Skip to main content

App User Management

Application-specific

User Management is shown on a per-application basis. It appears in several places throughout Control Center:

  • In Standard Mode: Integrations for each integration's associated RP Application
  • In Standard Mode: Workstation under the User Management tab
  • In Advanced Mode: App Properties for the Application selected under Choose an App

In all cases the experience is the same; clicking a username will reveal their associated authentication methods.

API Calls

The calls to perform CRUD operations on users, including lists, user alias and email associations, revealing recovery PINs, and locking/unlocking authenticators, can be found under RP Applications > Application Properties > User Management in the HYPR Passwordless API collection.

Calls for Magic Links administration can be found under RP Applications > Advanced Configuration > Magic Links in the HYPR Passwordless API Collection.

View and manage Application user activity. Users are added to the Application via Magic Links or the HYPR Passwordless client. Once they have completed registration via the HYPR Mobile App, they will appear in the table on this page.

In addition to seeing past activity for users, administrators can monitor a user’s login activity, view additional information about the devices they’ve registered, reveal a recovery PIN, or delete the user to prevent future logins.

Monitoring Workstation User Activity

The User Management page shows a list of all users who’ve installed HYPR Passwordless on their workstation and successfully registered a device. You can filter the results for a particular user by entering all or part of their name in the Search field.

The top-level entry for a user will display columns for Email, Username, Name, Device Count, Last Active, and Actions (Delete the user).

User ColumnsDescription
EmailThe user's email address.
UsernameUsername of the user who logged in to the Application. Workstation Applications show the workstation-authenticated username; Web Applications show the email used to authenticate
NameThe full name of the user, if applicable. Defaults to N/A if no value is present.
Device CountThe number of devices paired.
Last ActiveTime the user was last active on the workstation or web
ActionsDelete; see Deleting a Workstation User

Clicking the downward chevron next to the Email entry will expand to display more details about the user's activity. The expanded view lists all devices paired for that user, including fields for Device Name, Last Active, and Delete.

User ColumnsDescription
Device NameThe name of the device; this is changeable in the user's Device Manager page.
Last ActiveThe last time this device was used.
DeleteDelete the device pairing from the user account.

Clicking the Device Name entry will open a device details dialog that includes two tabs.

Mobile Devices

Details on the phone/tablet, including the ability to delete the paired device, are shown in the following columns:

Mobile Devices ColumnsDescription
ModelThe model of the device (e.g., Moto X or Samsung Galaxy S)
Mobile OSAndroid or iOS
Device IDThe unique identifier for the device.
FIDO IDThe unique FIDO identifier for the user.
Last ActiveThe time the device was last used.
Date CreatedThe time the device pairing was created.
AuthenticatorsIcons representing the number of viable methods in use with the pairing.
ActionsDelete the device pairing.
Workstation IDThe unique identifier for the machine.
WorkstationsName(s) of paired workstations.
Recovery PINOnly displays if Recovery Mode is enabled. Displays a button labeled Click to Reveal PIN which, when clicked, will retrieve the recovery PIN if needed
Date CreatedThe time the workstation pairing was created.
ActionsDelete the device pairing. This action cannot be undone, and the user must register again to access the Application with this device.

Security Keys

Details on the security key, smart-card or passkey (including native biometrics), plus the ability to delete the device, are shown in the following columns. In cases where a mobile device is being used as an Enterprise Passkey, it may appear in this list.

Security Keys ColumnsDescription
Device NameThis will display the manufacturer of the mobile device (e.g., iPhone or Samsung)
FirmwareThe device's firmware version
ModelA breakdown of the Mobile Devices the user has paired with the Application
Last Active(as Last Login, above) Time the user last logged in to the workstation or web
Date Created(as above) Time the user first registered the device to the workstation or web
Certificate Serial NumberThe certificate's serialized identifier, if present
Unlock CodeOnly displays if Security Key Recovery Mode is enabled. Displays a button labeled Click to reveal which, when clicked, will retrieve the security key or smart-card's PIN Unlock Key (PUK) if needed (Standard Security Key | YubiKey Bio MPE)
Delete(as above) Clicking the trash can icon will revoke the user's ability to log into workstation or web with this security key or smart-card; this action cannot be undone, and the user must register again to access the Application with this security key or smart-card.

Deleting a Workstation User

To revoke a user’s ability to login to their workstation using HYPR, click the Delete (trash can) icon at the right side of the user's entry. Confirm the choice by clicking YES, DELETE in the Delete User dialog.

Parting Is Such Sweet Sorrow

Deleting a login is an irreversible action and cannot be undone. Please make sure the user has a valid password for their workstation account since they’ll no longer be able to use their mobile device to log in.