# 1Kosmos Product Documentation

## Home

- [Home](https://docs.1kosmos.com/readme.md): Welcome to your team’s developer platform
- [Privacy policy](https://docs.1kosmos.com/privacy-policy.md): Digital identity verification and authentication software that verifies users, eliminates passwords, and stops fraud across workforce, customer, and resident identities.
- [Cookie policy](https://docs.1kosmos.com/cookie-policy.md): Digital identity verification and authentication software that verifies users, eliminates passwords, and stops fraud across workforce, customer, and resident identities.
- [Copyright Notice for 1Kosmos Inc. Product Source Code and Content](https://docs.1kosmos.com/copyright-notice-for-1kosmos-inc.-product-source-code-and-content.md)

## Identity Verification

- [Overview](https://docs.1kosmos.com/identity-verification/overview.md): Verify any user, anywhere, with a single identity platform that combines document, biometric, and database checks into one privacy-first workflow.
- [Core Concepts](https://docs.1kosmos.com/identity-verification/core-concepts.md)
- [Verification flow](https://docs.1kosmos.com/identity-verification/core-concepts/verification-flow.md): A reusable configuration that defines which checks run, on which documents, with what strictness.
- [Session](https://docs.1kosmos.com/identity-verification/core-concepts/session.md): One user's attempt at a verification flow, with its own URL, expiry, status, and result.
- [Viewing Verification Results](https://docs.1kosmos.com/identity-verification/core-concepts/viewing-verification-results.md): This page explains how community and helpdesk administrators can view and interpret document verification session results.
- [AI Analysis Summary](https://docs.1kosmos.com/identity-verification/core-concepts/ai-analysis-summary.md): The AI Analysis Summary adds an AI-powered analysis layer to the verification results view. It takes the underlying verification signals and translates them into a clear, plain-language summary.
- [Assurance Levels](https://docs.1kosmos.com/identity-verification/core-concepts/assurance-levels.md): NIST 800-63-3's scale for how much you can trust a verified identity, and where 1Kosmos sits on it.
- [Manual Review & Manual Capture](https://docs.1kosmos.com/identity-verification/core-concepts/manual-review-and-manual-capture.md): Manual Capture and Manual Review are fallback pathways. They must not be used as the primary route, always ensure the automated scan path is attempted first.
- [Event Reference](https://docs.1kosmos.com/identity-verification/core-concepts/event-reference.md): This page lists every event type recorded in the 1Kosmos Event Logs for ID Verification, along with the fields captured for each event. Events are grouped by activity category so you can quickly find
- [Verification Methods](https://docs.1kosmos.com/identity-verification/verification-methods.md): The catalog of checks you can run inside a flow — pick the combination that fits your risk and friction budget.
- [Document Verification](https://docs.1kosmos.com/identity-verification/verification-methods/document-verification.md): Scan a government-issued document, validate it server-side, and extract fields with field-level confidence scores.
- [Biometric and Liveness](https://docs.1kosmos.com/identity-verification/verification-methods/biometric-and-liveness.md): Bind a real, present person to the photo on their document passively, in seconds, without prompts to blink or turn.
- [Non-Doc verification](https://docs.1kosmos.com/identity-verification/verification-methods/non-doc-verification.md): Verify identity using authoritative data sources and possession signals, no document scan required.
- [Database Verification](https://docs.1kosmos.com/identity-verification/verification-methods/database-verification.md): Cross-check user-submitted data against authoritative government and carrier databases — AAMVA, eCBSV, SSA.
- [Notarized Document Bypass](https://docs.1kosmos.com/identity-verification/verification-methods/notarized-document-bypass.md): Bypass document scanning by having an administrator add a notarized affidavit to a user's wallet.
- [Web-to-Mobile Handoff](https://docs.1kosmos.com/identity-verification/verification-methods/web-to-mobile-handoff.md): Let users start verification on desktop and seamlessly continue on their phone no manual link copying.
- [1Kosmos as a Credential Service Provider (CSP)](https://docs.1kosmos.com/identity-verification/1kosmos-as-a-credential-service-provider-csp.md): How 1Kosmos performs identity proofing as a Credential Service Provider (CSP), aligned with NIST SP 800-63A enrollment and identity proofing requirements.
- [Configurations](https://docs.1kosmos.com/identity-verification/configurations.md): Community administrators—or users with the idproofing.add-journey permission—can create and manage verification journeys in the AdminX interface under Verification > Verification Flows.
- [Capture & Tips](https://docs.1kosmos.com/identity-verification/capture-and-tips.md)
- [Supported Documents](https://docs.1kosmos.com/identity-verification/supported-documents.md): Identity documents and regions supported by 1Kosmos for document scanning and verification.
- [Release Notes](https://docs.1kosmos.com/identity-verification/supported-documents/release-notes.md)
- [UX & Design](https://docs.1kosmos.com/identity-verification/ux-and-design.md): Great experiences are built on three pillars: a product that looks like yours, works for everyone, and speaks your customers' language. This section explains how {{Product}} supports each of these.
- [Branding Customization](https://docs.1kosmos.com/identity-verification/ux-and-design/branding-customization.md): 1Kosmos can be styled to reflect your brand so that, to your customers, it feels like a seamless extension of your own product. This page covers everything you can customize and how to apply it.
- [Responsive Design](https://docs.1kosmos.com/identity-verification/ux-and-design/responsive-design.md): 1Kosmos is built to work across the full range of screen sizes your customers use — from large desktop monitors to phones. The interface reflows automatically so content stays readable.
- [Accessibility](https://docs.1kosmos.com/identity-verification/ux-and-design/accessibility.md): We believe great products should be usable by everyone, regardless of ability. 1kosmos is designed and built to conform to the Web Content Accessibility Guidelines (WCAG) 2.2 at Level AA.
- [Localization](https://docs.1kosmos.com/identity-verification/ux-and-design/localization.md): 1Kosmos can be delivered in your customers' preferred language and regional formats, so the experience feels native wherever they are.
- [Overview](https://docs.1kosmos.com/identity-verification/database-validation/overview.md)
- [AAMVA Verification](https://docs.1kosmos.com/identity-verification/database-validation/aamva-verification.md)
- [Person Search Verification](https://docs.1kosmos.com/identity-verification/database-validation/person-search-verification.md)
- [Aadhaar Verification](https://docs.1kosmos.com/identity-verification/database-validation/aadhaar-verification.md)
- [Overview](https://docs.1kosmos.com/identity-verification/non-doc-verification/overview.md)
- [eID Verification](https://docs.1kosmos.com/identity-verification/non-doc-verification/eid-verification.md): Verify identity using a government-issued or bank-issued electronic ID scheme
- [SSN Verification](https://docs.1kosmos.com/identity-verification/non-doc-verification/ssn-verification.md): Validate a US Social Security Number against authoritative data sources without requiring a physical SSN card.
