Verification (User authentication)
Authentication is one of the major parts of security; it is the process by which we recognize the authenticity of the entity. Since cidaas offers a variety of authentication options, such as pattern, face, and many more, we take the utmost care about the originality of the identity.
In this section, you will get to know how you can log in using the configured authentication methods as well as how to authenticate using any of the methods below.
When client-side encryption is enabled for a method (for example PASSWORD, PATTERN, BACKUPCODE), sensitive fields such as password or pass_code may be sent encrypted on the perform step. See Client-side encryption.
Technical Integration
| API | Description | Link |
|---|---|---|
| Get the configured authentication methods | Returns the methods available for the current login request (public login picker). | Link to API |
| Initiate the authentication | Starts verification for a method (for example when the user chooses Touch ID on the login page). | Link to API |
| Perform the authentication | Completes an initiated authentication with the exchange_id from initiation (OTP, TOTP, FIDO2 assertion, and so on) via POST /verification-srv/authentication/{method}/verification — not an /authenticate path. | Link to API |
| Poll authentication status | For asynchronous methods (Push, Touch ID, Face, Pattern, Magic Link, pluggable), poll until status is AUTHENTICATED. | Link to API |
| Continue Login After Authentication | After success, POST /login-srv/verification/login as application/x-www-form-urlencoded with requestId, status_id, verificationType, and masked q. JSON returns 417. Success is often HTTP 302 with a code. | Link to API |
For MFA after a first factor, initiate with the masked q from setup / prelogin — not the real account sub. Custom / pluggable methods: see Pluggable Authentication Mechanism.
More In-Depth View per Method
| cidaas Authentication mechanism | Description | Authentication |
|---|---|---|
| You enter the code sent to your registered email address. | How to use Email | |
| Magic Link | The application sends a Magic Link and polls until the user opens the link and status becomes verified, then continues authentication. | How to use Magic Link |
| Text message | Identification via a code that is sent to your phone via SMS. | How to use Text message |
| FIDO2/Passkeys/FIDO U2F | This standard uses a private and public key to validate your identity. | How to use FIDO |
| TOTP Verification | Time-based One-time Password (TOTP) is a temporary passcode (six-or-eight digit) generated by an algorithm, used for authentication based on your time and device. | How to use TOTP |
| Smart Push notification | Technique that uses the Push notification feature of a mobile device and prompts you to choose the right code (as displayed on the web app) among a set of codes | How to use push |
| Touch ID Recognition | Biometric procedure to verify identity that is based on fingerprint | How to use touch-id |
| Pattern Recognition | Identity verification that requires you to confirm a pattern, like those commonly used in mobile lock patterns. | How to use pattern |
| IVR Recognition | You enter the code that is prompted via a phone call as proof of your identity. | Use the general API flow above (initiation → enter code on verification). Dedicated IVR guide pending. |
| Backup Code | An 8-digit backup code can be used to sign in to your account. | How to use Backup code |
| Face Recognition | Identity verification using advanced biometric methods where the face is uniquely identified. | Use the general API flow above (initiation → verification with photo). Dedicated Face guide pending. |
| Pluggable (custom) | Tenant-registered external verification method. | Pluggable Authentication Mechanism |
Authentication in the Default Hosted Page
Log In
Log in to your cidaas account and enter your credentials.
Choose the authentication method
Once you click on the desired authentication method,
- A push notification is triggered (in the case of pattern, touch, face, and push).
- A verification code is sent via text message or email (in the case of text message and email).
- a call that prompts the code (in the case of IVR)
- Enter the backup code (in case of a backup code).
Authenticate the MFA
-
Click on the notification sent to your phone or check your phone for a verification code.
-
Enter the required authenticity parameter.
-
For face, pattern, push, and touch, you need to enter the same parameter as entered during configuration.
-
For text, IVR, and email, you need to enter the verification code.
-
For the backup code, you need to enter the eight-digit code collected during configuration.
-
For FIDO, you just need to touch the fingerprint sensor
| API | Description | Link |
|---|---|---|
| Initiate FIDO | Starts FIDO2 / passkey authentication for the login request. | Link to API |
| Perform the FIDO authentication | Completes FIDO2 authentication with exchange_id and fido2_client_response. | Link to API |
Success message
A success message will pop up, and you will be logged into your account using the desired MFA.
Please contact us directly on our support page or reach out to cidaas support at [email protected].