Teams
Account and team security
Account and team security
Lettermint supports account-level and team-level controls for securing access to your email infrastructure.
Account security
Users can secure their own account with passkeys and connected OAuth providers.

Team MFA enforcement
Members with Manage team security can require team members to use multi-factor authentication before accessing team resources.

Enterprise identity
Use SSO to route managed users through your identity provider, and SCIM to provision and deprovision users.
Managing SSO providers, SCIM tokens, role mappings, and team MFA enforcement requires Manage team security. Reading recorded security events requires View audit log.
Token security
- Use Project API tokens only for sending.
- Use Team API tokens only for management automation.
- Create one token per integration.
- Add IP allowlists for tokens used from stable outbound IP addresses.
- Rotate or revoke tokens when ownership changes.
- Never expose tokens in client-side code.
Next steps
Last modified on