- [Phone-Based Verification](https://docs.1kosmos.com/identity-verification/non-doc-verification/phone-based-verification.md): Verify identity using mobile carrier intelligence and possession checks on the user's phone number.
- [Overview](https://docs.1kosmos.com/identity-verification/fraud-prevention/overview.md): Non-document fraud signals that assess identity risk from an IP address, email address, and phone number — adding a passive, low-friction layer to document and biometric verification.
- [IP Geolocation](https://docs.1kosmos.com/identity-verification/fraud-prevention/ip-geolocation.md): Assess risk from a user's IP address — approximate location, network type, and anonymizer use — to detect location spoofing, high-risk geographies, and suspicious access patterns.
- [Email Intelligence](https://docs.1kosmos.com/identity-verification/fraud-prevention/email-intelligence.md): Assess risk from a user's email address — domain validity, disposable-address detection, age, and online footprint — to spot fake and synthetic identities during onboarding.
- [Phone Intelligence](https://docs.1kosmos.com/identity-verification/fraud-prevention/phone-intelligence.md): Assess risk from a user's phone number — line type, carrier, portability, and SIM-swap signals — to prevent OTP interception, account takeover, and synthetic identities.
- [Overview](https://docs.1kosmos.com/identity-verification/ial2-verification/overview.md)
- [Create & Manage IAL2 Verification](https://docs.1kosmos.com/identity-verification/ial2-verification/create-and-manage-ial2-verification.md): Administrators can create and manage a new Identity Assurance Level 2 (IAL2) verification flow. This feature enables end users to complete a one-time IAL2 verification.
- [One-Time Verification](https://docs.1kosmos.com/identity-verification/ial2-verification/one-time-verification.md): The one-time IAL2 verification flow enables end users to verify their identity by submitting two specified identity documents, a biometric, and an SSN.
- [OAuth 2.0 and OIDC](https://docs.1kosmos.com/identity-verification/ial2-verification/oauth-2.0-and-oidc.md)
- [SAML](https://docs.1kosmos.com/identity-verification/ial2-verification/saml.md)
- [Identity Wallet-Based Verification](https://docs.1kosmos.com/identity-verification/ial2-verification/identity-wallet-based-verification.md): Identity wallets allow you to store identity documents, and social security details, all in one place on your smartphone or on the web. They allow you to reuse previously verified identities.
- [Overview](https://docs.1kosmos.com/identity-verification/verifiable-credentials/overview.md)
- [Setting Up Microsoft Verified ID Integration](https://docs.1kosmos.com/identity-verification/verifiable-credentials/setting-up-microsoft-verified-id-integration.md)
- [1Kosmos Interoperability with Verifiable Credentials Platforms](https://docs.1kosmos.com/identity-verification/verifiable-credentials/1kosmos-interoperability-with-verifiable-credentials-platforms.md)
- [Release Notes](https://docs.1kosmos.com/identity-verification/release-notes.md)

## Authentication

- [Getting started with passwordless authentication](https://docs.1kosmos.com/authentication/getting-started-with-passwordless-authentication.md): This guide introduces passwordless authentication. You'll understand how authentication works, what you can protect with it, and the steps to go from a new tenant to a working passwordless login.
- [Overview](https://docs.1kosmos.com/authentication/windows-workstation-mfa/overview.md): The Windows Workstation MFA Agent adds multi-factor and passwordless authentication to the Windows login experience, controlled centrally from AdminX Portal.
- [System Requirements](https://docs.1kosmos.com/authentication/windows-workstation-mfa/system-requirements.md): This page lists the supported operating systems and minimum hardware specifications for the Linux host on which the 1Kosmos PAM will be installed.
- [Installation](https://docs.1kosmos.com/authentication/windows-workstation-mfa/installation.md): The Windows Workstation MFA Agent supports two installer formats. Choose the right one for your environment before proceeding, switching formats later requires a full uninstall and reinstall.
- [Install using MSI](https://docs.1kosmos.com/authentication/windows-workstation-mfa/installation/install-using-msi.md): The MSI installer is the recommended method for all new deployments. It supports silent installation, SCCM, Intune, and GPO deployment natively.
- [Install using EXE (Legacy)](https://docs.1kosmos.com/authentication/windows-workstation-mfa/installation/install-using-exe-legacy.md): The EXE installer is supported for existing deployments and manual installations. For all new deployments, use the MSI installer instead.
- [Post-installation Verification](https://docs.1kosmos.com/authentication/windows-workstation-mfa/installation/post-installation-verification.md): After installing the agent, complete these steps to confirm the Credential Provider is active and authentication is working before rolling out to users.
- [Authentication Methods](https://docs.1kosmos.com/authentication/windows-workstation-mfa/authentication-methods.md): The Windows Workstation MFA Agent supports multiple authentication methods. The method presented to a user at login is determined by the Adaptive Auth Journey configured for them in AdminX.
- [Password + OTP](https://docs.1kosmos.com/authentication/windows-workstation-mfa/authentication-methods/password-+-otp.md): Users authenticate by entering their Active Directory password followed by a one-time passcode. This is the most common MFA configuration for organisations transitioning away from password-only login.
- [Push Notification](https://docs.1kosmos.com/authentication/windows-workstation-mfa/authentication-methods/push-notification.md): Users receive an approval request on the 1Kosmos mobile app. From v2.0.4.0, a Number Challenge option is available to protect against push bombing attacks.
- [QR code](https://docs.1kosmos.com/authentication/windows-workstation-mfa/authentication-methods/qr-code.md): Users scan a QR code displayed on the Windows login screen using the 1Kosmos mobile app. No password is required when QR is configured as the sole authentication method.
- [LiveID Selfie](https://docs.1kosmos.com/authentication/windows-workstation-mfa/authentication-methods/liveid-selfie.md): Configure LiveID Selfie with Push Notification for Windows login in 1Kosmos. Authenticate using facial biometrics and 1Kosmos app approval.
- [1Key Biometric](https://docs.1kosmos.com/authentication/windows-workstation-mfa/authentication-methods/1key-biometric.md): Users authenticate using a FIDO2 hardware security key. 1Kosmos supports both single-user keys and multi-user biometric keys (1Key Desktop, which supports up to 3 enrolled users per key).
- [SMS, Email, Voice, OTP](https://docs.1kosmos.com/authentication/windows-workstation-mfa/authentication-methods/sms-email-voice-otp.md): Available from v2.0.6.0. Users receive a one-time passcode via SMS, email, or voice call. No mobile app installation is required.
- [Behavior Authentication](https://docs.1kosmos.com/authentication/windows-workstation-mfa/authentication-methods/behavior-authentication.md): Users authenticate by typing a displayed phrase (typing biometrics) followed by a PIN. No mobile app or hardware key required. Supports offline authentication via cached PIN.
