Authentication levels
LuxID's auth_level authentication-strength scale, its informal eIDAS LoA alignment, and how to request a minimum level with acr_values.
LuxID's auth_level authentication-strength scale, its informal eIDAS LoA alignment, and how to request a minimum level with acr_values.
LuxID MFA methods (OTP, TOTP, passkeys, LuxTrust), token claims amr and acr, minimum assurance configuration, step-up flows, and recovery paths.
Step-up authentication UX, per-method flows for OTP, TOTP, passkeys, and LuxTrust, recovery paths, lockout prevention, and re-authentication patterns.
WebAuthn/FIDO2 passkeys on LuxID: device binding, platform and roaming authenticators, token claims, fallback behaviour, and phishing resistance.
Architectural decisions to make before writing production code: protocol, required auth_level, MFA, Sphere, session strategy, logout, and branding.
End-to-end sequence diagrams for first-time sign-in, returning sign-in, MFA challenge, LuxID Verified, LuxID Pro federation, account linking, and logout.