OOBStepHandler
In general, Out-of-Band (OOB) flows involve the user fulfilling some form of authentication step that relies on hser interacting with another application or device, such as responding to an Okta Verify push, or receiving an SMS message. Some OOB types involve resuming the verification using a continuation, while others involve the step handler polling the server to see if the user completes their authentication step on the separate app or device.
| Factor Type | Factor Name |
|---|---|
| Primary | oob |
| Secondary | oob |
| Continuation | transfer |
| Continuation | webauthn |
Workflow
In general the OOB step flow's behavior relies on something called a "Binding", which describes how the current application's authentication is bound to the out-of-band authenticator. There are several different "Binding Methods" which are used to control this behavior:
The process typically starts by requesting a code from the server to initiate that the authentication factor should be challenged. In this the server will return a "Binding Context", which indicates how the application should interact with the user:
- Prompt — The application will need to prompt the user for a verification code which will be sent out-of-band to the user (e.g. SMS message).
- Transfer — A code is sent to the user (e.g. a user verification code) which they should transfer to the other application out-of-band, before the handler should begin polling.
- None — No additional steps are necessary to bind this authentication session to the OOB authenticator, so the application should begin polling.
Polling for a Token
The primary behavior of the OOB step handler is there to handle background polling of the /token endpoint to see if the user has completed their authenticator verification on their other app/device. This involves periodically requesting a token, using the oob_code supplied by the server, and responding to the specific error states the server responds with.
Out-of-Band Authentication
When the current authentication status doesn't have a "Binding Context", which is required for authenticating an OOB factor, one should be requested. The result of requesting this binding context includes information about the method by which the authenticator will be bound to the session.
Depending on the binding method returned with this context, the workflow may immediately enter into the polling workflow, or may ask the developer to perform an additional step (using a continuation) before polling.