Overview of Authentication Methods (Verification)
cidaas Verification covers the second factors and passwordless methods used during login, step-up, and MFA: something the user knows (PIN, Pattern, TOTP), has (phone, hardware key, authenticator app), or is (Face, fingerprint / Touch ID).
Use this page to choose a method, then follow the enrollment and authentication guides. Before end users can enroll a method, an administrator usually enables it for the instance and assigns it through Verification Options on the application.
Getting started
- Activate methods for the instance — Activation of Authentication Methods
- Attach MFA rules to the app — Verification Options
- Enroll methods for the user — Verification Enrollment
- Authenticate at login — Verification (User authentication)
You need a registered cidaas user account (and, for device methods, the cidaas authenticator app where applicable).
| cidaas Authentication mechanism | Description | Enrollment | Authentication |
|---|---|---|---|
| You enter the code sent to your registered email address. | How to configure Email | How to use Email | |
| Magic Link | The application sends a Magic Link and polls until the user opens the link and status becomes verified, then continues authentication. | How to configure Magic Link | How to use Magic Link |
| Text message | Identification via a code that is sent to your phone via SMS. | How to configure Text message | How to use Text message |
| FIDO2/Passkeys/FIDO U2F | This standard uses a private and public key to validate your identity. | How to configure FIDO | How to use FIDO |
| TOTP Verification | Time-based One-time Password (TOTP) is a temporary passcode (six- or eight-digit) generated by an algorithm, used for authentication based on your time and device. | How to configure TOTP | How to use TOTP |
| Smart Push notification | Technique that uses the push notification feature of a mobile device and prompts you to choose the right code (as displayed on the web app) among a set of codes | How to configure push | How to use push |
| Touch ID Recognition | Biometric procedure to verify identity that is based on fingerprint | How to configure touch-id | How to use touch-id |
| Pattern Recognition | Identity verification that requires you to confirm a pattern, like those commonly used in mobile lock patterns. | How to configure pattern | How to use pattern |
| IVR Recognition | You enter the code that is prompted via a phone call as proof of your identity. | How to configure IVR | How to use IVR (API flow; dedicated guide pending) |
| Backup Code | An 8-digit backup code can be used to sign in to your account. | How to configure Backup-code | How to use Backup-code |
| Face Recognition | Identity verification using advanced biometric methods where the face is uniquely identified. | How to configure face-recognition | How to use face-recognition (API flow; dedicated guide pending) |
| Pluggable (custom) | Register an external verification SPI and reuse the standard initiation / status APIs. | Pluggable Authentication Mechanism | Pluggable Authentication Mechanism |
To list a signed-in user's methods and remove them (including EMAIL/SMS, which need a user-identity API and a verification DELETE), see Remove configured methods.
Please contact us directly on our support page or reach out to cidaas support at [email protected].