{"version":1,"pages":[{"id":"JsKd452Nu8XTrHz68zaF","title":"Home","pathname":"/","siteSpaceId":"sitesp_68Iic","description":"Welcome to your team’s developer platform","breadcrumbs":[{"label":"Home","icon":"house"}]},{"id":"lzvkm53IenphXGiF6a9Z","title":"Privacy policy","pathname":"/privacy-policy","siteSpaceId":"sitesp_68Iic","description":"Digital identity verification and authentication software that verifies users, eliminates passwords, and stops fraud across workforce, customer, and resident identities.","breadcrumbs":[{"label":"Home","icon":"house"}]},{"id":"trI62TKeXsoz4ksiSX6X","title":"Cookie policy","pathname":"/cookie-policy","siteSpaceId":"sitesp_68Iic","description":"Digital identity verification and authentication software that verifies users, eliminates passwords, and stops fraud across workforce, customer, and resident identities.","breadcrumbs":[{"label":"Home","icon":"house"}]},{"id":"CqyvClcIYvGj2Pe4rXAj","title":"Copyright Notice for 1Kosmos Inc. Product Source Code and Content","pathname":"/copyright-notice-for-1kosmos-inc.-product-source-code-and-content","siteSpaceId":"sitesp_68Iic","breadcrumbs":[{"label":"Home","icon":"house"}]},{"id":"1ff4605217b5977ffae0d3d66cb040a900f4b039","title":"Overview","pathname":"/identity-verification","siteSpaceId":"sitesp_gP1Te","description":"Verify any user, anywhere, with a single identity platform that combines document, biometric, and database checks into one privacy-first workflow.","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"}]},{"id":"HG2L9wUUBtpyfRA3KBqi","title":"Core Concepts","pathname":"/identity-verification/core-concepts","siteSpaceId":"sitesp_gP1Te","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"}]},{"id":"J7UacFXEhMnCN5SGTQiA","title":"Verification flow","pathname":"/identity-verification/core-concepts/verification-flow","siteSpaceId":"sitesp_gP1Te","description":"A reusable configuration that defines which checks run, on which documents, with what strictness.","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"Core Concepts"}]},{"id":"c4dMDQw0vU4o6cDpBanA","title":"Session","pathname":"/identity-verification/core-concepts/session","siteSpaceId":"sitesp_gP1Te","description":"One user's attempt at a verification flow, with its own URL, expiry, status, and result.","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"Core Concepts"}]},{"id":"OcvcwmmtSPDE529qTjlG","title":"Viewing Verification Results","pathname":"/identity-verification/core-concepts/viewing-verification-results","siteSpaceId":"sitesp_gP1Te","description":"This page explains how community and helpdesk administrators can view and interpret document verification session results.","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"Core Concepts"}]},{"id":"vzA6Jtqtr9DqoCLBaLOW","title":"AI Analysis Summary","pathname":"/identity-verification/core-concepts/ai-analysis-summary","siteSpaceId":"sitesp_gP1Te","description":"The AI Analysis Summary adds an AI-powered analysis layer to the verification results view. It takes the underlying verification signals and translates them into a clear, plain-language summary.","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"Core Concepts"}]},{"id":"q5KP09RhewWDVRJwTzIQ","title":"Assurance Levels","pathname":"/identity-verification/core-concepts/assurance-levels","siteSpaceId":"sitesp_gP1Te","description":"NIST 800-63-3's scale for how much you can trust a verified identity, and where 1Kosmos sits on it.","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"Core Concepts"}]},{"id":"PN4N5KxVvfFSvl1qzpNH","title":"Manual Review & Manual Capture","pathname":"/identity-verification/core-concepts/manual-review-and-manual-capture","siteSpaceId":"sitesp_gP1Te","description":"Manual Capture and Manual Review are fallback pathways. They must not be used as the primary route, always ensure the automated scan path is attempted first.","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"Core Concepts"}]},{"id":"l8zDgQw5OgPsj6brosKz","title":"Event Reference","pathname":"/identity-verification/core-concepts/event-reference","siteSpaceId":"sitesp_gP1Te","description":"This page lists every event type recorded in the 1Kosmos Event Logs for ID Verification, along with the fields captured for each event. Events are grouped by activity category so you can quickly find","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"Core Concepts"}]},{"id":"D974lJMdbdzVxlAo4RYV","title":"Verification Methods","pathname":"/identity-verification/verification-methods","siteSpaceId":"sitesp_gP1Te","description":"The catalog of checks you can run inside a flow — pick the combination that fits your risk and friction budget.","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"}]},{"id":"SUoe98sZGEr6zaSAunV4","title":"Document Verification","pathname":"/identity-verification/verification-methods/document-verification","siteSpaceId":"sitesp_gP1Te","description":"Scan a government-issued document, validate it server-side, and extract fields with field-level confidence scores.","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"Verification Methods"}]},{"id":"cIHFGfyCOqVeiC2Qb3vQ","title":"Biometric and Liveness","pathname":"/identity-verification/verification-methods/biometric-and-liveness","siteSpaceId":"sitesp_gP1Te","description":"Bind a real, present person to the photo on their document passively, in seconds, without prompts to blink or turn.","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"Verification Methods"}]},{"id":"lPn4kvDHOTI1MUbHPUKK","title":"Non-Doc verification","pathname":"/identity-verification/verification-methods/non-doc-verification","siteSpaceId":"sitesp_gP1Te","description":"Verify identity using authoritative data sources and possession signals, no document scan required.","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"Verification Methods"}]},{"id":"gWXKkh0vhFMKS4u0nH42","title":"Database Verification","pathname":"/identity-verification/verification-methods/database-verification","siteSpaceId":"sitesp_gP1Te","description":"Cross-check user-submitted data against authoritative government and carrier databases — AAMVA, eCBSV, SSA.","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"Verification Methods"}]},{"id":"cox9oIVNovuiCQru2BiQ","title":"Notarized Document Bypass","pathname":"/identity-verification/verification-methods/notarized-document-bypass","siteSpaceId":"sitesp_gP1Te","description":"Bypass document scanning by having an administrator add a notarized affidavit to a user's wallet.","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"Verification Methods"}]},{"id":"mgSSsvvj2IYTU83W6pL3","title":"Web-to-Mobile Handoff","pathname":"/identity-verification/verification-methods/web-to-mobile-handoff","siteSpaceId":"sitesp_gP1Te","description":"Let users start verification on desktop and seamlessly continue on their phone no manual link copying.","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"Verification Methods"}]},{"id":"oraJdjFRy2xIGmYqjKVq","title":"1Kosmos as a Credential Service Provider (CSP)","pathname":"/identity-verification/1kosmos-as-a-credential-service-provider-csp","siteSpaceId":"sitesp_gP1Te","description":"How 1Kosmos performs identity proofing as a Credential Service Provider (CSP), aligned with NIST SP 800-63A enrollment and identity proofing requirements.","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"}]},{"id":"93b9e83bf9d2ff22801d2d775966ebcbb279ca9a","title":"Configurations","pathname":"/identity-verification/configurations","siteSpaceId":"sitesp_gP1Te","description":"Community administrators—or users with the idproofing.add-journey permission—can create and manage verification journeys in the AdminX interface under Verification > Verification Flows.","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"}]},{"id":"3f361d260543ecd107d98c2d570f704ec3de9710","title":"Capture & Tips","pathname":"/identity-verification/capture-and-tips","siteSpaceId":"sitesp_gP1Te","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"}]},{"id":"fk7JUpFvSZ3w6InnS1QJ","title":"Supported Documents","pathname":"/identity-verification/supported-documents","siteSpaceId":"sitesp_gP1Te","description":"Identity documents and regions supported by 1Kosmos for document scanning and verification.","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"}]},{"id":"OQhIKQekgtMMGRFHYnBB","title":"Release Notes","pathname":"/identity-verification/supported-documents/release-notes","siteSpaceId":"sitesp_gP1Te","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"Supported Documents"}]},{"id":"SMLlz5wP6pZNKW9nF6lC","title":"UX & Design","pathname":"/identity-verification/ux-and-design","siteSpaceId":"sitesp_gP1Te","description":"Great experiences are built on three pillars: a product that looks like yours, works for everyone, and speaks your customers' language. This section explains how {{Product}} supports each of these.","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"}]},{"id":"LMd9BYiCRhbcteQ4RZzJ","title":"Branding Customization","pathname":"/identity-verification/ux-and-design/branding-customization","siteSpaceId":"sitesp_gP1Te","description":"1Kosmos can be styled to reflect your brand so that, to your customers, it feels like a seamless extension of your own product. This page covers everything you can customize and how to apply it.","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"UX & Design"}]},{"id":"FqgcswVPNmB8QdzdoWHX","title":"Responsive Design","pathname":"/identity-verification/ux-and-design/responsive-design","siteSpaceId":"sitesp_gP1Te","description":"1Kosmos is built to work across the full range of screen sizes your customers use — from large desktop monitors to phones. The interface reflows automatically so content stays readable.","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"UX & Design"}]},{"id":"rsBdXxBOZpphrkNrHQXP","title":"Accessibility","pathname":"/identity-verification/ux-and-design/accessibility","siteSpaceId":"sitesp_gP1Te","description":"We believe great products should be usable by everyone, regardless of ability. 