- [Fallback Authentication](https://docs.1kosmos.com/authentication/windows-workstation-mfa/authentication-methods/fallback-authentication.md): Configure a secure fallback authentication method for Windows login so users can regain access with a Helpdesk-issued one-time passcode when their primary method fails.
- [Run As & UAC](https://docs.1kosmos.com/authentication/windows-workstation-mfa/authentication-methods/run-as-and-uac.md): 1Kosmos Credential Provider intercepts Run As and UAC elevation prompts, requiring MFA before elevated access is granted. From v2.0.7.0, passwordless authentication is supported for these scenarios.
- [Deployment Scenarios](https://docs.1kosmos.com/authentication/windows-workstation-mfa/deployment-scenarios.md): 1Kosmos Credential Provider intercepts Run As and UAC elevation prompts, requiring MFA before elevated access is granted. From v2.0.7.0, passwordless authentication is supported for these scenarios.
- [Standard Domain Joined Workstations](https://docs.1kosmos.com/authentication/windows-workstation-mfa/deployment-scenarios/standard-domain-joined-workstations.md): Baseline deployment scenario for 1Kosmos Windows Workstation MFA Agent. Covers Active Directory domain-joined machines with full network connectivity to 1Kosmos tenant.
- [RDP](https://docs.1kosmos.com/authentication/windows-workstation-mfa/deployment-scenarios/rdp.md): 1Kosmos Credential Provider supports MFA enforcement for both incoming and outgoing Remote Desktop Protocol (RDP) sessions.
- [Shared Workstations](https://docs.1kosmos.com/authentication/windows-workstation-mfa/deployment-scenarios/shared-workstations.md): Shared workstation environments allow multiple users to authenticate on the same physical machine using their individual identities, then access shared or privileged accounts managed by CyberArk.
- [Offline Scenario](https://docs.1kosmos.com/authentication/windows-workstation-mfa/deployment-scenarios/offline-scenario.md): Securely log into your Windows workstation even without internet access or when the 1Kosmos cloud is unreachable, using offline authentication methods supported by the 1Kosmos Credential Provider.
- [Entra Joined Workstations](https://docs.1kosmos.com/authentication/windows-workstation-mfa/deployment-scenarios/entra-joined-workstations.md): Support for Microsoft Entra ID joined machines (formerly Azure AD joined) is on 1Kosmos product roadmap. This page will be updated when the feature is available.
- [Uninstall](https://docs.1kosmos.com/authentication/windows-workstation-mfa/uninstall.md): 1Kosmos Windows Workstation MFA Agent can be uninstalled using either the MSI or EXE method, depending on how it was originally installed. A reboot is required after uninstall to remove the machine.
- [Uninstall MSI](https://docs.1kosmos.com/authentication/windows-workstation-mfa/uninstall/uninstall-msi.md): Uninstalling 1Kosmos Windows Workstation MFA Agent via MSI package. Supports both silent (command-line) and UI-guided removal.
- [Uninstall EXE](https://docs.1kosmos.com/authentication/windows-workstation-mfa/uninstall/uninstall-exe.md): Uninstalling 1Kosmos Windows Workstation MFA Agent when it was installed using EXE installer package. Supports both silent (command-line) and UI-guided removal.
- [Troubleshooting & Support](https://docs.1kosmos.com/authentication/windows-workstation-mfa/troubleshooting-and-support.md): This page covers cross-cutting issues with 1Kosmos Windows Workstation MFA Agent, installation failures, Credential Provider service problems, log collection, and connectivity diagnostics.
- [Release Notes for Windows Workstation MFA](https://docs.1kosmos.com/authentication/windows-workstation-mfa/release-notes-for-windows-workstation-mfa.md): Release history for the 1Kosmos Workstation Login Credential Provider for Windows
- [FAQs](https://docs.1kosmos.com/authentication/windows-workstation-mfa/faqs.md)
- [Overview](https://docs.1kosmos.com/authentication/passwordless-for-web-apps/overview.md): Passwordless for Web Apps lets users access web applications without entering a password. 1Kosmos acts as the Identity Provider (IdP) for web applications integrated using standard protocols.
- [Authentication Matrix](https://docs.1kosmos.com/authentication/passwordless-for-web-apps/authentication-matrix.md): The table below outlines the authentication modes supported across different login methods. Availability of each mode depends on how authentication journeys are configured.
- [Analytics](https://docs.1kosmos.com/authentication/passwordless-for-web-apps/analytics.md): The Analytics Dashboard gives Community Administrators a graphical overview of user activity across the tenant. Data can be filtered by today, last 7 days, last 30 days, or a custom date range.
- [Login Methods](https://docs.1kosmos.com/authentication/passwordless-for-web-apps/login-methods.md)
- [Password Reset](https://docs.1kosmos.com/authentication/passwordless-for-web-apps/login-methods/password-reset.md): 1Kosmos gives Community Administrators control over how end users reset forgotten passwords.
- [FIDO Keys](https://docs.1kosmos.com/authentication/passwordless-for-web-apps/login-methods/fido-keys.md): FIDO passkeys enable passwordless login using biometrics or hardware security keys instead of passwords.
- [WebAuthn](https://docs.1kosmos.com/authentication/passwordless-for-web-apps/login-methods/fido-keys/webauthn.md): FIDO2 Web Authentication (WebAuthn) is a standard web API, built into modern web browsers and related web platform infrastructure, used to securely authenticate users across various sites and devices.
- [LiveID (Biometric Authentication)](https://docs.1kosmos.com/authentication/passwordless-for-web-apps/login-methods/liveid-biometric-authentication.md): LiveID is a 1Kosmos signature feature that enables workforce users to enroll their face once and authenticate on any supported device - desktop, mobile, or any camera-enabled device.
- [Behavioral Authentication](https://docs.1kosmos.com/authentication/passwordless-for-web-apps/login-methods/behavioral-authentication.md): Behavioral Authentication in 1Kosmos analyzes how a user interacts with their device, specifically their typing pattern, and compares it against their enrolled behavioral profile to verify identity.
- [Orion Desktop Authenticator](https://docs.1kosmos.com/authentication/passwordless-for-web-apps/login-methods/orion-desktop-authenticator.md): Orion Authenticator is a desktop application that delivers strong, passwordless authentication and TOTP-based MFA directly from a user's Mac or Windows workstation — without requiring a mobile device.
- [Hardware Tokens](https://docs.1kosmos.com/authentication/passwordless-for-web-apps/login-methods/hardware-tokens.md): HMAC-based One-Time Password (HOTP) tokens are hardware devices that generate single-use passcodes based on a shared secret and an incrementing counter.
