Selection Option
Description
Configuration of a selectable subflow.
May be used by
Properties
Name (
name) Description
Name of this option.
This name appears in the list of available options (POST /<loginapp-uri>/rest/public/authentication/selection/options/retrieve) and is used as the "id" parameter to select an option (POST /<loginapp-uri>/rest/public/authentication/selection/options/<id>/select).
The name is also used in the UI (single-page application) as "id" of the options string resource key "authentication.selection.options.<id>".
Note that the name is converted to lowercase and underscores "_" are replaced by a hyphen "-", e.g. the resource key for AIRLOCK_2FA would be "authentication.selection.options.airlock-2fa".
Attributes
String
Mandatory
Suggested values
AIRLOCK_2FA, MTAN, CRONTO, CRONTO_ACTIVATION, FIDO, OATH_OTP, RADIUS_OTP, VASCO_OTP, DEVICE_TOKEN, MATRIX, SSO_TICKET
Steps (
steps) Description
Steps of this subflow.
Attributes
Plugin-List
Mandatory
Assignable plugins
Abort Step Account Link Linking Initiation Step Account Link Removal Initiation Step Acknowledge Message Step Airlock 2FA Activation Letter Order Step Airlock 2FA Activation Step Airlock 2FA Activation Step (with additional Activation) Airlock 2FA Activation Trusted Session Binding Step Airlock 2FA Authentication Step Airlock 2FA Delete Devices Step Airlock 2FA Device Deletion Initiation Step Airlock 2FA Device Edit Initiation Step Airlock 2FA Device Edit Step Airlock 2FA Mobile Only Authentication Step Airlock 2FA Public Self-Service Approval Step Airlock 2FA Recovery Trusted Session Binding Step Airlock 2FA Self-Service Approval Step Airlock 2FA Transaction Approval Step Airlock 2FA Usernameless Authentication Step Apply Changes Step Certificate Credential Extraction Step Complete Migration Step Cronto Activation Step Cronto Approval Stealth Step Cronto Authentication Step Cronto Device Reset Step Cronto Device Selection Step Cronto Letter Order Step Cronto Public Self-Service Approval Step Cronto Self-Service Approval Step Cronto Transaction Approval Step CrontoSign Swiss Push Activation Step Delete All Device Tokens Step Delete Cronto Device Initiation Step Delete FIDO Credential Initiation Step Delete OAuth 2.0 Session Initiation Step Delete Remember-Me Device Initiation Step Delete mTAN Number Initiation Step Device Token Authentication Step Device Token Identity Verification Step Device Token Registration Step Disable Cronto Device Initiation Step Disable Cronto Push Initiation Step Disable FIDO Credential Initiation Step Email Change Verification Step Email Identity Verification Step Email Notification Step Email OTP Authentication Step Email OTP Transaction Approval Step Email Verification Step Enable Cronto Device Initiation Step Enable Cronto Push Initiation Step Enable FIDO Credential Initiation Step FIDO Authentication Step FIDO Credential Display Name Change Step FIDO Credential Selection Step FIDO Passwordless Authentication Step FIDO Public Self-Service Approval Step FIDO Registration Step FIDO Self-Service Approval Step FIDO Transaction Approval Step Failure Step Flow Continuation Step Flow Continuation Token Consumption Step HTTP Basic Authentication Step Kerberos Authentication Step Legacy Email OTP Authentication Step Login From New Device Step Mandatory Password Change Step Matrix Checking Step Matrix Public Self-Service Approval Step Matrix Self-Service Approval Step Migration Selection Step Missing Account Link Step Never Migrate Step No Operation Step OATH OTP Activation Step OATH OTP Authentication Step OAuth 2.0 Client Persisting Step OAuth 2.0 Client Registration Step OAuth 2.0 Consent Deny Initiation Step OAuth 2.0 Consent Grant Initiation Step OAuth 2.0 Consent Step OAuth 2.0 Consents Delete Initiation Step OAuth 2.0 SSO Step OAuth 2.0 Session Reset Step OTP Check via RADIUS Step Password Change Self-Service Step Password Letter Order Step Password Reset Step Password-only Authentication Step Phone Number Verification Step Public Self-Service OATH OTP Approval Step Realm Assignment Step Red Flag Raising Step Remember-Me Reset Step Remember-Me Token Generating Step Remember-Me User Identifying Step Rename Cronto Device Step Representation SSO Ticket Identifying Step Risk Assessment Step Role-based Tag Acquisition Step SAML 2.0 SP User Identifying Step SMS Identity Verification Step SSI Authentication Step SSI Issuance Step SSI Passwordless Authentication Step SSI Self-Registration Issuance Step SSI Verification Step SSO Ticket Authentication Step Scriptable Step Secret Questions Identity Verification Step Secret Questions Provisioning Step Select mTAN Token Step Selection Step Selection Step for Public Self-Service Selection Step for Self-Service Selection Step for User Self-Registration Send Email Link Step Set Authentication Method Migration Step Set Authentication Method Step Set Context Data Step Set Password Step Start User Representation Step Stop User Representation Step Tag Removal Step Terms Of Services Step Transaction Approval Parameter Step Unlock User Step (Public Self-Service) User Data Edit Step User Data Registration Step User Identification By Data Step User Identification By Data Step (Public Self-Service) User Identification Step User Identification Step (Public Self-Service) User Identification with FIDO Authentication Step User Lock Step User Persisting Step User Role Assignment Step User Unlock Step (Self-Registration) Username Generation Step Username Password Authentication Step Username Password with FIDO Authentication Step Vasco OTP Authentication Step Vasco OTP Device Activation Vasco OTP Public Self-Service Approval Step Vasco OTP Self-Service Approval Step Voluntary Password Change Step mTAN Authentication Step mTAN Public Self-Service Approval Step mTAN Self-Service Approval Step mTAN Token Edit Step mTAN Token Registration Step mTAN Transaction Approval Step mTAN Verification Step
Condition (
condition) Description
Defines the condition under which this option can be selected.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Account Linking Required Red Flag Condition Active Authentication Method Airlock 2FA Device Deletion Possible Airlock 2FA was used for login (Transaction Approval only) Always False Always True Boolean Condition Cronto Activation Possible Cronto Activation Required Cronto Device Removal Possible Cronto Letter Order Condition Cronto was used for login (Transaction Approval only) CrontoSign Swiss Push Activation Possible Email OTP was used for login (Transaction Approval only) FIDO Credential Removal Possible FIDO was used for login (Transaction Approval only) First Usage of Device Has Cronto Account Has Cronto Device Has Device Token Has Email Address Has FIDO Credential Has Matching Role Has Matrix Card Has OATH OTP Token Has Password Has Suitable Airlock 2FA Device Has Tag Has Vasco OTP Token Has mTAN Activation Letter Has mTAN Token IdP-Initiated SSO Flow On SP Logical AND Logical NOT Logical OR Matching Username Never Migrate Possible New Device Condition Next Authentication Method-based Migration Condition OAuth 2.0 Authorization Code Grant In Progress OIDC prompt=none Condition Password Letter Order Interval Condition Public Self-Service Allowed Condition Red Flag Raised Request Has SSO Ticket Step Activated String Regex Condition User Attribute Is Unique User Identified User Represented Condition Vasco Activation Possible mTAN Number Changed mTAN Number Deletion Possible mTAN Number Registration Possible mTAN was used for login (Transaction Approval only)
YAML Template (with default values)
type: SelectionOption
id: SelectionOption-xxxxxx
displayName:
comment:
properties:
condition:
name:
steps: