Skip to main content
Version: 11.3.0

Beta: Adapt-Affirm Integration in CC

Beta

This integration is in a beta phase. Provide any feedback or enhancement requests to your HYPR Account Manager, and these will be worked into our next release.

API Calls

HYPR Affirm calls for this feature can be found in the HYPR Affirm API in the HYPR Passwordless API.

See also the HYPR Adapt policy evaluation call, which determines whether HYPR Affirm comes into play.

If an Adapt policy finds that a user has exited the bounds set for an event, the policy triggers Affirm, and the user must re-verify their identity. Keycloak enforces this.

To configure HYPR to use Adapt and Affirm together, complete the following steps:

  1. Configure the HYPR Affirm verification flow to be used.

  2. Complete the following fields in Okta for affected users:

    • Mobile phone
    • Street address
    • City
    • State
    • Zip code
    • Manager
    • ManagerId
  3. Modify the Adapt policy to be used, and add any additional checks as desired. The Adapt policy must be written with the following additions specifically for triggering the Affirm authenticator:

      verificationFlowId = 123456789012345678
      allowedAuthenticators = authenticators {
    not allowed # This ensures the rule only applies if condition is true
    authenticators := ["AFFIRM"]
    }

    The following sample shows a complete policy:

      package authz

    import future.keywords.if
    import future.keywords.in

    default allowed := false

    verificationFlowId = 123456789012345678

    result = {"verificationFlowId" : verificationFlowId}

    currentSystemTime := time.now_ns() / 1000000

    # Rule to get the last KC auth event based on eventTimeInUTC
    latestAffirmEvent = last_event {
    # Filter events
    affirmEvents := {event |
    event := input.events[_]
    filterSuccessfulAffirmEvents(event)
    }

    # Extract event times and sort them
    event_times := [event.eventTimeInUTC | event := affirmEvents[_]]
    sorted_times := sort(event_times)

    # Get the last time
    last_time := sorted_times[count(sorted_times) - 1]

    # Find the event that matches the last time
    event := affirmEvents[_]
    event.eventTimeInUTC == last_time

    # Return the event
    last_event := event
    }

    # Get latest Affirm event - make sure attestationResult is successful - check within hardcoded 3 minute time window
    latestAffirmEventIsSuccessful if {
    latestSignal := latestAffirmEvent
    #latestSignal.additionalDetails.affirmInformation.attestationResult == "SUCCESS"
    checkAgainstTimeWindow(latestSignal.eventTimeInUTC)
    }

    # *** Using current system time and event time we check against configured blocked user time window to determine if event should be considered
    checkAgainstTimeWindow(eventTime) if {
    timeDifferenceMillis = currentSystemTime-(to_number(eventTime))
    timeDifferenceMillis < 3 * 1000 * 60
    }

    # *** events to search for
    filterSuccessfulAffirmEvents(event) if {
    event.isSuccessful == true
    event.eventName == "KEYCLOAK_USER_EVENT"
    event.eventTags == "AUTHENTICATION"
    }

    allowed if {
    latestAffirmEventIsSuccessful
    }

    # ***
    allowedAuthenticators = authenticators {
    not allowed # *** This ensures the rule only applies if condition is true
    authenticators := ["AFFIRM"]
    }

    allowedAuthenticators = authenticators {
    allowed # *** This ensures the rule only applies if condition is false
    authenticators := ["PUSH"]
    }

    message = "Forcing KC flow, could not find Affirm success event in last 3 minutes" if {
    not allowed
    }

    message = "Successful KC flow event found, skipping Affirm requirement" if {
    allowed
    }
  4. Contact HYPR Support to turn on the Adapt-Affirm integration feature.

  5. Create a new API Access (Bearer) Token in each affected RP application to connect the HYPR API.