← Back to plugin index

Device Token Settings

Description

Configures device token registration and authentication

Allows devices (e.g. mobile apps on smart phones) to register a public key (after successful authentication) and use the key for later authentication.

For example, this can be used as follows: when logging in for the first time using the mobile app, the user authenticates using the password and a second factor. After this initial login, the mobile app registers its public key and obtains a device token. For later logins, the user authenticates using password only. The second factor can be omitted as long as the app has the device token.

Type name
DeviceTokenSettings
Class
com.airlock.iam.flow.shared.application.configuration.devicetoken.DeviceTokenSettings
May be used by
License-Tags
DeviceToken
Properties
Token Data Provider (tokenDataProvider)
Description
Token data provider used to load and store device token data.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Allowed Signature Algorithms (allowedSignatureAlgorithms)
Description
Allowed signature algorithms that can be used to authenticate with the device.
Attributes
String-List
Optional
Default value
[ES256, ES256K, ES384, ES512]
Token Validity [days] (tokenValidityDays)
Description

The validity period of a "binding", i.e. the amount of time a registered key is accepted for authentication after it has been registered. Afterwards, a registered key is no more accepted for authentication and a new key must be registered.

The validity is only relevant when the device token is registered. When using a device token, the expiry date that was computed at registration time is relevant.

Attributes
Integer
Optional
Default value
30
YAML Template (with default values)

type: DeviceTokenSettings
id: DeviceTokenSettings-xxxxxx
displayName: 
comment: 
properties:
  allowedSignatureAlgorithms: [ES256, ES256K, ES384, ES512]
  tokenDataProvider:
  tokenValidityDays: 30