> For the complete documentation index, see [llms.txt](https://docs.1kosmos.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.1kosmos.com/authentication/1kosmos-mobile-application/onboarding-methods.md).

# Onboarding Methods

***

### Choosing the right method

Use this matrix to pick the onboarding method that fits your scenario:

| Scenario                                            | Recommended method              |
| --------------------------------------------------- | ------------------------------- |
| Standard workforce onboarding at scale              | Email invite — QR scan          |
| User-initiated self-service onboarding              | Self-service request invite     |
| In-person, helpdesk-led onboarding                  | Admin-generated QR code         |
| Bring-your-own-device or remote consumer            | Magic link onboarding           |
| User without easy access to email                   | SMS invite onboarding           |
| Banking, fintech, or regulated industries           | SIM binding onboarding          |
| Migrating from Verizon ID                           | Verizon ID migration            |
| Linking an additional device to an existing account | Self-onboarding from My Profile |

***

### Prerequisites for all methods

Before any onboarding method can be used, the user must:

1. **Install the 1Kosmos mobile app** from the App Store, Google Play, or via APK sideloading
2. **Set an 8-digit PIN** during first-time launch
3. **Enroll Touch ID, Face ID, or LiveID** (recommended, optional based on device)
4. **Grant permissions** for camera, notifications, and (where applicable) location

{% hint style="info" %}
The PIN and biometric setup happen the **first time** the app is launched and apply to the device — not the account. Onboarding methods listed below link a specific tenant or organization account to the already-initialized app.
{% endhint %}

***

### Email invite — QR scan via 1Kosmos app

The default onboarding flow for most workforce and consumer users.

**What it does** — An administrator sends a passwordless authentication invite to the user's registered email address. The email contains a QR code that the user scans using the **Scan QR Code** option inside the already-installed 1Kosmos app. The account is linked instantly.

**When to use it** — Standard onboarding for employees, contractors, and consumers who already have the 1Kosmos app installed.

**Key details**

* Invite typically expires in **72 hours** (admin-configurable)
* Account details appear at the top of the home screen on success
* Requires the user to have already initialized the app (PIN + biometrics)
* QR code is single-use

**Steps**

1. Administrator sends an invite to the user's registered email
2. User opens the email on a separate screen (e.g., desktop)
3. User opens the 1Kosmos app and taps **Scan QR Code**
4. User scans the QR code displayed in the email
5. Account is linked and the user is signed in to the tenant

***

### Email invite — QR scan via device camera

A variant of the email invite flow for users who don't have the app open.

**What it does** — Same as the standard email invite flow, but the user scans the QR code using their device's native **Camera** app instead of the 1Kosmos app. The camera deep-links into the 1Kosmos app to complete onboarding.

**When to use it** — When users are reading the email on their mobile device and want to onboard without manually launching the app first.

**Key details**

* Requires **Scan QR Codes** to be enabled in the device camera settings
* Triggers a deep link that opens the 1Kosmos app automatically
* Same 72-hour invite expiration
* Same single-use QR code behavior

**Steps**

1. Administrator sends an invite to the user's registered email
2. User opens the email on their mobile device
3. User opens the device **Camera** app and points it at the QR code
4. The Camera app prompts to open the 1Kosmos app
5. The 1Kosmos app completes onboarding

***

### Magic link onboarding

The fastest mobile-first onboarding path — no scanning required.

**What it does** — The email invite contains a **Register for Passwordless Authentication** link. Tapping the link on a mobile device opens the 1Kosmos app directly and triggers the onboarding flow without any QR scanning.

**When to use it** — Mobile-first audiences, consumer flows, and remote users where the simplest possible UX is required. Also the recommended fallback when QR scanning fails.

**Key details**

* No QR scanning required
* Works even if the user has not yet installed the app — link offers app store fallback
* Same 72-hour invite expiration
* Single-use link

**Steps**

1. Administrator sends an invite to the user's email
2. User opens the email on their mobile device
3. User taps the **Register for Passwordless Authentication** link
4. The 1Kosmos app opens (or prompts install if missing)
5. User completes biometric authentication and account is linked

***

### SMS invite onboarding

Email-free onboarding for users without easy email access.