1kosmos is designed and built to conform to the Web Content Accessibility Guidelines (WCAG) 2.2 at Level AA.","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"UX & Design"}]},{"id":"mwNGDoZtE9PhRhqkMt6B","title":"Localization","pathname":"/identity-verification/ux-and-design/localization","siteSpaceId":"sitesp_gP1Te","description":"1Kosmos can be delivered in your customers' preferred language and regional formats, so the experience feels native wherever they are.","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"UX & Design"}]},{"id":"KsATbCh3luIuWihglZX8","title":"Overview","pathname":"/identity-verification/database-validation/overview","siteSpaceId":"sitesp_gP1Te","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"Database Validation"}]},{"id":"SubYefeH4YxTreDaD2bm","title":"AAMVA Verification","pathname":"/identity-verification/database-validation/aamva-verification","siteSpaceId":"sitesp_gP1Te","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"Database Validation"}]},{"id":"L1XCprtYbrrCvHtRrU5F","title":"Person Search Verification","pathname":"/identity-verification/database-validation/person-search-verification","siteSpaceId":"sitesp_gP1Te","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"Database Validation"}]},{"id":"pn51p8WjuQwL9gAOBiYi","title":"Aadhaar Verification","pathname":"/identity-verification/database-validation/aadhaar-verification","siteSpaceId":"sitesp_gP1Te","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"Database Validation"}]},{"id":"8DuTsxOGljFiW75u9gFV","title":"Overview","pathname":"/identity-verification/non-doc-verification/overview","siteSpaceId":"sitesp_gP1Te","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"Non-doc Verification"}]},{"id":"5C0VSM3beKI5vxDV7Awa","title":"eID Verification","pathname":"/identity-verification/non-doc-verification/eid-verification","siteSpaceId":"sitesp_gP1Te","description":"Verify identity using a government-issued or bank-issued electronic ID scheme","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"Non-doc Verification"}]},{"id":"wl139DDX164O45tPPrlc","title":"SSN Verification","pathname":"/identity-verification/non-doc-verification/ssn-verification","siteSpaceId":"sitesp_gP1Te","description":"Validate a US Social Security Number against authoritative data sources without requiring a physical SSN card.","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"Non-doc Verification"}]},{"id":"gkyb9mIyS8rfYENASTTK","title":"Phone-Based Verification","pathname":"/identity-verification/non-doc-verification/phone-based-verification","siteSpaceId":"sitesp_gP1Te","description":"Verify identity using mobile carrier intelligence and possession checks on the user's phone number.","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"Non-doc Verification"}]},{"id":"LhRKm4sI9N4m194BIn1W","title":"Overview","pathname":"/identity-verification/fraud-prevention/overview","siteSpaceId":"sitesp_gP1Te","description":"Non-document fraud signals that assess identity risk from an IP address, email address, and phone number — adding a passive, low-friction layer to document and biometric verification.","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"Fraud Prevention"}]},{"id":"OoRTkwebEdpo1UCWmUHm","title":"IP Geolocation","pathname":"/identity-verification/fraud-prevention/ip-geolocation","siteSpaceId":"sitesp_gP1Te","description":"Assess risk from a user's IP address — approximate location, network type, and anonymizer use — to detect location spoofing, high-risk geographies, and suspicious access patterns.","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"Fraud Prevention"}]},{"id":"F1I8zEttFTzVqCAhaN4Z","title":"Email Intelligence","pathname":"/identity-verification/fraud-prevention/email-intelligence","siteSpaceId":"sitesp_gP1Te","description":"Assess risk from a user's email address — domain validity, disposable-address detection, age, and online footprint — to spot fake and synthetic identities during onboarding.","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"Fraud Prevention"}]},{"id":"nuh3UKOUNUZce6jlRChb","title":"Phone Intelligence","pathname":"/identity-verification/fraud-prevention/phone-intelligence","siteSpaceId":"sitesp_gP1Te","description":"Assess risk from a user's phone number — line type, carrier, portability, and SIM-swap signals — to prevent OTP interception, account takeover, and synthetic identities.","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"Fraud Prevention"}]},{"id":"dHr1piHw37weX2roX20w","title":"Overview","pathname":"/identity-verification/ial2-verification/overview","siteSpaceId":"sitesp_gP1Te","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"IAL2 Verification"}]},{"id":"fiaOvn40laab0oxJ0g6x","title":"Create & Manage IAL2 Verification","pathname":"/identity-verification/ial2-verification/create-and-manage-ial2-verification","siteSpaceId":"sitesp_gP1Te","description":"Administrators can create and manage a new Identity Assurance Level 2 (IAL2) verification flow. This feature enables end users to complete a one-time IAL2 verification.","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"IAL2 Verification"}]},{"id":"aGhxVnrB7NGb5FZ5WJXm","title":"One-Time Verification","pathname":"/identity-verification/ial2-verification/one-time-verification","siteSpaceId":"sitesp_gP1Te","description":"The one-time IAL2 verification flow enables end users to verify their identity by submitting two specified identity documents, a biometric, and an SSN.","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"IAL2 Verification"}]},{"id":"ILIlCaFYyPMdfBuIWLza","title":"OAuth 2.0 and OIDC","pathname":"/identity-verification/ial2-verification/oauth-2.0-and-oidc","siteSpaceId":"sitesp_gP1Te","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"IAL2 Verification"}]},{"id":"camIsnVyf8T6H8AO7Vi8","title":"SAML","pathname":"/identity-verification/ial2-verification/saml","siteSpaceId":"sitesp_gP1Te","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"IAL2 Verification"}]},{"id":"8IuV1O0Id6FiC6Zd4Udn","title":"Identity Wallet-Based Verification","pathname":"/identity-verification/ial2-verification/identity-wallet-based-verification","siteSpaceId":"sitesp_gP1Te","description":"Identity wallets allow you to store identity documents, and social security details, all in one place on your smartphone or on the web. They allow you to reuse previously verified identities.","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"IAL2 Verification"}]},{"id":"HNPOMEmKRSFQCvCY9dve","title":"Overview","pathname":"/identity-verification/verifiable-credentials/overview","siteSpaceId":"sitesp_gP1Te","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"Verifiable Credentials"}]},{"id":"a6VKQNXWrYjJFIT1raAd","title":"Setting Up Microsoft Verified ID Integration","pathname":"/identity-verification/verifiable-credentials/setting-up-microsoft-verified-id-integration","siteSpaceId":"sitesp_gP1Te","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"Verifiable Credentials"}]},{"id":"YC8YQIBqz9JfDF6UPkPq","title":"1Kosmos Interoperability with Verifiable Credentials Platforms","pathname":"/identity-verification/verifiable-credentials/1kosmos-interoperability-with-verifiable-credentials-platforms","siteSpaceId":"sitesp_gP1Te","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"},{"label":"Verifiable Credentials"}]},{"id":"a5U5EvCUEocY7vcZzVnb","title":"Release Notes","pathname":"/identity-verification/release-notes","siteSpaceId":"sitesp_gP1Te","breadcrumbs":[{"label":"Identity Verification","icon":"user-viewfinder"}]},{"id":"RQc1lxSlFwoHffZvEvvD","title":"Getting started with passwordless authentication","pathname":"/authentication","siteSpaceId":"sitesp_SlPSl","description":"This guide introduces passwordless authentication. You'll understand how authentication works, what you can protect with it, and the steps to go from a new tenant to a working passwordless login.","breadcrumbs":[{"label":"Authentication","icon":"laptop"}]},{"id":"733341f99f78ab9976f71f920ce74c13af5483c6","title":"Overview","pathname":"/authentication/windows-workstation-mfa/overview","siteSpaceId":"sitesp_SlPSl","description":"The Windows Workstation MFA Agent adds multi-factor and passwordless authentication to the Windows login experience, controlled centrally from AdminX Portal.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Windows Workstation MFA"}]},{"id":"As9B3Hav9KmrSOWIvtHZ","title":"System Requirements","pathname":"/authentication/windows-workstation-mfa/system-requirements","siteSpaceId":"sitesp_SlPSl","description":"This page lists the supported operating systems and minimum hardware specifications for the Linux host on which the 1Kosmos PAM will be installed.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Windows Workstation MFA"}]},{"id":"QXxW3SdUM6mji4fyABQ6","title":"Installation","pathname":"/authentication/windows-workstation-mfa/installation","siteSpaceId":"sitesp_SlPSl","description":"The Windows Workstation MFA Agent supports two installer formats. Choose the right one for your environment before proceeding, switching formats later requires a full uninstall and reinstall.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Windows Workstation MFA"}]},{"id":"Y2A84UVpEXoTGNtKT1QX","title":"Install using MSI","pathname":"/authentication/windows-workstation-mfa/installation/install-using-msi","siteSpaceId":"sitesp_SlPSl","description":"The MSI installer is the recommended method for all new deployments. It supports silent installation, SCCM, Intune, and GPO deployment natively.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Windows Workstation MFA"},{"label":"Installation"}]},{"id":"CkHoV3NKzG6pyOVwCM5V","title":"Install using EXE (Legacy)","pathname":"/authentication/windows-workstation-mfa/installation/install-using-exe-legacy","siteSpaceId":"sitesp_SlPSl","description":"The EXE installer is supported for existing deployments and manual installations. For all new deployments, use the MSI installer instead.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Windows Workstation MFA"},{"label":"Installation"}]},{"id":"HQnuhU6wa4bLaILSR0Sl","title":"Post-installation Verification","pathname":"/authentication/windows-workstation-mfa/installation/post-installation-verification","siteSpaceId":"sitesp_SlPSl","description":"After installing the agent, complete these steps to confirm the Credential Provider is active and authentication is working before rolling out to users.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Windows Workstation MFA"},{"label":"Installation"}]},{"id":"c8gWyvmuWZah7gWr2NvD","title":"Authentication Methods","pathname":"/authentication/windows-workstation-mfa/authentication-methods","siteSpaceId":"sitesp_SlPSl","description":"The Windows Workstation MFA Agent supports multiple authentication methods. The method presented to a user at login is determined by the Adaptive Auth Journey configured for them in AdminX.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Windows Workstation MFA"}]},{"id":"1q0iOl0I5AfZq7YXYhNM","title":"Password + OTP","pathname":"/authentication/windows-workstation-mfa/authentication-methods/password-+-otp","siteSpaceId":"sitesp_SlPSl","description":"Users authenticate by entering their Active Directory password followed by a one-time passcode. This is the most common MFA configuration for organisations transitioning away from password-only login.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Windows Workstation MFA"},{"label":"Authentication Methods"}]},{"id":"c3867f0dbfdd3c68105187773e7a6fb985540d33","title":"Push Notification","pathname":"/authentication/windows-workstation-mfa/authentication-methods/push-notification","siteSpaceId":"sitesp_SlPSl","description":"Users receive an approval request on the 1Kosmos mobile app. From v2.0.4.0, a Number Challenge option is available to protect against push bombing attacks.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Windows Workstation MFA"},{"label":"Authentication Methods"}]},{"id":"8a320a6478cdf930216d2fae25c7060d80624764","title":"QR code","pathname":"/authentication/windows-workstation-mfa/authentication-methods/qr-code","siteSpaceId":"sitesp_SlPSl","description":"Users scan a QR code displayed on the Windows login screen using the 1Kosmos mobile app. No password is required when QR is configured as the sole authentication method.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Windows Workstation MFA"},{"label":"Authentication Methods"}]},{"id":"6jEzg7Wav7L1VtXmHI0x","title":"LiveID Selfie","pathname":"/authentication/windows-workstation-mfa/authentication-methods/liveid-selfie","siteSpaceId":"sitesp_SlPSl","description":"Configure LiveID Selfie with Push Notification for Windows login in 1Kosmos. Authenticate using facial biometrics and 1Kosmos app approval.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Windows Workstation MFA"},{"label":"Authentication Methods"}]},{"id":"1842f2793edb875b7685eb3aaf623e52eabc5e52","title":"1Key Biometric","pathname":"/authentication/windows-workstation-mfa/authentication-methods/1key-biometric","siteSpaceId":"sitesp_SlPSl","description":"Users authenticate using a FIDO2 hardware security key. 1Kosmos supports both single-user keys and multi-user biometric keys (1Key Desktop, which supports up to 3 enrolled users per key).","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Windows Workstation MFA"},{"label":"Authentication Methods"}]},{"id":"a123b423fca32bcaaee845387dba4c678fa6940a","title":"SMS, Email, Voice, OTP","pathname":"/authentication/windows-workstation-mfa/authentication-methods/sms-email-voice-otp","siteSpaceId":"sitesp_SlPSl","description":"Available from v2.0.6.0. Users receive a one-time passcode via SMS, email, or voice call. No mobile app installation is required.