This guide walks through setting up ManyLayers to serve multiple organizations.
1

Turn on accounts and signup

suite:
  enabled: true
  local_users_enabled: true

saas:
  signup_approval_required: false  # set to true for manual org vetting
local_users_enabled is what gives the console its sign-in and sign-up forms; without it the only way in is single sign-on. There is no longer a mode: key to set — multi-org scoping is always on.Restart the gateway to apply.
2

New orgs sign up (self-serve)

Your customers sign up via the workspace UI or directly via API:
curl -X POST http://localhost:8180/auth/signup \
  -H "Content-Type: application/json" \
  -d '{
    "email": "admin@newcorp.com",
    "password": "secure-password",
    "org_name": "NewCorp"
  }'
If signup_approval_required: true, the org starts as pending and cannot use the platform until you approve it.
3

Approve pending orgs (if required)

# List pending signups
curl http://localhost:8180/admin/signups \
  -H "Authorization: Bearer $ADMIN_KEY"

# Approve an org
curl -X POST http://localhost:8180/admin/orgs/$ORG_ID/approve \
  -H "Authorization: Bearer $ADMIN_KEY"
4

Create quota plans

Define the plans your customers can be assigned to:
curl -X POST http://localhost:8180/admin/plans \
  -H "Authorization: Bearer $ADMIN_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "Starter",
    "max_users": 10,
    "max_requests_per_month": 100000,
    "max_tokens_per_month": 50000000
  }'
5

Assign a plan to an org

curl -X PUT http://localhost:8180/admin/orgs/$ORG_ID/subscription \
  -H "Authorization: Bearer $ADMIN_KEY" \
  -H "Content-Type: application/json" \
  -d '{"plan_id": "'$PLAN_ID'"}'
6

Configure billing webhooks

Receive billing events in your own systems:
billing:
  webhook_url: https://billing.example.com/events
  webhook_secret: ${MANYLAYERS_BILLING_WEBHOOK_SECRET}
You will receive quota_exceeded events (HMAC-SHA256 signed) when an org hits its plan limits.
7

Enable SCIM provisioning for orgs

Org admins can generate a SCIM token to automate user provisioning from their IdP:
curl -X POST http://localhost:8180/org/scim/token \
  -H "Cookie: session=..."
Configure this token in Okta, Azure AD, or any SCIM-compatible IdP to automate user lifecycle management.

Monitoring your orgs

  • Org list: GET /admin/orgs — view all orgs with status
  • Per-org analytics: GET /admin/orgs/{id}/analytics — usage breakdown
  • Usage export: GET /admin/orgs/{id}/usage/export — CSV for billing
  • Org billing view (for org admins): GET /org/billing