Introduction
Quick Authentication, or Quick Auth, enables you to create a faster authentication experience for users in areas with slow networks or who use low-bandwidth devices. Regular authentication requires two round trips between the App SDK and the Auth Server. Quick Auth cuts out one of those round trips.
Control Quick Authentication through a FIDO policy. Quick Auth applies to the UAF and FIDO2 authenticators. Quick Authentication can be used during regular authentication and Adaptive Authentication. Configure Quick Auth by setting a value for the Quick Authentication attribute in a FIDO policy.
The table below shows what each value means when the Auth Server receives a Quick Auth request for both a regular authentication and Adaptive Authentication request.
Value | Regular Authentication | Adaptive Authentication |
|---|---|---|
allow | Processes the Quick Auth payload, verifies the signature. If the authenticator matches what is approved in the policy, then authentication succeeds. Otherwise, it fails. | Same as regular authentication. If Quick Auth succeeds and there are other auth methods contained in the sequence, then authentication continues with the next method. |
ignore | Ignores the Quick Auth payload in the request and falls back to doing regular authentication with the current authentication method. | Ignores the Quick Auth payload in the request and falls back to doing normal Adaptive Authentication with the current authentication method. |
disallow | Authentication fails, no processing is done. | Authentication fails, no processing is done. |
When you use Quick Auth with Adaptive Authentication, you must pay careful attention to the Adaptive Rules you create. Quick Auth only makes sense in an authentication sequence that contains a single FIDO authentication method or External Authentication method. Creating an authentication sequence with multiple FIDO authentication methods and non-FIDO authentication methods eliminates the advantages of Quick Auth.
Configure Quick Auth
In the Admin Console, navigate to Authentication > FIDO Policies.
Add a new policy or edit an existing policy.
Enable FIDO UAF or FIDO2 authenticators by doing one or both of the following:
In the FIDO UAF Authenticators panel, check Allow FIDO UAF Authenticators.
In the FIDO2/WebAuthn Authenticators panel, check Allow FIDO2/WebAuthn Authenticators.
On the Policy Details page, in the Additional Features panel, select a value from the dropdown for Quick Authentication.
To enable Quick Authentication in your application, see Registering for Quick Authentication in the iOS, Android, and Web Developer Guides, and Implementing Quick Authentication in the iOS, Android, and Web Developer Guides.