Custom Verification Steps
Custom Verification Steps let you add your organization's own verification logic to HYPR Affirm workflows, alongside the built-in verification steps. A custom step is a single-page application (SPA) registered with Affirm. When the workflow runs the step, HYPR serves the registered SPA inside the verification flow. The SPA collects evidence and runs its own verification, and the step returns an outcome that drives the rest of the flow.
Custom Verification Step is available in HYPR 11.3 and later.
In 11.3, custom steps are configured through the Code Customization API. The API, together with the Helpdesk activity log integration, makes custom steps usable in production verification flows.
Use Cases
Custom steps suit cases such as the following:
- Organization-specific knowledge-based authentication (KBA): present questions only your organization can ask, drawn from internal systems
- Proprietary fraud-detection integration: call your in-house fraud system as a verification step, with its decision feeding the workflow outcome
- Partner-provided verification services: embed a partner's specialty verification, for example utility-bill verification or postal address validation, as a workflow step
- Custom compliance attestations: require the requester to acknowledge organization-specific compliance language as a tracked verification step
Tenant Enablement
Custom Verification Steps must be enabled on your tenant. Contact HYPR to enable them on your environment.
How to Deploy a Custom Step
To deploy a custom step, build the SPA and register it with Affirm through the Code Customization API. Then assign a Content Security Policy (CSP) to it and attach it to a verification flow. A custom step runs only when a CSP is assigned to it.
For the API requests, see the HYPR Affirm API. For how customizations are created and assigned to a verification flow, see Affirm Code Customizations.
Placement, Retries and Failure Outcome
Each custom step names the built-in step it runs after: Login Identifier, Phone Number / Email Verification, Location, Verified Credential, Document and Biometric Verification, Photo ID and Liveness Capture or Approver Chat and Video. A verification flow can hold up to 10 custom steps.
Like the built-in steps, each custom step has a retry limit (1 to 10 attempts, within 0 to 60 minutes), a failure outcome (Deny Verification, Redirect to URL or Continue Workflow) and an optional escalation to live chat. The defaults are 3 attempts within 0 minutes and Continue Workflow without escalation. For what each failure outcome does, see Injectable Outcomes and Retry Limits.
What the Requester Sees
Affirm shows the custom step inside the standard Affirm card, with your logo and branding. The content of the card is your SPA: its text, fields and buttons are yours, and Affirm adds no fixed text of its own. The SPA runs under the Content Security Policy assigned to the step and reports its result back to Affirm when it finishes.
Because the SPA decides what it asks for, the data a custom step collects is whatever your organization builds into it. Document that data for your requesters alongside the rest of the flow.
Helpdesk Activity Log Integration
Custom steps appear in the Affirm Helpdesk activity log alongside built-in verification steps. Helpdesk agents can see when a custom step ran, what outcome it returned and any metadata the SPA chose to show.
Observability
Custom-step outcomes are verification results like those of the built-in steps. They appear in the Activity Log, are emitted as Events and are visible to Helpdesk agents. The pass or fail outcome of a custom step contributes to the overall outcome of the flow in the same way as a built-in step outcome.
Related
- Affirm Customizations: creating Code Customizations and assigning them to verification flows
- Affirm Helpdesk: Helpdesk activity log integration
- Configure Verification Steps: HYPR's built-in verification steps