Authentication methods

FoxIDs authenticates users with authentication methods. You can use the built-in login experience, trust external identity providers with OpenID Connect or SAML 2.0, or validate credentials against an existing user store with External Login - API.

Application registrations use authentication methods to sign users in. See Applications for how apps and APIs connect to FoxIDs.

FoxIDs authentication methods and application registrations

Take a look at the FoxIDs test connections in FoxIDs Control: https://control.foxids.com/test-corp
Get read access with the user reader@foxids.com and password gEh#V6kSw

Authentication method types

FoxIDs supports four authentication method types:

For two-factor and multi-factor scenarios, see Two-factor and multi-factor authentication (2FA/MFA).

Authentication method session

Each authentication method creates its own session when a user authenticates. There are two session types:

  • Login authentication methods create a user session.
  • OpenID Connect and SAML 2.0 authentication methods create an authentication method session that stores the data required to continue the login flow and perform logout.

Both session types support configuring lifetime, absolute lifetime, and persistence.

Connect external identity providers

An external OpenID Provider (OP) or Identity Provider (IdP) can be connected with an OpenID Connect or SAML 2.0 authentication method.

All IdPs supporting either OpenID Connect or SAML 2.0 can be connected to FoxIDs. The following are common integration guides.

OpenID Connect

Configure OpenID Connect to trust an external OpenID Provider.

Always request the sub claim, even if you only plan to use the email claim or another custom user ID claim.

How-to guides:

SAML 2.0

Configure SAML 2.0 to trust an external Identity Provider.

Always request the NameID claim, even if you primarily use the email (http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress) claim or another custom user ID claim. SAML 2.0 logout requires NameID.
Prefer metadata-driven configuration so the customer's IdP can automatically download certificate(s). When possible, ask the customer for a live IdP metadata endpoint.

How-to guides:

Connect FoxIDs environments

FoxIDs environments can be connected in two ways:

Environment Link is the fastest and simplest option, but it only works inside one tenant.
OpenID Connect takes more configuration, but it works across tenants and deployments.

Verified platforms

List of customer-verified platforms.

Try the test tenant

FoxIDs cloud is configured with the test tenant test-corp, which contains multiple connected authentication methods.

La tua privacy

Usiamo i cookie per migliorare la tua esperienza sui nostri siti. Fai clic sul pulsante 'Accetta tutti i cookie' per acconsentire all'uso dei cookie. Per rifiutare i cookie non essenziali, fai clic su 'Solo cookie necessari'.

Visita la nostra pagina di Informativa sulla privacy per saperne di più