Status Responses
This authentication flow is driven through a series of status responses which all of the start and resume functions return. These statuses describes what options are available to the user, and can help developers drive their user interfaces.
A developer will start an authentication flow using a primary factor, which will return one of the following statuses:
- Success, which indicates the sign in was successful, and contains the token response to the developer.
- MFA Required, tells the developer that the first factor was authenticated successfully, but the server policy requires that an additional factor be verified.
- Continuation Required, is a pseudo-factor type, used when developer or user intervention is required to complete verifying the current factor.
All status responses represent successful API responses from the server. In the event an error occurs, an appropriate error response will be thrown from the function, which should be handled by the developer.
These status responses form the basis for how a developer can interact with the server to walk the user through the sign-in process.
Success
The Success status is returned whenever a user successfully completes signing in.
MFA Required
In the event that the server indicates MFA is required, the developer can prompt the user to select a secondary factor, which can then be used in the appropriate resume function. The response cycle is similar to selecting a primary factor, and the response status indicates if another step is required by the developer.
Continuation Required
Some authentication factors, such as WebAuthn, involves having the server issue a challenge payload to the client which must be signed and returned to the server. Out-of-band factors, such as SMS verification codes, require the user to supply a verification code to the server to continue authenticaiton.
For these sorts of factors, the Continuation Factor is used by the developer to select the appropriate response type, which then is passed to the resume function.