Trust Center

Single sign-on, set up in about fifteen minutes.

One page per identity provider, written for the administrator who has to do the work rather than for the buyer. Each is a single page, and each covers the same five things, so whichever provider you run the shape is the same.

Your provider

Choose the one you run.

Every guide is one page, and nothing in it assumes you have read another.

What each page covers

The same five things, every time.

Creating the application

The exact console path, the redirect URIs, the four scopes Bolt asks for, and where access is granted. Bolt never calls back into your directory with an admin token.

Giving Bolt the credentials

Both routes: the first-run wizard, and the configuration keys for a self-hosted deployment. Plus the SAML fields where SAML is the house standard.

The four levers that grant access

Who may sign in, who administers Bolt, joiner and leaver through SCIM 2.0, and what data each person's account actually reaches. They are separate on purpose.

What Bolt is able to read

Read-only scopes, granted one surface at a time, and how each source's own permissions are enforced at retrieval rather than at indexing.

Rolling the desktop app out

MDM on macOS, Group Policy on Windows, a DNS SRV record, or the first-launch wizard, in the order the client resolves them.