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Windows Workstation MFA"},{"label":"Authentication Methods"}]},{"id":"2480ed24555291732b9ff2abc35b7e23e16b6a84","title":"Behavior Authentication","pathname":"/authentication/windows-workstation-mfa/authentication-methods/behavior-authentication","siteSpaceId":"sitesp_SlPSl","description":"Users authenticate by typing a displayed phrase (typing biometrics) followed by a PIN. No mobile app or hardware key required. Supports offline authentication via cached PIN.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Windows Workstation MFA"},{"label":"Authentication Methods"}]},{"id":"hGFK8Jj2FNOKyrHYohgZ","title":"Fallback Authentication","pathname":"/authentication/windows-workstation-mfa/authentication-methods/fallback-authentication","siteSpaceId":"sitesp_SlPSl","description":"Configure a secure fallback authentication method for Windows login so users can regain access with a Helpdesk-issued one-time passcode when their primary method fails.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Windows Workstation MFA"},{"label":"Authentication Methods"}]},{"id":"96d614e89de09abc4b80462ef2df919190dfe815","title":"Run As & UAC","pathname":"/authentication/windows-workstation-mfa/authentication-methods/run-as-and-uac","siteSpaceId":"sitesp_SlPSl","description":"1Kosmos Credential Provider intercepts Run As and UAC elevation prompts, requiring MFA before elevated access is granted. From v2.0.7.0, passwordless authentication is supported for these scenarios.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Windows Workstation MFA"},{"label":"Authentication Methods"}]},{"id":"928de88bf22ccbe87baf9701a24f230090d3545c","title":"Deployment Scenarios","pathname":"/authentication/windows-workstation-mfa/deployment-scenarios","siteSpaceId":"sitesp_SlPSl","description":"1Kosmos Credential Provider intercepts Run As and UAC elevation prompts, requiring MFA before elevated access is granted. From v2.0.7.0, passwordless authentication is supported for these scenarios.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Windows Workstation MFA"}]},{"id":"aab264a294b277cdd4f4d5de32ea74a7d14bfdad","title":"Standard Domain Joined Workstations","pathname":"/authentication/windows-workstation-mfa/deployment-scenarios/standard-domain-joined-workstations","siteSpaceId":"sitesp_SlPSl","description":"Baseline deployment scenario for 1Kosmos Windows Workstation MFA Agent. Covers Active Directory domain-joined machines with full network connectivity to 1Kosmos tenant.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Windows Workstation MFA"},{"label":"Deployment Scenarios"}]},{"id":"0f40b8e41509065142ab4724cefe06012ecccb99","title":"RDP","pathname":"/authentication/windows-workstation-mfa/deployment-scenarios/rdp","siteSpaceId":"sitesp_SlPSl","description":"1Kosmos Credential Provider supports MFA enforcement for both incoming and outgoing Remote Desktop Protocol (RDP) sessions.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Windows Workstation MFA"},{"label":"Deployment Scenarios"}]},{"id":"55cfd9a8bbfa9be31caba8aa0d0650132a42afa1","title":"Shared Workstations","pathname":"/authentication/windows-workstation-mfa/deployment-scenarios/shared-workstations","siteSpaceId":"sitesp_SlPSl","description":"Shared workstation environments allow multiple users to authenticate on the same physical machine using their individual identities, then access shared or privileged accounts managed by CyberArk.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Windows Workstation MFA"},{"label":"Deployment Scenarios"}]},{"id":"0fc2ce53131d4bbc9f83c902f202f735df1e8c89","title":"Offline Scenario","pathname":"/authentication/windows-workstation-mfa/deployment-scenarios/offline-scenario","siteSpaceId":"sitesp_SlPSl","description":"Securely log into your Windows workstation even without internet access or when the 1Kosmos cloud is unreachable, using offline authentication methods supported by the 1Kosmos Credential Provider.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Windows Workstation MFA"},{"label":"Deployment Scenarios"}]},{"id":"09bb3d3862e8ee866e8ec7f6ca0763589e7ddec0","title":"Entra Joined Workstations","pathname":"/authentication/windows-workstation-mfa/deployment-scenarios/entra-joined-workstations","siteSpaceId":"sitesp_SlPSl","description":"Support for Microsoft Entra ID joined machines (formerly Azure AD joined) is on 1Kosmos product roadmap. This page will be updated when the feature is available.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Windows Workstation MFA"},{"label":"Deployment Scenarios"}]},{"id":"9POwVEjWWvT2hWc9UIYP","title":"Uninstall","pathname":"/authentication/windows-workstation-mfa/uninstall","siteSpaceId":"sitesp_SlPSl","description":"1Kosmos Windows Workstation MFA Agent can be uninstalled using either the MSI or EXE method, depending on how it was originally installed. A reboot is required after uninstall to remove the machine.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Windows Workstation MFA"}]},{"id":"5faaa3d98686d68287f273a697cfed228912f6cb","title":"Uninstall MSI","pathname":"/authentication/windows-workstation-mfa/uninstall/uninstall-msi","siteSpaceId":"sitesp_SlPSl","description":"Uninstalling 1Kosmos Windows Workstation MFA Agent via MSI package. Supports both silent (command-line) and UI-guided removal.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Windows Workstation MFA"},{"label":"Uninstall"}]},{"id":"98459e1f5b1dd7c9ef2a9c9a0bc61b7a7aa87fff","title":"Uninstall EXE","pathname":"/authentication/windows-workstation-mfa/uninstall/uninstall-exe","siteSpaceId":"sitesp_SlPSl","description":"Uninstalling 1Kosmos Windows Workstation MFA Agent when it was installed using EXE installer package. Supports both silent (command-line) and UI-guided removal.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Windows Workstation MFA"},{"label":"Uninstall"}]},{"id":"LGvOf6Xiwua1n8FXeBY1","title":"Troubleshooting & Support","pathname":"/authentication/windows-workstation-mfa/troubleshooting-and-support","siteSpaceId":"sitesp_SlPSl","description":"This page covers cross-cutting issues with 1Kosmos Windows Workstation MFA Agent, installation failures, Credential Provider service problems, log collection, and connectivity diagnostics.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Windows Workstation MFA"}]},{"id":"OjHTaaGpZxpNA9Vzq3Vl","title":"Release Notes for Windows Workstation MFA","pathname":"/authentication/windows-workstation-mfa/release-notes-for-windows-workstation-mfa","siteSpaceId":"sitesp_SlPSl","description":"Release history for the 1Kosmos Workstation Login Credential Provider for Windows","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Windows Workstation MFA"}]},{"id":"tVMGL9IZPFOPvf3Ozh6V","title":"FAQs","pathname":"/authentication/windows-workstation-mfa/faqs","siteSpaceId":"sitesp_SlPSl","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Windows Workstation MFA"}]},{"id":"re3QvBuFMW2GjztAoBAv","title":"Overview","pathname":"/authentication/passwordless-for-web-apps/overview","siteSpaceId":"sitesp_SlPSl","description":"Passwordless for Web Apps lets users access web applications without entering a password. 1Kosmos acts as the Identity Provider (IdP) for web applications integrated using standard protocols.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"PASSWORDLESS FOR WEB APPS"}]},{"id":"uLvYv44QpcFERuJgsDgl","title":"Authentication Matrix","pathname":"/authentication/passwordless-for-web-apps/authentication-matrix","siteSpaceId":"sitesp_SlPSl","description":"The table below outlines the authentication modes supported across different login methods. Availability of each mode depends on how authentication journeys are configured.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"PASSWORDLESS FOR WEB APPS"}]},{"id":"TtQNggyFvwCbSZRTmaEv","title":"Analytics","pathname":"/authentication/passwordless-for-web-apps/analytics","siteSpaceId":"sitesp_SlPSl","description":"The Analytics Dashboard gives Community Administrators a graphical overview of user activity across the tenant. Data can be filtered by today, last 7 days, last 30 days, or a custom date range.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"PASSWORDLESS FOR WEB APPS"}]},{"id":"t6Uu43ca6HPlfONTx86f","title":"Login Methods","pathname":"/authentication/passwordless-for-web-apps/login-methods","siteSpaceId":"sitesp_SlPSl","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"PASSWORDLESS FOR WEB APPS"}]},{"id":"j0C4BSDQvTApPUR3XyOj","title":"Password Reset","pathname":"/authentication/passwordless-for-web-apps/login-methods/password-reset","siteSpaceId":"sitesp_SlPSl","description":"1Kosmos gives Community Administrators control over how end users reset forgotten passwords.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"PASSWORDLESS FOR WEB APPS"},{"label":"Login Methods"}]},{"id":"BCKcD1Fz6pgTSuH560Zt","title":"FIDO Keys","pathname":"/authentication/passwordless-for-web-apps/login-methods/fido-keys","siteSpaceId":"sitesp_SlPSl","description":"FIDO passkeys enable passwordless login using biometrics or hardware security keys instead of passwords.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"PASSWORDLESS FOR WEB APPS"},{"label":"Login Methods"}]},{"id":"f1aNOyJFx5iSb9itbNUR","title":"WebAuthn","pathname":"/authentication/passwordless-for-web-apps/login-methods/fido-keys/webauthn","siteSpaceId":"sitesp_SlPSl","description":"FIDO2 Web Authentication (WebAuthn) is a standard web API, built into modern web browsers and related web platform infrastructure, used to securely authenticate users across various sites and devices.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"PASSWORDLESS FOR WEB APPS"},{"label":"Login Methods"},{"label":"FIDO Keys"}]},{"id":"3cw07nW2ci9JAL5ThAqw","title":"LiveID (Biometric Authentication)","pathname":"/authentication/passwordless-for-web-apps/login-methods/liveid-biometric-authentication","siteSpaceId":"sitesp_SlPSl","description":"LiveID is a 1Kosmos signature feature that enables workforce users to enroll their face once and authenticate on any supported device - desktop, mobile, or any camera-enabled device.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"PASSWORDLESS FOR WEB APPS"},{"label":"Login Methods"}]},{"id":"UTkU7wyPtsXwRTOHheiK","title":"Behavioral Authentication","pathname":"/authentication/passwordless-for-web-apps/login-methods/behavioral-authentication","siteSpaceId":"sitesp_SlPSl","description":"Behavioral Authentication in 1Kosmos analyzes how a user interacts with their device, specifically their typing pattern, and compares it against their enrolled behavioral profile to verify identity.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"PASSWORDLESS FOR WEB APPS"},{"label":"Login Methods"}]},{"id":"hrfUPTywwXPRaLPvIFzB","title":"Orion Desktop Authenticator","pathname":"/authentication/passwordless-for-web-apps/login-methods/orion-desktop-authenticator","siteSpaceId":"sitesp_SlPSl","description":"Orion Authenticator is a desktop application that delivers strong, passwordless authentication and TOTP-based MFA directly from a user's Mac or Windows workstation — without requiring a mobile device.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"PASSWORDLESS FOR WEB APPS"},{"label":"Login Methods"}]},{"id":"6dBmmNns7iNnqFyGSUYY","title":"Hardware Tokens","pathname":"/authentication/passwordless-for-web-apps/login-methods/hardware-tokens","siteSpaceId":"sitesp_SlPSl","description":"HMAC-based One-Time Password (HOTP) tokens are hardware devices that generate single-use passcodes based on a shared secret and an incrementing counter.