**What it does** — Instead of an email, the administrator sends the onboarding link via SMS. The user taps the link on their mobile device, which opens the 1Kosmos app and starts onboarding.

**When to use it** — Users without primary email accounts, deskless workers, contractors, and high-volume consumer onboarding scenarios where SMS conversion outperforms email.

**Key details**

* Requires SMS gateway configured at the tenant level
* Same single-use, time-limited link as magic link onboarding
* Works alongside email invites — admins can send both for redundancy

**Steps**

1. Administrator sends an SMS invite to the user's mobile number
2. User taps the link in the SMS on their mobile device
3. The 1Kosmos app opens
4. User completes biometric authentication and account is linked

***

### Self-service request invite

User-initiated onboarding without admin intervention.

**What it does** — Users navigate to the tenant sign-in page, click **Request an Invite**, and enter their registered email address. The system sends them an invite automatically — they then complete onboarding via QR scan or magic link.

**When to use it** — Organizations that want to reduce administrator workload, allow users to onboard at their own pace, or recover access after invite expiration without contacting helpdesk.

**Key details**

* Requires the **Allow users to self-onboard devices using email invitations** setting in AdminX
* Available from the tenant Sign-In page → Request an Invite
* Email must already exist in the tenant's user directory
* Same 72-hour invite expiration

**Steps**

1. User opens the tenant URL in a browser
2. On the Sign-In page, user clicks **Request an Invite**
3. User enters their registered email and clicks **Send Invite**
4. User receives an email with QR code or magic link
5. User completes onboarding via the email contents

***

### Self-onboarding from My Profile

Add additional devices to an existing account.

**What it does** — Users who are already signed in to AdminX can link a new mobile device directly from their profile page. Useful for users adding a second phone or replacing a device without contacting an administrator.

**When to use it** — Adding a backup device, replacing a device, or onboarding multiple devices to the same account.

**Key details**

* Requires the **Allow users to self-onboard devices from user's profile page** setting in AdminX
* User must be already authenticated to AdminX
* Multiple devices per account allowed (subject to admin policy)

**Steps**

1. User signs in to AdminX
2. User navigates to **My Profile → Devices**
3. User initiates device enrollment, generating a QR code
4. User scans the QR code with the 1Kosmos app on the new device
5. New device is linked to the existing account

***

### Admin-generated QR code (in-person)

Helpdesk-led onboarding when the user is physically present.

**What it does** — A community or helpdesk administrator generates a short-lived QR code from AdminX while the user is in their presence. The user scans the QR code with their 1Kosmos app to complete onboarding immediately.

**When to use it** — High-touch onboarding scenarios — new hire orientation, branch onboarding, helpdesk troubleshooting, or any situation where the admin and user are in the same room.

**Key details**

* QR code is **valid for 2 minutes only**
* Requires `user.generate.qr` permission for the admin
* Generates an `E_ACCESSCODE_GENERATED` event for audit logging
* Stronger fraud resistance than email-based methods (no email interception risk)

**Steps**

1. Admin signs in to AdminX as a community or helpdesk administrator
2. Admin navigates to **Users → All Users**, selects the target user
3. Admin opens the **Devices** tab and clicks **Generate Onboarding Invite**
4. AdminX displays a QR code valid for 2 minutes
5. User scans the QR code with their 1Kosmos app
6. AdminX confirms the device was successfully onboarded

{% hint style="warning" %}
**The 2-minute window is non-extensible.** If the user fails to scan the code in time, the admin must regenerate it.
{% endhint %}

***

### SIM binding onboarding

High-assurance onboarding for regulated industries.

**What it does** — During account registration, the 1Kosmos platform validates that the user's mobile number matches the number registered with their financial institution or employer. It does this through a combination of **SIM detection** and **SMS verification** — confirming the SIM card physically present in the device matches the expected number on file.