- [Adaptive Authentication](https://docs.1kosmos.com/authentication/passwordless-for-web-apps/adaptive-authentication.md): Adaptive Authentication verifies the user's identity based on factors such as location, device status, and end-user context.
- [Multi-Factor Authentication](https://docs.1kosmos.com/authentication/passwordless-for-web-apps/multi-factor-authentication.md): Multi-factor Authentication (MFA) requires users to verify their identity using two or more factors before gaining access.
- [Use cases](https://docs.1kosmos.com/authentication/passwordless-for-web-apps/use-cases.md)
- [Entra Passkey for Frontline Workers](https://docs.1kosmos.com/authentication/passwordless-for-web-apps/use-cases/entra-passkey-for-frontline-workers.md): 1Kosmos enables frontline workers to authenticate into Microsoft Entra using a passkey verified through LiveID biometric (selfie).
- [Mobile Authentication via Microsoft Intune MDM](https://docs.1kosmos.com/authentication/passwordless-for-web-apps/use-cases/entra-passkey-for-frontline-workers/mobile-authentication-via-microsoft-intune-mdm.md)
- [Browser Authentication via Chrome Extension](https://docs.1kosmos.com/authentication/passwordless-for-web-apps/use-cases/entra-passkey-for-frontline-workers/browser-authentication-via-chrome-extension.md)
- [In-Flight Enrollment for EAM (Behavior Auth + PIN)](https://docs.1kosmos.com/authentication/passwordless-for-web-apps/use-cases/in-flight-enrollment-for-eam-behavior-auth-+-pin.md): Enable frontline workers to enroll Behavior Auth (typing pattern) and set a PIN in-flight during EAM login - passwordless second-factor authentication with no personal device required.
- [FAQs](https://docs.1kosmos.com/authentication/passwordless-for-web-apps/faqs.md)
- [Overview](https://docs.1kosmos.com/authentication/authentication-broker/overview.md): AdminX Broker connects 1Kosmos to an existing Active Directory or LDAP directory so administrators can manage directory-backed accounts from AdminX.
- [System Requirements](https://docs.1kosmos.com/authentication/authentication-broker/system-requirements.md)
- [AdminX Broker (Directory Connector)](https://docs.1kosmos.com/authentication/authentication-broker/adminx-broker-directory-connector.md)
- [Connect Directory via the AdminX Broker](https://docs.1kosmos.com/authentication/authentication-broker/connect-directory-via-the-adminx-broker.md): AdminX Broker allows a tenant or community administrator to connect and integrate an existing Active Directory (AD) or LDAP user directory with AdminX.
- [Connect to LDAP via Broker](https://docs.1kosmos.com/authentication/authentication-broker/connect-to-ldap-via-broker.md)
- [Configuration Parameters Reference](https://docs.1kosmos.com/authentication/authentication-broker/configuration-parameters-reference.md): This section provides detailed configuration elements and operational parameters used in RADIUS and LDAP Auth Proxy setups.
- [FAQs](https://docs.1kosmos.com/authentication/authentication-broker/faqs.md)
- [Release Notes for Authentication Broker](https://docs.1kosmos.com/authentication/authentication-broker/release-notes-for-authentication-broker.md)
- [Overview](https://docs.1kosmos.com/authentication/authentication-proxy/overview.md)
- [System Requirements](https://docs.1kosmos.com/authentication/authentication-proxy/system-requirements.md)
- [Installation & Configuration](https://docs.1kosmos.com/authentication/authentication-proxy/installation-and-configuration.md): The community administrator uses the AdminX interface to download and configure the Auth Proxy server. This covers creating, modifying, and deleting configurations.
- [Auth Proxy for RADIUS](https://docs.1kosmos.com/authentication/authentication-proxy/auth-proxy-for-radius.md): The RADIUS server is a command-line executable that enables communication between Active Directory (AD) or LDAP users onboarded in 1Kosmos and a RADIUS client.
- [RADIUS Setup](https://docs.1kosmos.com/authentication/authentication-proxy/radius-setup.md): Follow these steps to start the RADIUS server, configure its parameters, and set the RADIUS secret.
- [LDAP Setup](https://docs.1kosmos.com/authentication/authentication-proxy/ldap-setup.md): Follow these steps to start the LDAP server and configure its parameters.
- [Authentication Methods (Push, OTP, IVR)](https://docs.1kosmos.com/authentication/authentication-proxy/authentication-methods-push-otp-ivr.md)
- [FAQs](https://docs.1kosmos.com/authentication/authentication-proxy/faqs.md)
- [Overview](https://docs.1kosmos.com/authentication/passwordless-for-linux-ssh/overview.md): 1Kosmos Login for Linux integrates with the Pluggable Authentication Module (PAM) to enable MFA for SSH login on Linux systems. It supports standalone authentication as well as 2FA/MFA combinations.
- [Prerequisites & Planning](https://docs.1kosmos.com/authentication/passwordless-for-linux-ssh/prerequisites-and-planning.md)
- [System Requirements](https://docs.1kosmos.com/authentication/passwordless-for-linux-ssh/prerequisites-and-planning/system-requirements.md)
- [1Kosmos Platform Prerequisites](https://docs.1kosmos.com/authentication/passwordless-for-linux-ssh/prerequisites-and-planning/1kosmos-platform-prerequisites.md)
- [Installation](https://docs.1kosmos.com/authentication/passwordless-for-linux-ssh/installation.md): This section covers installing the 1Kosmos Linux PAM package, configuring the required license and PAM files, setting up sshd, and verifying the setup with a test SSH login.
- [AdminX Configuration](https://docs.1kosmos.com/authentication/passwordless-for-linux-ssh/adminx-configuration.md): Journeys let you control which authentication factors are required based on who the user is or which group they belong to. By default, a new journey applies to all users.
- [Authentication Methods](https://docs.1kosmos.com/authentication/passwordless-for-linux-ssh/authentication-methods.md): After the 1Kosmos PAM is installed and configured, users SSH into the Linux host and are presented with the available authentication methods based on the configured journey.
- [Uninstallation](https://docs.1kosmos.com/authentication/passwordless-for-linux-ssh/uninstallation.md)
- [SSH Login for Linux Release Notes](https://docs.1kosmos.com/authentication/passwordless-for-linux-ssh/ssh-login-for-linux-release-notes.md): Release history for 1Kosmos SSH MFA for Linux (BlockID PAM for Linux).
- [FAQs](https://docs.1kosmos.com/authentication/passwordless-for-linux-ssh/faqs.md): This page covers common troubleshooting scenarios and useful commands for managing the 1Kosmos Linux PAM.
- [Overview](https://docs.1kosmos.com/authentication/1kosmos-mobile-application/editor.md): 1Kosmos app is a privacy-first identity app that does passwordless authentication, verifies user identity to government-grade assurance, and stores verifiable credentials in a secure digital wallet.
