Skip to main content

Intents

Intents are a special argument to the DirectAuth workflow that allows a developer to indicate their intention behind the user authentication. By default, this is assumed to be signIn, but the authentication flow may be entered for other purposes, for example to recover a user's password.

Self-Service Password Reset (SSPR)​

DirectAuth only supports authentication, deferring other operations to other APIs more suited to enabling a user to reset their password. In order to enable this feature, the recovery intent should be used along with some additional changes to the token request. This results in the generation of an access token which can only be used to perform requests to change the user's password.

For example, in Swift, a developer could do the following:

let flow = try DirectAuthenticationFlow()
let status = try await flow.start(username,
with: .otp('123456'),
intent: .recovery)

switch status {
case .success(let token):
// Use the token to reset the password
...
}

Implementation​

To achieve this, the Intent enumeration should support the ProvidesOAuth2Parameters interface, allowing it to simplify the arguments supplied to the token request calls.

signIn​

When the signIn intent is supplied, the intent should not supply any additional OAuth2 parameters.

recovery​

During a password recovery process, the only supported scope is okta.myAccount.password.manage. As a result, the additional OAuth2 parameters should be overridden, replacing the developer-supplied scope, as well as including intent=recovery.

OAuth2 ParameterValue
scopeokta.myAccount.password.manage }
intentrecovery