Skip to main content

OktaDirectAuth

Authenticate users using Okta's Direct Authentication API, enabling native sign-in experiences supporting Multi-Factor Authentication (MFA).

This enables developers to build native sign-in workflows into their applications, while leveraging MFA to securely authenticate users, without the need to present a browser. Furthermore, this enables passwordless authentication scenarios by giving developers the power to choose which primary and secondary authentication factors to use when challenging a user for their credentials.

This library provides the classes and methods necessary to implement native sign-in, directed by the developer, to follow specific workflows to meet your application's user experience.

Background​

Traditionally OAuth2 is associated with web-based redirect sign-in, whereby web applications redirect to another identity provider (IdP) to sign in. Once the user has authenticated they are redirected back to the originating web URL along with an authorization code, which is exchanged for access tokens from the authorization server.

If a client wants to implement native sign-in, they are usually limited to the simple username/password (aka Resource Owner Password Grant) flow, which doesn't support options for MFA.

Okta's DirectAuth API works around this by extending ROPG to support multifactor scenarios, additional grant types for different factors (such as WebAuthn, SMS, etc), in an extensible way that builds upon existing standards.

Since these APIs extend existing workflows, and there are different mechanisms involved depending on the factor being authenticated (e.g. direct token exchange, challenge/response, or background polling) the APIs involved are sufficiently complex to make directly invoking these APIs difficult for a developer to use.

As a result, the Direct Auth SDK aims to simplify these flows and to encapsulate the factor-specific behaviors into a homogenous set of interfaces that are easy for a developer to interact with.