Hi Team, i want to give access to Gooddata to one ...
# gooddata-cloud
s
Hi Team, i want to give access to Gooddata to one of my internal stakeholder. Can anyone tell me how i can provide access??. I have added him as a user in GD with his email ID. But when he logs in to good data, the platform is asking for a password. When i hit forget --> resend, the user doesn't receives any email . Please help with this.
k
This behavior depends on how authentication (OIDC) is set up for your GoodData Cloud organization. From similar cases, there are two common situations: 1. You are still using GoodData’s managed OIDC (Auth0) and are in a transition period to your own OIDC In many paid/professional environments, invitations and password‑reset emails are disabled once the org is preconfigured for using your own OIDC. In that state: - Adding a user in the UI creates them only in the GoodData org, not in the authentication layer. - As a result, login fails and no “Forgot password” email is sent. [[Transition to own OIDC](https://gooddataconnect.slack.com/archives/C04S1MSLEAW/p1748987524824719); [Managed OIDC off](https://gooddataconnect.slack.com/archives/C04S1MSLEAW/p1749697297365139)] In these cases, Support has to manually provision the user (and sometimes set/reset the password or send a reset link) until you implement your own OIDC. [[Users must be added by GD](https://gooddataconnect.slack.com/archives/C04S1MSLEAW/p1736520940160289); [Manual user creation](https://gooddataconnect.slack.com/archives/C04S1MSLEAW/p1758050544427449)] 2. User exists in the org but is missing/has incorrect Auth ID in OIDC Sometimes the user record is present in GoodData but missing the
authId
/ Auth0 ID, or was partially deleted/recreated. Then: - Login fails with “invalid email or password” - “Forgot password” emails are not delivered Support typically fixes this by updating the
authId
or recreating the user in Auth0; after that, the user can use Forgot password successfully. [[Auth ID missing](https://gooddataconnect.slack.com/archives/C04S1MSLEAW/p1744353797454049); [Auth ID fix](https://gooddataconnect.slack.com/archives/C04S1MSLEAW/p1743780495047439)] Because there is no self‑service fix for these in the knowledge sources, the next step is: ### What you should do now 1. Contact GoodData Support (or your GoodData CSM) / post in your support channel and provide: - Your GoodData hostname (e.g.
<http://yourcompany.cloud.gooddata.com|yourcompany.cloud.gooddata.com>
) - The stakeholder’s email address - A short description: - You added the user via UI - They are prompted for a password - “Forgot password” email never arrives 2. Ask them specifically to: - Check whether your org is in the managed OIDC → own OIDC transition (in which case they must manually add the user to Auth0 / OIDC for you). [[Transition explanation](https://gooddataconnect.slack.com/archives/C04S1MSLEAW/p1749697297365139); [Professional-tier transition](https://gooddataconnect.slack.com/archives/C04S1MSLEAW/p1749577555084099)] - Verify that the user has a valid Auth ID / Auth0 ID and fix it if missing. [[Auth0 id missing](https://gooddataconnect.slack.com/archives/C04S1MSLEAW/p1744353797454049)] 3. After Support confirms the fix, have your stakeholder: - Go to your GoodData login page - Click “Forgot password?” - Use the link they receive to set their password and log in. [[Forgot password after manual add](https://gooddataconnect.slack.com/archives/C04S1MSLEAW/p1747040615320449); [Same pattern](https://gooddataconnect.slack.com/archives/C04S1MSLEAW/p1740683244432379)] If you share (with Support) whether you already use your own OIDC or still GoodData’s, they can resolve this faster.
s
@kapa.ai please help.
k
A message from kapa.ai
This issue isn’t something you can fully fix yourself in the UI; it’s almost certainly related to how your organization’s authentication (OIDC/Auth0) is configured. From the cases in the knowledge sources, when a user: - Is added in GoodData with their email, - Is asked for a password on login, - And does not receive any “Forgot password” email, it’s usually because: 1. Your org is in the transition to its own OIDC - The user is created only in the GoodData organization, not in the authentication layer (Auth0 / OIDC). - In this state, invitation and password‑reset emails do not work, and GoodData Support must provision users for you until you switch to your own OIDC. [[Transition to own OIDC](https://gooddataconnect.slack.com/archives/C04S1MSLEAW/p1748987524824719); [Professional-tier transition](https://gooddataconnect.slack.com/archives/C04S1MSLEAW/p1749697297365139)] 2. Or the user is missing a valid Auth ID / Auth0 ID - The user exists in the org but has no
authId
(or an incorrect one), so login and password reset both fail. - In all examples, Support fixed this by updating the Auth ID or recreating the user in Auth0. [[Auth0 id missing](https://gooddataconnect.slack.com/archives/C04S1MSLEAW/p1744353797454049); [Auth ID fix](https://gooddataconnect.slack.com/archives/C04S1MSLEAW/p1739395018610799)] The knowledge sources do not describe a self‑service way for you to repair this; it’s always done by GoodData Support. ### What you should do now 1. Contact GoodData Support (or your GoodData contact) and provide: - Your GoodData hostname (e.g.
