{
    "componentChunkName": "component---src-pages-blog-markdown-remark-fields-slug-js",
    "path": "/blog/step-up-auth",
    "result": {"data":{"markdownRemark":{"html":"<p>Applying the same level of security to all user actions often creates an imbalance between usability and risk, either overwhelming users with unnecessary authentication steps or exposing sensitive operations to potential threats.</p>\n<p><strong>Step-up authentication</strong> provides a solution by dynamically enforcing stronger verification only when certain risk thresholds are met ensuring that routine tasks remain frictionless while critical actions receive the heightened protection they demand. Solutions such as\n<a href=\"https://supertokens.com/\" target=\"_blank\" rel=\"nofollow\">SuperTokens</a> streamline this approach by allowing developers to store custom session claims, validate assurance levels via middleware, and orchestrate multiple verification flows in a unified framework.</p>\n<h2 id=\"what-is-step-up-authentication\" style=\"position:relative;\"><a href=\"#what-is-step-up-authentication\" aria-label=\"what is step up authentication permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>What Is Step-Up Authentication?</strong></h2>\n<h3 id=\"definition\" style=\"position:relative;\"><a href=\"#definition\" aria-label=\"definition permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Definition</strong></h3>\n<p>At its core, step-up authentication is a security mechanism that triggers additional user verification based on the context or risk level of a particular action. It acknowledges that not all activities within an application carry the same level of risk, and therefore shouldn’t require the same level of authentication assurance.</p>\n<h3 id=\"purpose\" style=\"position:relative;\"><a href=\"#purpose\" aria-label=\"purpose permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Purpose</strong></h3>\n<p>The primary purpose of step-up authentication is to add stronger verification methods for sensitive operations, while maintaining a smooth user experience for routine activities. This approach is particularly valuable for:</p>\n<ul>\n<li>\n<p>Financial applications that process money transfers.</p>\n</li>\n<li>\n<p>Healthcare platforms with protected patient information.</p>\n</li>\n<li>\n<p>Administrative dashboards with system-wide controls.</p>\n</li>\n<li>\n<p>Account management systems where personal data can be changed.</p>\n</li>\n</ul>\n<h3 id=\"real-world-examples\" style=\"position:relative;\"><a href=\"#real-world-examples\" aria-label=\"real world examples permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Real-World Examples</strong></h3>\n<p><span\n      class=\"gatsby-resp-image-wrapper\"\n      style=\"position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 630px; \"\n    >\n      <a\n    class=\"gatsby-resp-image-link\"\n    href=\"/static/b9ee3be823ee6c567a42101cc1c7b24a/bb27a/Real-World-Examples.png\"\n    style=\"display: block\"\n    target=\"_blank\"\n    rel=\"noopener\"\n  >\n    <span\n    class=\"gatsby-resp-image-background-image\"\n    style=\"padding-bottom: 44.93670886075949%; position: relative; bottom: 0; left: 0; background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAJCAYAAAAywQxIAAAACXBIWXMAAAsTAAALEwEAmpwYAAABm0lEQVQoz2WR646bMBCFydXGEHy3CaSwEHa1UlW1atX3f7Mz1XiVKFJ/HAnGZz7NzKl2ux2x9vt90eFwKDoej7TbVVRV/+t4PDx9j74Hp3oFMeR0Oj01jiPd73fato2WZaF1XWmaJjqfz08P97zCq9eJ2MBmIQRJKckYQ977p0IIZK0tb+xh7yuQVXFBNTWM1fDRUoietOlgnYEPlmLycN5+1byBj45yH0lr/tfIY6A8RmjTFXh1Pp/QXlqKKWBaRgzDgJBcAc/bDcv7TMPtipg93eYrvd1vmNcJIXni2vr5DevHhHxNxKxKCIG6Voijofe/PYXgyQUHYzS2Pz1NHz1iTOS8Qxo8bb+vNEy5eBrVYvkVafrkiQ2EFFRJKUjWNbRvMWwOxhpywaLrOgx3j+scwLdjAK+8/MxcI+ssb4b5h8f0PdClu0BKiUoKQapRqJWCqht0uivT8A2NtrDWIqZIKUUwRGuLr7Ace6FUA9WwFBUgr6yUorZt+dCcLB6JppQo50x9zuj7vnynnCjGWDycuNa69CqlwMn/A4Lm0ug9nYyOAAAAAElFTkSuQmCC'); background-size: cover; display: block;\"\n  ></span>\n  <img\n        class=\"gatsby-resp-image-image\"\n        alt=\"Real-World Examples\"\n        title=\"Real-World Examples\"\n        src=\"/static/b9ee3be823ee6c567a42101cc1c7b24a/f058b/Real-World-Examples.png\"\n        srcset=\"/static/b9ee3be823ee6c567a42101cc1c7b24a/c26ae/Real-World-Examples.png 158w,\n/static/b9ee3be823ee6c567a42101cc1c7b24a/6bdcf/Real-World-Examples.png 315w,\n/static/b9ee3be823ee6c567a42101cc1c7b24a/f058b/Real-World-Examples.png 630w,\n/static/b9ee3be823ee6c567a42101cc1c7b24a/40601/Real-World-Examples.png 945w,\n/static/b9ee3be823ee6c567a42101cc1c7b24a/78612/Real-World-Examples.png 1260w,\n/static/b9ee3be823ee6c567a42101cc1c7b24a/bb27a/Real-World-Examples.png 1371w\"\n        sizes=\"(max-width: 630px) 100vw, 630px\"\n        style=\"width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;\"\n        loading=\"lazy\"\n        decoding=\"async\"\n      />\n  </a>\n    </span></p>\n<p>Step-up authentication is already part of many digital experiences you encounter daily:</p>\n<ul>\n<li>\n<p>Banking apps that require fingerprint verification before completing a wire transfer, even if you’re already logged in.</p>\n</li>\n<li>\n<p>E-commerce platforms that ask you to re-enter your password or credit card CVV before finalizing a purchase.</p>\n</li>\n<li>\n<p>Cloud services that send a one-time password (OTP) when you attempt to change account recovery information.</p>\n</li>\n</ul>\n<p>These extra verification steps create a security barrier around your most sensitive actions, so even if someone hijacks your session, they’re blocked from sensitive actions unless they can pass the extra security checks.</p>\n<h2 id=\"why-use-step-up-authentication\" style=\"position:relative;\"><a href=\"#why-use-step-up-authentication\" aria-label=\"why use step up authentication permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Why Use Step-Up Authentication?</strong></h2>\n<p>In a world of increasing cyber threats, implementing step-up authentication offers significant advantages for both security posture and user satisfaction.</p>\n<h3 id=\"reduces-risk-for-sensitive-actions\" style=\"position:relative;\"><a href=\"#reduces-risk-for-sensitive-actions\" aria-label=\"reduces risk for sensitive actions permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Reduces Risk for Sensitive Actions</strong></h3>\n<p>Not all user sessions require the highest level of identity assurance, but certain actions definitely do. Step-up authentication allows you to implement a tiered security approach where:</p>\n<ul>\n<li>\n<p>Regular browsing or viewing activities can proceed with standard login credentials.</p>\n</li>\n<li>\n<p>Medium-risk actions might require password re-entry.</p>\n</li>\n<li>\n<p>High-risk operations demand multi-factor authentication.</p>\n</li>\n</ul>\n<p>This targeted approach means your most vulnerable operations receive appropriate protection, without overburdening the entire user experience.</p>\n<h3 id=\"improves-ux-compared-to-always-high-assurance\" style=\"position:relative;\"><a href=\"#improves-ux-compared-to-always-high-assurance\" aria-label=\"improves ux compared to always high assurance permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Improves UX Compared to Always High Assurance</strong></h3>\n<p>From a user perspective, constantly authenticating with multiple factors creates unnecessary friction. When users encounter security measures that seem disproportionate to the task they’re performing, they often:</p>\n<ul>\n<li>\n<p>Become frustrated with the application.