**When to use it** — Banking, fintech, internet retail banking, healthcare, and any regulated industry where preventing unauthorized device registration is a regulatory or fraud-prevention priority. Specifically required by directives like the **Reserve Bank of India device binding mandate**.

**Key details**

* Combines SIM card detection with SMS code verification
* Validates against the phone number registered with the institution
* Prevents attackers from registering an unauthorized device on a victim's account
* Ensures only the customer with the registered SIM can pair their device as an authenticator
* Configured at the tenant level by the administrator

**Steps**

1. Institution sends an email invite to the user
2. User clicks the invite, which opens the 1Kosmos app
3. The app challenges the user to verify their phone number
4. The app detects the active SIM and sends a verification SMS to the registered number
5. User confirms the SMS verification
6. Platform validates the SIM and phone number match the institution's records
7. On successful validation, the device is paired as an authenticator

{% hint style="info" %}
SIM binding addresses a specific fraud pattern: attackers attempting to register their own device against a victim's account. By requiring the SIM to match the institution's records, SIM binding makes this attack impractical.
{% endhint %}

***

### Verizon ID migration

A guided migration path for users moving from the Verizon ID app to 1Kosmos.

**What it does** — Users with an existing Verizon ID account can migrate their identity data to the 1Kosmos mobile app through a self-service consent flow. The migration can be initiated from either app and is fully automated once the user provides consent.

**When to use it** — Existing Verizon ID users transitioning to the 1Kosmos platform. No administrator action is required.

**Key details**

* Self-service migration after user consent
* Can be initiated from either the Verizon ID app or the 1Kosmos app
* Migrates account data automatically
* Single-direction migration (Verizon ID → 1Kosmos)

***

### Onboarding via partner integrations

For users onboarding through a partner platform (e.g., Saviynt for contractor enrollment), the onboarding flow is handled via a magic link generated by the 1Kosmos platform on behalf of the partner.

**Example flow — Saviynt contractor onboarding:**

1. Partner platform requests a magic link from 1Kosmos
2. User receives the magic link via email or SMS
3. User clicks the link, opens the 1Kosmos app
4. User completes MFA via OTP (email or SMS)
5. User provides LiveID and consent for PII sharing
6. Identity data is encrypted and shared with the partner platform

These flows are configured by the partner integration and follow the same underlying mechanisms as standard magic link onboarding, with additional partner-specific data exchange.

***

### Method comparison

| Method                     | Initiated by | Security level | Best for                      |
| -------------------------- | ------------ | -------------- | ----------------------------- |
| Email invite — QR (app)    | Admin        | Standard       | Default workforce onboarding  |
| Email invite — QR (camera) | Admin        | Standard       | Mobile-first email readers    |
| Magic link                 | Admin        | Standard       | Mobile-first audiences        |
| SMS invite                 | Admin        | Standard       | Deskless workers, no email    |
| Self-service invite        | User         | Standard       | Reducing admin overhead       |
| Self-onboarding (profile)  | User         | Standard       | Adding additional devices     |
| Admin-generated QR         | Admin        | High           | In-person, helpdesk-led       |
| SIM binding                | Admin        | **Highest**    | Banking, regulated industries |
| Verizon ID migration       | User         | Standard       | Verizon ID users only         |

### Troubleshooting onboarding

| Issue                       | Common cause                  | Resolution                                     |
| --------------------------- | ----------------------------- | ---------------------------------------------- |
| Invite expired              | More than 72 hours since send | User requests a new invite via Self-service    |
| QR scan shows white screen  | Camera permission denied      | Re-enable camera permission in device settings |
| "No accounts found" message | Account not yet onboarded     | Contact administrator to send a fresh invite   |
| Stuck on loading screen     | SIM verification webhook down | Contact administrator                          |
| SMS invite not received     | Wrong phone number on file    | Update phone in user profile, resend invite    |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.1kosmos.com/authentication/1kosmos-mobile-application/onboarding-methods.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