<http://yourcompany.cloud.gooddata.com|yourcompany.cloud.gooddata.com>
) - The stakeholder’s email address - Description: - You added the user via UI - They are prompted for a password - “Forgot password” email never arrives 2. Ask Support to: - Confirm whether your org is in the managed OIDC → own OIDC transition and, if so, manually provision this user in Auth0/OIDC. [[Transition explanation](https://gooddataconnect.slack.com/archives/C04S1MSLEAW/p1749577555084099); [Users must be added by GD](https://gooddataconnect.slack.com/archives/C04S1MSLEAW/p1736520940160289)] - Check that the user has a correct Auth ID / Auth0 ID and fix it if missing. [[Auth0 id fix](https://gooddataconnect.slack.com/archives/C04S1MSLEAW/p1743780495047439)] 3. After Support confirms the fix, have your stakeholder: - Go to your GoodData login page - Click “Forgot password?” - Use the email they receive to set a password and then log in. [[Forgot password after manual add](https://gooddataconnect.slack.com/archives/C04S1MSLEAW/p1747040615320449)] If you can, also tell Support whether you already use your own OIDC or still GoodData’s managed OIDC—that helps them resolve it faster.
s
Hi Sameer. Please provide more details about this issue via DM.
Hello Sameer. Thank you for your patience. We have checked internally and can confirm that the user does not have an auth ID. Please, delete him from the project and send an invite again. If it wouldn't help, let us know.
m
Hi Sammer, After further investigation, we found the invitation in our logs. However, for clarification, could you let us know how you added the user? Did you use the APIs to directly 'POST' the user to the entities/user endpoint? If that’s the case, this could explain why the invitation was not triggered. When you POST a user and your organization is part of our OIDC (as is yours), the invitation flow does not activate, and you miss an important component: the AuthenticationId, which is synchronized with our Auth0. In contrast, when you add a user through the UI, the workflow is triggered properly. To create a user via APIs in your situation, I recommend using the "Invite User" call. This method mirrors the UI process, ensuring that the workflow is triggered. To resolve the issue quickly, please consider following the suggestion from my colleague Shamil.
s
@Shamil Akhmadyshev can you help me with the exact steps . It would be helpful and would avoid back n forth. 🤝
m
Hi Sameer, from your domain you’ll go to the Users & groups section:
https://<Your-Domain>/users-and-groups
Here you will all the users and groups - Then on the far-right, you’ll see the 3 dots icon “…” of each user and group and you will click on this, and from there, you’ll have the option to “Delete” the user.
s
Cools, i have deleted the user now. Can you tell me the next steps.
s
Hi Sameer. Here is the instruction: In GoodData Cloud, go to Users & groups. 1. Click Add user. 2. Enter there: First name, last name Email (Optionally) assign user groups 3. Click Create. After creation, you can open the user, go to Groups, and add them to groups that have workspace access.
s
I did this, but the user doesnt get an invite email to join GD.
s
Could you please provide the exact date, time, and email of the user you added? We will check it internally. Thank you for your patience.
s
I have added the user now again. Please lmk asap. User ID - amit_.sahu.dcad6021-8b63-466c-9d96-f9113ff06fc2 User Email - amit@bookeeapp.com
s
Could you please also provide information on the authentication tools you use? You can share that with me via DM if you want.
Hi Sameer. You are using Auth0, but you need to check it and set it up. I have noticed that you are missing
oauthSubjectIdClaim
within your IdP while looking at
{yourProjectURL}/api/v1/entities/identityProviders
. This field (
oauthSubjectIdClaim
) tells GoodData which claim in the ID token should be used as the stable user identifier when creating or mapping users. For most OIDC providers (including Auth0), the correct value is
"sub"
. You can read the documentation about authentication setup here.
Hi again, Sameer. We investigated further and escalated your issue to our L2 technical support. One of our specialists will reach you soon.
m
Hi Sameer, this is Moises from the Technical Support Team. Your case was escalated to me. Let me clarify what happened. The user whose password you attempted to reset was originally provisioned outside of our Auth0 flow. Because of that, they were not able to log in directly to the platform or reset their password. From a quick review of the user endpoints in your org, it looks like authentication is primarily handled via JWT. In most embedding use cases, direct UI access is not required, which explains why this likely did not surface earlier. Since the user now needs to reset their password and go through the standard authentication flow, I have gone ahead and properly provisioned them in our GoodData IDP. Please ask them to use the “Forgot password?” link to complete the reset and gain access. I also understand that the current UI based provisioning flow can be confusing, as it requests an authID even though authentication is still managed by our IDP. I have submitted an internal ticket to fix this so you will be able to handle it independently moving forward. Lastly, as discussed previously, we generally recommend moving to your own IDP to avoid user limits and simplify configuration. Tagging your Account Manager, @Pavel Doubek, since he has also been discussing this topic with you. Please let me know if you have any questions. Happy to help.
s
Hey Moises, thanks a lot, the user is able to successfully log in to the platform . Will discuss with my teammates for moving to our own IDP internally.
1