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"PASSWORDLESS FOR WEB APPS"},{"label":"Login Methods"}]},{"id":"apWVbsi3HPuSsPcF1ENu","title":"Adaptive Authentication","pathname":"/authentication/passwordless-for-web-apps/adaptive-authentication","siteSpaceId":"sitesp_SlPSl","description":"Adaptive Authentication verifies the user's identity based on factors such as location, device status, and end-user context.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"PASSWORDLESS FOR WEB APPS"}]},{"id":"mGkjaFIMx9URD2yen1hU","title":"Multi-Factor Authentication","pathname":"/authentication/passwordless-for-web-apps/multi-factor-authentication","siteSpaceId":"sitesp_SlPSl","description":"Multi-factor Authentication (MFA) requires users to verify their identity using two or more factors before gaining access.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"PASSWORDLESS FOR WEB APPS"}]},{"id":"oxTGXkky9HD7LbxNOyhW","title":"Use cases","pathname":"/authentication/passwordless-for-web-apps/use-cases","siteSpaceId":"sitesp_SlPSl","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"PASSWORDLESS FOR WEB APPS"}]},{"id":"XNhOPIatdqv8zRF9ry9V","title":"Entra Passkey for Frontline Workers","pathname":"/authentication/passwordless-for-web-apps/use-cases/entra-passkey-for-frontline-workers","siteSpaceId":"sitesp_SlPSl","description":"1Kosmos enables frontline workers to authenticate into Microsoft Entra using a passkey verified through LiveID biometric (selfie).","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"PASSWORDLESS FOR WEB APPS"},{"label":"Use cases"}]},{"id":"jzu925mqfKD00A9lvxJe","title":"Mobile Authentication via Microsoft Intune MDM","pathname":"/authentication/passwordless-for-web-apps/use-cases/entra-passkey-for-frontline-workers/mobile-authentication-via-microsoft-intune-mdm","siteSpaceId":"sitesp_SlPSl","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"PASSWORDLESS FOR WEB APPS"},{"label":"Use cases"},{"label":"Entra Passkey for Frontline Workers"}]},{"id":"2CQDeaKUV8kRsOmhxWsL","title":"Browser Authentication via Chrome Extension","pathname":"/authentication/passwordless-for-web-apps/use-cases/entra-passkey-for-frontline-workers/browser-authentication-via-chrome-extension","siteSpaceId":"sitesp_SlPSl","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"PASSWORDLESS FOR WEB APPS"},{"label":"Use cases"},{"label":"Entra Passkey for Frontline Workers"}]},{"id":"ceoGwV1GQb2wmpDQqAFM","title":"In-Flight Enrollment for EAM (Behavior Auth + PIN)","pathname":"/authentication/passwordless-for-web-apps/use-cases/in-flight-enrollment-for-eam-behavior-auth-+-pin","siteSpaceId":"sitesp_SlPSl","description":"Enable frontline workers to enroll Behavior Auth (typing pattern) and set a PIN in-flight during EAM login - passwordless second-factor authentication with no personal device required.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"PASSWORDLESS FOR WEB APPS"},{"label":"Use cases"}]},{"id":"uxiBHVyoh8HIXvGuzbsj","title":"FAQs","pathname":"/authentication/passwordless-for-web-apps/faqs","siteSpaceId":"sitesp_SlPSl","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"PASSWORDLESS FOR WEB APPS"}]},{"id":"bbRctF1JSstI9znvdItE","title":"Overview","pathname":"/authentication/authentication-broker/overview","siteSpaceId":"sitesp_SlPSl","description":"AdminX Broker connects 1Kosmos to an existing Active Directory or LDAP directory so administrators can manage directory-backed accounts from AdminX.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Authentication Broker"}]},{"id":"1ZGct9zD5FPjS625Uaqx","title":"System Requirements","pathname":"/authentication/authentication-broker/system-requirements","siteSpaceId":"sitesp_SlPSl","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Authentication Broker"}]},{"id":"AmLEUDcF8sr0pkgQVayt","title":"AdminX Broker (Directory Connector)","pathname":"/authentication/authentication-broker/adminx-broker-directory-connector","siteSpaceId":"sitesp_SlPSl","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Authentication Broker"}]},{"id":"UxMKGDd6hpH1jsCSgb34","title":"Connect Directory via the AdminX Broker","pathname":"/authentication/authentication-broker/connect-directory-via-the-adminx-broker","siteSpaceId":"sitesp_SlPSl","description":"AdminX Broker allows a tenant or community administrator to connect and integrate an existing Active Directory (AD) or LDAP user directory with AdminX.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Authentication Broker"}]},{"id":"dQ5IsGlg4k8oFyCtGm3t","title":"Connect to LDAP via Broker","pathname":"/authentication/authentication-broker/connect-to-ldap-via-broker","siteSpaceId":"sitesp_SlPSl","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Authentication Broker"}]},{"id":"IknvDUWedzeGduS0vJAt","title":"Configuration Parameters Reference","pathname":"/authentication/authentication-broker/configuration-parameters-reference","siteSpaceId":"sitesp_SlPSl","description":"This section provides detailed configuration elements and operational parameters used in RADIUS and LDAP Auth Proxy setups.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Authentication Broker"}]},{"id":"m3rTfSRDJBG1bxWjy4aA","title":"FAQs","pathname":"/authentication/authentication-broker/faqs","siteSpaceId":"sitesp_SlPSl","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Authentication Broker"}]},{"id":"23Hd8JAxO9GsMadrqbd8","title":"Release Notes for Authentication Broker","pathname":"/authentication/authentication-broker/release-notes-for-authentication-broker","siteSpaceId":"sitesp_SlPSl","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Authentication Broker"}]},{"id":"y04c631JICaDr9SVSb4a","title":"Overview","pathname":"/authentication/authentication-proxy/overview","siteSpaceId":"sitesp_SlPSl","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Authentication Proxy"}]},{"id":"ekp1mRzGwJ2xRhE7QxWM","title":"System Requirements","pathname":"/authentication/authentication-proxy/system-requirements","siteSpaceId":"sitesp_SlPSl","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Authentication Proxy"}]},{"id":"k4OsEJPMPHn2d0PDcsSu","title":"Installation & Configuration","pathname":"/authentication/authentication-proxy/installation-and-configuration","siteSpaceId":"sitesp_SlPSl","description":"The community administrator uses the AdminX interface to download and configure the Auth Proxy server. This covers creating, modifying, and deleting configurations.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Authentication Proxy"}]},{"id":"P92D4TUthnw41M0TG3UQ","title":"Auth Proxy for RADIUS","pathname":"/authentication/authentication-proxy/auth-proxy-for-radius","siteSpaceId":"sitesp_SlPSl","description":"The RADIUS server is a command-line executable that enables communication between Active Directory (AD) or LDAP users onboarded in 1Kosmos and a RADIUS client.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Authentication Proxy"}]},{"id":"YqH2SZ60A468Jl2ZXpuj","title":"RADIUS Setup","pathname":"/authentication/authentication-proxy/radius-setup","siteSpaceId":"sitesp_SlPSl","description":"Follow these steps to start the RADIUS server, configure its parameters, and set the RADIUS secret.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Authentication Proxy"}]},{"id":"SYFLciMDmVXiFpciKkE0","title":"LDAP Setup","pathname":"/authentication/authentication-proxy/ldap-setup","siteSpaceId":"sitesp_SlPSl","description":"Follow these steps to start the LDAP server and configure its parameters.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Authentication Proxy"}]},{"id":"o4ngE8Ci6AIXFr9LPBfB","title":"Authentication Methods (Push, OTP, IVR)","pathname":"/authentication/authentication-proxy/authentication-methods-push-otp-ivr","siteSpaceId":"sitesp_SlPSl","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Authentication Proxy"}]},{"id":"ogpx3Zh6xkfNFndNd7lA","title":"FAQs","pathname":"/authentication/authentication-proxy/faqs","siteSpaceId":"sitesp_SlPSl","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Authentication Proxy"}]},{"id":"AMmsznJ9eArF93421pjK","title":"Overview","pathname":"/authentication/passwordless-for-linux-ssh/overview","siteSpaceId":"sitesp_SlPSl","description":"1Kosmos Login for Linux integrates with the Pluggable Authentication Module (PAM) to enable MFA for SSH login on Linux systems. It supports standalone authentication as well as 2FA/MFA combinations.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Passwordless for Linux SSH"}]},{"id":"kJmAfYueswrVB8hsgzET","title":"Prerequisites & Planning","pathname":"/authentication/passwordless-for-linux-ssh/prerequisites-and-planning","siteSpaceId":"sitesp_SlPSl","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Passwordless for Linux SSH"}]},{"id":"aG6bes8TnAVXzhqrkxPe","title":"System Requirements","pathname":"/authentication/passwordless-for-linux-ssh/prerequisites-and-planning/system-requirements","siteSpaceId":"sitesp_SlPSl","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Passwordless for Linux SSH"},{"label":"Prerequisites & Planning"}]},{"id":"laCq8lpP2vWzy3n6OE96","title":"1Kosmos Platform Prerequisites","pathname":"/authentication/passwordless-for-linux-ssh/prerequisites-and-planning/1kosmos-platform-prerequisites","siteSpaceId":"sitesp_SlPSl","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Passwordless for Linux SSH"},{"label":"Prerequisites & Planning"}]},{"id":"MONeq1TQUqJwea44R14D","title":"Installation","pathname":"/authentication/passwordless-for-linux-ssh/installation","siteSpaceId":"sitesp_SlPSl","description":"This section covers installing the 1Kosmos Linux PAM package, configuring the required license and PAM files, setting up sshd, and verifying the setup with a test SSH login.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Passwordless for Linux SSH"}]},{"id":"CQidIaOIFurqdtJDurjB","title":"AdminX Configuration","pathname":"/authentication/passwordless-for-linux-ssh/adminx-configuration","siteSpaceId":"sitesp_SlPSl","description":"Journeys let you control which authentication factors are required based on who the user is or which group they belong to. By default, a new journey applies to all users.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Passwordless for Linux SSH"}]},{"id":"rYtg1AyuiNRRMOUkn45Z","title":"Authentication Methods","pathname":"/authentication/passwordless-for-linux-ssh/authentication-methods","siteSpaceId":"sitesp_SlPSl","description":"After the 1Kosmos PAM is installed and configured, users SSH into the Linux host and are presented with the available authentication methods based on the configured journey.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Passwordless for Linux SSH"}]},{"id":"rixJDSWg8JjdJLw5NzKs","title":"Uninstallation","pathname":"/authentication/passwordless-for-linux-ssh/uninstallation","siteSpaceId":"sitesp_SlPSl","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Passwordless for Linux SSH"}]},{"id":"CtSaLM7cTnX0VvcIx8lD","title":"SSH Login for Linux Release Notes","pathname":"/authentication/passwordless-for-linux-ssh/ssh-login-for-linux-release-notes","siteSpaceId":"sitesp_SlPSl","description":"Release history for 1Kosmos SSH MFA for Linux (BlockID PAM for Linux).","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Passwordless for Linux SSH"}]},{"id":"rLbTtdl27uEiPawUK6ln","title":"FAQs","pathname":"/authentication/passwordless-for-linux-ssh/faqs","siteSpaceId":"sitesp_SlPSl","description":"This page covers common troubleshooting scenarios and useful commands for managing the 1Kosmos Linux PAM.