Authentication Factors
We often thing about different types of factors when a user authenticates, and this SDK is no different. These factors are grouped into three main categories to simplify the workflow for developers. They are:
- Primary factors, which are used with the start function.
- Secondary factors, which use one of the resume functions.
- Continuation factors, which use an overloaded (or additional) resume function.
Primary factors
Primary factors represent the types of authentication factors that can be performed at an initial sign-in. Some factors, such as password, cannot be used as an MFA step, and are therefore included in this list of factors.
If the application sign-on policy only requires one of these single factors, the sign-in completes after the first step and a token is provided to the developer. In the event that multifactor authentication is required, or the selected factor needs to issue a challenge/response flow, the developer is prompted to provide another response.
Secondary factors
In the event that the server indicates MFA is required, the developer can prompt the user to select a secondary factor, which can then be used in the appropriate resume function. The response cycle is similar to selecting a primary factor, and the response status indicates if another step is required by the developer.
Continuation factors
Some authentication factors, such as WebAuthn, involves having the server issue a challenge payload to the client which must be signed and returned to the server. Out-of-band factors, such as SMS verification codes, require the user to supply a verification code to the server to continue authenticaiton.
For these sorts of factors, the Continuation Factor is used by the developer to select the appropriate response type, which then is passed to the resume function.