For the complete documentation index, see llms.txt. This page is also available as Markdown.

Managing My Profile

Users can use the My Profile tab under the Dashboard menu of the AdminX interface to manage their devices and accounts.


Viewing My Profile

End users can use the My Profile tab to view their profile details, such as first name, last name, and email ID. Users can also add or remove phone numbers directly through the AdminX interface, giving them the flexibility to update their numbers as needed and ensuring they can receive passcodes on a new number.

To open the My Profile tab:

  1. Log in to a tenant.

  2. Navigate to Dashboard > My Profile.

The My Profile page appears.

Prerequisite: To allow end users to link their mobile or landline numbers, community administrators must first enable Allow users to enroll mobile / landline number under Authentication > Multi-factor Authentication > Enroll Phone Number.

To enroll a phone number:

  1. In the My Profile tab, click Add Phone Number.

  2. On the Enroll a phone number page, select the country code and enter the new phone number.

  3. Select Mobile or Landline, then click Next.

  4. On the Enter your verification code page, enter the OTP received on the newly enrolled device.

After the OTP is validated, the user is notified that the new phone number has been added, and it appears in the Other Phone Numbers field.

To delete a phone number:

  1. Go to the Other Phone Numbers field in the Profile information section of the My Profile tab.

  2. Click the Delete icon beside the phone number. The Remove Phone Number window appears.

  3. Click Remove phone number.

Note: Each time an end user links a new mobile or landline number, an E_USER_PROFILE_UPDATED event is triggered. This event shows the newly updated phone number along with the timestamp of the update.

Managing the Identity Wallet

The Identity Wallet stores all the identity information you have provided to the portal. Users can upload new identity documents and view previously uploaded ones.

To access previously uploaded documents, you must enter your 8-digit PIN to unlock the wallet. This PIN is an additional layer of security and must be entered each time you access sensitive information stored in your wallet.

Tip: If you lose your 8-digit PIN, we recommend creating a new account.

To unlock your wallet and enroll a document:

  1. In the Identity Wallet tab, enter your 8-digit PIN in the Enter an 8-digit PIN field and click Next.

  2. View the identity documents that appear.

  3. To enroll a specific identity document, click Enroll on the corresponding card. For ID Card enrollment, users can select from supported document types such as Green Card, US State IDs, and Global Entry Card, based on eligibility. After successful enrollment, the document appears as a tile in the Identity Wallet.

  4. On the Receive a link on your smartphone page, enter the phone number where you will receive a link to upload your identity document, then click Continue.

  5. The UI confirms that a link has been shared. You will receive the link by SMS on your mobile.

  6. Open the message on your mobile and tap the link. You are redirected to a mobile browser.

  7. Select your language and click Continue.

  8. Tap the checkbox to give consent, then tap Let's get started.

  9. Scan the front and back of the document.

  10. Once scanning is complete, capture your facial image for LiveID verification.

  11. After all verification checks are completed, the document is added to your Identity Wallet.

  12. Return to the UI to confirm that the enrollment is successful.

Primary Documents and IAL2 Eligibility

The Identity Wallet distinguishes between primary identity documents and secondary documents (such as SSN). A primary document must be enrolled before secondary documents can be added, and the combination of enrolled documents determines the user's Identity Assurance Level (IAL).

Recognized primary documents are Driver's License, Passport, Green Card, Global Entry Card, and US State ID (non-Driver's License). A US State ID is classified as a primary document when the scanned document returns type "id", country "usa", and a valid US state region. Once a State ID is enrolled, the user can enroll an SSN and elevate to IAL2.

SSN enrollment

  • SSN enrollment is enabled once any primary document (including a State ID) is successfully added to the wallet.

  • If State ID enrollment fails and no other primary document exists, SSN enrollment remains disabled.

IAL levels by document combination

Enrolled documents
IAL level

State ID alone

IAL1

State ID + another primary document (DL, Passport, Green Card, Global Entry)

IAL2

State ID + SSN

IAL2

State ID + Affidavit (DL, Passport, or SSN)

IAL2

State ID support as a primary document applies only to State IDs enrolled after this update. A State ID is identified using the document's type, country, and state values. Documents enrolled before the update did not store country and state, so a State ID enrolled earlier must be re-enrolled to reach IAL2.

Viewing the expiry status of enrolled documents

The AdminX interface notifies users when a previously enrolled document or affidavit is about to expire or has already expired. This information appears in the Identity Wallet tab under My Profile, allowing users to re-enroll documents as needed.

Two status indicators are displayed on document cards:

  • Expiring Soon — shown for documents that will expire within 30 days. The UI displays the corresponding expiry date.

  • Expired — shown for documents that have already expired. The status appears beside the expired document and prompts the user to re-enroll it.

For both statuses, a Renew Now button appears beneath the card. Clicking it launches the document re-enrollment flow (front/back scan and verification). Upon successful verification, the status changes back to Verified (✔): the existing document is unenrolled and the new document is enrolled.

Note:

  • For affidavits, the expiry date is displayed, but end users cannot update or renew them. Expired affidavits continue to appear in the wallet, with no renewal mechanism.

  • If renewal fails, the document card displays an Enroll → button, because the document has been unenrolled.

  • Expiry checks apply to all documents except LiveID and Social Security Number (SSN).

  • The text Currently supports USA & Canada has been removed.

Enrolling Devices

The Devices tab lets you view enrolled devices. Users can also:

Removing enrolled devices

End users can use the Devices tab to remove their own enrolled devices:

  1. Go to the Devices tab.

  2. Select the device to remove and click the Delete icon under the Actions column.

  3. A confirmation message asks whether you want to remove the device.

  4. Click Remove.

Tracking Invites

End users can use the Invites tab to track the number of invites they have received, along with the date of receipt. This tab also shows the email address the invite was sent to and whether the user has been onboarded. If an invite has expired, users can delete it by clicking the Delete icon next to the Expired status.

Viewing Login Activity

This tab lets end users view their login activity, including the authentication method used, the date and time of login, and the IP address they logged in from.

Viewing Generated Passcodes

Starting with Release v1.10.09, the user's profile page displays the Passcode tab, which can be used during authentication. The OTP displayed here is for situations where users cannot carry their mobile device or install the 1Kosmos app but still need a passcode to authenticate to 1Kosmos applications. The passcode displayed on this page is identical to the Account OTP shown on the mobile device.

IDP Initiated SAML SSO

Administrators can enable IDP-initiated SAML SSO for SAML applications by navigating to the SAML configuration and turning on the Enable IDP Initiated Login toggle. This allows users to launch applications directly without requiring an SP-initiated login flow. An optional Relay State URL can be configured to control where the user is redirected after authentication. If not specified, the user is redirected to the default landing page of the application. Once enabled, users can view and access all SAML applications configured for IDP-initiated login from the My Apps tab on their profile page. Each application is displayed with its name and logo, and users can click Login to launch the application directly.

Last updated

Was this helpful?