Skip to main content
Question

Pathfinder-Enabled Password Safe Cloud – Access Method & Resource Broker Endpoint Clarification

  • April 9, 2026
  • 3 replies
  • 9 views

Forum|alt.badge.img+4

When a BeyondTrust Password Safe Cloud tenant is provisioned with Pathfinder, is direct access via the default subdomain (e.g., example.ps.beyondtrustcloud.com) completely restricted or disabled? If so, could you clarify the exact URL, FQDN, or endpoint that needs to be allowed from the Resource Broker to access Password Safe, including any required ports or protocols?

3 replies

Forum|alt.badge.img+4

Direct access is possible using the hostname of your pathfinder tenant.

This is something like “pfxxxxxx.ps.beyondtrustcloud.com” where the X character are some random value defined by BeyondTrust. Browsing to this url will redirect to “ap.beyondtrust.io...”

At this moment there is, as far as I know, no way to configure a user-friendly URL for a pathfinder-enabled PWS instance.


Forum|alt.badge.img+4
  • Author
  • Trailblazer
  • April 9, 2026

@Vercruysse Steven  Thank you for yout prompt response.That’s mean ps tenant accessing through app.beyondtrust.io right ? Do you have any idea where to find this hostname ? When considering local users,do we need to same local user in path finder & inside ps tenant ?

 

 


Forum|alt.badge.img+4

There are no local users for PWS specifically when using Pathfinder. You use either an external security provider or PF-local users.

 

The url can be tracked down by creating a new API key, at the bottom you’ll see “API base endpoint”, this contains the url.