- [Application Capabilities](https://docs.1kosmos.com/authentication/1kosmos-mobile-application/application-capabilities.md)
- [Authentication](https://docs.1kosmos.com/authentication/1kosmos-mobile-application/application-capabilities/authentication.md): Authentication capabilities define how the 1Kosmos mobile app verifies a user during login. Each method addresses a different scenario, from default online flows to fully offline workstation access.
- [Identity Verification](https://docs.1kosmos.com/authentication/1kosmos-mobile-application/application-capabilities/identity-verification.md): Identity verification capabilities allow the 1Kosmos mobile app to bind a user to their real-world identity through verified personal attributes, government-issued documents, and biometric assets.
- [Digital Wallet](https://docs.1kosmos.com/authentication/1kosmos-mobile-application/application-capabilities/digital-wallet.md): The digital wallet is the user-controlled, on-device container for all identity assets and credentials. It uses public-private key cryptography and secure enclave storage to keep data tamper-proof.
- [Account Management](https://docs.1kosmos.com/authentication/1kosmos-mobile-application/application-capabilities/account-management.md): Account management capabilities let users add, remove, and manage multiple organization accounts on a single device. They cover the full lifecycle from onboarding.
- [Recovery and Continuity](https://docs.1kosmos.com/authentication/1kosmos-mobile-application/application-capabilities/recovery-and-continuity.md): Recovery and continuity capabilities ensure users never lose access to their identity wallet or accounts due to a lost device, app reinstall, or version mismatch.
- [Application Usecase](https://docs.1kosmos.com/authentication/1kosmos-mobile-application/application-usecase.md): 1Kosmos app serves a wide range of authentication and identity scenarios, from everyday workstation login to high-assurance government identity verification. This page outlines the common use cases.
- [Onboarding Methods](https://docs.1kosmos.com/authentication/1kosmos-mobile-application/onboarding-methods.md): 1Kosmos supports multiple ways to onboard a user's device and account — from self-service email invites to in-person admin-led onboarding to high-assurance SIM binding for regulated industries.
- [Installation](https://docs.1kosmos.com/authentication/1kosmos-mobile-application/installation.md): The 1Kosmos mobile app is available on iOS and Android. We recommend installing from your device's app store to ensure automatic updates and complete functionality.
- [FAQs](https://docs.1kosmos.com/authentication/1kosmos-mobile-application/faqs.md)
- [Release Notes for 1K App](https://docs.1kosmos.com/authentication/1kosmos-mobile-application/release-notes-for-1k-app.md): Latest updates, new features, improvements, and bug fixes for the 1Kosmos mobile app on iOS and Android.
- [Overview](https://docs.1kosmos.com/authentication/1key-biometric/overview.md): 1Key is a biometric authentication solution for Windows. End users authenticate to their Active Directory (network ID) account using their fingerprint, captured by a 1Key hardware device.
- [Prerequisites & Planning](https://docs.1kosmos.com/authentication/1key-biometric/prerequisites-and-planning.md): Before deploying 1Key, ensure the following requirements are met.
- [Deployment Guide](https://docs.1kosmos.com/authentication/1key-biometric/deployment-guide.md)
- [Auth Server installation](https://docs.1kosmos.com/authentication/1key-biometric/deployment-guide/auth-server-installation.md)
- [Auth Agent installation](https://docs.1kosmos.com/authentication/1key-biometric/deployment-guide/auth-agent-installation.md)
- [Auth Manager installation](https://docs.1kosmos.com/authentication/1key-biometric/deployment-guide/auth-manager-installation.md): The Auth Manager is the application end users open to enroll their fingerprint and security key. It appears in the Windows Start menu as ThinC Manager.
- [Administration Configuration](https://docs.1kosmos.com/authentication/1key-biometric/administration-configuration.md)
- [Fingerprint Consent Enforcement](https://docs.1kosmos.com/authentication/1key-biometric/fingerprint-consent-enforcement.md): Configure and enforce user consent for 1Key fingerprint biometric across enrollment and Windows login. Set up unified or separate biometric consent, manage consent versioning, bulk-import records, and
- [User Guide](https://docs.1kosmos.com/authentication/1key-biometric/user-guide.md): This guide is for end users enrolling, authentication with the 1Key device. Enrollment links your fingerprint to your Active Directory (network ID) account.
- [FAQs](https://docs.1kosmos.com/authentication/1key-biometric/faqs.md)
- [Overview](https://docs.1kosmos.com/authentication/orion-desktop-authenticator/overview.md): Orion Authenticator is a desktop application that delivers strong, passwordless authentication and TOTP-based MFA directly from a user's Mac or Windows workstation — without requiring a mobile device.
- [Prerequisites and Requirements](https://docs.1kosmos.com/authentication/orion-desktop-authenticator/prerequisites-and-requirements.md): Before installing Orion Authenticator, ensure the target workstation meets the requirements below
- [Installation](https://docs.1kosmos.com/authentication/orion-desktop-authenticator/installation.md): Orion Authenticator can be deployed manually or distributed at scale through SCCM, Intune, or any Mobile Device Management (MDM) solution
- [Administrator configuration](https://docs.1kosmos.com/authentication/orion-desktop-authenticator/administrator-configuration.md): Before end users can onboard their accounts, a community administrator must enable Orion in the AdminX portal and optionally configure adaptive authentication policies that use Orion as a factor
- [End-user setup and authentication](https://docs.1kosmos.com/authentication/orion-desktop-authenticator/end-user-setup-and-authentication.md): This topic is for end users who need to onboard their 1Kosmos account to Orion Authenticator and use it to log in to applications
- [Operations and maintenance](https://docs.1kosmos.com/authentication/orion-desktop-authenticator/operations-and-maintenance.md): This page covers ongoing operational tasks for Orion Authenticator: viewing logs, performing in-place upgrades, resetting the agent, and uninstalling
- [AdminX Configuration](https://docs.1kosmos.com/authentication/orion-desktop-authenticator/adminx-configuration.md): Orion Authenticator must be enabled and configured in AdminX before it becomes available to users.
- [End User Guide](https://docs.1kosmos.com/authentication/orion-desktop-authenticator/end-user-guide.md): This section explains how users set up Orion Authenticator on their workstation and use it during login.
- [FAQs](https://docs.1kosmos.com/authentication/orion-desktop-authenticator/faqs.md)
- [Getting Started with AdminX](https://docs.1kosmos.com/authentication/admin-portal/getting-started-with-adminx.md): This page covers everything you need to get started with AdminX: an introduction to the portal and its modules, how to set your preferred user stores, how to configure and use password resets.
