Skip to main content

Cross-Organization vs Organization-Scoped Passwords

Stytch offers two different approaches to passwords within our B2B product, depending on how passwords are treated across Organizations:
  1. Cross-Organization: an email has a single password associated with it, and the end user can use that password to log into any of their Organizations that allow passwords as an authentication method
  2. Organization-Scoped: a password is scoped to a specific MemberID, and can only be used to log into that specific Organization
If you have a single, centralized login page for all Organizations, we recommend you use Cross-Organization passwords by enabling Allow passwords to be used between Organizations in the Passwords Policy page of the Dashboard. If you have tenanted login pages for each Organization, and want to enforce strict data isolation between your Organizations we recommend you use Organization-Scoped passwords and disable this setting.
This is a project-level setting, and cannot be changed if you have active passwords. Make sure you have selected the password type you want in the Dashboard prior to integrating.