Skip to main content

Bravura OneAuth

Connector name

agthypr

Connector type

Python script

Type (UI field value)

Bravura OneAuth

Connector status / support

Bravura Security-Verified

This connector has been tested and is fully supported by Bravura Security.

Installation / setup

The agthypr connector for the Bravura OneAuth target type consists of a Python script, agthypr.py and a scripted platform definition file, agthypr.con , that associates the script with the Python connector (agtpython) to access Bravura OneAuth .

It also has an agthypr_requirements.txt file that is used to install the Python requirements for this connector. To install the Python packages required by the agthypr connector, run the following command from a command prompt:

py -m pip install -r agthypr_requirements.txt

Upgrade notes

Added the Bravura OneAuth connector in Connector Pack 4.4.0.

Bravura OneAuth is powered by HYPR and accomplishes passwordless MFA by using the challenge response operation and authenticating against the user's previously registered HYPR mobile app. An authentication chain configured for the agthypr connector sends a push notification to the user’s mobile app and on approval of the mobile app request, authentication is then granted for the user.

The following Bravura Security Fabric operations are supported by the Bravura OneAuth connector:

  • challenge response authentication

  • List:

    • accounts

    • attributes

For a full list and explanation of each connector operation, see Connector operations.

Preparation

Before you can target Bravura OneAuth , you must:

Bravura OneAuth supports mobile versions iOS13+ and Android 9+.

Log in to the HYPR Control Center

These instructions assume that the following steps have been completed:

To log in to the HYPR Control Center:

  1. From your browser, navigate to your tenant HYPR Control Center URL.

    safe_hypr_cs_login
  2. Enter your Username.

  3. Click the button corresponding to the device you registered during onboarding (e.g. Smartphone).

    safe_hypr_cs_login2
  4. On the selected device:

    1. Tap the authentication notification; HYPR Tap to Authenticate.

    2. Tap Login.

    3. Authenticate using a biometric method configured for your device.

    You are logged in to the HYPR Control Center website on your computer.

Set up a target administrator

The following steps demonstrate how to configure the target administrator credentials on the HYPR server:

  1. Log in to the HYPR Control Center .

  2. From the HYPR administrative Control Center, select the application that you will be using to target Bravura OneAuth in Bravura Security Fabric .

  3. Under Advanced Config, click Access Tokens.

  4. Click Create Token.

  5. Enter a name for the token and choose API Token.

  6. Click Next .

  7. Click Select All to choose all permission types.

  8. Click Next .

    A Token Value will be displayed.

  9. Copy this value down and store it in a safe place.

    Caution

    This value will not be visible after dismissing this prompt.

    This value will be used for the administrator password for the Bravura OneAuth target in Bravura Security Fabric .

  10. Check the checkbox and click Done .

    When listing users from auto discovery, if you get an error message such as " Error: Failed to get users ", check the expiry date of the API Token to ensure that it is still valid.

See also

Refer to the following HYPR documentation:

https://docs.hypr.com/installinghypr/docs/control-center-users

Includes the following topics:

  • Control Center User Roles

  • Adding a Control Center User

  • Modifying a Control Center User

Set up policy management

Ensure that biometric authentication is enforced when using the HYPR mobile app.

The following steps demonstrate how this is enforced on the HYPR server for the native management settings:

  1. Log in to the HYPR Control Center .

  2. From the HYPR Control Center, select the application that you will be using to target Bravura OneAuth in Bravura Security Fabric .

  3. Click on Policy Management for the HYPR application.

  4. Ensure that Native Management is set to On.

  5. Ensure that the listed native authenticators for iOS and Android are also set to On .

There is also a Policy Management section on this page that allows you to set policies for using the mobile app native authentication and for PINs for 6-digit codes for use with the authentication and registration of the HYPR app.

For example, you can set policies for the following for the native authentication and PIN management:

  • completeMediumTransaction

  • defaultRegAction

  • defaultAuthAction

Use these policies to set single or multiple authenticators to match your policy requirements. The following is an example:

  • completeMediumTransaction

    • (1) **** PIN

  • defaultRegAction

    • (1) NATIVE + **** PIN

  • defaultAuthAction

    • (1) NATIVE

    • (2) **** PIN

Install the mobile app and register users

Ensure that the HYPR mobile app has been installed on a user’s mobile device from the mobile device’s app store.

The following steps demonstrate how to register a user for Bravura OneAuth authentication:

  1. Log in to the HYPR Control Center .

  2. From the menu panel on the left, click Choose an App.

  3. Select Bravura OneAuth .

  4. Under ADVANCED CONFIG, click Magic Links.

  5. Enter the Username (email address) of the person for whom you want to generate a magic link.

    The Token Validity Time In Seconds and Domain Prefix will be filled in for you.

  6. Click Create Magic Link.

    A "LINK CREATED" pop-up appears.

  7. Under Web Link, click the Copy icon that follows the URL.

    This will copy the magic link to your clipboard.

  8. Paste and send the URL to the user via email or other method such as a Bravura Safe Share.

    Tip

    Do not send the magic link URL via chat, as the one-use link will be consumed and expire prematurely.

  9. On the "LINK CREATED" pop-up, click Close.

Once the new user successfully pairs their mobile device using the magic link, they will be able to use Bravura OneAuth as a second factor (along with their master password) to authenticate to Bravura Security Fabric .

If a magic link expires, repeat the steps above to generate another magic link for the same user.

As the user, open the URL then click on the device that you want to pair (for example, smartphone) .

Targeting the system for Bravura OneAuth

For each HYPR system, add a target system in Bravura Security Fabric (Manage the System > Resources > Target systems):

  • Type is Bravura OneAuth

  • Address uses options described in the table below:

Options marked with a redstar.png are required.

Option

Description

Script file: redstar.png

The hard-coded script file that is used by the Bravura OneAuth connector (agthypr.con).

(key: script)

Server: redstar.png

The domain name URL for the HYPR instance.

(key: server)

HTTP Network Proxy:

Specifies a network proxy URL to use for connecting.

(key: proxy)

Application ID: redstar.png

The application ID within the HYPR instance that will be used to target.

(key: appId)

The full list of target parameters is explained in Target system options .

List groups is not supported for the Bravura OneAuth connector; ensure that it is unchecked.

Setting the administrator credentials

Set the administrator ID to any value since it is not used.

Set the administrator password to the token value from the API Access Token that was previously configured for the HYPR Application that will be used for the Bravura OneAuth target in Bravura Security Fabric , as outlined above in the section to set up a target administrator.

Adding Bravura OneAuth authentication to Bravura Security Fabric

Configure a custom authentication chain for Bravura OneAuth

You can integrate Bravura OneAuth authentication in Bravura Security Fabric by configuring a custom authentication chain, using the agent.pss authentication module with the Bravura OneAuth connector agthypr , to perform a challenge response operation.

The following steps demonstrate how to integrate Bravura OneAuth in Bravura Security Fabric :

  1. Add the Bravura OneAuth target system.

  2. Add a new custom authentication chain:

    1. Add the Connector package agent (agent.pss) module to the chain.

    2. In the module’s settings:

      • Set Target system to use for address and credentials to the target you created.

      • Set Password verification operation to ”Challenge response authentication”.

    3. Enable the custom authentication chain.

  3. Add the new custom authentication chain to the DEFAULT_LOGIN chain:

    1. Click Policies > Authentication chains > Front-end login .

    2. Disable the chain so that you can edit it.

    3. Edit the select_chain module to add the new custom authentication chain to the list of Available chains .

    4. Update and enable the DEFAULT_LOGIN chain.

Test challenge response authentication with Bravura OneAuth

The following steps demonstrate how to authenticate with Bravura OneAuth in Bravura Security Fabric :

  1. Test the authentication by logging in as an end user associated with the target system.

    You will be notified that an authentication request will be sent to the HYPR app on the user’s registered device,

  2. Click Continue.

    A Bravura OneAuth push notification for the authentication request will appear on the HYPR app for "Login" or "Deny" to approve or deny the request.

  3. Tap Login to approve the authentication request.

    The app will indicate that login is successful.

  4. Access is then granted on Bravura Security Fabric .

Handling account attributes

You can view the complete list of attributes that Bravura Security Fabric can manage, including native and pseudo-attributes, using the Manage the system (PSA) module. To do this, select Bravura OneAuth from the Manage the system > Resources > Account attributes > Target system type menu.

For information about the native HYPR attributes managed by Bravura Security Fabric , consult HYPR documentation.

Bravura OneAuth user experience

The following topics show you how to install the HYPR app that powers Bravura OneAuth, pair your phone to Bravura OneAuth during login, and manage paired devices.

The HYPR oneauth_hypr_app_icon mobile app allows you to securely authenticate to Bravura Security Fabric from anywhere.

  1. Download and install the HYPR mobile app by using one of the following links:

    • The HYPR app for Android is available for download from Google Play.

    • The HYPR app for Apple iOS is available for download from the App Store.

  2. Follow the instructions on your mobile device to set up biometric authentication (Touch ID or Face ID).

After you have installed the HYPR app on your device and set up biometric authentication (Touch ID or Face ID) you can pair your phone to Bravura OneAuth during Bravura Security Fabric login.

  1. Go to the Bravura Security Fabric login page in your browser. See Front-end login.

  2. Log in.

    Bravura OneAuth automatically detects if you do not yet have a mobile device registered for authentication.

    safe_login_oneauth3_no_device_found
    1. Click or tap Send registration email.

  3. On your mobile device:

    1. Open the Bravura Security Fabric " Bravura OneAuth device registration" email.

    2. Tap Register Device.

      safe_login_oneauth_mobile3_get_started
    3. Tap Get Started.

      A Bravura OneAuth web account is created using your email address, and your mobile device begins pairing:

      safe_login_oneauth_mobile4_pairing

      A prompt appears for biometric authentication:

      safe_login_oneauth_mobile5_touch_id

      Note

      In this example, the user has configured Touch ID. You may also use Face ID.

    4. Authenticate to Bravura OneAuth using your mobile device's configured biometric method.

      You may be prompted with PIN enrollment.

      hypr_app_pin H 800
    5. Enter and confirm a 6-digit PIN.

      Pairing continues.

      safe_login_oneauth_mobile4_pairing
      safe_login_oneauth_mobile6_successfully_paired

      After successful biometric authentication, your device is successfully paired to your Bravura OneAuth web account.

    6. Tap OK.

      Bravura OneAuth displays your application web account.

      safe_login_oneauth_mobile7_account
    7. Tap the account row to view details; for example, the associated email address.

      Note

      You may register/pair multiple devices to your Bravura OneAuth web account via the Bravura OneAuth Device Manager.

You may now log in to Bravura Security Fabric using Bravura OneAuth and/or other authentication methods if configured by your product administrator.

After you have installed the HYPR app on your device and set up biometric authentication (Touch ID or Face ID) you can pair your phone to Bravura OneAuth via a magic link on your web browser. A magic link is usually sent by email from your product administrator.

  1. On your computer:

    1. Open your email to locate the message containing the magic link (URL) that was sent to you by your Bravura OneAuth administrator.

    2. Click the link.

    3. Bravura OneAuth Device Manager opens.

      oneauth_pair_what_device H 500
    4. Under "What device would you like to pair?" click Smartphone.

      A QR code and instructions are displayed.

      oneauth_pair_scan_qr H 500
  2. On your phone:

    1. Open the HYPR oneauth_hypr_app_icon app.

      hypr_app_taptoscan H 500
    2. Tap the scan icon located at the top right.

    3. Aim your phone's camera at the QR code on the computer screen.

      Your phone will begin pairing to Bravura OneAuth and then prompt for biometric authentication.

      Note

      In this example, the user has configured Touch ID. You may also use Face ID.

      hypr_app_touchid H 500
    4. Authenticate to the HYPR app using a biometric authentication method configured for your device (Touch ID, Face ID).

      You may be prompted with PIN enrollment.

      hypr_app_pin H 800
    5. The HYPR app will indicate that your phone has been successfully paired to your Bravura OneAuth account.

    6. Tap OK.

      The HYPR app shows the paired application account. If your phone is paired to more than one Bravura OneAuth account, they will all be listed here.

      hypr_app_account H 500
    7. Click on an account to view details (such as your Username/email address).

      Tip

      You can delete an account from this screen.

      hypr_app_account_open H 500
  3. On your computer:

    1. The Bravura OneAuth Device Manager will display your paired device.

      oneauth_pair_my_devices H 500

      Tip

      From this page, you can Add Another Device to your Bravura OneAuth account, or Unpair an existing device.

    2. Click Logout to log out from Bravura OneAuth Device Manager and then close the browser tab.

      oneauth_pair_logged_out H 500

Once you have successfully paired your phone to your Bravura OneAuth account using the magic link, you will be able to use Bravura OneAuth as a second factor to authenticate to Bravura Security Fabric.

These instructions assume that Bravura OneAuth has been enabled for your enterprise and the following steps have been completed:

On your computer or mobile device

The steps that you take to identify yourself and authenticate and then carry out tasks can vary according to how your organization customizes the interface between Bravura Security Fabric , the corporate intranet, and other applications.

In general, the front-end login process works as follows:

  1. Go to the URL for the Bravura Security Fabric Log in page in your browser.

    login
  2. At the login page, type your:

    • Login ID on a system on which you have an account (for example, your Windows user name)

      or

    • Profile ID (this is your unique ID in Bravura Security Fabric )

    Depending on the configuration, you might be able to select a system from a drop-down list.

  3. Click Continue.

  4. Authenticate to Bravura Security Fabric .

    Depending on configuration and your access privileges, Bravura Security Fabric may display a list of authentication methods to choose from, or direct you to a particular method.

    Fabric-authentication-options127
  5. Click the Bravura OneAuth option.

    Fabric-authentication-request-hypr
  6. Click Continue.

    The authentication request is sent to the HYPR app on your registered device.

    If you have not yet paired your mobile device, see Pair your device to Bravura OneAuth during Bravura Security Fabric web login.

On your phone

hypr_app_taptoauth H 500
  1. Tap the HYPR authentication notification; HYPR Tap to Authenticate.

    If the notification appears on your phone's lock screen, open the HYPR app and unlock your phone to proceed.

    hypr_app_login H 500
  2. Tap Login.

    To cancel, tap Deny.

    You are prompted for biometric authentication (Touch ID or Face ID).

    hypr_app_touchid H 500
  3. Authenticate to the HYPR app using a configured biometric method for your device.

    hypr_app_login_success H 500

After successful multi-factor authentication including Bravura OneAuth, you are logged in to Bravura Security Fabric on your computer.

This topic shows you how to replace a device paired with Bravura OneAuth, either as a planned replacement or after an unplanned loss of the old device.

If you want to replace a mobile device and still have access to the old one, follow these steps.

  1. Transfer all data from your old device to your new device. The exact procedure will vary depending on the operating system.

  2. Install the HYPR app on your new mobile device.

  3. Set up biometric authentication (e.g. Touch ID, Face ID) on your new device.

    This is typically done in device settings. Instructions vary by operating system.

  4. If you have been using an authenticator app (e.g., Google Authenticator, Microsoft Authenticator, etc.) for two-step login (2FA), check that TOTP codes were automatically transferred to the new device.Generate TOTP Codes

    If the codes were not automatically transferred to the new device, manually transfer/export authenticator accounts from your old phone to your new phone. Instructions vary based on the authenticator app(s) you are using. Perform this task for each authenticator, as required.

  5. Access the Bravura OneAuth Device Manager to de-register your old device and register your new device:

    You may register/pair multiple devices to your Bravura OneAuth web account.

    See Manage registered (paired) Bravura OneAuth devices.

If you want to replace a mobile device and do not have access to the old one, follow these steps.

  1. Install the HYPR app on your new mobile device.

  2. Set up biometric authentication (e.g. Touch ID, Face ID) on your new device.

    This is typically done in device settings. Instructions vary by operating system.

  3. If you were using an authenticator app(s) for two-step login (2FA) on your old device; for example, Google Authenticator, Microsoft Authenticator, etc.:

    • Install the desired authenticator app(s) on your new device.

    • Set up authenticator accounts/ TOTP codes again for use in 2FA.Generate TOTP Codes

  4. Log into Bravura Safe using another two-step login method.

    Warning

    If do not have an EMAIL option and any previously used AUTHENTICATOR APP accounts/TOTP codes were not successfully transferred from your OLD device to your NEW device, you will not be able to log in to Bravura Security Fabric . Please contact Bravura Security Support. A manual change to the Bravura Security Fabric database is required to restore Email PIN as an available two-step login (2FA) method, after which you can select EMAIL.

  5. Access the Bravura OneAuth Device Manager to de-register your old device and register your new device:

    You may register/pair multiple devices to your Bravura OneAuth web account.

    See Manage registered (paired) Bravura OneAuth devices.

This topic shows you how to manage mobile devices that are registered/paired to your Bravura OneAuth account.

Access Bravura OneAuth Device Manager

Access the Bravura OneAuth Device Manager. If you have access to Bravura Safe, use the following procedure. If you do not have access to this feature, contact your product administrator to send you a magic link to register a device.

To access Bravura OneAuth Device Manager from Bravura Safe:

  1. Log in to the Bravura Safe web interface.

  2. Click Teams.

  3. Select the Enterprise Team from the Team drop-down (i.e., your main/global company team).

  4. Click the Options tab.

    safe_options_my_team
  5. Click Open Bravura OneAuth device manager.

    A confirmation message appears.

    safe_options_open_device_manager
  6. Click Yes.

    The Bravura OneAuth Device Manager opens in a new browser tab showing all devices currently paired to your Bravura OneAuth account.

safe_options_device_manager

From here you can De-register/unpair a device and Register a new device.

De-register/unpair a device

To de-register/unpair a device:

  1. Click Remove beneath the desired device.

    A confirmation message appears.

  2. Click Remove.

    The selected device is de-registered/unpaired from your Bravura OneAuth account, removed from your Device Manager Login Methods list and removed from MY WEB ACCOUNTS in the Bravura OneAuth app on your mobile device.

    If the removed registered device was your only one, the Device Manager UI displays "No Login Methods Found":

    safe_options_device_manager_login_methods_none
Register a new device

This procedure assumes you have installed the HYPR app on your new mobile device.

  1. From the Bravura OneAuth Device Manager, click Add New Login Method.

    A pop-up appears:

    safe_options_device_manager_add_new_login_method

    Tip

    To see a walk-through of all steps included here, click Walk me through how to add a login method.

  2. To proceed with adding a new login method, click HYPR Mobile App.

    A QR code appears:

    safe_options_device_manager_add_new_login_method2
  3. Follow on-screen instructions to pair your device.

    Note

    If you are having an issue scanning the QR code, click Pair Manually and follow the on-screen instructions:

    safe_options_device_manager_add_new_manual

    Once your mobile device is successfully paired to your Bravura OneAuth Device Manager displays the "Login Method Added Successfully!" message.

    safe_options_device_manager_add_new_login_method3

Once pairing is successful, your new device will appear listed under Login Methods. You may now use this device for passwordless authentication to Bravura Safe using Bravura OneAuth.