What the portal gives a recipient
The download portal is a recipient-only page where one of your recipients manages their own read-only download keys. They can issue, rotate and revoke the keys created through their invitation — nothing else. They cannot widen a grant, see your organization, or touch another recipient's keys.
Invite a recipient
- Open Registry → Recipients and choose the recipient. New recipients are created while issuing a key or through the management API.
- On the recipient page, invite a portal admin: name their email and choose one of your active download keys as the delegation key. Its package grant is the ceiling — every key the recipient issues through the portal is capped by it and expires no later than it.
- Copy the one-time invitation link shown and send it through a secure channel. The link expires after 30 days; invite again if it lapses.
Stay in control
The recipient page shows the keys issued through each invitation alongside the keys you issued directly. Revoking an invitation revokes the keys created through it, and changing or revoking your delegation key revokes them too — so a relationship that ends takes its self-service access with it. registry_recipient_portal.created and registry_recipient_portal.revoked webhook events let your systems follow invitations.
If you prefer to provision keys yourself, the sales automation guide covers API issuance; both approaches mix freely on the same recipient.