Phone Number Verification Step
User self-registration flow step that verifies the phone number of a user by sending a text message with an OTP that has to be entered correctly for the flow to continue.
Note that channel verification is the only way to ensure the uniqueness of phone numbers while at the same time not revealing already registered phone numbers (if Stealth Mode is enabled).
phoneNumberItem) smsGateway) otpGenerator) messageResourceKey) The resource key for the SMS message.
The following syntax can be used to include data in the template:
- ${TOKEN} to include the generated OTP.
- ${USERNAME} to include the name of the registering user.
- ${Now,date,format} to include the current date/time, where "format" is a date pattern like "yyyy-MM-dd HH:mm:ss".
- ${contextDataName} to include the value of the context data field "contextDataName". Note that only context data of type "string" can be included.
Note that non-replaced variables result in a failure and no text message is sent. Therefore, only variable names should be used that are guaranteed to be available when the phone number verification is performed.
originator) maxFailedAttempts) otpValidity) otpCaseSensitive) maxOtpResends) resendSameOtp) true is less secure but helps avoiding erroneous user input when the initial OTP is received before retransmission. defaultCountryCode) captchaProvider) - the response of the flow selecting request (when this step is the first interactive step in a flow).
- the step response immediately preceding the protected step (when this step is not the first interactive step in a flow).
Caution: The CAPTCHA only protects the verification of the OTP. The OTP is send to the user before the CAPTCHA is solved.
interactiveGotoTargets) dynamicStepActivations) skipCondition) If this condition is configured and fulfilled, the step is skipped and the flow execution continues with the subsequent step.
preCondition) requiresActivation) tagsOnSuccess) stepId) onFailureGotos) If the step fails (no retry) and a goto target for the error code is defined here, the flow does not fail and instead a "goto" to the specified target step is executed. Note that even when the "goto" is executed, any error codes that are considered a failed factor attempt will still increment the "failed attempts" counter, and may lead to the user being locked. Therefore, this may still result in a failed flow.
A typical application of this feature is switching to an alternative authentication factor step, if an external service (e.g. Futurae server, SMS gateway) is not available (error code EXTERNAL_SERVICE_UNAVAILABLE with "Strict Counting" disabled, which will not increment the "failed attempts" counter). Other error codes can be found in the IAM REST documentation, in both the general "Error Codes" section and in the documentation of specific endpoints.
customResponseAttributes) A list of custom attributes that are returned in the REST response in addition to the standard attributes the step already returns. The custom attributes defined here are only returned if the step result does not lead to an error response.
Custom attributes are added to the response when a step is initialized and when actions are executed on the step. They will therefore be available in the response leading to this step, and in any responses from endpoints specific to this step. For non-interactive steps, custom attributes are accumulated and added to the response leading to the next interactive step.
Custom attributes are not returned for 'retrieve' endpoints.
customFailureResponseAttributes)
type: PhoneNumberVerificationStep
id: PhoneNumberVerificationStep-xxxxxx
displayName:
comment:
properties:
captchaProvider:
customFailureResponseAttributes:
customResponseAttributes:
defaultCountryCode: 41
dynamicStepActivations:
interactiveGotoTargets:
maxFailedAttempts: 1
maxOtpResends: 0
messageResourceKey: user-self-reg.sms.verification.message
onFailureGotos:
originator:
otpCaseSensitive: true
otpGenerator:
otpValidity: 300
phoneNumberItem:
preCondition:
requiresActivation: false
resendSameOtp: false
skipCondition:
smsGateway:
stepId:
tagsOnSuccess: