Skip to content

Relying parties

The Relying parties module declares the domain names on which the Mediation Controller is allowed to enrol and control security keys (FIDO / WebAuthn). Any key enrolled from a page whose URL does not belong to one of those domains is automatically refused.

An administrator uses it to authorise the domain name(s) under which users reach the user portal (for example portal.example.com, auth.example.com).

At least one relying party required

The relying party ID is mandatory for any operation involving security keys and the authentication client. When no identifier is registered, security key features are disabled in the user portal (authentication then only relies on passwords and classic additional factors such as OTPs).

Relying party list

Column Description
Name Free label, unique within the organization. Only used for management in this console.
Relying party ID Valid domain string, unique within the organization. Used to validate the origin of key operations.

While no relying party is declared, the grid reads No relying parties.

The toolbar carries the add button (tooltip New relying party), the Properties icon, the delete icon and a search field. Pagination at the bottom follows the console standard.

Add a relying party

Click +. The Add a relying party window opens.

Field Description
Name Mandatory. Free, unique label.
Relying party ID: Mandatory. Must be a valid domain string (for example example.com) — the field prompts Please enter a valid domain string. Unique within the organization.

Click Validate.

Edit a relying party

Select a row then click the Properties icon (or double-click it). The Edit a relying party window is identical to the add one.

Delete a relying party

Select one or several rows then click ×. A confirmation is requested, adapted to singular or plural. Multi-selection is supported.