- [Dashboard](https://docs.1kosmos.com/authentication/admin-portal/dashboard.md): AdminX Dashboard is the starting point for 1Kosmos setup—configure session attributes, manage invite emails, connect directories (LDAP), and access profile and analytics
- [Managing My Profile](https://docs.1kosmos.com/authentication/admin-portal/dashboard/managing-my-profile.md): Users can use the My Profile tab under the Dashboard menu of the AdminX interface to manage their devices and accounts.
- [Analytics Dashboard](https://docs.1kosmos.com/authentication/admin-portal/dashboard/analytics-dashboard.md): The Analytics Dashboard gives administrators an overview of user activity for a tenant.
- [Directory Integrations](https://docs.1kosmos.com/authentication/admin-portal/directory-integrations.md): Connect 1Kosmos to your existing directories to source user identities and attributes for authentication.
- [Connect to Microsoft Entra ID](https://docs.1kosmos.com/authentication/admin-portal/directory-integrations/connect-to-microsoft-entra-id.md): Connect and integrate your Microsoft Entra ID user store with your AdminX tenant so you can manage all your Entra ID users from AdminX.
- [User Attribute Transformation](https://docs.1kosmos.com/authentication/admin-portal/directory-integrations/user-attribute-transformation.md): Reshape user attributes before they are sent in an assertion. Concatenate values, parse phone numbers from a single directory attribute, filter sensitive AD groups, and prepare directory data.
- [User Management](https://docs.1kosmos.com/authentication/admin-portal/user-management.md): User management covers how administrators create and manage user accounts in 1Kosmos from initial setup and role assignment to onboarding, device management, and session control.
- [Authentication](https://docs.1kosmos.com/authentication/admin-portal/authentication.md)
- [Restricting Access Based on Geolocation](https://docs.1kosmos.com/authentication/admin-portal/authentication/restricting-access-based-on-geolocation.md): 1Kosmos lets organizations manage access using a user's geographic location, helping protect applications from malicious actors while ensuring access is granted only to legitimate users.
- [Setting up IP-based Authentication Journey in AdminX](https://docs.1kosmos.com/authentication/admin-portal/authentication/setting-up-ip-based-authentication-journey-in-adminx.md): This guide explains how to create an IP-based authentication journey in AdminX, allowing you to manage a range of IP addresses for specific user journeys, allowlists, or blocklists.
- [Setup Multi-Factor Authentication](https://docs.1kosmos.com/authentication/admin-portal/authentication/setup-multi-factor-authentication.md): This page provides you detail on how to enable Multi factor authentication (MFA) through AdminX Portal.
- [Enrollment Preferences Policy](https://docs.1kosmos.com/authentication/admin-portal/authentication/enrollment-preferences-policy.md): Enrollment Preference policy allows administrator to associate appropriate authenticators for securely accessing the 1Kosmos application.
- [Configure Adaptive Authentication](https://docs.1kosmos.com/authentication/admin-portal/authentication/configure-adaptive-authentication.md): This page covers how to set up Adaptive Authentication in the Admin Portal by creating journeys with conditions and decision actions.
- [Configure Device Restriction Policy](https://docs.1kosmos.com/authentication/admin-portal/authentication/configure-device-restriction-policy.md): Enforce device enrollment limits by user group or username to reduce unauthorized device sprawl and strengthen authentication governance across your 1Kosmos community
- [Configure Passwordless Login](https://docs.1kosmos.com/authentication/admin-portal/authentication/configure-passwordless-login.md): Community and helpdesk administrators can use the Passwordless Login page in AdminX to manage authentication factors and device configurations for a smooth onboarding experience.
- [Monitoring & Reporting](https://docs.1kosmos.com/authentication/admin-portal/monitoring-and-reporting.md): Know exactly who's accessing what, when, and how. AdminX brings login history, event activity, access denials, and administrator actions together in one place.
- [Event Reference](https://docs.1kosmos.com/authentication/admin-portal/monitoring-and-reporting/event-reference.md)
- [Settings](https://docs.1kosmos.com/authentication/admin-portal/settings.md)
- [General Settings](https://docs.1kosmos.com/authentication/admin-portal/settings/general-settings.md): The page has two tabs — Preferred User Stores and Self Registration — plus tenant information and session controls.
- [Managing Email Templates](https://docs.1kosmos.com/authentication/admin-portal/settings/managing-email-templates.md): Every message your users receive — OTPs, verification links, onboarding invites, password resets — comes from a ready-to-use 1Kosmos template.
- [1Kosmos Attributes](https://docs.1kosmos.com/authentication/admin-portal/settings/1kosmos-attributes.md): 1Kosmos attributes let you define exactly what gets shared.
- [Identity Provider (IdP) Configuration](https://docs.1kosmos.com/authentication/admin-portal/settings/identity-provider-idp-configuration.md): Connect your identity provider to AdminX and unlock user-friendly features like single sign-on. This page walks you through adding an IdP and configuring its metadata, endpoints, and certificates.
- [Branding Customization](https://docs.1kosmos.com/authentication/admin-portal/settings/branding-customization.md): Make the 1Kosmos login experience unmistakably yours. From your logo and colors to the QR code and background, you can tailor the sign-in page to match your organization's brand.
- [Gateway Settings](https://docs.1kosmos.com/authentication/admin-portal/settings/gateway-settings.md): Send your emails, texts, and voice calls through your own providers. On the Gateway Settings page, add your provider details and 1Kosmos will route all outgoing communications using specify account.
- [Consent Management](https://docs.1kosmos.com/authentication/admin-portal/settings/consent-management.md): Put users in control of their biometric data — and keep your organization compliant.
- [Managing Secrets](https://docs.1kosmos.com/authentication/admin-portal/settings/managing-secrets.md): Keep your sensitive data out of your code. Secret Store lets administrators securely store and manage API keys, client secrets, and tokens used in workflows and integrations.
- [Release Notes for AdminX](https://docs.1kosmos.com/authentication/admin-portal/release-notes-for-adminx.md): New features, enhancements, bug fixes, and security updates for the 1Kosmos AdminX platform, listed by release version and date.
- [Release Notes](https://docs.1kosmos.com/authentication/release-notes.md): Stay current with the latest 1Kosmos updates, new features, improvements, and bug fixes across AdminX, authentication, and identity verification.

## Integrations

- [Overview](https://docs.1kosmos.com/integrations/identity-verification/overview.md): 1Kosmos identity verification integrations extend IAL2-compliant identity proofing into the platforms and workflows where access decisions already happen.
- [Okta - Identity Verification for Account Management](https://docs.1kosmos.com/integrations/identity-verification/okta-identity-verification-for-account-management.md): This topic explains how to connect 1Kosmos with Okta to securely verify users’ identities inside of the account management policy.