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Passwordless for Linux SSH"}]},{"id":"i73g4LZQanoLj7XtSO18","title":"Overview","pathname":"/authentication/1kosmos-mobile-application/editor","siteSpaceId":"sitesp_SlPSl","description":"1Kosmos app is a privacy-first identity app that does passwordless authentication, verifies user identity to government-grade assurance, and stores verifiable credentials in a secure digital wallet.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"1Kosmos Mobile Application"}]},{"id":"9UrqtAwjTb0a8qIm79mZ","title":"Application Capabilities","pathname":"/authentication/1kosmos-mobile-application/application-capabilities","siteSpaceId":"sitesp_SlPSl","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"1Kosmos Mobile Application"}]},{"id":"QrRUc2lhY9YgDE7JfiVb","title":"Authentication","pathname":"/authentication/1kosmos-mobile-application/application-capabilities/authentication","siteSpaceId":"sitesp_SlPSl","description":"Authentication capabilities define how the 1Kosmos mobile app verifies a user during login. Each method addresses a different scenario, from default online flows to fully offline workstation access.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"1Kosmos Mobile Application"},{"label":"Application Capabilities"}]},{"id":"422z7ZiudKjdtJ7i5CMt","title":"Identity Verification","pathname":"/authentication/1kosmos-mobile-application/application-capabilities/identity-verification","siteSpaceId":"sitesp_SlPSl","description":"Identity verification capabilities allow the 1Kosmos mobile app to bind a user to their real-world identity through verified personal attributes, government-issued documents, and biometric assets.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"1Kosmos Mobile Application"},{"label":"Application Capabilities"}]},{"id":"QTQrUNoHs0EZMEjrNERC","title":"Digital Wallet","pathname":"/authentication/1kosmos-mobile-application/application-capabilities/digital-wallet","siteSpaceId":"sitesp_SlPSl","description":"The digital wallet is the user-controlled, on-device container for all identity assets and credentials. It uses public-private key cryptography and secure enclave storage to keep data tamper-proof.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"1Kosmos Mobile Application"},{"label":"Application Capabilities"}]},{"id":"ckgfaBLOy5HVVoGtNWZq","title":"Account Management","pathname":"/authentication/1kosmos-mobile-application/application-capabilities/account-management","siteSpaceId":"sitesp_SlPSl","description":"Account management capabilities let users add, remove, and manage multiple organization accounts on a single device. They cover the full lifecycle from onboarding.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"1Kosmos Mobile Application"},{"label":"Application Capabilities"}]},{"id":"17D31pBHsUS1lhThz0bU","title":"Recovery and Continuity","pathname":"/authentication/1kosmos-mobile-application/application-capabilities/recovery-and-continuity","siteSpaceId":"sitesp_SlPSl","description":"Recovery and continuity capabilities ensure users never lose access to their identity wallet or accounts due to a lost device, app reinstall, or version mismatch.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"1Kosmos Mobile Application"},{"label":"Application Capabilities"}]},{"id":"1rfb744MJ5sIULjya0Nb","title":"Application Usecase","pathname":"/authentication/1kosmos-mobile-application/application-usecase","siteSpaceId":"sitesp_SlPSl","description":"1Kosmos app serves a wide range of authentication and identity scenarios, from everyday workstation login to high-assurance government identity verification. This page outlines the common use cases.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"1Kosmos Mobile Application"}]},{"id":"z06XNKIOL5ZkxaS3rDly","title":"Onboarding Methods","pathname":"/authentication/1kosmos-mobile-application/onboarding-methods","siteSpaceId":"sitesp_SlPSl","description":"1Kosmos supports multiple ways to onboard a user's device and account — from self-service email invites to in-person admin-led onboarding to high-assurance SIM binding for regulated industries.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"1Kosmos Mobile Application"}]},{"id":"NVEb2Sw3sLlSPh0BvRET","title":"Installation","pathname":"/authentication/1kosmos-mobile-application/installation","siteSpaceId":"sitesp_SlPSl","description":"The 1Kosmos mobile app is available on iOS and Android. We recommend installing from your device's app store to ensure automatic updates and complete functionality.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"1Kosmos Mobile Application"}]},{"id":"oZFbUux9lLylhzuTfqL2","title":"FAQs","pathname":"/authentication/1kosmos-mobile-application/faqs","siteSpaceId":"sitesp_SlPSl","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"1Kosmos Mobile Application"}]},{"id":"oLxmyHgVC41mekhdB8CL","title":"Release Notes for 1K App","pathname":"/authentication/1kosmos-mobile-application/release-notes-for-1k-app","siteSpaceId":"sitesp_SlPSl","description":"Latest updates, new features, improvements, and bug fixes for the 1Kosmos mobile app on iOS and Android.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"1Kosmos Mobile Application"}]},{"id":"oR5auSVqdRY9NJQl5yEC","title":"Overview","pathname":"/authentication/1key-biometric/overview","siteSpaceId":"sitesp_SlPSl","description":"1Key is a biometric authentication solution for Windows. End users authenticate to their Active Directory (network ID) account using their fingerprint, captured by a 1Key hardware device.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"1Key Biometric"}]},{"id":"jDhgr1lzXY7oGDjshlCN","title":"Prerequisites & Planning","pathname":"/authentication/1key-biometric/prerequisites-and-planning","siteSpaceId":"sitesp_SlPSl","description":"Before deploying 1Key, ensure the following requirements are met.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"1Key Biometric"}]},{"id":"Nf3xltPmLchCC1JYAX4n","title":"Deployment Guide","pathname":"/authentication/1key-biometric/deployment-guide","siteSpaceId":"sitesp_SlPSl","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"1Key Biometric"}]},{"id":"W32irVkPKOQlorUHcDWh","title":"Auth Server installation","pathname":"/authentication/1key-biometric/deployment-guide/auth-server-installation","siteSpaceId":"sitesp_SlPSl","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"1Key Biometric"},{"label":"Deployment Guide"}]},{"id":"EyxWVpnUXJFyWlj6lmh4","title":"Auth Agent installation","pathname":"/authentication/1key-biometric/deployment-guide/auth-agent-installation","siteSpaceId":"sitesp_SlPSl","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"1Key Biometric"},{"label":"Deployment Guide"}]},{"id":"3o2wXnMCBsNfmVfCFCwf","title":"Auth Manager installation","pathname":"/authentication/1key-biometric/deployment-guide/auth-manager-installation","siteSpaceId":"sitesp_SlPSl","description":"The Auth Manager is the application end users open to enroll their fingerprint and security key. It appears in the Windows Start menu as ThinC Manager.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"1Key Biometric"},{"label":"Deployment Guide"}]},{"id":"jQrecKUpq6YZSIY2jbWb","title":"Administration Configuration","pathname":"/authentication/1key-biometric/administration-configuration","siteSpaceId":"sitesp_SlPSl","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"1Key Biometric"}]},{"id":"qQD1zbsK4pCeeSjcIcgO","title":"Fingerprint Consent Enforcement","pathname":"/authentication/1key-biometric/fingerprint-consent-enforcement","siteSpaceId":"sitesp_SlPSl","description":"Configure and enforce user consent for 1Key fingerprint biometric across enrollment and Windows login. Set up unified or separate biometric consent, manage consent versioning, bulk-import records, and","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"1Key Biometric"}]},{"id":"zisPSsbUtfEPoqjCLg9C","title":"User Guide","pathname":"/authentication/1key-biometric/user-guide","siteSpaceId":"sitesp_SlPSl","description":"This guide is for end users enrolling, authentication with the 1Key device. Enrollment links your fingerprint to your Active Directory (network ID) account.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"1Key Biometric"}]},{"id":"iOA3SqYUgiyIeOniEeMg","title":"FAQs","pathname":"/authentication/1key-biometric/faqs","siteSpaceId":"sitesp_SlPSl","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"1Key Biometric"}]},{"id":"eCMMhQIV5iWhnDV3NLTY","title":"Overview","pathname":"/authentication/orion-desktop-authenticator/overview","siteSpaceId":"sitesp_SlPSl","description":"Orion Authenticator is a desktop application that delivers strong, passwordless authentication and TOTP-based MFA directly from a user's Mac or Windows workstation — without requiring a mobile device.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Orion Desktop Authenticator"}]},{"id":"G5ll0Y4ffYco3GHwcQZ3","title":"Prerequisites and Requirements","pathname":"/authentication/orion-desktop-authenticator/prerequisites-and-requirements","siteSpaceId":"sitesp_SlPSl","description":"Before installing Orion Authenticator, ensure the target workstation meets the requirements below","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Orion Desktop Authenticator"}]},{"id":"EwP64Nce9sW7zWSXce3k","title":"Installation","pathname":"/authentication/orion-desktop-authenticator/installation","siteSpaceId":"sitesp_SlPSl","description":"Orion Authenticator can be deployed manually or distributed at scale through SCCM, Intune, or any Mobile Device Management (MDM) solution","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Orion Desktop Authenticator"}]},{"id":"0BFnDDbGlzTXVkhca6VM","title":"Administrator configuration","pathname":"/authentication/orion-desktop-authenticator/administrator-configuration","siteSpaceId":"sitesp_SlPSl","description":"Before end users can onboard their accounts, a community administrator must enable Orion in the AdminX portal and optionally configure adaptive authentication policies that use Orion as a factor","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Orion Desktop Authenticator"}]},{"id":"tkpohITdXd3dMyC7daY7","title":"End-user setup and authentication","pathname":"/authentication/orion-desktop-authenticator/end-user-setup-and-authentication","siteSpaceId":"sitesp_SlPSl","description":"This topic is for end users who need to onboard their 1Kosmos account to Orion Authenticator and use it to log in to applications","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Orion Desktop Authenticator"}]},{"id":"nzgzQDxwgy5VNUytmamh","title":"Operations and maintenance","pathname":"/authentication/orion-desktop-authenticator/operations-and-maintenance","siteSpaceId":"sitesp_SlPSl","description":"This page covers ongoing operational tasks for Orion Authenticator: viewing logs, performing in-place upgrades, resetting the agent, and uninstalling","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Orion Desktop Authenticator"}]},{"id":"UaVGdJCKjiz9Jv3ae5Le","title":"AdminX Configuration","pathname":"/authentication/orion-desktop-authenticator/adminx-configuration","siteSpaceId":"sitesp_SlPSl","description":"Orion Authenticator must be enabled and configured in AdminX before it becomes available to users.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Orion Desktop Authenticator"}]},{"id":"BVHzSHFHlXD9o1PEsrvt","title":"End User Guide","pathname":"/authentication/orion-desktop-authenticator/end-user-guide","siteSpaceId":"sitesp_SlPSl","description":"This section explains how users set up Orion Authenticator on their workstation and use it during login.