New in THOR Cloud: SSO, Granular Permissions, and Account API Keys

by Aug 10, 2026

This update adds: OIDC SSO with group-based role mapping, configurable roles and permissions, campaign-scoped access, and more secure personal and account-wide API keys.

Enterprise Access Control for THOR Cloud

THOR Cloud now includes a major update to identity and access management. New Single Sign-On, role and permission, and API key capabilities give administrators more control over who can access the platform, what they can do, and how integrations authenticate.

The update is designed for organizations managing larger teams, multiple scan campaigns, or automated workflows. It brings authentication and authorization closer to established enterprise operating models while keeping administration straightforward.

Single Sign-On with Your Identity Provider

Organizations can now connect their own external identity provider to THOR Cloud through OpenID Connect (OIDC). Users sign in with their existing company credentials instead of maintaining a separate THOR Cloud password.

This makes it easier to align THOR Cloud access with existing identity lifecycle processes. When an employee joins, changes responsibilities, or leaves the organization, access can be managed through the central identity provider.

THOR Cloud Single Sign-On configuration

Configure an external OIDC identity provider under Settings > Single Sign-On.

Role Mapping Through SSO Claims

SSO is combined with role mapping based on a groups claim supplied by the identity provider. Administrators choose which claim carries the group list (defaulting to groups) and map the group names used in their directory to one or more THOR Cloud roles.

At sign-in and on every session refresh, THOR Cloud re-reads the groups claim and grants exactly the roles assigned to matching groups — a group added at the identity provider takes effect on the next refresh, and a group removed there revokes the corresponding role just as quickly. Because the identity provider is the source of truth for SSO users, roles assigned by hand in THOR Cloud are not preserved across refreshes; grant them through group mappings instead.

Group names are matched literally, so the values in the mapping must match the identity provider's output character-for-character, including case. This keeps SSO access tightly coupled to the same organizational groups already used throughout the company, reducing manual user administration.

THOR Cloud SSO role mapping

Map IdP group claims to one or more THOR Cloud roles.

Granular Roles and Permissions

The new permission system provides more flexibility than a small set of fixed user levels. Customers can create their own roles, select the permissions assigned to each role, and update those roles as responsibilities change.

Reusable Roles

Roles bundle permissions for common responsibilities. A customer can create roles for administrators, analysts, campaign operators, auditors, or other internal functions and assign them to any number of users.

Direct Permissions

Users can also receive permissions directly. This is useful for exceptions where a user needs a specific capability without creating or changing a shared role. A user's effective permissions are the combined result of all assigned roles and direct permissions.

Campaign-Scoped Access

Permissions can be limited to specific campaigns. This enables teams to separate customers, business units, regions, or investigation cases while allowing users to work only with the campaigns relevant to them.

THOR Cloud roles and effective permissions

Review assigned roles, effective permissions, and direct permissions in one place.

Account API Keys for Controlled Automation

API access has also been expanded to support both personal and account-wide use cases.

Time-Limited Personal API Keys

Personal API keys are now capped at a maximum lifetime of three months. They authenticate as their owner and always reflect that user's current permissions, so revoking access from the user immediately restricts every key they created.

Account-Wide API Keys

Customers can now create account-wide API keys for shared automation and service integrations. These keys carry their own roles and direct permissions, independent of any human user, making it possible to grant only the actions required by a specific integration. Account keys support optional expiration; unlike personal keys they have no built-in maximum lifetime, so we recommend setting one and rotating on a schedule that matches your integration's risk profile.

Allow and Deny IP Restrictions

Both personal and account API keys can be protected with allow and deny IP lists (deny wins over allow). This adds a network-level control that limits where a key can be used and helps reduce the risk associated with exposed or misused credentials.

Practical Security Improvements

Together, these capabilities provide a stronger foundation for operating THOR Cloud in enterprise environments. Centralized authentication reduces password overhead. Role mapping automates access assignment. Granular permissions support least-privilege administration. Time-limited API keys and IP restrictions add safeguards for integrations and unattended workflows.

The result is more control without forcing administrators to manage every user and integration individually.

Getting Started

Administrators can configure the new capabilities from the THOR Cloud Settings area:

  • Single Sign-On: connect an OIDC identity provider, choose the groups claim, and configure group-to-role mappings.
  • Roles: create reusable permission sets and assign them to users.
  • Account Users: review user roles, direct permissions, and campaign-scoped access.
  • Account API Keys: create restricted keys for automation and define IP allow or deny lists.

These additions make THOR Cloud easier to integrate into established identity, security, and automation processes while giving customers precise control over access to their account and campaigns.

More control. Less manual administration. Safer automation.

About the author:

Avatar photo

Tobias Michalski

Tobias Michalski is the Product Owner of THOR Cloud at Nextron Systems. He leads the product strategy and roadmap for the platform, working at the intersection of cybersecurity, engineering, and user experience. His role focuses on understanding the needs of security practitioners and transforming those requirements into effective product capabilities. By collaborating closely with development and research teams, Tobias helps ensure that THOR Cloud delivers intuitive workflows, meaningful insights, and practical solutions for threat detection and incident response. Drawing on his background in software engineering and SaaS platforms, Tobias combines technical understanding with product leadership to guide the evolution of THOR Cloud. His work is driven by a commitment to usability, scalability, and helping organizations strengthen their security operations through innovative technology.

Subscribe to our Newsletter

Monthly news, tips and insights.

Follow Us

Upgrade Your Cyber Defense with THOR

Detect hacker activity with the advanced APT scanner THOR. Utilize signature-based detection, YARA rules, anomaly detection, and fileless attack analysis to identify and respond to sophisticated intrusions.