- [Creating an OIDC client for Okta in 1Kosmos](https://docs.1kosmos.com/integrations/identity-verification/okta-identity-verification-for-account-management/creating-an-oidc-client-for-okta-in-1kosmos.md): Creating an OIDC client for Okta in 1Kosmos
- [Configuring verification flow & workflow in 1Kosmos](https://docs.1kosmos.com/integrations/identity-verification/okta-identity-verification-for-account-management/configuring-verification-flow-and-workflow-in-1kosmos.md): You will need to configure the identity verification steps that you want the end user to go through. To do this, you must configure a verification flow and a workflow.
- [Configuring 1Kosmos as a custom identity verification vendor in Okta](https://docs.1kosmos.com/integrations/identity-verification/okta-identity-verification-for-account-management/configuring-1kosmos-as-a-custom-identity-verification-vendor-in-okta.md): Configuring 1Kosmos as an Identity Verification Vendor in Okta
- [Epic - Identity Verification in MyChart and EpicCare Link](https://docs.1kosmos.com/integrations/identity-verification/epic-identity-verification-in-mychart-and-epiccare-link.md): This topic explains how to implement 1Kosmos for identity verification in MyChart and EpicCare Link using the Epic Toolbox.
- [Setting up an Epic OIDC Client in 1Kosmos](https://docs.1kosmos.com/integrations/identity-verification/epic-identity-verification-in-mychart-and-epiccare-link/setting-up-an-epic-oidc-client-in-1kosmos.md)
- [Configuring verification flow & workflow in 1Kosmos](https://docs.1kosmos.com/integrations/identity-verification/epic-identity-verification-in-mychart-and-epiccare-link/configuring-verification-flow-and-workflow-in-1kosmos.md): You will need to configure the identity verification steps that you want the end user to go through. To do this, you must configure a verification flow and a workflow.
- [Configuring 1Kosmos as an identity verification vendor in Epic](https://docs.1kosmos.com/integrations/identity-verification/epic-identity-verification-in-mychart-and-epiccare-link/configuring-1kosmos-as-an-identity-verification-vendor-in-epic.md)
- [Microsoft Entra - Account Recovery](https://docs.1kosmos.com/integrations/identity-verification/microsoft-entra-account-recovery.md): This topic explains how to configure 1Kosmos for Microsoft Entra Account Recovery using the Microsoft Security Store.
- [Recovering user accounts in Microsoft Entra](https://docs.1kosmos.com/integrations/identity-verification/microsoft-entra-account-recovery/recovering-user-accounts-in-microsoft-entra.md): Microsoft Entra Account Recovery follows a structured, multi-step process. 1Kosmos powers the identity verification step at the core of this flow.
- [Plans & pricing](https://docs.1kosmos.com/integrations/identity-verification/microsoft-entra-account-recovery/plans-and-pricing.md): Identity Verification by 1Kosmos is available through the Microsoft Security Store at pay-as-you-go pricing.
- [Purchasing 1Kosmos in the Microsoft Security Store](https://docs.1kosmos.com/integrations/identity-verification/microsoft-entra-account-recovery/purchasing-1kosmos-in-the-microsoft-security-store.md): How to purchase 1Kosmos through the Microsoft Security Store
- [Sailpoint - Identity Verification for Workflows](https://docs.1kosmos.com/integrations/identity-verification/sailpoint-identity-verification-for-workflows.md): This topic explains how to connect 1Kosmos with Sailpoint to initiate identity verification from within Sailpoint Workflows.
- [Initial Sailpoint set up](https://docs.1kosmos.com/integrations/identity-verification/sailpoint-identity-verification-for-workflows/initial-sailpoint-set-up.md)
- [Sailpoint Workflows](https://docs.1kosmos.com/integrations/identity-verification/sailpoint-identity-verification-for-workflows/sailpoint-workflows.md)
- [Workflow 1: Enroll a New Identity for Verification](https://docs.1kosmos.com/integrations/identity-verification/sailpoint-identity-verification-for-workflows/sailpoint-workflows/workflow-1-enroll-a-new-identity-for-verification.md)
- [Workflow 2: Record the Verification Result](https://docs.1kosmos.com/integrations/identity-verification/sailpoint-identity-verification-for-workflows/sailpoint-workflows/workflow-2-record-the-verification-result.md)
- [1Kosmos Workflow: Identity Verification](https://docs.1kosmos.com/integrations/identity-verification/sailpoint-identity-verification-for-workflows/1kosmos-workflow-identity-verification.md)
- [Saviynt - Identity Verification for Workflows](https://docs.1kosmos.com/integrations/identity-verification/saviynt-identity-verification-for-workflows.md): This topic explains how to connect 1Kosmos with Saviynt to initiate identity verification from within Saviynt Workflows.
- [Configuring a verification journey in 1Kosmos](https://docs.1kosmos.com/integrations/identity-verification/saviynt-identity-verification-for-workflows/configuring-a-verification-journey-in-1kosmos.md)
- [Configuring identity proofing settings in Saviynt](https://docs.1kosmos.com/integrations/identity-verification/saviynt-identity-verification-for-workflows/configuring-identity-proofing-settings-in-saviynt.md)
- [ServiceNow - Identity Verification for Account Management](https://docs.1kosmos.com/integrations/identity-verification/servicenow-identity-verification-for-account-management.md): This topic explains how to connect 1Kosmos with Okta to securely verify users’s identities for account management.
- [Installing & configuring 1Kosmos-Verify](https://docs.1kosmos.com/integrations/identity-verification/servicenow-identity-verification-for-account-management/installing-and-configuring-1kosmos-verify.md)
- [Testing 1Kosmos-Verify in ServiceNow](https://docs.1kosmos.com/integrations/identity-verification/servicenow-identity-verification-for-account-management/testing-1kosmos-verify-in-servicenow.md)
- [Custom Integrations](https://docs.1kosmos.com/integrations/authentication/custom-integrations.md)
- [OIDC Application Integrations](https://docs.1kosmos.com/integrations/authentication/custom-integrations/oidc-application-integrations.md): OpenID Connect (OIDC) is an industry-standard authentication layer built on top of the OAuth 2.0 authorization protocol. OAuth 2.0 provides security through scoped access tokens.
- [SAML Application Integrations](https://docs.1kosmos.com/integrations/authentication/custom-integrations/saml-application-integrations.md): The Security Assertion Markup Language (SAML) integration enables passwordless authentication for users logging into a service provider's web application.
- [WS-Fed Application Integrations](https://docs.1kosmos.com/integrations/authentication/custom-integrations/ws-fed-application-integrations.md): WS-Fed (WS-Federation) Application Integration is a way to enable Single Sign-On (SSO) between an Identity Provider (IdP) and an application using the WS-Federation protocol.
