Skip to main content
Version: 4.0.4

Verification (User authentication)

Authentication is one of the major parts of security; it is the process by which we recognize the authenticity of the entity. Since cidaas offers a variety of authentication options, such as pattern, face, and many more, we take the utmost care about the originality of the identity.

In this section, you will get to know how you can log in using the configured authentication methods as well as how to authenticate using any of the methods below.

When client-side encryption is enabled for a method (for example PASSWORD, PATTERN, BACKUPCODE), sensitive fields such as password or pass_code may be sent encrypted on the perform step. See Client-side encryption.

Technical Integration​

APIDescriptionLink
Get the configured authentication methodsReturns the methods available for the current login request (public login picker).Link to API
Initiate the authenticationStarts verification for a method (for example when the user chooses Touch ID on the login page).Link to API
Perform the authenticationCompletes an initiated authentication with the exchange_id from initiation (OTP, TOTP, FIDO2 assertion, and so on) via POST /verification-srv/authentication/{method}/verification — not an /authenticate path.Link to API
Poll authentication statusFor asynchronous methods (Push, Touch ID, Face, Pattern, Magic Link, pluggable), poll until status is AUTHENTICATED.Link to API
Continue Login After AuthenticationAfter success, POST /login-srv/verification/login as application/x-www-form-urlencoded with requestId, status_id, verificationType, and masked q. JSON returns 417. Success is often HTTP 302 with a code.Link to API

For MFA after a first factor, initiate with the masked q from setup / prelogin — not the real account sub. Custom / pluggable methods: see Pluggable Authentication Mechanism.

More In-Depth View per Method​

cidaas Authentication mechanismDescriptionAuthentication
EmailYou enter the code sent to your registered email address.How to use Email
Magic LinkThe application sends a Magic Link and polls until the user opens the link and status becomes verified, then continues authentication.How to use Magic Link
Text messageIdentification via a code that is sent to your phone via SMS.How to use Text message
FIDO2/Passkeys/FIDO U2FThis standard uses a private and public key to validate your identity.How to use FIDO
TOTP VerificationTime-based One-time Password (TOTP) is a temporary passcode (six-or-eight digit) generated by an algorithm, used for authentication based on your time and device.How to use TOTP
Smart Push notificationTechnique that uses the Push notification feature of a mobile device and prompts you to choose the right code (as displayed on the web app) among a set of codesHow to use push
Touch ID RecognitionBiometric procedure to verify identity that is based on fingerprintHow to use touch-id
Pattern RecognitionIdentity verification that requires you to confirm a pattern, like those commonly used in mobile lock patterns.How to use pattern
IVR RecognitionYou enter the code that is prompted via a phone call as proof of your identity.Use the general API flow above (initiation → enter code on verification). Dedicated IVR guide pending.
Backup CodeAn 8-digit backup code can be used to sign in to your account.How to use Backup code
Face RecognitionIdentity verification using advanced biometric methods where the face is uniquely identified.Use the general API flow above (initiation → verification with photo). Dedicated Face guide pending.
Pluggable (custom)Tenant-registered external verification method.Pluggable Authentication Mechanism

Authentication in the Default Hosted Page​

Log In​

Log in to your cidaas account and enter your credentials.

Choose the authentication method​

Once you click on the desired authentication method,

  • A push notification is triggered (in the case of pattern, touch, face, and push).
  • A verification code is sent via text message or email (in the case of text message and email).
  • a call that prompts the code (in the case of IVR)
  • Enter the backup code (in case of a backup code).

Authenticate the MFA​

  1. Click on the notification sent to your phone or check your phone for a verification code.

  2. Enter the required authenticity parameter.

  • For face, pattern, push, and touch, you need to enter the same parameter as entered during configuration.

  • For text, IVR, and email, you need to enter the verification code.

  • For the backup code, you need to enter the eight-digit code collected during configuration.

  • For FIDO, you just need to touch the fingerprint sensor

APIDescriptionLink
Initiate FIDOStarts FIDO2 / passkey authentication for the login request.Link to API
Perform the FIDO authenticationCompletes FIDO2 authentication with exchange_id and fido2_client_response.Link to API

Success message​

A success message will pop up, and you will be logged into your account using the desired MFA.

info
Need Support?

Please contact us directly on our support page or reach out to cidaas support at [email protected].