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Orion Desktop Authenticator"}]},{"id":"XggUykDfCFN5olP0RHTj","title":"FAQs","pathname":"/authentication/orion-desktop-authenticator/faqs","siteSpaceId":"sitesp_SlPSl","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Orion Desktop Authenticator"}]},{"id":"UQnKftf8NZAPOWTQqlzH","title":"Getting Started with AdminX","pathname":"/authentication/admin-portal/getting-started-with-adminx","siteSpaceId":"sitesp_SlPSl","description":"This page covers everything you need to get started with AdminX: an introduction to the portal and its modules, how to set your preferred user stores, how to configure and use password resets.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Admin Portal"}]},{"id":"V8VeEdrOddK3SwqNOsD8","title":"Dashboard","pathname":"/authentication/admin-portal/dashboard","siteSpaceId":"sitesp_SlPSl","description":"AdminX Dashboard is the starting point for 1Kosmos setup—configure session attributes, manage invite emails, connect directories (LDAP), and access profile and analytics","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Admin Portal"}]},{"id":"9Jv2p1tsS0N5iJ3ZzoAj","title":"Managing My Profile","pathname":"/authentication/admin-portal/dashboard/managing-my-profile","siteSpaceId":"sitesp_SlPSl","description":"Users can use the My Profile tab under the Dashboard menu of the AdminX interface to manage their devices and accounts.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Admin Portal"},{"label":"Dashboard"}]},{"id":"aMRCHjMuumKPfNvOCpvB","title":"Analytics Dashboard","pathname":"/authentication/admin-portal/dashboard/analytics-dashboard","siteSpaceId":"sitesp_SlPSl","description":"The Analytics Dashboard gives administrators an overview of user activity for a tenant.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Admin Portal"},{"label":"Dashboard"}]},{"id":"cKdWyurRdKlc7QPXvj7A","title":"Directory Integrations","pathname":"/authentication/admin-portal/directory-integrations","siteSpaceId":"sitesp_SlPSl","description":"Connect 1Kosmos to your existing directories to source user identities and attributes for authentication.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Admin Portal"}]},{"id":"4y9cgdDj0q57GzWW9yMR","title":"Connect to Microsoft Entra ID","pathname":"/authentication/admin-portal/directory-integrations/connect-to-microsoft-entra-id","siteSpaceId":"sitesp_SlPSl","description":"Connect and integrate your Microsoft Entra ID user store with your AdminX tenant so you can manage all your Entra ID users from AdminX.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Admin Portal"},{"label":"Directory Integrations"}]},{"id":"V5Jzma52VCZStCCfyKT9","title":"User Attribute Transformation","pathname":"/authentication/admin-portal/directory-integrations/user-attribute-transformation","siteSpaceId":"sitesp_SlPSl","description":"Reshape user attributes before they are sent in an assertion. Concatenate values, parse phone numbers from a single directory attribute, filter sensitive AD groups, and prepare directory data.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Admin Portal"},{"label":"Directory Integrations"}]},{"id":"JoAVyFvJACC778b2yWHL","title":"User Management","pathname":"/authentication/admin-portal/user-management","siteSpaceId":"sitesp_SlPSl","description":"User management covers how administrators create and manage user accounts in 1Kosmos from initial setup and role assignment to onboarding, device management, and session control.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Admin Portal"}]},{"id":"jbTVzuVpH5k3QGcuaoMx","title":"Authentication","pathname":"/authentication/admin-portal/authentication","siteSpaceId":"sitesp_SlPSl","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Admin Portal"}]},{"id":"Eq8V9tptFDkuFBTA8Vus","title":"Restricting Access Based on Geolocation","pathname":"/authentication/admin-portal/authentication/restricting-access-based-on-geolocation","siteSpaceId":"sitesp_SlPSl","description":"1Kosmos lets organizations manage access using a user's geographic location, helping protect applications from malicious actors while ensuring access is granted only to legitimate users.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Admin Portal"},{"label":"Authentication"}]},{"id":"VxNaLUn0lgCmgi63Pcnj","title":"Setting up IP-based Authentication Journey in AdminX","pathname":"/authentication/admin-portal/authentication/setting-up-ip-based-authentication-journey-in-adminx","siteSpaceId":"sitesp_SlPSl","description":"This guide explains how to create an IP-based authentication journey in AdminX, allowing you to manage a range of IP addresses for specific user journeys, allowlists, or blocklists.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Admin Portal"},{"label":"Authentication"}]},{"id":"yDM7OBipE1WhjPnqUsGr","title":"Setup Multi-Factor Authentication","pathname":"/authentication/admin-portal/authentication/setup-multi-factor-authentication","siteSpaceId":"sitesp_SlPSl","description":"This page provides you detail on how to enable Multi factor authentication (MFA) through AdminX Portal.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Admin Portal"},{"label":"Authentication"}]},{"id":"iOQj17UNGkTOQaxVm1CO","title":"Enrollment Preferences Policy","pathname":"/authentication/admin-portal/authentication/enrollment-preferences-policy","siteSpaceId":"sitesp_SlPSl","description":"Enrollment Preference policy allows administrator to associate appropriate authenticators for securely accessing the 1Kosmos application.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Admin Portal"},{"label":"Authentication"}]},{"id":"yHPQVnlaiGYzWKvsBZqn","title":"Configure Adaptive Authentication","pathname":"/authentication/admin-portal/authentication/configure-adaptive-authentication","siteSpaceId":"sitesp_SlPSl","description":"This page covers how to set up Adaptive Authentication in the Admin Portal by creating journeys with conditions and decision actions.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Admin Portal"},{"label":"Authentication"}]},{"id":"izYOnbpugEGrs8346Zyn","title":"Configure Device Restriction Policy","pathname":"/authentication/admin-portal/authentication/configure-device-restriction-policy","siteSpaceId":"sitesp_SlPSl","description":"Enforce device enrollment limits by user group or username to reduce unauthorized device sprawl and strengthen authentication governance across your 1Kosmos community","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Admin Portal"},{"label":"Authentication"}]},{"id":"AiakabcbeRpmzpLcmKf4","title":"Configure Passwordless Login","pathname":"/authentication/admin-portal/authentication/configure-passwordless-login","siteSpaceId":"sitesp_SlPSl","description":"Community and helpdesk administrators can use the Passwordless Login page in AdminX to manage authentication factors and device configurations for a smooth onboarding experience.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Admin Portal"},{"label":"Authentication"}]},{"id":"yufkRZ8tGThVL1TWt4oZ","title":"Monitoring & Reporting","pathname":"/authentication/admin-portal/monitoring-and-reporting","siteSpaceId":"sitesp_SlPSl","description":"Know exactly who's accessing what, when, and how. AdminX brings login history, event activity, access denials, and administrator actions together in one place.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Admin Portal"}]},{"id":"GmtpXcinT9TPq8xHG5TY","title":"Event Reference","pathname":"/authentication/admin-portal/monitoring-and-reporting/event-reference","siteSpaceId":"sitesp_SlPSl","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Admin Portal"},{"label":"Monitoring & Reporting"}]},{"id":"BrUc1e6MlF9kxTv3NWtf","title":"Settings","pathname":"/authentication/admin-portal/settings","siteSpaceId":"sitesp_SlPSl","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Admin Portal"}]},{"id":"rU2odtpt4wahIinFD7Y9","title":"General Settings","pathname":"/authentication/admin-portal/settings/general-settings","siteSpaceId":"sitesp_SlPSl","description":"The page has two tabs — Preferred User Stores and Self Registration — plus tenant information and session controls.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Admin Portal"},{"label":"Settings"}]},{"id":"VMolKNpsYg4pXuhJtYGF","title":"Managing Email Templates","pathname":"/authentication/admin-portal/settings/managing-email-templates","siteSpaceId":"sitesp_SlPSl","description":"Every message your users receive — OTPs, verification links, onboarding invites, password resets — comes from a ready-to-use 1Kosmos template.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Admin Portal"},{"label":"Settings"}]},{"id":"0S17omtH2grVsqPe5oGN","title":"1Kosmos Attributes","pathname":"/authentication/admin-portal/settings/1kosmos-attributes","siteSpaceId":"sitesp_SlPSl","description":"1Kosmos attributes let you define exactly what gets shared.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Admin Portal"},{"label":"Settings"}]},{"id":"C8RNWxaK8wp7yY07TkWa","title":"Identity Provider (IdP) Configuration","pathname":"/authentication/admin-portal/settings/identity-provider-idp-configuration","siteSpaceId":"sitesp_SlPSl","description":"Connect your identity provider to AdminX and unlock user-friendly features like single sign-on. This page walks you through adding an IdP and configuring its metadata, endpoints, and certificates.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Admin Portal"},{"label":"Settings"}]},{"id":"GDnfCtZc40751rHFpIeG","title":"Branding Customization","pathname":"/authentication/admin-portal/settings/branding-customization","siteSpaceId":"sitesp_SlPSl","description":"Make the 1Kosmos login experience unmistakably yours. From your logo and colors to the QR code and background, you can tailor the sign-in page to match your organization's brand.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Admin Portal"},{"label":"Settings"}]},{"id":"nVVNF3UpwSIQli1IA7Kd","title":"Gateway Settings","pathname":"/authentication/admin-portal/settings/gateway-settings","siteSpaceId":"sitesp_SlPSl","description":"Send your emails, texts, and voice calls through your own providers. On the Gateway Settings page, add your provider details and 1Kosmos will route all outgoing communications using specify account.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Admin Portal"},{"label":"Settings"}]},{"id":"8dzx3hq0JUbQ3FeJFU7w","title":"Consent Management","pathname":"/authentication/admin-portal/settings/consent-management","siteSpaceId":"sitesp_SlPSl","description":"Put users in control of their biometric data — and keep your organization compliant.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Admin Portal"},{"label":"Settings"}]},{"id":"TCwfUp9BJE9kI4XZ8LNy","title":"Managing Secrets","pathname":"/authentication/admin-portal/settings/managing-secrets","siteSpaceId":"sitesp_SlPSl","description":"Keep your sensitive data out of your code. Secret Store lets administrators securely store and manage API keys, client secrets, and tokens used in workflows and integrations.