- [Desktop SSO](https://docs.1kosmos.com/integrations/authentication/desktop-sso.md)
- [Kerberos Single Sign-On](https://docs.1kosmos.com/integrations/authentication/desktop-sso/kerberos-single-sign-on.md): 1Kosmos uses Kerberos with Active Directory (AD) to provide seamless SSO. Users authenticated on their AD network are automatically signed in to 1Kosmos applications without re-entering credentials.
- [External Identity Provider (SSO Federation)](https://docs.1kosmos.com/integrations/authentication/external-identity-provider-sso-federation.md): 1Kosmos can participate in single sign-on (SSO) in different roles depending on your scenario. Use the guide that matches your setup.
- [Microsoft Azure as an External Identity Provider](https://docs.1kosmos.com/integrations/authentication/external-identity-provider-sso-federation/microsoft-azure-as-an-external-identity-provider.md): The steps to configure Azure as an External Identity Provider (IdP) for the 1Kosmos Service Provider (SP) using SAML (Security Assertion Markup Language) for authentication.
- [Setting Up 1Kosmos as an Identity Provider](https://docs.1kosmos.com/integrations/authentication/external-identity-provider-sso-federation/setting-up-1kosmos-as-an-identity-provider.md): Configure Okta as a service provider (SP) in addition to using it as an identity provider (IdP). When Okta acts as a service provider, it integrates with an external Identity Provider using SAML
- [1Kosmos as a Service Provider in Okta](https://docs.1kosmos.com/integrations/authentication/external-identity-provider-sso-federation/1kosmos-as-a-service-provider-in-okta.md): The steps to configure 1Kosmos as a Service Provider (SP) in Okta using SAML for authentication.
- [1Kosmos as an External Identity Provider in Okta](https://docs.1kosmos.com/integrations/authentication/external-identity-provider-sso-federation/1kosmos-as-an-external-identity-provider-in-okta.md): The steps to configure 1Kosmos as an External Identity Provider (IdP) with an Okta Service Provider (SP) using SAML for authentication.
- [Setting up 1Kosmos as an External Authentication Method for Microsoft Entra ID](https://docs.1kosmos.com/integrations/authentication/external-identity-provider-sso-federation/setting-up-1kosmos-as-an-external-authentication-method-for-microsoft-entra-id.md): The steps to configure 1Kosmos as an External Authentication Method (EAM) for Microsoft Entra ID using OIDC.
- [Pre-built Integrations](https://docs.1kosmos.com/integrations/authentication/pre-built-integrations.md)
- [Auth0](https://docs.1kosmos.com/integrations/authentication/pre-built-integrations/auth0.md): Enable passwordless, biometric login for your Auth0 users using 1Kosmos as a SAML 2.0 Identity Provider. Once connected, users authenticate with Touch ID, Face ID, or LiveID instead of a password.
- [Entra EAM (Beta)](https://docs.1kosmos.com/integrations/authentication/pre-built-integrations/entra-eam-beta.md): Enable passwordless, biometric login for Microsoft Entra External Authentication Method (EAM) users using 1Kosmos as an OIDC Identity Provider.
- [G-Suite](https://docs.1kosmos.com/integrations/authentication/pre-built-integrations/g-suite.md): Enable passwordless, biometric login for your Google Workspace users using 1K as a SAML 2.0 Identity Provider. Once connected, users authenticate with Touch ID, Face ID, or LiveID.
- [Office 365](https://docs.1kosmos.com/integrations/authentication/pre-built-integrations/office-365.md): Enable passwordless, biometric authentication for Microsoft Office 365 using 1Kosmos as a SAML 2.0 Identity Provider — allowing users to sign in with Touch ID, Face ID, or LiveID instead of a password
- [Okta](https://docs.1kosmos.com/integrations/authentication/pre-built-integrations/okta.md): Enable passwordless, biometric login for your Okta users using 1Kosmos as a SAML 2.0 Identity Provider. Once connected, users authenticate with Touch ID, Face ID, or LiveID instead of a password.
- [Okta Identity Verification](https://docs.1kosmos.com/integrations/authentication/pre-built-integrations/okta-identity-verification.md): Connect Okta BYO IDV with 1Kosmos from a prebuilt AdminX tile — one guided form adds the OIDC client, auto-generates the Okta IDP config, and returns verified claims.
- [OneLogin](https://docs.1kosmos.com/integrations/authentication/pre-built-integrations/onelogin.md): Integrate 1Kosmos passwordless authentication with OneLogin using SAML 2.0 — enabling biometric login with Touch ID, Face ID, or LiveID for your OneLogin users.
- [Salesforce](https://docs.1kosmos.com/integrations/authentication/pre-built-integrations/salesforce.md): Enable passwordless, biometric login for your Salesforce users using 1K as a SAML 2.0 Identity Provider. Once connected, users authenticate with Touch ID, Face ID, or LiveID instead of a password.
- [PingOne DaVinci Connector](https://docs.1kosmos.com/integrations/authentication/pre-built-integrations/pingone-davinci-connector.md): Integrate 1Kosmos passwordless authentication with PingOne DaVinci using the 1Kosmos OIDC connector — enabling seamless biometric login within your DaVinci authentication flows.

## Workflow Builder

- [Overview](https://docs.1kosmos.com/workflow-builder/overview.md): Design, test, run, and manage identity verification journeys with a visual, drag-and-drop Workflow Builder, no backend development required.
- [Build a Workflow](https://docs.1kosmos.com/workflow-builder/build-a-workflow.md): Build an identity verification workflow end to end on the canvas — add nodes, connect them, configure settings, preview, and save.
- [Node Library](https://docs.1kosmos.com/workflow-builder/node-library.md): The complete catalog of Workflow Builder nodes — User Interaction, Capture, Outcome, and Advanced — and how to configure each one in the Node Editor.
- [Customize Preview & Save](https://docs.1kosmos.com/workflow-builder/customize-preview-and-save.md): Import workflows from JSON, customize branding with theme colors and custom HTML/CSS, preview the journey before publishing, and save your workflow.
- [Manage Workflows](https://docs.1kosmos.com/workflow-builder/manage-workflows.md): Edit or delete existing identity verification workflows, with control over whether changes override the current workflow or create a copy.
- [Launch and Monitor Verification Sessions](https://docs.1kosmos.com/workflow-builder/launch-and-monitor-verification-sessions.md): Launch a verification session from a workflow and track its progress, executed nodes, output, and status from the Instances page.
- [Release Notes](https://docs.1kosmos.com/workflow-builder/release-notes.md)

## Master Release Notes

- [Master Release Notes](https://docs.1kosmos.com/master-release-notes/master-release-notes.md): A comprehensive record of product updates, new features, enhancements, bug fixes, and other changes across all releases.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information, you can query the documentation dynamically by asking a question.
Perform an HTTP GET request on a page URL with the `ask` query parameter:
```
GET https://docs.1kosmos.com/readme.md?ask=<question>
```
The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.
Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
