Skip to main content
Version 0.1Draft

Requesting changes today (interim operations)

Who this is for

IT administrators and developers who need a configuration change on a live LuxID integration today, while the self-service Console is still on the roadmap.

One rule

Until the LuxID Console ships, every operation described in this section is performed by LuxID on your request. Send requests from a known Partner contact to servicedesk@post.lu (the Partner-facing operational address - see Contact and support channels for routing and verification rules). The Console pages in this section tell you exactly which fields to include for each operation; this page condenses them into ready-to-send requests.

Always include in every request:

  • Your Organisation and Partner name
  • The Application name and the environment (UAT or Production)
  • A reachable technical contact for follow-up questions

Request templates per operation

Register a new Application

Subject: Application registration - [Partner] - [Application name] - [UAT|Production]

Include the full field list from Register an Application: application name, protocol (OIDC/SAML), redirect URIs or ACS URL, requested claims/Claim Template, branding assets reference, and the environment. UAT registration normally comes first; production follows the go-live review.

Add, change or remove redirect URIs

Subject: Redirect URI change - [Application] - [UAT|Production]

List the exact URIs to add and to remove, one per line, copied from your deployment configuration (exact match matters - see Redirect URIs and domains for the validation rules that will be applied). State when the change is needed; for a production outage caused by a missing URI, say so explicitly in the subject.

Rotate or replace client credentials

Subject: Credential rotation - [Application] - [UAT|Production]

State whether this is routine rotation (request an overlap window so live traffic keeps working) or suspected compromise (LuxID treats it as an incident - mention SECURITY INCIDENT in the subject and the old secret is revoked immediately). For SAML, attach the new signing certificate. Details: Client credentials.

Promote from UAT to Production

Subject: Go-live request - [Application]

Confirm the production redirect URIs, production branding, and the claims you will use. The go-live review criteria are described in Service provider onboarding; environment specifics in Environments.

Request a log extract

Subject: Log extract - [Application] - [date range]

State the stream (authentication, subscription or audit - see Logs and audit trails), the date range, and the purpose (troubleshooting vs compliance/audit - audit requests may need longer processing, see SLA and support).

Create or modify UAT test users

Subject: Test users - [Application] - UAT

List the test users you need with the attribute states that matter for your tests. Remember the UAT passlist: email domains must be ones you own (no free-mail providers) and phone numbers must be registered - see Configure LuxID and Test users and simulation.

Update branding

Subject: Branding update - [Application]

Attach the logo and localised display names per Branding configuration. Branding shown on the login and consent screens is validated by LuxID before activation.

Change your Claim Template

Subject: Claim Template update - [Application]

List the claims to add or remove and one line of business justification per added claim - LuxID reviews requests against data-minimisation principles (Privacy and consent). Claims carrying PII may change your consent screen.

When the Console ships

These templates disappear in favour of self-service - the Console pages in this section describe that future surface. Watch Change management and roadmap for availability announcements.

Updated 2026-06-11