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Admin Portal"},{"label":"Settings"}]},{"id":"Yl5CJo0XyDIn8FEi1leM","title":"Release Notes for AdminX","pathname":"/authentication/admin-portal/release-notes-for-adminx","siteSpaceId":"sitesp_SlPSl","description":"New features, enhancements, bug fixes, and security updates for the 1Kosmos AdminX platform, listed by release version and date.","breadcrumbs":[{"label":"Authentication","icon":"laptop"},{"label":"Admin Portal"}]},{"id":"g59nDuRYAo7iOrUcUmDy","title":"Release Notes","pathname":"/authentication/release-notes","siteSpaceId":"sitesp_SlPSl","description":"Stay current with the latest 1Kosmos updates, new features, improvements, and bug fixes across AdminX, authentication, and identity verification.","breadcrumbs":[{"label":"Authentication","icon":"laptop"}]},{"id":"8cgs3RQTEU5fGeSlcQCn","title":"Overview","pathname":"/integrations","siteSpaceId":"sitesp_YTZfG","description":"1Kosmos identity verification integrations extend IAL2-compliant identity proofing into the platforms and workflows where access decisions already happen.","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Identity Verification"}]},{"id":"aNqbiXiUQ9mqZEZR48Tc","title":"Okta - Identity Verification for Account Management","pathname":"/integrations/identity-verification/okta-identity-verification-for-account-management","siteSpaceId":"sitesp_YTZfG","description":"This topic explains how to connect 1Kosmos with Okta to securely verify users’ identities inside of the account management policy.","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Identity Verification"}]},{"id":"WLfcf1OtyyH7dDZvg1LX","title":"Creating an OIDC client for Okta in 1Kosmos","pathname":"/integrations/identity-verification/okta-identity-verification-for-account-management/creating-an-oidc-client-for-okta-in-1kosmos","siteSpaceId":"sitesp_YTZfG","description":"Creating an OIDC client for Okta in 1Kosmos","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Identity Verification"},{"label":"Okta - Identity Verification for Account Management"}]},{"id":"Xwd7UH7tbz6K9tacWMNT","title":"Configuring verification flow & workflow in 1Kosmos","pathname":"/integrations/identity-verification/okta-identity-verification-for-account-management/configuring-verification-flow-and-workflow-in-1kosmos","siteSpaceId":"sitesp_YTZfG","description":"You will need to configure the identity verification steps that you want the end user to go through. To do this, you must configure a verification flow and a workflow.","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Identity Verification"},{"label":"Okta - Identity Verification for Account Management"}]},{"id":"DzmtwIPDxQOxbtabwkLm","title":"Configuring 1Kosmos as a custom identity verification vendor in Okta","pathname":"/integrations/identity-verification/okta-identity-verification-for-account-management/configuring-1kosmos-as-a-custom-identity-verification-vendor-in-okta","siteSpaceId":"sitesp_YTZfG","description":"Configuring 1Kosmos as an Identity Verification Vendor in Okta","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Identity Verification"},{"label":"Okta - Identity Verification for Account Management"}]},{"id":"dMzWkf6KJiC3O3AEHtzL","title":"Epic - Identity Verification in MyChart and EpicCare Link","pathname":"/integrations/identity-verification/epic-identity-verification-in-mychart-and-epiccare-link","siteSpaceId":"sitesp_YTZfG","description":"This topic explains how to implement 1Kosmos for identity verification in MyChart and EpicCare Link using the Epic Toolbox.","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Identity Verification"}]},{"id":"HRUZ2pSyWBJdEtbv7oDE","title":"Setting up an Epic OIDC Client in 1Kosmos","pathname":"/integrations/identity-verification/epic-identity-verification-in-mychart-and-epiccare-link/setting-up-an-epic-oidc-client-in-1kosmos","siteSpaceId":"sitesp_YTZfG","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Identity Verification"},{"label":"Epic - Identity Verification in MyChart and EpicCare Link"}]},{"id":"8btQQRA54joURmtO1TyA","title":"Configuring verification flow & workflow in 1Kosmos","pathname":"/integrations/identity-verification/epic-identity-verification-in-mychart-and-epiccare-link/configuring-verification-flow-and-workflow-in-1kosmos","siteSpaceId":"sitesp_YTZfG","description":"You will need to configure the identity verification steps that you want the end user to go through. To do this, you must configure a verification flow and a workflow.","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Identity Verification"},{"label":"Epic - Identity Verification in MyChart and EpicCare Link"}]},{"id":"YTJh9AddjwdKytrO5dY2","title":"Configuring 1Kosmos as an identity verification vendor in Epic","pathname":"/integrations/identity-verification/epic-identity-verification-in-mychart-and-epiccare-link/configuring-1kosmos-as-an-identity-verification-vendor-in-epic","siteSpaceId":"sitesp_YTZfG","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Identity Verification"},{"label":"Epic - Identity Verification in MyChart and EpicCare Link"}]},{"id":"HSEyrCSPNJRTaOl3XEbj","title":"Microsoft Entra - Account Recovery","pathname":"/integrations/identity-verification/microsoft-entra-account-recovery","siteSpaceId":"sitesp_YTZfG","description":"This topic explains how to configure 1Kosmos for Microsoft Entra Account Recovery using the Microsoft Security Store.","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Identity Verification"}]},{"id":"V73DbbvmMko3xWjHRW2e","title":"Recovering user accounts in Microsoft Entra","pathname":"/integrations/identity-verification/microsoft-entra-account-recovery/recovering-user-accounts-in-microsoft-entra","siteSpaceId":"sitesp_YTZfG","description":"Microsoft Entra Account Recovery follows a structured, multi-step process. 1Kosmos powers the identity verification step at the core of this flow.","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Identity Verification"},{"label":"Microsoft Entra - Account Recovery"}]},{"id":"1Dj04kcxINFz5poRn9Vm","title":"Plans & pricing","pathname":"/integrations/identity-verification/microsoft-entra-account-recovery/plans-and-pricing","siteSpaceId":"sitesp_YTZfG","description":"Identity Verification by 1Kosmos is available through the Microsoft Security Store at pay-as-you-go pricing.","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Identity Verification"},{"label":"Microsoft Entra - Account Recovery"}]},{"id":"Aj8n4xqyNRxlPLv7xFj3","title":"Purchasing 1Kosmos in the Microsoft Security Store","pathname":"/integrations/identity-verification/microsoft-entra-account-recovery/purchasing-1kosmos-in-the-microsoft-security-store","siteSpaceId":"sitesp_YTZfG","description":"How to purchase 1Kosmos through the Microsoft Security Store","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Identity Verification"},{"label":"Microsoft Entra - Account Recovery"}]},{"id":"AuCzE7SV7QXekJE6AJdF","title":"Sailpoint - Identity Verification for Workflows","pathname":"/integrations/identity-verification/sailpoint-identity-verification-for-workflows","siteSpaceId":"sitesp_YTZfG","description":"This topic explains how to connect 1Kosmos with Sailpoint to initiate identity verification from within Sailpoint Workflows.","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Identity Verification"}]},{"id":"jRS4qTh2mw2oyiTMi9KD","title":"Initial Sailpoint set up","pathname":"/integrations/identity-verification/sailpoint-identity-verification-for-workflows/initial-sailpoint-set-up","siteSpaceId":"sitesp_YTZfG","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Identity Verification"},{"label":"Sailpoint - Identity Verification for Workflows"}]},{"id":"pCCE5OBj8hgyp4NJwEad","title":"Sailpoint Workflows","pathname":"/integrations/identity-verification/sailpoint-identity-verification-for-workflows/sailpoint-workflows","siteSpaceId":"sitesp_YTZfG","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Identity Verification"},{"label":"Sailpoint - Identity Verification for Workflows"}]},{"id":"aTq2JRUwr4kqAfim383Z","title":"Workflow 1: Enroll a New Identity for Verification","pathname":"/integrations/identity-verification/sailpoint-identity-verification-for-workflows/sailpoint-workflows/workflow-1-enroll-a-new-identity-for-verification","siteSpaceId":"sitesp_YTZfG","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Identity Verification"},{"label":"Sailpoint - Identity Verification for Workflows"},{"label":"Sailpoint Workflows"}]},{"id":"kAFGIEAEvnMUPiiejbvL","title":"Workflow 2: Record the Verification Result","pathname":"/integrations/identity-verification/sailpoint-identity-verification-for-workflows/sailpoint-workflows/workflow-2-record-the-verification-result","siteSpaceId":"sitesp_YTZfG","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Identity Verification"},{"label":"Sailpoint - Identity Verification for Workflows"},{"label":"Sailpoint Workflows"}]},{"id":"8dbKsZ7LlTQDJSAfDSLu","title":"1Kosmos Workflow: Identity Verification","pathname":"/integrations/identity-verification/sailpoint-identity-verification-for-workflows/1kosmos-workflow-identity-verification","siteSpaceId":"sitesp_YTZfG","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Identity Verification"},{"label":"Sailpoint - Identity Verification for Workflows"}]},{"id":"NJMjPWwqvCZDmo5B47uN","title":"Saviynt - Identity Verification for Workflows","pathname":"/integrations/identity-verification/saviynt-identity-verification-for-workflows","siteSpaceId":"sitesp_YTZfG","description":"This topic explains how to connect 1Kosmos with Saviynt to initiate identity verification from within Saviynt Workflows.","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Identity Verification"}]},{"id":"UAuG2wI73LzNUpM1eVuI","title":"Configuring a verification journey in 1Kosmos","pathname":"/integrations/identity-verification/saviynt-identity-verification-for-workflows/configuring-a-verification-journey-in-1kosmos","siteSpaceId":"sitesp_YTZfG","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Identity Verification"},{"label":"Saviynt - Identity Verification for Workflows"}]},{"id":"Eo1IyAGBoa0bZFqHxmwz","title":"Configuring identity proofing settings in Saviynt","pathname":"/integrations/identity-verification/saviynt-identity-verification-for-workflows/configuring-identity-proofing-settings-in-saviynt","siteSpaceId":"sitesp_YTZfG","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Identity Verification"},{"label":"Saviynt - Identity Verification for Workflows"}]},{"id":"Ez702mr8TVyNk9sXhzVL","title":"ServiceNow - Identity Verification for Account Management","pathname":"/integrations/identity-verification/servicenow-identity-verification-for-account-management","siteSpaceId":"sitesp_YTZfG","description":"This topic explains how to connect 1Kosmos with Okta to securely verify users’s identities for account management.","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Identity Verification"}]},{"id":"TOCg6KVxDhP3bAwapo38","title":"Installing & configuring 1Kosmos-Verify","pathname":"/integrations/identity-verification/servicenow-identity-verification-for-account-management/installing-and-configuring-1kosmos-verify","siteSpaceId":"sitesp_YTZfG","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Identity Verification"},{"label":"ServiceNow - Identity Verification for Account Management"}]},{"id":"LSYQf0UdigNWEyhIhxSw","title":"Testing 1Kosmos-Verify in ServiceNow","pathname":"/integrations/identity-verification/servicenow-identity-verification-for-account-management/testing-1kosmos-verify-in-servicenow","siteSpaceId":"sitesp_YTZfG","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Identity Verification"},{"label":"ServiceNow - Identity Verification for Account Management"}]},{"id":"oYkcTt43VbjvfCeGpXpz","title":"Custom Integrations","pathname":"/integrations/authentication/custom-integrations","siteSpaceId":"sitesp_YTZfG","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Authentication"}]},{"id":"JLQLJtAbU6v52i45XvTt","title":"OIDC Application Integrations","pathname":"/integrations/authentication/custom-integrations/oidc-application-integrations","siteSpaceId":"sitesp_YTZfG","description":"OpenID Connect (OIDC) is an industry-standard authentication layer built on top of the OAuth 2.0 authorization protocol. OAuth 2.0 provides security through scoped access tokens.","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Authentication"},{"label":"Custom Integrations"}]},{"id":"1K8qVGdUOGeBEPpbU0Qa","title":"SAML Application