Skip to main content
Version: 11.3.0

Affirm OIDC Settings

OIDC Settings​

An OIDC setting triggers OpenID Connect (OIDC) authentication for the requester or the approver of a verification flow.

For the requester, the setting forces OIDC authentication at a specified point in the flow. Assign the setting to the verification flow, and enable the setting on the step where the authentication should take place.

For the approver, the setting forces OIDC authentication before the approver enters a verification flow they were invited to by email or SMS.

Create an OIDC Setting​

  1. Go to HYPR Affirm > Advanced Settings > OIDC Settings.
  2. Click New OIDC Settings. The New OIDC Setting dialog opens.
  3. Enter the settings. They match the settings in Identity Provider (IdP) Management, which describes the core OIDC fields, with the following exceptions:
    • PKCE Enabled: Select this checkbox if you use Proof Key for Code Exchange (PKCE)
    • Additional scopes on auth request: If you use non-default Okta API scopes, list them here, separated by commas
    • RP Base URL: This value is the same as the HYPR URL in IdP Management
    • Resource and Generic Parameters: See Pass Additional Authorization-Request Parameters
  4. Click Continue.
New OIDC Setting dialog with Display Name, PKCE Enabled, endpoint and URL fields, RP Base URL, Client ID and Client Secret, and a Continue button

Assign an OIDC Setting to a Verification Flow​

To assign an OIDC setting to the approver of a verification flow:

  1. Open the flow.
  2. Under Advanced Customization, select OIDC Settings.
  3. From the Approver OIDC Setting drop-down, choose the setting.

You can also assign OIDC settings through the HYPR Affirm API.

Pass Additional Authorization-Request Parameters​

The OIDC settings form has fields that add parameters to the authorization request Affirm sends to the IdP. Use them when your IdP expects a parameter that has no dedicated field on the form, for example to enforce a particular authentication behavior or to route the request to a specific policy or resource server.

The following table lists these fields.

FieldWhat it does
Additional scopes on auth requestComma-separated scopes appended to the /authorization request.
ResourceIdentifies the target service or resource that access is being requested for. Affirm adds it to the authorization request as the resource parameter. Enter a valid URL of up to 255 characters.
Generic ParametersA key-value editor. Affirm appends every pair you add to the authorization request.

For example, use a Generic Parameters pair with acr_values to demand a specific assurance level, or with prompt to control whether the IdP re-challenges the user rather than reusing an existing session.

Configure these parameters with your IdP team, and confirm the exact parameter names and accepted values against your IdP's documentation. Affirm passes them through without interpreting them.