Groups
A groups record lists the groups that an identifier belongs to. Websites that support triauth receive the list at sign-in and at every session check, and they can turn it into roles and permissions. The record is published next to the identifier's keys, by whoever manages the domain's DNS.
dns
john._at.example.com. TXT "groups admins,billing"When groups matter
Group names belong to your domain and carry its authority. A website may use them for access rules and other settings, for example:
- a website may let you share an item with the members of a group, for example
management@example.com - a website may give you a role, for example account owner, or apply other settings based on your group membership
Publish a membership
Add a groups record at the same DNS name as the identifier's key records.
dns
john._at.example.com. TXT "groups admins,billing"- List several groups in one record, separated by commas, or publish one record per group. All
groupsrecords of an identifier combine into one list. - A group name is short and lowercase, with letters, digits, and hyphens, for example
adminsorproject-x. - A group name belongs to the domain. Websites see it as
admins@example.com, and a record cannot claim a group at another domain.
What websites see
At sign-in, a website receives the list of groups with the domain attached. When it checks the session later, it receives the current list again. How a group maps to a role is the website's decision.
Change or remove a membership
Edit the record to change the list, or delete it to remove the memberships it names. The change takes effect at each website's next sign-in or background session check, after the record's time to live in DNS has passed.
Websites accept a record only when all of their DNS resolvers return the same value. While an edited value spreads, websites may see none of the groups from that record, for up to its TTL, and a session check in that time can take away the roles that depend on them. If that matters to you, keep one group per record. Adding and deleting whole records causes no such gap.
What groups are not
- A group grants nothing on its own. It is a claim that a website may or may not act on.
- A group does not let anyone sign in. Only the identifier's own keys, or a delegation, do that.
- Groups do not work across domains. A
groupsrecord atexample.comcannot grant or modify group membership for identifiers under other domains.