Integrations","pathname":"/integrations/authentication/custom-integrations/saml-application-integrations","siteSpaceId":"sitesp_YTZfG","description":"The Security Assertion Markup Language (SAML) integration enables passwordless authentication for users logging into a service provider's web application.","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Authentication"},{"label":"Custom Integrations"}]},{"id":"KyZcMlZzgcZG3ctCo8jo","title":"WS-Fed Application Integrations","pathname":"/integrations/authentication/custom-integrations/ws-fed-application-integrations","siteSpaceId":"sitesp_YTZfG","description":"WS-Fed (WS-Federation) Application Integration is a way to enable Single Sign-On (SSO) between an Identity Provider (IdP) and an application using the WS-Federation protocol.","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Authentication"},{"label":"Custom Integrations"}]},{"id":"cjoLEmiNnDdvbNcU8KKP","title":"Desktop SSO","pathname":"/integrations/authentication/desktop-sso","siteSpaceId":"sitesp_YTZfG","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Authentication"}]},{"id":"ywsrWKbG7vBsIteHZuLy","title":"Kerberos Single Sign-On","pathname":"/integrations/authentication/desktop-sso/kerberos-single-sign-on","siteSpaceId":"sitesp_YTZfG","description":"1Kosmos uses Kerberos with Active Directory (AD) to provide seamless SSO. Users authenticated on their AD network are automatically signed in to 1Kosmos applications without re-entering credentials.","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Authentication"},{"label":"Desktop SSO"}]},{"id":"jpLwWRHKPKLDwvDYl7nr","title":"External Identity Provider (SSO Federation)","pathname":"/integrations/authentication/external-identity-provider-sso-federation","siteSpaceId":"sitesp_YTZfG","description":"1Kosmos can participate in single sign-on (SSO) in different roles depending on your scenario. Use the guide that matches your setup.","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Authentication"}]},{"id":"U65EScQqI9LZAVoN1HQf","title":"Microsoft Azure as an External Identity Provider","pathname":"/integrations/authentication/external-identity-provider-sso-federation/microsoft-azure-as-an-external-identity-provider","siteSpaceId":"sitesp_YTZfG","description":"The steps to configure Azure as an External Identity Provider (IdP) for the 1Kosmos Service Provider (SP) using SAML (Security Assertion Markup Language) for authentication.","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Authentication"},{"label":"External Identity Provider (SSO Federation)"}]},{"id":"QGlgWVYU0tpY5QAfHyX1","title":"Setting Up 1Kosmos as an Identity Provider","pathname":"/integrations/authentication/external-identity-provider-sso-federation/setting-up-1kosmos-as-an-identity-provider","siteSpaceId":"sitesp_YTZfG","description":"Configure Okta as a service provider (SP) in addition to using it as an identity provider (IdP). When Okta acts as a service provider, it integrates with an external Identity Provider using SAML","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Authentication"},{"label":"External Identity Provider (SSO Federation)"}]},{"id":"8bCuHierW4xaBfh4CqLD","title":"1Kosmos as a Service Provider in Okta","pathname":"/integrations/authentication/external-identity-provider-sso-federation/1kosmos-as-a-service-provider-in-okta","siteSpaceId":"sitesp_YTZfG","description":"The steps to configure 1Kosmos as a Service Provider (SP) in Okta using SAML for authentication.","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Authentication"},{"label":"External Identity Provider (SSO Federation)"}]},{"id":"CPkEAJW4LqV3OOQAUBZH","title":"1Kosmos as an External Identity Provider in Okta","pathname":"/integrations/authentication/external-identity-provider-sso-federation/1kosmos-as-an-external-identity-provider-in-okta","siteSpaceId":"sitesp_YTZfG","description":"The steps to configure 1Kosmos as an External Identity Provider (IdP) with an Okta Service Provider (SP) using SAML for authentication.","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Authentication"},{"label":"External Identity Provider (SSO Federation)"}]},{"id":"hj3LOrKxtz5yglK3gPYF","title":"Setting up 1Kosmos as an External Authentication Method for Microsoft Entra ID","pathname":"/integrations/authentication/external-identity-provider-sso-federation/setting-up-1kosmos-as-an-external-authentication-method-for-microsoft-entra-id","siteSpaceId":"sitesp_YTZfG","description":"The steps to configure 1Kosmos as an External Authentication Method (EAM) for Microsoft Entra ID using OIDC.","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Authentication"},{"label":"External Identity Provider (SSO Federation)"}]},{"id":"LjBGUuzH7XrWrZ08YR80","title":"Pre-built Integrations","pathname":"/integrations/authentication/pre-built-integrations","siteSpaceId":"sitesp_YTZfG","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Authentication"}]},{"id":"H50E84E8VettiqLUHrXQ","title":"Auth0","pathname":"/integrations/authentication/pre-built-integrations/auth0","siteSpaceId":"sitesp_YTZfG","description":"Enable passwordless, biometric login for your Auth0 users using 1Kosmos as a SAML 2.0 Identity Provider. Once connected, users authenticate with Touch ID, Face ID, or LiveID instead of a password.","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Authentication"},{"label":"Pre-built Integrations"}]},{"id":"7z6rbhHyaLnBirh37uwy","title":"Entra EAM (Beta)","pathname":"/integrations/authentication/pre-built-integrations/entra-eam-beta","siteSpaceId":"sitesp_YTZfG","description":"Enable passwordless, biometric login for Microsoft Entra External Authentication Method (EAM) users using 1Kosmos as an OIDC Identity Provider.","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Authentication"},{"label":"Pre-built Integrations"}]},{"id":"yuUt6TW1osaCjPcDGmf3","title":"G-Suite","pathname":"/integrations/authentication/pre-built-integrations/g-suite","siteSpaceId":"sitesp_YTZfG","description":"Enable passwordless, biometric login for your Google Workspace users using 1K as a SAML 2.0 Identity Provider. Once connected, users authenticate with Touch ID, Face ID, or LiveID.","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Authentication"},{"label":"Pre-built Integrations"}]},{"id":"gqaWHj0KPq3YLtDBc82A","title":"Office 365","pathname":"/integrations/authentication/pre-built-integrations/office-365","siteSpaceId":"sitesp_YTZfG","description":"Enable passwordless, biometric authentication for Microsoft Office 365 using 1Kosmos as a SAML 2.0 Identity Provider — allowing users to sign in with Touch ID, Face ID, or LiveID instead of a password","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Authentication"},{"label":"Pre-built Integrations"}]},{"id":"iVb66H4aHMDKZObqITNG","title":"Okta","pathname":"/integrations/authentication/pre-built-integrations/okta","siteSpaceId":"sitesp_YTZfG","description":"Enable passwordless, biometric login for your Okta users using 1Kosmos as a SAML 2.0 Identity Provider. Once connected, users authenticate with Touch ID, Face ID, or LiveID instead of a password.","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Authentication"},{"label":"Pre-built Integrations"}]},{"id":"727CO7OUQcDXNaEUAlMO","title":"Okta Identity Verification","pathname":"/integrations/authentication/pre-built-integrations/okta-identity-verification","siteSpaceId":"sitesp_YTZfG","description":"Connect Okta BYO IDV with 1Kosmos from a prebuilt AdminX tile — one guided form adds the OIDC client, auto-generates the Okta IDP config, and returns verified claims.","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Authentication"},{"label":"Pre-built Integrations"}]},{"id":"d3FVwcCfvPcZT4u1Jlgs","title":"OneLogin","pathname":"/integrations/authentication/pre-built-integrations/onelogin","siteSpaceId":"sitesp_YTZfG","description":"Integrate 1Kosmos passwordless authentication with OneLogin using SAML 2.0 — enabling biometric login with Touch ID, Face ID, or LiveID for your OneLogin users.","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Authentication"},{"label":"Pre-built Integrations"}]},{"id":"szgRJewLSfdSx6cXUV6q","title":"Salesforce","pathname":"/integrations/authentication/pre-built-integrations/salesforce","siteSpaceId":"sitesp_YTZfG","description":"Enable passwordless, biometric login for your Salesforce users using 1K as a SAML 2.0 Identity Provider. Once connected, users authenticate with Touch ID, Face ID, or LiveID instead of a password.","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Authentication"},{"label":"Pre-built Integrations"}]},{"id":"zBA7QpTe8W5CzYrYQMz5","title":"PingOne DaVinci Connector","pathname":"/integrations/authentication/pre-built-integrations/pingone-davinci-connector","siteSpaceId":"sitesp_YTZfG","description":"Integrate 1Kosmos passwordless authentication with PingOne DaVinci using the 1Kosmos OIDC connector — enabling seamless biometric login within your DaVinci authentication flows.","breadcrumbs":[{"label":"Integrations","icon":"code-merge"},{"label":"Authentication"},{"label":"Pre-built Integrations"}]},{"id":"gvRbwTnqQKVHekJf9c4n","title":"Overview","pathname":"/workflow-builder","siteSpaceId":"sitesp_p1shO","description":"Design, test, run, and manage identity verification journeys with a visual, drag-and-drop Workflow Builder, no backend development required.","breadcrumbs":[{"label":"Workflow Builder","icon":"chart-diagram"}]},{"id":"mOEbEd0g16yVHbZgyR8n","title":"Build a Workflow","pathname":"/workflow-builder/build-a-workflow","siteSpaceId":"sitesp_p1shO","description":"Build an identity verification workflow end to end on the canvas — add nodes, connect them, configure settings, preview, and save.","breadcrumbs":[{"label":"Workflow Builder","icon":"chart-diagram"}]},{"id":"SrXnA7rd5nMh4F1oj4Nr","title":"Node Library","pathname":"/workflow-builder/node-library","siteSpaceId":"sitesp_p1shO","description":"The complete catalog of Workflow Builder nodes — User Interaction, Capture, Outcome, and Advanced — and how to configure each one in the Node Editor.","breadcrumbs":[{"label":"Workflow Builder","icon":"chart-diagram"}]},{"id":"UdNU9yXZNt6dKZkVQTaY","title":"Customize Preview & Save","pathname":"/workflow-builder/customize-preview-and-save","siteSpaceId":"sitesp_p1shO","description":"Import workflows from JSON, customize branding with theme colors and custom HTML/CSS, preview the journey before publishing, and save your workflow.","breadcrumbs":[{"label":"Workflow Builder","icon":"chart-diagram"}]},{"id":"gIIWKDJmwTeDjL5VyjFq","title":"Manage Workflows","pathname":"/workflow-builder/manage-workflows","siteSpaceId":"sitesp_p1shO","description":"Edit or delete existing identity verification workflows, with control over whether changes override the current workflow or create a copy.","breadcrumbs":[{"label":"Workflow Builder","icon":"chart-diagram"}]},{"id":"BjodMHKNvOGNucbkKBPC","title":"Launch and Monitor Verification Sessions","pathname":"/workflow-builder/launch-and-monitor-verification-sessions","siteSpaceId":"sitesp_p1shO","description":"Launch a verification session from a workflow and track its progress, executed nodes, output, and status from the Instances page.","breadcrumbs":[{"label":"Workflow Builder","icon":"chart-diagram"}]},{"id":"celES7x7zlKPEiiGm8KQ","title":"Release Notes","pathname":"/workflow-builder/release-notes","siteSpaceId":"sitesp_p1shO","breadcrumbs":[{"label":"Workflow Builder","icon":"chart-diagram"}]},{"id":"c115c685925ecf5ef4d655a99b6fe8d334979cfd","title":"Master Release Notes","pathname":"/master-release-notes","siteSpaceId":"sitesp_svwIA","description":"A comprehensive record of product updates, new features, enhancements, bug fixes, and other changes across all releases.","breadcrumbs":[{"label":"Master Release Notes"}]}]}