Skip to main content

Organization Settings

This document will cover the tabs of the Organization settings page, which is accessible to admins (the triage team).

Members​

On the Members tab, you can invite new users to your organization or remove existing ones.

SevHunt provides a limited initial set of roles:

  • Admin / Owner - Can perform all actions on the site, including triaging reports.
  • Member - Can create reports, access the store, and view high-level data like the homepage graphs and leaderboard.

The majority of your users will be "normal" employees and given the "Member" role.

Homepage​

When users log into SevHunt, they see two tabs: "Welcome" and "Hunting Tips". The Homepage tab lets you configure these to greet your users and guide them through finding bugs.

Name & Slug​

Your organization name and slug (the path piece that comes after https://sevhunt.com/o/) can be changed at any time. Slugs are unique across SevHunt, but free users must have slugs that end in -free to mitigate abuse/enumeration.

Auth​

The Auth tab allows you to configure how users log in and join your organization.

Auto-join domains​

This section configures allowed email domains for your organization. When set, users with a matching email domain can join your organization without an invite, which is nice if you don't care what login method they used.

For more complex (typically enterprise) needs, see "SSO providers" below.

New users will be given the "member" role by default, which allows for report submission and other non-triage tasks.

Note: If you plan to use this feature to (exhaustively) allow all email domains, please contact us first, as we'd rather enable external reports as a first-class feature.

SSO providers​

This section allows you to add OpenID Connect (OIDC) compatible SSO providers to your organization. Once configured, users with a matching email domain will only be able to log in with the given provider, and will automatically be added to your organization with the "member" role.

Domain verification​

You will need access to add TXT records to your email domain to verify your ownership. Once a new SSO provider is added, instructions will be provided on adding a DNS entry.

Supported issuers​

For security reasons, only Okta, Microsoft, and Auth0 are available as issuers for now. If you would like an issuer added, please contact us. Here are issuer-specific instructions:

Okta SSO setup​

  1. Visit https://{your-org}-admin.okta.com/admin/apps/active and create a new OIDC integration for a web application
  2. For the redirect URI, enter https://sevhunt.com/api/auth/sso/callback and continue
  3. Take note of the client ID and secret
  4. When adding the SSO provider in SevHunt, use the following values:
    • Display name: Okta
    • Issuer URL: https://{your-org}.okta.com
    • Email domain: Any email domain associated with this Okta organization that you control
    • Client ID: The client ID from (3)
    • Client Secret: The client secret from (3)

Once complete, you should be able to test login by using the "Log in with email" feature at https://sevhunt.com/auth/login

Microsoft Entra ID SSO setup​

Notes:

  • We only support non-external Entra ID tenants at this time.
  • Users must have an "email" (primary email) set up for SSO to work. This is typically set in their "Contact Information"

Setup:

  1. Create a new App Registration
  2. Choose "Single tenant only"
  3. For the redirect URI, enter https://sevhunt.com/api/auth/sso/callback and submit the registration
  4. Once created, visit "Certificates & secrets" and create a new secret and take note of it
  5. Go to Overview and hit "Endpoints", then copy the first part of your "OpenID Connect metadata document" URI (ex: https://login.microsoftonline.com/{tenantid}/v2.0)
  6. When adding the SSO provider in SevHunt, use the following values:
    • Display name: Microsoft Entra ID
    • Issuer URL: The URL from (5), ex: https://login.microsoftonline.com/{tenantid}/v2.0
    • Email domain: Any email domain associated with this Okta organization that you control
    • Client ID: Your tenant ID (typically a UUID found on your "Overview" page)
    • Client Secret: The client secret from (4)

Once complete, you should be able to test login by using the "Log in with email" feature at https://sevhunt.com/auth/login

Subscription​

This page lets you manage your subscription with SevHunt. For more information on the behavior of upgrading/downgrading your subscription, please visit that page.

Encryption​

Your organization has one or more encryption keys, which are shared by your triage team (admins) so that they can access incoming reports that are client-side encrypted by your users.

This tab allows your admins to rotate to new keys, and to enter passphrases for keys if they do not already have them stored.

Each encryption key contains the following:

  • A public key that your users "share" reports with
  • A private key, encrypted with a strong, salted, randomly generated passphrase
  • Test encrypted values that are used to validate that an admin has the correct passphrase

Organizations can have any number of encryption keys - users submitting reports will default to using the public key of the latest organization keypair, so you should feel comfortable that rotating to new keys will not disrupt users.