sign in with Apple, Google, GitHub, or Microsoft, pages that test a configuration against your Affinidi Vault ask you to create a Vault and paste its DID instead.

How systems act on your behalf

A Personal Access Token (PAT) lets a backend service, script, or CI job call Affinidi services as your developer account, without a person signing in. Like a collaborator, a token reaches a project only when a policy grants it access.

The Personal Access Tokens page under Affinidi Forge shows a card for each token with its Scopes, Personal Access Token Id, Owner ARI, and Token ARI. Tokens are created and updated with Affinidi CLI: Create token shows the command to copy. A project’s page lists the tokens that can access that project, marking tokens owned by someone else Owned by others. See Manage Personal Access Tokens.