Manage Users

Trustly assigns a merchant administrator to the Merchant Portal and they are responsible for managing and assigning user access. To help maintain data security, Trustly recommends that only users with official company domain email addresses be granted access to the Merchant Portal. The use of personal email addresses is not recommended.

❗️

Trustly may periodically provide a list to the merchant administrator of the merchant's users who have been granted access to the Merchant Portal, and request that the merchant administrator attest that the list contains only authorized users of the Merchant Portal. The merchant administrator is required to respond to any such requests within 30 days to ensure uninterrupted access to the Merchant Portal.

Available Roles

The following table lists the roles available to merchants.

RoleDescription
Merchant AdminHas full access to the Merchant Portal (can add users)
Merchant FullHas full access to the Merchant Portal except for User Management
Merchant Read OnlyCan only view data in the Merchant Portal (cannot edit)
Merchant Approve TrxnsThis is a limited merchant user role that can only approve transactions
Merchant Refund TrxnsThis is a limited merchant user role that can only refund transactions
Merchant Cancel TrxnsThis is a limited merchant user role that can only cancel transactions

Authentication Types

The merchant's Merchant Portal authorization type determines their authentication method. The following authentication methods are available:

  • Standard: General login information created by Trustly and sent to users to login
  • OIDC: Single sign-sn capabilities through Okta OIDC configuration with the merchant’s Okta instance
  • SAML: Single Sign-On capabilities through Okta SAML configuration with the merchant’s Okta instance

Deactivate a User

To prevent a user from accessing the Merchant Portal, select Disable on the User Management page.

Reactivate a User

To reactivate a user, click Reset Password on the User Management page. An email is sent to the user with instructions to reactivate their account.