</p>\n</li>\n<li>\n<p>Look for shortcuts or workarounds.</p>\n</li>\n<li>\n<p>Develop negative attitudes toward security practices in general.</p>\n</li>\n</ul>\n<p>Step-up authentication introduces friction only when justified, thus preserving a smooth experience for most interactions while still protecting what matters most.</p>\n<h3 id=\"compliance-and-regulatory-requirements\" style=\"position:relative;\"><a href=\"#compliance-and-regulatory-requirements\" aria-label=\"compliance and regulatory requirements permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Compliance and Regulatory Requirements</strong></h3>\n<p>Many regulatory frameworks explicitly require elevated authentication for sensitive operations:</p>\n<ul>\n<li>\n<p><a href=\"https://www.pcisecuritystandards.org/\" target=\"_blank\" rel=\"nofollow\">PCI DSS</a> (Payment Card Industry Data Security Standard) requires additional authentication for accessing cardholder data or making significant changes to payment systems.</p>\n</li>\n<li>\n<p><a href=\"https://www.ecb.europa.eu/press/intro/mip-online/2018/html/1803_revisedpsd.en.html\" target=\"_blank\" rel=\"nofollow\">PSD2</a> (Payment Services Directive 2) in Europe mandates strong customer authentication for financial transactions.</p>\n</li>\n<li>\n<p><a href=\"https://www.cdc.gov/phlp/php/resources/health-insurance-portability-and-accountability-act-of-1996-hipaa.html#:~:text=At%20a%20glance,from%20disclosure%20without%20patient&#x27;s%20consent.\" target=\"_blank\" rel=\"nofollow\">HIPAA</a> (Health Insurance Portability and Accountability Act) requires appropriate safeguards for accessing protected health information.</p>\n</li>\n<li>\n<p><a href=\"https://gdpr-info.eu/\" target=\"_blank\" rel=\"nofollow\">GDPR</a> (General Data Protection Regulation) mandates appropriate technical measures to protect personal data.</p>\n</li>\n</ul>\n<p>Step-up authentication not only assists organizations in meeting these compliance obligations, but it also addresses real financial risks.\nAccording to a recent <a href=\"https://www.ibm.com/reports/data-breach\" target=\"_blank\" rel=\"nofollow\">IBM report on data breaches</a>, organizations without elevated authentication controls experienced breach costs up to 42% higher than companies who implement robust security. By implementing step-up authentication, companies can strengthen their security posture effectively, without imposing maximum security measures on every interaction.</p>\n<h2 id=\"how-step-up-authentication-works\" style=\"position:relative;\"><a href=\"#how-step-up-authentication-works\" aria-label=\"how step up authentication works permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>How Step-Up Authentication Works</strong></h2>\n<p><span\n      class=\"gatsby-resp-image-wrapper\"\n      style=\"position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 630px; \"\n    >\n      <a\n    class=\"gatsby-resp-image-link\"\n    href=\"/static/338793e87432cfda107e85d6f4eb7727/96e92/How-Step-Up-Authentication-Works.png\"\n    style=\"display: block\"\n    target=\"_blank\"\n    rel=\"noopener\"\n  >\n    <span\n    class=\"gatsby-resp-image-background-image\"\n    style=\"padding-bottom: 39.87341772151899%; position: relative; bottom: 0; left: 0; background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAICAYAAAD5nd/tAAAACXBIWXMAAAsTAAALEwEAmpwYAAABcklEQVQoz22Q247bIBRFDxcbsDE2jO0kTiJ1JjNT5a19qtT//669K9NpG7V92MCBw2IJEasprqHqHfXYUT8NNOtIe8xsTpntVujPhWEr6E6Z4TCiWwbENSEtA1PpMU6BY3IcY0MRrSjWUJyl6lqq6KlSoJ566vyRqYeeOro54fL+jE/3V5RtQRMdXXRwXUvnLZ0zFFHCCq3RlMZQ7cahpYSWzdCxKwNCHmhjgB8j4pRgOw9p7C4DZTWU0VQ7Q0QgIswl4+XzFWUu2OHKmjo/LQu+fX/jl683hhgpWurFEHs+3058eT1xylNlfKQO8N4xl0QffK2ruZL68nqcMZURohRFKRitoI3mvGRs5wPsbvpTDL8Np9njdt+wXHtMZ8fx4pAujvHS4nI/4Phe0J0t47VFurZ1vb6VemZ79cvwD3AYepy2FUMKMK2idRq6VXR9i+U4o8wJxqk91E7Reo2yZsxrhm3Mv8AH5cf67/3Hv/pv/w9t1rBxGcLifwAAAABJRU5ErkJggg=='); background-size: cover; display: block;\"\n  ></span>\n  <img\n        class=\"gatsby-resp-image-image\"\n        alt=\"How Step Up Authentication Works\"\n        title=\"How Step Up Authentication Works\"\n        src=\"/static/338793e87432cfda107e85d6f4eb7727/f058b/How-Step-Up-Authentication-Works.png\"\n        srcset=\"/static/338793e87432cfda107e85d6f4eb7727/c26ae/How-Step-Up-Authentication-Works.png 158w,\n/static/338793e87432cfda107e85d6f4eb7727/6bdcf/How-Step-Up-Authentication-Works.png 315w,\n/static/338793e87432cfda107e85d6f4eb7727/f058b/How-Step-Up-Authentication-Works.png 630w,\n/static/338793e87432cfda107e85d6f4eb7727/96e92/How-Step-Up-Authentication-Works.png 779w\"\n        sizes=\"(max-width: 630px) 100vw, 630px\"\n        style=\"width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;\"\n        loading=\"lazy\"\n        decoding=\"async\"\n      />\n  </a>\n    </span></p>\n<p>A typical step-up authentication flow follows these key stages:</p>\n<h3 id=\"initial-authentication-with-low-assurance\" style=\"position:relative;\"><a href=\"#initial-authentication-with-low-assurance\" aria-label=\"initial authentication with low assurance permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Initial Authentication with Low Assurance</strong></h3>\n<p>The user journey begins with standard authentication—often just a username and password, or perhaps a passwordless method such as magic links via email or social logins. This provides basic identity verification sufficient for general application access.</p>\n<h3 id=\"context-triggers-a-risk-check\" style=\"position:relative;\"><a href=\"#context-triggers-a-risk-check\" aria-label=\"context triggers a risk check permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Context Triggers a Risk Check</strong></h3>\n<p>As the user navigates the application, certain actions or requests trigger a risk evaluation. This evaluation might consider:</p>\n<ul>\n<li>\n<p>The sensitivity of the requested resource.</p>\n</li>\n<li>\n<p>The user’s role and permissions.</p>\n</li>\n<li>\n<p>Location and device information.</p>\n</li>\n<li>\n<p>Behavioral patterns or anomalies.</p>\n</li>\n<li>\n<p>Previous authentication methods used.</p>\n</li>\n</ul>\n<h3 id=\"step-up-flow-is-initiated\" style=\"position:relative;\"><a href=\"#step-up-flow-is-initiated\" aria-label=\"step up flow is initiated permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Step-Up Flow Is Initiated</strong></h3>\n<p>When the system determines that the current authentication level isn’t sufficient for the requested action, it initiates a step-up flow. This typically means:</p>\n<ol>\n<li>\n<p>The user’s current action is paused.</p>\n</li>\n<li>\n<p>A verification prompt appears (modal, redirect, or new screen).</p>\n</li>\n<li>\n<p>The user is asked to provide additional verification.</p>\n</li>\n<li>\n<p>The system validates the new authentication factor.</p>\n</li>\n</ol>\n<p>Common step-up methods include:</p>\n<ul>\n<li>\n<p>One-time passwords (via SMS, email, or authenticator apps)</p>\n</li>\n<li>\n<p>Biometric verification (fingerprint, face ID)</p>\n</li>\n<li>\n<p>Hardware security keys</p>\n</li>\n<li>\n<p>Knowledge-based answers to security questions</p>\n</li>\n<li>\n<p><a href=\"https://webauthn.io/\" target=\"_blank\" rel=\"nofollow\">WebAuthn</a>/FIDO2 credentials</p>\n</li>\n</ul>\n<h3 id=\"on-success-sensitive-action-proceeds\" style=\"position:relative;\"><a href=\"#on-success-sensitive-action-proceeds\" aria-label=\"on success sensitive action proceeds permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>On Success, Sensitive Action Proceeds</strong></h3>\n<p>Once the user successfully completes the additional verification, several things happen:</p>\n<ol>\n<li>\n<p>Their session is updated to reflect the higher assurance level.</p>\n</li>\n<li>\n<p>The originally requested action is allowed to proceed.</p>\n</li>\n<li>\n<p>The elevated session assurance may persist for a limited time.</p>\n</li>\n<li>\n<p>The system logs the successful step-up event for audit purposes.</p>\n</li>\n</ol>\n<p>This elevated assurance level might be temporary—perhaps lasting 15 minutes or until the user closes their browser—after which any further sensitive actions would require repeating the step-up process.</p>\n<h2 id=\"common-step-up-triggers\" style=\"position:relative;\"><a href=\"#common-step-up-triggers\" aria-label=\"common step up triggers permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Common Step-Up Triggers</strong></h2>\n<p>While each application has unique security requirements, certain actions commonly trigger step-up authentication:</p>\n<h3 id=\"high-privilege-resource-access\" style=\"position:relative;\"><a href=\"#high-privilege-resource-access\" aria-label=\"high privilege resource access permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>High-Privilege Resource Access</strong></h3>\n<p>When users attempt to access highly sensitive information such as:</p>\n<ul>\n<li>\n<p>Financial statements or transaction histories</p>\n</li>\n<li>\n<p>Personal health records</p>\n</li>\n<li>\n<p>Customer lists or proprietary business data</p>\n</li>\n<li>\n<p>Security settings or private keys</p>\n</li>\n</ul>\n<h3 id=\"administrative-actions\" style=\"position:relative;\"><a href=\"#administrative-actions\" aria-label=\"administrative actions permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Administrative Actions</strong></h3>\n<p>System-wide changes that could affect multiple users or core functionality:</p>\n<ul>\n<li>\n<p>Adding or removing user accounts</p>\n</li>\n<li>\n<p>Changing system configurations</p>\n</li>\n<li>\n<p>Updating security policies</p>\n</li>\n<li>\n<p>Modifying global settings or preferences</p>\n</li>\n</ul>\n<h3 id=\"financial-transactions\" style=\"position:relative;\"><a href=\"#financial-transactions\" aria-label=\"financial transactions permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Financial Transactions</strong></h3>\n<p>Money transfers always warrant extra security:</p>\n<ul>\n<li>\n<p>Transferring funds between accounts</p>\n</li>\n<li>\n<p>Making payments to new recipients</p>\n</li>\n<li>\n<p>Changing payment methods or banking information</p>\n</li>\n<li>\n<p>Withdrawing funds above a certain threshold</p>\n</li>\n</ul>\n<h3 id=\"authentication-from-new-devicesips\" style=\"position:relative;\"><a href=\"#authentication-from-new-devicesips\" aria-label=\"authentication from new devicesips permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Authentication from New Devices/IPs</strong></h3>\n<p>Environmental changes that might indicate account takeover:</p>\n<ul>\n<li>\n<p>Login from a previously unused device</p>\n</li>\n<li>\n<p>Access attempts from unusual geographic locations</p>\n</li>\n<li>\n<p>Connection through unfamiliar networks or proxies</p>\n</li>\n</ul>\n<h3 id=\"elevated-api-scopes\" style=\"position:relative;\"><a href=\"#elevated-api-scopes\" aria-label=\"elevated api scopes permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Elevated API Scopes</strong></h3>\n<p>For developer-focused applications or when automating sensitive operations:</p>\n<ul>\n<li>\n<p>Transitioning from read-only to write permissions</p>\n</li>\n<li>\n<p>Accessing admin-level API endpoints</p>\n</li>\n<li>\n<p>Performing batch operations affecting multiple accounts</p>\n</li>\n<li>\n<p>Requesting extended token lifetimes or permissions</p>\n</li>\n</ul>\n<h2 id=\"implementing-step-up-authentication--best-practices\" style=\"position:relative;\"><a href=\"#implementing-step-up-authentication--best-practices\" aria-label=\"implementing step up authentication  best practices permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Implementing Step-Up Authentication—Best Practices</strong></h2>\n<p>Implementing effective step-up authentication requires thoughtful planning and a systematic approach:</p>\n<h3 id=\"define-risky-actions-and-routes\" style=\"position:relative;\"><a href=\"#define-risky-actions-and-routes\" aria-label=\"define risky actions and routes permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Define Risky Actions and Routes</strong></h3>\n<p>First, analyze your application to identify operations that warrant additional security. Consider both:</p>\n<ul>\n<li>\n<p><strong>Business risk</strong>: Operations with financial implications, data exposure potential, or compliance requirements.</p>\n</li>\n<li>\n<p><strong>Technical risk</strong>: Actions that could compromise system integrity or security.</p>\n</li>\n</ul>\n<p>Create a comprehensive inventory of these sensitive routes, endpoints, or actions, and then categorize them by risk level. This mapping will form the foundation of your step-up strategy.</p>\n<h3 id=\"design-authentication-assurance-levels\" style=\"position:relative;\"><a href=\"#design-authentication-assurance-levels\" aria-label=\"design authentication assurance levels permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Design Authentication Assurance Levels</strong></h3>\n<p><span\n      class=\"gatsby-resp-image-wrapper\"\n      style=\"position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 630px; \"\n    >\n      <a\n    class=\"gatsby-resp-image-link\"\n    href=\"/static/1293798810618001decde27e96a0aa03/96e92/Auth-Assurance-Levels.png\"\n    style=\"display: block\"\n    target=\"_blank\"\n    rel=\"noopener\"\n  >\n    <span\n    class=\"gatsby-resp-image-background-image\"\n    style=\"padding-bottom: 74.0506329113924%; position: relative; bottom: 0; left: 0; background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAPCAYAAADkmO9VAAAACXBIWXMAAAsTAAALEwEAmpwYAAAB+UlEQVQ4y41Sy27bQAzcl7R6rrS2JL+qqG4ODVDH5yCHomkPNtCkH+D//w5OwU1kJG4c9zAwMTMckVwLYRSEjSBzC1VlUNMSuqtgFh7xcgK7mlCymiBdTpAtPeULj2Jeo+wcyqaAm+ao6hSVs6iLCEIoCWE0hDWQaQxZJJAuhXApZJWRrDOoOiftc9J1Bl2lZFyKmFEmsIWFzWLYxMBaDSGkQAjVCiLSELGBTCKk3lHeeCpaDz9vyXeeysajbGrKvSOdxlDWQMUGKtJQRkFpCSGEQMAYrCRUZLAarmi4/kLzfoXvP3/Qw68HWvQrrK/X1A896Tg6+oWUz/3PWcfiCKU1+qsem9sNfb25wW6/p9+Pj6H+druh4fMAzWd6p1ecIVGWJdq2pa7r0HUdzbou1Mw55+hc3z+BSqkQluc5ZVlGSZLAe0/N1FOapmCONfbwJhcDoyjCYrFgUNM02Gw2dDgc6OnpD223W2rbNmjsieP4cqAxBrPZjBGah2Gg+/t7uru7o/V6HTjW5vN5+PjFQCklrLUjiKcY1xy5UWfvh4E8XVEUHBBuyOAb9n1Pn1bLUI88e9jLPWcDeYW6rlFVVfjlx+CH2O12tNvtQ83ca887a7+d0DkXXvkFxPfkCRl8N+ZGnb0fTjje8AT0SqNT/b//2CegF1z0/gX6F06ld0tk4AAAAABJRU5ErkJggg=='); background-size: cover; display: block;\"\n  ></span>\n  <img\n        class=\"gatsby-resp-image-image\"\n        alt=\"Auth Assurance Levels\"\n        title=\"Auth Assurance Levels\"\n        src=\"/static/1293798810618001decde27e96a0aa03/f058b/Auth-Assurance-Levels.png\"\n        srcset=\"/static/1293798810618001decde27e96a0aa03/c26ae/Auth-Assurance-Levels.png 158w,\n/static/1293798810618001decde27e96a0aa03/6bdcf/Auth-Assurance-Levels.png 315w,\n/static/1293798810618001decde27e96a0aa03/f058b/Auth-Assurance-Levels.png 630w,\n/static/1293798810618001decde27e96a0aa03/96e92/Auth-Assurance-Levels.png 779w\"\n        sizes=\"(max-width: 630px) 100vw, 630px\"\n        style=\"width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;\"\n        loading=\"lazy\"\n        decoding=\"async\"\n      />\n  </a>\n    </span></p>\n<p>Next, establish a clear framework of authentication assurance levels that align with your application’s risk profile. A simple approach\nmight include:</p>\n<ul>\n<li>\n<p><strong>Level 1</strong>: Basic authentication (password, social login).</p>\n</li>\n<li>\n<p><strong>Level 2</strong>: Level 1 + additional factor (OTP, biometric).</p>\n</li>\n<li>\n<p><strong>Level 3</strong>: Level 2 + hardware key or advanced verification.</p>\n</li>\n</ul>\n<p>Each level should clearly define what authentication methods satisfy its requirements, and which application areas or actions require that level.</p>\n<h3 id=\"store-authentication-context-in-session\" style=\"position:relative;\"><a href=\"#store-authentication-context-in-session\" aria-label=\"store authentication context in session permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Store Authentication Context in Session</strong></h3>\n<p>Your authentication system needs to track which assurance level a user has achieved during their current session. This typically involves:</p>\n<ul>\n<li>\n<p>Including assurance-level claims in <a href=\"https://jwt.io/introduction/\" target=\"_blank\" rel=\"nofollow\">JWT access tokens</a>.</p>\n</li>\n<li>\n<p>Storing authentication context in server-side session data.</p>\n</li>\n<li>\n<p>Maintaining cryptographically signed records of completed verifications.</p>\n</li>\n</ul>\n<p>This session context should be tamper-proof and designed to expire appropriately, based on security requirements.</p>\n<h3 id=\"add-conditional-checks-to-critical-routes\" style=\"position:relative;\"><a href=\"#add-conditional-checks-to-critical-routes\" aria-label=\"add conditional checks to critical routes permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Add Conditional Checks to Critical Routes</strong></h3>\n<p>Protect your sensitive routes by implementing middleware or guards that verify sufficient authentication before allowing access:</p>\n<div\n              class=\"gatsby-code-button-container\"\n              data-toaster-id=\"77357162546693470000\"\n              data-toaster-class=\"gatsby-code-button-toaster\"\n              data-toaster-text-class=\"gatsby-code-button-toaster-text\"\n              data-toaster-text=\"Copied!\"\n              data-toaster-duration=\"3500\"\n              onClick=\"copyToClipboard(`// Example Express.js middleware checking auth level*\n\nfunction requireAuthLevel(requiredLevel) {\n\nreturn function(req, res, next) {\n\nconst currentAuthLevel = req.session.authLevel || 1;\n\nif (currentAuthLevel >= requiredLevel) {\n\n// User has sufficient authentication*\n\nnext();\n\n} else {\n\n// Redirect to step-up flow*\n\nres.redirect(\\`/auth/step-up?required=\\${requiredLevel}&returnTo=\\${req.originalUrl}\\`);\n\n}\n\n}\n\n}\n\n// Apply to sensitive routes*\n\napp.post('/admin/users', requireAuthLevel(3),\nadminController.createUser);\n\napp.put('/api/payment-methods', requireAuthLevel(2),\npaymentController.update);`, `77357162546693470000`)\"\n            >\n              <div\n                class=\"gatsby-code-button\"\n                data-tooltip=\"\"\n              >\n                <svg class=\"gatsby-code-button-icon\" xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\"><path fill=\"none\" d=\"M0 0h24v24H0V0z\"/><path d=\"M16 1H2v16h2V3h12V1zm-1 4l6 6v12H6V5h9zm-1 7h5.5L14 6.5V12z\"/></svg>\n              </div>\n            </div>\n<div class=\"gatsby-highlight\" data-language=\"js\"><pre class=\"language-js\"><code class=\"language-js\"><span class=\"token comment\">// Example Express.js middleware checking auth level*</span>\n\n<span class=\"token keyword\">function</span> <span class=\"token function\">requireAuthLevel</span><span class=\"token punctuation\">(</span><span class=\"token parameter\">requiredLevel</span><span class=\"token punctuation\">)</span> <span class=\"token punctuation\">{</span>\n\n<span class=\"token keyword\">return</span> <span class=\"token keyword\">function</span><span class=\"token punctuation\">(</span><span class=\"token parameter\">req<span class=\"token punctuation\">,</span> res<span class=\"token punctuation\">,</span> next</span><span class=\"token punctuation\">)</span> <span class=\"token punctuation\">{</span>\n\n<span class=\"token keyword\">const</span> currentAuthLevel <span class=\"token operator\">=</span> req<span class=\"token punctuation\">.</span>session<span class=\"token punctuation\">.</span>authLevel <span class=\"token operator\">||</span> <span class=\"token number\">1</span><span class=\"token punctuation\">;</span>\n\n<span class=\"token keyword\">if</span> <span class=\"token punctuation\">(</span>currentAuthLevel <span class=\"token operator\">>=</span> requiredLevel<span class=\"token punctuation\">)</span> <span class=\"token punctuation\">{</span>\n\n<span class=\"token comment\">// User has sufficient authentication*</span>\n\n<span class=\"token function\">next</span><span class=\"token punctuation\">(</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span>\n\n<span class=\"token punctuation\">}</span> <span class=\"token keyword\">else</span> <span class=\"token punctuation\">{</span>\n\n<span class=\"token comment\">// Redirect to step-up flow*</span>\n\nres<span class=\"token punctuation\">.</span><span class=\"token function\">redirect</span><span class=\"token punctuation\">(</span><span class=\"token template-string\"><span class=\"token template-punctuation string\">`</span><span class=\"token string\">/auth/step-up?required=</span><span class=\"token interpolation\"><span class=\"token interpolation-punctuation punctuation\">${</span>requiredLevel<span class=\"token interpolation-punctuation punctuation\">}</span></span><span class=\"token string\">&amp;returnTo=</span><span class=\"token interpolation\"><span class=\"token interpolation-punctuation punctuation\">${</span>req<span class=\"token punctuation\">.</span>originalUrl<span class=\"token interpolation-punctuation punctuation\">}</span></span><span class=\"token template-punctuation string\">`</span></span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span>\n\n<span class=\"token punctuation\">}</span>\n\n<span class=\"token punctuation\">}</span>\n\n<span class=\"token punctuation\">}</span>\n\n<span class=\"token comment\">// Apply to sensitive routes*</span>\n\napp<span class=\"token punctuation\">.</span><span class=\"token function\">post</span><span class=\"token punctuation\">(</span><span class=\"token string\">'/admin/users'</span><span class=\"token punctuation\">,</span> <span class=\"token function\">requireAuthLevel</span><span class=\"token punctuation\">(</span><span class=\"token number\">3</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">,</span>\nadminController<span class=\"token punctuation\">.</span>createUser<span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span>\n\napp<span class=\"token punctuation\">.</span><span class=\"token function\">put</span><span class=\"token punctuation\">(</span><span class=\"token string\">'/api/payment-methods'</span><span class=\"token punctuation\">,</span> <span class=\"token function\">requireAuthLevel</span><span class=\"token punctuation\">(</span><span class=\"token number\">2</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">,</span>\npaymentController<span class=\"token punctuation\">.</span>update<span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span></code></pre></div>\n<p>This approach ensures that users can’t bypass authentication requirements, even through direct API calls.</p>\n<h3 id=\"implement-step-up-prompt-flow\" style=\"position:relative;\"><a href=\"#implement-step-up-prompt-flow\" aria-label=\"implement step up prompt flow permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Implement Step-Up Prompt Flow</strong></h3>\n<p>Create a seamless experience for when users need to elevate their authentication level:</p>\n<ol>\n<li>\n<p>Design clear, informative prompts explaining why additional verification is needed.</p>\n</li>\n<li>\n<p>Offer appropriate authentication methods based on the user’s available options.</p>\n</li>\n<li>\n<p>Handle errors gracefully with specific feedback.</p>\n</li>\n<li>\n<p>Provide fallback options if the preferred method fails.</p>\n</li>\n<li>\n<p>Consider accessibility needs for all authentication methods.</p>\n</li>\n</ol>\n<p>The step-up process should feel like a natural extension of the user flow rather than an abrupt interruption.</p>\n<h3 id=\"update-session-or-token-on-success\" style=\"position:relative;\"><a href=\"#update-session-or-token-on-success\" aria-label=\"update session or token on success permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Update Session or Token on Success</strong></h3>\n<p>After successful step-up authentication, securely update the user’s session to reflect their new assurance level:</p>\n<div\n              class=\"gatsby-code-button-container\"\n              data-toaster-id=\"95761023678247240000\"\n              data-toaster-class=\"gatsby-code-button-toaster\"\n              data-toaster-text-class=\"gatsby-code-button-toaster-text\"\n              data-toaster-text=\"Copied!\"\n              data-toaster-duration=\"3500\"\n              onClick=\"copyToClipboard(`// Example session update after successful step-up\nfunction completeStepUp(req, res, authLevel) {\n\n// Update session with new auth level\n\nreq.session.authLevel = authLevel;\n\nreq.session.stepUpTimestamp = Date.now();\n\n// For JWT-based auth, you might issue a new token\n\nconst newToken = generateTokenWithClaims({\n\n...userClaims,\n\nauth_level: authLevel,\n\nstep_up_time: Date.now()\n\n});\n\n// Redirect back to original requested route\n\nres.redirect(req.query.returnTo || '/dashboard');\n\n}`, `95761023678247240000`)\"\n            >\n              <div\n                class=\"gatsby-code-button\"\n                data-tooltip=\"\"\n              >\n                <svg class=\"gatsby-code-button-icon\" xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\"><path fill=\"none\" d=\"M0 0h24v24H0V0z\"/><path d=\"M16 1H2v16h2V3h12V1zm-1 4l6 6v12H6V5h9zm-1 7h5.5L14 6.5V12z\"/></svg>\n              </div>\n            </div>\n<div class=\"gatsby-highlight\" data-language=\"js\"><pre class=\"language-js\"><code class=\"language-js\"><span class=\"token comment\">// Example session update after successful step-up</span>\n<span class=\"token keyword\">function</span> <span class=\"token function\">completeStepUp</span><span class=\"token punctuation\">(</span><span class=\"token parameter\">req<span class=\"token punctuation\">,</span> res<span class=\"token punctuation\">,</span> authLevel</span><span class=\"token punctuation\">)</span> <span class=\"token punctuation\">{</span>\n\n<span class=\"token comment\">// Update session with new auth level</span>\n\nreq<span class=\"token punctuation\">.</span>session<span class=\"token punctuation\">.</span>authLevel <span class=\"token operator\">=</span> authLevel<span class=\"token punctuation\">;</span>\n\nreq<span class=\"token punctuation\">.</span>session<span class=\"token punctuation\">.</span>stepUpTimestamp <span class=\"token operator\">=</span> Date<span class=\"token punctuation\">.</span><span class=\"token function\">now</span><span class=\"token punctuation\">(</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span>\n\n<span class=\"token comment\">// For JWT-based auth, you might issue a new token</span>\n\n<span class=\"token keyword\">const</span> newToken <span class=\"token operator\">=</span> <span class=\"token function\">generateTokenWithClaims</span><span class=\"token punctuation\">(</span><span class=\"token punctuation\">{</span>\n\n<span class=\"token operator\">...</span>userClaims<span class=\"token punctuation\">,</span>\n\n<span class=\"token literal-property property\">auth_level</span><span class=\"token operator\">:</span> authLevel<span class=\"token punctuation\">,</span>\n\n<span class=\"token literal-property property\">step_up_time</span><span class=\"token operator\">:</span> Date<span class=\"token punctuation\">.</span><span class=\"token function\">now</span><span class=\"token punctuation\">(</span><span class=\"token punctuation\">)</span>\n\n<span class=\"token punctuation\">}</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span>\n\n<span class=\"token comment\">// Redirect back to original requested route</span>\n\nres<span class=\"token punctuation\">.</span><span class=\"token function\">redirect</span><span class=\"token punctuation\">(</span>req<span class=\"token punctuation\">.</span>query<span class=\"token punctuation\">.</span>returnTo <span class=\"token operator\">||</span> <span class=\"token string\">'/dashboard'</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span>\n\n<span class=\"token punctuation\">}</span></code></pre></div>\n<p>Consider implementing appropriate timeouts for elevated privileges—perhaps allowing the higher assurance level to persist for\n15-30 minutes before requiring re-verification.</p>\n<h2 id=\"how-supertokens-supports-step-up-authentication\" style=\"position:relative;\"><a href=\"#how-supertokens-supports-step-up-authentication\" aria-label=\"how supertokens supports step up authentication permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>How SuperTokens Supports Step-Up Authentication</strong></h2>\n<p><span\n      class=\"gatsby-resp-image-wrapper\"\n      style=\"position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 630px; \"\n    >\n      <a\n    class=\"gatsby-resp-image-link\"\n    href=\"/static/04ed09bafa0c4b8349eb1a3a678d9afb/7ebf9/Supertokens.png\"\n    style=\"display: block\"\n    target=\"_blank\"\n    rel=\"noopener\"\n  >\n    <span\n    class=\"gatsby-resp-image-background-image\"\n    style=\"padding-bottom: 50.632911392405056%; position: relative; bottom: 0; left: 0; background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAKCAYAAAC0VX7mAAAACXBIWXMAAA7DAAAOwwHHb6hkAAACP0lEQVQozx3R227bRhRGYRa1LJ6HM5whh8OjKcqhLUeQ7ToJgrYIolh2DCQBmt7mkfzMK5Au9t3Guvg/r7aG69Gx3VxxPc/0bUvX9XT9SDOsqboJ3axQticvG0rbYEuHLSuMMQgh2G63vL6+stvt8KSUGK05hletYx575mlk6EemNzf0l28Zh4mLacPlekNftdRK41SOTgVJlLD0Q/7484zF+RJPZoKqyOnrkqlzrPuasXWMw8BfDx+42T2wubrhbvfA/faW+/mKtTH0Sp2iKtNEqSYUGj9K8USaUGpFXWqaUnPRWKah42p+w38//+fw9MI//+55fnzm++GZb58+8W41clmW1HmBUpZI1fiyZhkrvDSOyKXAqIxSS1pnedx/5uXrC7d393zeP/J0eOZp/4UfhwM/v+z59f0bTx//plIWpTtCPbDUFywSgyfiCJnGSJGQywytJLmSOOeo65q6drSuYt04rpuKt03FXBb0ucHqBmEGlvlI4mYS0+AVIkKnESIOSZMYkaYnOaMkRS6pTE5daNrjzkVOm2e0KsNKjVIVcd5xlrW49T3d6gbvQic0KkbGAXEYEh4visj8BYUUDLWjd5ZVW9O7isw/R4dLZJqdMHxhOUstRbPGVj3epkqZTIJJA9LQx/d9wiBAxAGlCOhNzHa0XHc5vQ6xIkDGPlEYnVSPEIsgIRt2yGGHd1sL5jLBihARHYNLAt8niwMqFTJVCbuVYTsoVjamkiFZ7J9+ln6AH8acny8Qwx1ifM9vqdoHJdKZY1wAAAAASUVORK5CYII='); background-size: cover; display: block;\"\n  ></span>\n  <img\n        class=\"gatsby-resp-image-image\"\n        alt=\"Supertokens\"\n        title=\"Supertokens\"\n        src=\"/static/04ed09bafa0c4b8349eb1a3a678d9afb/f058b/Supertokens.png\"\n        srcset=\"/static/04ed09bafa0c4b8349eb1a3a678d9afb/c26ae/Supertokens.png 158w,\n/static/04ed09bafa0c4b8349eb1a3a678d9afb/6bdcf/Supertokens.png 315w,\n/static/04ed09bafa0c4b8349eb1a3a678d9afb/f058b/Supertokens.png 630w,\n/static/04ed09bafa0c4b8349eb1a3a678d9afb/40601/Supertokens.png 945w,\n/static/04ed09bafa0c4b8349eb1a3a678d9afb/78612/Supertokens.png 1260w,\n/static/04ed09bafa0c4b8349eb1a3a678d9afb/7ebf9/Supertokens.png 1919w\"\n        sizes=\"(max-width: 630px) 100vw, 630px\"\n        style=\"width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;\"\n        loading=\"lazy\"\n        decoding=\"async\"\n      />\n  </a>\n    </span></p>\n<p>Supertokens provides a flexible authentication framework that makes implementing step-up authentication straightforward.</p>\n<h3 id=\"session-context-control\" style=\"position:relative;\"><a href=\"#session-context-control\" aria-label=\"session context control permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Session Context Control</strong></h3>\n<p>SuperTokens’ session management allows custom session claims to be stored, making it easy to track authentication assurance levels:</p>\n<div\n              class=\"gatsby-code-button-container\"\n              data-toaster-id=\"12347771818371078000\"\n              data-toaster-class=\"gatsby-code-button-toaster\"\n              data-toaster-text-class=\"gatsby-code-button-toaster-text\"\n              data-toaster-text=\"Copied!\"\n              data-toaster-duration=\"3500\"\n              onClick=\"copyToClipboard(`// Store auth level in session after step-up\n\nawait Session.updateSessionData(sessionHandle, {\n\nauthLevel: 2,\n\nstepUpCompletedAt: Date.now()\n\n});\n`, `12347771818371078000`)\"\n            >\n              <div\n                class=\"gatsby-code-button\"\n                data-tooltip=\"\"\n              >\n                <svg class=\"gatsby-code-button-icon\" xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\"><path fill=\"none\" d=\"M0 0h24v24H0V0z\"/><path d=\"M16 1H2v16h2V3h12V1zm-1 4l6 6v12H6V5h9zm-1 7h5.5L14 6.5V12z\"/></svg>\n              </div>\n            </div>\n<div class=\"gatsby-highlight\" data-language=\"js\"><pre class=\"language-js\"><code class=\"language-js\"><span class=\"token comment\">// Store auth level in session after step-up</span>\n\n<span class=\"token keyword\">await</span> Session<span class=\"token punctuation\">.</span><span class=\"token function\">updateSessionData</span><span class=\"token punctuation\">(</span>sessionHandle<span class=\"token punctuation\">,</span> <span class=\"token punctuation\">{</span>\n\n<span class=\"token literal-property property\">authLevel</span><span class=\"token operator\">:</span> <span class=\"token number\">2</span><span class=\"token punctuation\">,</span>\n\n<span class=\"token literal-property property\">stepUpCompletedAt</span><span class=\"token operator\">:</span> Date<span class=\"token punctuation\">.</span><span class=\"token function\">now</span><span class=\"token punctuation\">(</span><span class=\"token punctuation\">)</span>\n\n<span class=\"token punctuation\">}</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span>\n</code></pre></div>\n<p>These session claims can then be accessed during subsequent requests to determine if the user has sufficient privileges.</p>\n<h3 id=\"custom-claims-validation\" style=\"position:relative;\"><a href=\"#custom-claims-validation\" aria-label=\"custom claims validation permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Custom Claims Validation</strong></h3>\n<p>SuperTokens middleware can be extended to check authentication levels before allowing access to protected routes:</p>\n<div\n              class=\"gatsby-code-button-container\"\n              data-toaster-id=\"9828996079203844000\"\n              data-toaster-class=\"gatsby-code-button-toaster\"\n              data-toaster-text-class=\"gatsby-code-button-toaster-text\"\n              data-toaster-text=\"Copied!\"\n              data-toaster-duration=\"3500\"\n              onClick=\"copyToClipboard(`\nfunction verifyAuthLevel(requiredLevel) {\n\nreturn async (req, res, next) => {\n\nlet session = req.session;\n\nlet currentLevel = session.getSessionData()?.authLevel || 1;\n\nif (currentLevel >= requiredLevel) {\n\nnext();\n\n} else {\n\nres.redirect(\\`/step-up?level=\\${requiredLevel}&redirect=\\${req.originalUrl}\\`);\n\n}\n\n};\n\n}\n\n// Apply to routes needing elevated auth\n\napp.post(&quot;/api/payment/transfer&quot;, verifyAuthLevel(2), transferFunds);`, `9828996079203844000`)\"\n            >\n              <div\n                class=\"gatsby-code-button\"\n                data-tooltip=\"\"\n              >\n                <svg class=\"gatsby-code-button-icon\" xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\"><path fill=\"none\" d=\"M0 0h24v24H0V0z\"/><path d=\"M16 1H2v16h2V3h12V1zm-1 4l6 6v12H6V5h9zm-1 7h5.5L14 6.5V12z\"/></svg>\n              </div>\n            </div>\n<div class=\"gatsby-highlight\" data-language=\"js// middleware to verify sufficient auth level\"><pre class=\"language-js// middleware to verify sufficient auth level\"><code class=\"language-js// middleware to verify sufficient auth level\">\nfunction verifyAuthLevel(requiredLevel) {\n\nreturn async (req, res, next) =&gt; {\n\nlet session = req.session;\n\nlet currentLevel = session.getSessionData()?.authLevel || 1;\n\nif (currentLevel &gt;= requiredLevel) {\n\nnext();\n\n} else {\n\nres.redirect(`/step-up?level=${requiredLevel}&amp;redirect=${req.originalUrl}`);\n\n}\n\n};\n\n}\n\n// Apply to routes needing elevated auth\n\napp.post(&quot;/api/payment/transfer&quot;, verifyAuthLevel(2), transferFunds);</code></pre></div>\n<h3 id=\"multiple-authentication-flows\" style=\"position:relative;\"><a href=\"#multiple-authentication-flows\" aria-label=\"multiple authentication flows permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Multiple Authentication Flows</strong></h3>\n<p>SuperTokens supports various authentication methods, which can be combined to create flexible step-up flows:</p>\n<ul>\n<li>\n<p>Password authentication</p>\n</li>\n<li>\n<p>One-time passwords via SMS or email</p>\n</li>\n<li>\n<p>Magic links</p>\n</li>\n<li>\n<p>OAuth/social logins</p>\n</li>\n<li>\n<p>Custom authentication providers</p>\n</li>\n</ul>\n<p>This variety allows implementing the right authentication factor for each security context.</p>\n<h3 id=\"granular-session-control\" style=\"position:relative;\"><a href=\"#granular-session-control\" aria-label=\"granular session control permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Granular Session Control</strong></h3>\n<p>SuperTokens provides fine-grained control over session management, enabling implementations to:</p>\n<ul>\n<li>\n<p>Create new sessions with elevated privileges.</p>\n</li>\n<li>\n<p>Update existing sessions with additional claims.</p>\n</li>\n<li>\n<p>Set appropriate timeouts for elevated access.</p>\n</li>\n<li>\n<p>Revoke sessions when suspicious activity is detected.</p>\n</li>\n</ul>\n<p>For full implementation details, refer to the <a href=\"https://supertokens.com/docs/additional-verification/mfa/step-up-auth\" target=\"_blank\" rel=\"nofollow\">SuperTokens Step-Up Authentication Example</a> in their documentation.</p>\n<h2 id=\"technical-design-patterns-for-step-up-authentication\" style=\"position:relative;\"><a href=\"#technical-design-patterns-for-step-up-authentication\" aria-label=\"technical design patterns for step up authentication permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Technical Design Patterns for Step-Up Authentication</strong></h2>\n<p>When architecting a step-up authentication system, several design patterns have proven effective:</p>\n<h3 id=\"token-based-sessions\" style=\"position:relative;\"><a href=\"#token-based-sessions\" aria-label=\"token based sessions permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Token-Based Sessions</strong></h3>\n<p>JSON Web Tokens (JWT) or similar token-based authentication mechanisms work well for step-up authentication because:</p>\n<ul>\n<li>\n<p>They can include claims about authentication level and methods.</p>\n</li>\n<li>\n<p>They’re cryptographically signed to prevent tampering.</p>\n</li>\n<li>\n<p>They can be verified without database lookups.</p>\n</li>\n<li>\n<p>They can include expiration times for elevated privileges.</p>\n</li>\n</ul>\n<p>A typical implementation might include claims such as:</p>\n<div\n              class=\"gatsby-code-button-container\"\n              data-toaster-id=\"97255432526601100000\"\n              data-toaster-class=\"gatsby-code-button-toaster\"\n              data-toaster-text-class=\"gatsby-code-button-toaster-text\"\n              data-toaster-text=\"Copied!\"\n              data-toaster-duration=\"3500\"\n              onClick=\"copyToClipboard(`{\n\n&quot;sub&quot;: &quot;user123&quot;,\n\n&quot;iat&quot;: 1617293982,\n\n&quot;exp&quot;: 1617297582,\n\n&quot;auth_level&quot;: 2,\n\n&quot;auth_methods&quot;: [&quot;password&quot;, &quot;otp&quot;],\n\n&quot;step_up_exp&quot;: 1617295782\n\n}`, `97255432526601100000`)\"\n            >\n              <div\n                class=\"gatsby-code-button\"\n                data-tooltip=\"\"\n              >\n                <svg class=\"gatsby-code-button-icon\" xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\"><path fill=\"none\" d=\"M0 0h24v24H0V0z\"/><path d=\"M16 1H2v16h2V3h12V1zm-1 4l6 6v12H6V5h9zm-1 7h5.5L14 6.5V12z\"/></svg>\n              </div>\n            </div>\n<div class=\"gatsby-highlight\" data-language=\"json\"><pre class=\"language-json\"><code class=\"language-json\"><span class=\"token punctuation\">{</span>\n\n<span class=\"token property\">\"sub\"</span><span class=\"token operator\">:</span> <span class=\"token string\">\"user123\"</span><span class=\"token punctuation\">,</span>\n\n<span class=\"token property\">\"iat\"</span><span class=\"token operator\">:</span> <span class=\"token number\">1617293982</span><span class=\"token punctuation\">,</span>\n\n<span class=\"token property\">\"exp\"</span><span class=\"token operator\">:</span> <span class=\"token number\">1617297582</span><span class=\"token punctuation\">,</span>\n\n<span class=\"token property\">\"auth_level\"</span><span class=\"token operator\">:</span> <span class=\"token number\">2</span><span class=\"token punctuation\">,</span>\n\n<span class=\"token property\">\"auth_methods\"</span><span class=\"token operator\">:</span> <span class=\"token punctuation\">[</span><span class=\"token string\">\"password\"</span><span class=\"token punctuation\">,</span> <span class=\"token string\">\"otp\"</span><span class=\"token punctuation\">]</span><span class=\"token punctuation\">,</span>\n\n<span class=\"token property\">\"step_up_exp\"</span><span class=\"token operator\">:</span> <span class=\"token number\">1617295782</span>\n\n<span class=\"token punctuation\">}</span></code></pre></div>\n<p>Note how the step_up_exp (step-up expiration) is earlier than the overall token expiration, allowing the elevated privileges to time out\nbefore the entire session.</p>\n<h3 id=\"session-cookie-updates\" style=\"position:relative;\"><a href=\"#session-cookie-updates\" aria-label=\"session cookie updates permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Session Cookie Updates</strong></h3>\n<p>For traditional cookie-based sessions, implement step-up by:</p>\n<ol>\n<li>\n<p>Storing authentication levels in server-side session data.</p>\n</li>\n<li>\n<p>Updating this data after successful additional verification.</p>\n</li>\n<li>\n<p>Setting appropriate timeouts for elevated privileges.</p>\n</li>\n<li>\n<p>Optionally rotating session IDs after significant privilege changes.</p>\n</li>\n</ol>\n<p>Ensure the session data is protected against tampering and that cookies have appropriate security flags (HttpOnly, SameSite, Secure).</p>\n<h3 id=\"frontend-ux-strategy\" style=\"position:relative;\"><a href=\"#frontend-ux-strategy\" aria-label=\"frontend ux strategy permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Frontend UX Strategy</strong></h3>\n<p>The user experience of step-up authentication is crucial for adoption:</p>\n<ol>\n<li>\n<p><strong>Anticipate needs</strong>: If possible, prompt for step-up authentication before the user reaches a protected action.</p>\n</li>\n<li>\n<p><strong>Clear communication</strong>: Explain why additional verification is needed.</p>\n</li>\n<li>\n<p><strong>Seamless flows</strong>: Use modal dialogs rather than full page redirects, when possible.</p>\n</li>\n<li>\n<p><strong>Remember choices</strong>: Offer appropriate “remember this device” options for trusted environments.</p>\n</li>\n<li>\n<p><strong>Progressive disclosure</strong>: Only show authentication options the user has previously configured.</p>\n</li>\n</ol>\n<h3 id=\"granular-api-protection\" style=\"position:relative;\"><a href=\"#granular-api-protection\" aria-label=\"granular api protection permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Granular API Protection</strong></h3>\n<p>For applications with extensive APIs, protect sensitive endpoints\nthrough:</p>\n<ol>\n<li>\n<p><strong>API gateways</strong> that verify authentication levels before routing requests.</p>\n</li>\n<li>\n<p><strong>Middleware layers</strong> that check session claims against required assurance levels.</p>\n</li>\n<li>\n<p><strong>Scope-based authorization</strong> where elevated scopes require step-up authentication.</p>\n</li>\n<li>\n<p><strong>Audit logging</strong> of all sensitive operations and authentication events.</p>\n</li>\n</ol>\n<h2 id=\"step-up-authentication-vs-mfa\" style=\"position:relative;\"><a href=\"#step-up-authentication-vs-mfa\" aria-label=\"step up authentication vs mfa permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Step-Up Authentication vs MFA</strong></h2>\n<p>There’s often confusion between step-up authentication and multi-factor authentication (MFA). While related, they serve different purposes:</p>\n<h3 id=\"mfa--authentication-at-login\" style=\"position:relative;\"><a href=\"#mfa--authentication-at-login\" aria-label=\"mfa  authentication at login permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>MFA = Authentication at Login</strong></h3>\n<p>Multi-factor authentication occurs during the initial login process:</p>\n<ul>\n<li>\n<p>Typically enforced for all users when they first authenticate.</p>\n</li>\n<li>\n<p>Usually combines something you know (password) with something you have (device, token), or something you are (biometric).</p>\n</li>\n<li>\n<p>Applied universally, regardless of what actions the user intends to perform.</p>\n</li>\n<li>\n<p>Establishes a baseline level of identity assurance for the entire session.</p>\n</li>\n</ul>\n<h3 id=\"step-up--conditional-second-authentication\" style=\"position:relative;\"><a href=\"#step-up--conditional-second-authentication\" aria-label=\"step up  conditional second authentication permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Step-Up = Conditional Second Authentication</strong></h3>\n<p>Step-up authentication is contextual and triggered by specific actions:</p>\n<ul>\n<li>\n<p>Only enforced when attempting sensitive operations.</p>\n</li>\n<li>\n<p>May use additional factors beyond those used during initial log in.</p>\n</li>\n<li>\n<p>Applied selectively, based on risk assessment.</p>\n</li>\n<li>\n<p>Can establish different levels of assurance for different operations.</p>\n</li>\n</ul>\n<h3 id=\"can-be-used-together\" style=\"position:relative;\"><a href=\"#can-be-used-together\" aria-label=\"can be used together permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Can Be Used Together</strong></h3>\n<p>These approaches complement each other in a comprehensive security strategy:</p>\n<ol>\n<li>\n<p><strong>Base MFA at login</strong> establishes initial identity assurance.</p>\n</li>\n<li>\n<p><strong>Step-up for sensitive actions</strong> adds contextual security.</p>\n</li>\n<li>\n<p><strong>Risk-based authentication</strong> can determine when to enforce each.</p>\n</li>\n</ol>\n<p>This layered approach creates defense-in-depth while minimizing unnecessary friction.</p>\n<h2 id=\"challenges-and-mitigations\" style=\"position:relative;\"><a href=\"#challenges-and-mitigations\" aria-label=\"challenges and mitigations permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Challenges and Mitigations</strong></h2>\n<p>Implementing step-up authentication introduces certain challenges that require careful consideration:</p>\n<h3 id=\"ux-friction\" style=\"position:relative;\"><a href=\"#ux-friction\" aria-label=\"ux friction permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>UX Friction</strong></h3>\n<p><strong>Challenge</strong>: Additional authentication steps interrupt user flow and can cause frustration.</p>\n<p><strong>Solution</strong>:</p>\n<ul>\n<li>\n<p>Only trigger step-up authentication when genuinely necessary.</p>\n</li>\n<li>\n<p>Clearly explain why additional verification is needed.</p>\n</li>\n<li>\n<p>Remember step-up status for a reasonable period (e.g., 15-30 minutes).</p>\n</li>\n<li>\n<p>Offer biometric options when available, for faster verification.</p>\n</li>\n<li>\n<p>Use contextual triggers that anticipate user needs.</p>\n</li>\n</ul>\n<h3 id=\"token-misuse-or-replay\" style=\"position:relative;\"><a href=\"#token-misuse-or-replay\" aria-label=\"token misuse or replay permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Token Misuse or Replay</strong></h3>\n<p><strong>Challenge</strong>: Elevated session tokens might be vulnerable to theft or replay attacks.</p>\n<p><strong>Solution</strong>:</p>\n<ul>\n<li>\n<p>Use short-lived tokens for elevated sessions.</p>\n</li>\n<li>\n<p>Implement one-time-use authentication challenges.</p>\n</li>\n<li>\n<p>Bind tokens to device fingerprints when possible.</p>\n</li>\n<li>\n<p>Apply appropriate cookie security controls (HttpOnly, SameSite, Secure).</p>\n</li>\n<li>\n<p>Consider using secure enclaves or TPM for key storage.</p>\n</li>\n</ul>\n<h3 id=\"session-hijacking\" style=\"position:relative;\"><a href=\"#session-hijacking\" aria-label=\"session hijacking permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Session Hijacking</strong></h3>\n<p><strong>Challenge</strong>: Even with step-up authentication, compromised sessions remain a risk.</p>\n<p><strong>Solution</strong>:</p>\n<ul>\n<li>\n<p>Pair with device fingerprinting to detect anomalies.</p>\n</li>\n<li>\n<p>Implement location-based verification checks.</p>\n</li>\n<li>\n<p>Apply continuous authentication through behavioral biometrics.</p>\n</li>\n<li>\n<p>Set appropriate session timeouts.</p>\n</li>\n<li>\n<p>Log authentication events for anomaly detection.</p>\n</li>\n</ul>\n<h2 id=\"conclusion\" style=\"position:relative;\"><a href=\"#conclusion\" aria-label=\"conclusion permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Conclusion</strong></h2>\n<p>Step-up authentication represents an optimal balance between security and usability in modern application design. By applying  additional authentication measures only when justified by risk, applications can maintain strong security postures without creating unnecessary friction.</p>\n<p>Key takeaways include:</p>\n<ol>\n<li>\n<p><strong>Contextual security</strong> adapts to the sensitivity of actions being performed.</p>\n</li>\n<li>\n<p><strong>Improved user experience</strong> by removing universal high-friction authentication.</p>\n</li>\n<li>\n<p><strong>Regulatory compliance</strong> with frameworks requiring strong authentication for sensitive operations.</p>\n</li>\n<li>\n<p><strong>Defense-in-depth</strong> through layered authentication approaches.</p>\n</li>\n</ol>\n<p>As digital threats continue to evolve, step-up authentication provides a flexible framework that can incorporate new verification methods, while maintaining a focus on user experience.</p>\n<p>Tools such as SuperTokens make implementation straightforward with session claims, customizable flows, and multi-factor support, allowing\ndevelopers to focus on creating secure applications that users actually enjoy using.</p>\n<p>By thoughtfully implementing step-up authentication, organizations can protect what matters most while still delivering the seamless experiences users expect in today’s digital landscape.</p>","frontmatter":{"date":"April 30, 2025","title":"What Is Step-Up Authentication? A Guide for Secure Access","cover":"what-is-step-up-authentication.png","author":"Mostafa Ibrahim","description":"An in-depth guide to step-up authentication—when to use it and how to implement it to secure high-risk actions in your app."},"fields":{"slug":"/step-up-auth/"}},"site":{"siteMetadata":{"title":"SuperTokens Blog"}}},"pageContext":{"id":"82d08a58-3c26-58f3-ae08-4c8f792cfb04","fields__slug":"/step-up-auth/","__params":{"fields__slug":"step-up-auth"}}},
    "staticQueryHashes": []}