Skip to main content
Version: 4.0.4

Overview of Authentication Methods (Verification)

cidaas Verification covers the second factors and passwordless methods used during login, step-up, and MFA: something the user knows (PIN, Pattern, TOTP), has (phone, hardware key, authenticator app), or is (Face, fingerprint / Touch ID).

Use this page to choose a method, then follow the enrollment and authentication guides. Before end users can enroll a method, an administrator usually enables it for the instance and assigns it through Verification Options on the application.

Getting started​

  1. Activate methods for the instance — Activation of Authentication Methods
  2. Attach MFA rules to the app — Verification Options
  3. Enroll methods for the user — Verification Enrollment
  4. Authenticate at login — Verification (User authentication)

You need a registered cidaas user account (and, for device methods, the cidaas authenticator app where applicable).

cidaas Authentication mechanismDescriptionEnrollmentAuthentication
EmailYou enter the code sent to your registered email address.How to configure EmailHow to use Email
Magic LinkThe application sends a Magic Link and polls until the user opens the link and status becomes verified, then continues authentication.How to configure Magic LinkHow to use Magic Link
Text messageIdentification via a code that is sent to your phone via SMS.How to configure Text messageHow to use Text message
FIDO2/Passkeys/FIDO U2FThis standard uses a private and public key to validate your identity.How to configure FIDOHow to use FIDO
TOTP VerificationTime-based One-time Password (TOTP) is a temporary passcode (six- or eight-digit) generated by an algorithm, used for authentication based on your time and device.How to configure TOTPHow to use TOTP
Smart Push notificationTechnique that uses the push notification feature of a mobile device and prompts you to choose the right code (as displayed on the web app) among a set of codesHow to configure pushHow to use push
Touch ID RecognitionBiometric procedure to verify identity that is based on fingerprintHow to configure touch-idHow to use touch-id
Pattern RecognitionIdentity verification that requires you to confirm a pattern, like those commonly used in mobile lock patterns.How to configure patternHow to use pattern
IVR RecognitionYou enter the code that is prompted via a phone call as proof of your identity.How to configure IVRHow to use IVR (API flow; dedicated guide pending)
Backup CodeAn 8-digit backup code can be used to sign in to your account.How to configure Backup-codeHow to use Backup-code
Face RecognitionIdentity verification using advanced biometric methods where the face is uniquely identified.How to configure face-recognitionHow to use face-recognition (API flow; dedicated guide pending)
Pluggable (custom)Register an external verification SPI and reuse the standard initiation / status APIs.Pluggable Authentication MechanismPluggable Authentication Mechanism

To list a signed-in user's methods and remove them (including EMAIL/SMS, which need a user-identity API and a verification DELETE), see Remove configured methods.

Need Support?

Please contact us directly on our support page or reach out to cidaas support at [email protected].