Skip to content
AuthMantraPraxis
authmantra.com ↗Start free trial

Lexicon

Identity terms, in plain English.

78 terms. 37 have a diagram. Every entry has its own link.

ABACAttribute-based access control

An access model that decides using attributes of the person, the resource and the context (for example department, data sensitivity, time of day) instead of only a fixed role. More flexible than RBAC, and harder to audit.

Why it matters Rules by attribute scale better than hundreds of roles, if you can still explain each decision.

RelatedRBAC

Access reviewRecertification

A periodic check where a named reviewer confirms that each person's access is still needed. The evidence, who reviewed what and when, matters as much as the decision.

Why it matters Auditors ask for proof that access was checked, not just granted.

RelatedLeast privilegeRBAC

Access review: list, decide, remove, keep evidenceListaccessReviewerdecidesRemoveextraKeepevidence

Access token

A credential an application presents to an API to show it may act for a user or itself. Keep it short-lived and treat it like a password while it is valid.

Why it matters It is the key to your API, so lifetime and storage matter most.

RelatedRefresh tokenOAuth 2.0JWT

Account recovery

The route back into an account when the usual factor is lost. It is the weakest link, so design it as carefully as sign-in.

Why it matters Attackers go for recovery when sign-in itself is strong.

RelatedPasskeyMFA

acrAuthentication Context Class Reference

An OpenID Connect claim that says how strongly a person authenticated, using values the relying party and provider agree on. An application can ask for a higher level when an action is sensitive.

Why it matters It lets an app demand a stronger sign-in only when the action needs it.

RelatedamrStep-up authenticationOIDC

acr says how strongly someone signed inhigherhigherPasswordonlyMFAPasskey

amrAuthentication Methods References

A claim listing the methods used during sign-in, such as password, one-time code or hardware key. Values are registered in RFC 8176.

Why it matters It records how someone really signed in, which helps investigation.

RelatedacrOIDC

API key

A static secret that identifies a caller to an API. Simple to use and easy to leak; scope it narrowly, rotate it and know who owns it.

Why it matters It never expires on its own, so rotation is your job.

RelatedService account

AssertionSAML assertion

A signed statement from the identity provider telling an application who the user is and, often, their attributes. It is the SAML counterpart of an ID token.

Why it matters It is the single signed message a SAML app trusts, so its signature check is critical.

RelatedSAML 2.0IdPID token

SAML assertion: signed statement about the usersignsIdPAssertionwho + attributesApp (SP)

aud (audience)

The claim that names which application a token is meant for. A relying party must reject tokens addressed to someone else.

Why it matters Skipping this check lets a token for one app work in another.

RelatedClaimJWT

Audit log

A time-ordered record of who did what, to which resource, from where and with what result. Useful only if it is complete, protected from edits and kept long enough.

Why it matters When something goes wrong, the log is the only honest witness.

RelatedSIEM

Audit log: who, did what, to what, when, from whereactoractiontargettime

AuthenticationAuthN

Proving that a person or system is who it claims to be. It answers 'who are you?', not 'what may you do?'.

Why it matters Everything else rests on getting this one question right.

RelatedAuthorization

AuthorizationAuthZ

Deciding what an authenticated identity is allowed to do. Done by roles, attributes or policies, and enforced by the application or an API gateway.

Why it matters Most real breaches are over-broad access, not broken sign-in.

RelatedAuthenticationRBAC

Authorization code flow

The OAuth 2.0 flow where the browser receives a one-time code and the application exchanges it for tokens over a back channel. With PKCE it is the recommended flow for web, mobile and single-page apps.

Why it matters It keeps tokens out of the browser address bar.

RelatedPKCEOAuth 2.0OIDC

Authorization code flowsign incodeexchangeBrowserProviderApp back endTokens

Bearer token

A token that works for whoever holds it, like cash. Send it only over HTTPS and keep its life short.

Why it matters Anyone who copies it can use it, so protect it like a password.

RelatedAccess token

Break-glass account

An emergency administrator account kept for the day normal sign-in fails. Store its credentials safely, protect it with a strong factor and alert whenever it is used.

Why it matters Without one, an outage can lock out every administrator.

RelatedLeast privilegeMFA

Challenge

A random value a server sends so a device can sign it. Because it is fresh each time, a recorded signature cannot be replayed.

Why it matters Freshness is what makes recorded signatures useless.

RelatedPasskeyWebAuthn

Claim

A statement about a subject inside a token, such as who they are (sub), who issued it (iss) or when it ends (exp).

Why it matters Claims are what the app actually reads and acts on.

RelatedJWTID token

Client credentials grant

An OAuth 2.0 grant where an application authenticates as itself, with no user present. Used for service-to-service calls.

Why it matters It is how back-end jobs get tokens without a person.

RelatedService accountOAuth 2.0

Credential stuffing

Trying passwords leaked from one site against many others, betting on reuse. Passkeys and one-time codes defeat it.

Why it matters Reused passwords turn one leak into many break-ins.

RelatedPhishingMFA

Data export

Giving a person a copy of the personal data you hold about them. AuthMantra includes data export to help answer such requests.

Why it matters A quick, complete export makes access requests manageable.

RelatedDPDP ActData Principal

Data Fiduciary

The DPDP Act 2023 term for the organisation that decides why and how personal data is processed. An employer is usually the Data Fiduciary for employee data.

Why it matters It names who carries the duties under the Act.

RelatedDPDP ActData Principal

Data Principal

The DPDP Act 2023 term for the individual whose personal data is processed. For workforce identity, that is the employee, contractor or applicant.

Why it matters It names whose rights you must be ready to honour.

RelatedDPDP ActData Fiduciary

Data residency

The requirement or choice to keep data in a specific country or region. AuthMantra data is hosted in the Mumbai region (asia-south1).

Why it matters Some policies and customers require records to stay in India.

RelatedDPDP Act

Data residency: records stay in the chosen regionPeoplein IndiaMumbai regionasia-south1Elsewhere

Directory

The list of people and groups an organisation keeps, with their attributes. It is often the source other systems copy from.

Why it matters The directory is usually the source of truth for who works here.

RelatedProvisioningFederation

DPDP ActDigital Personal Data Protection Act, 2023

India's law on the processing of digital personal data. It sets duties for Data Fiduciaries and rights for Data Principals. Check with your compliance counsel for how it applies to you.

Why it matters It sets duties for how you treat employee identity data; ask counsel how it applies.

RelatedData FiduciaryData PrincipalConsent

Entitlement

A specific permission or access right in an application, such as a licence, a role or a group membership.

Why it matters Review entitlements, not just accounts, to find excess access.

RelatedRBACAccess review

FederationIdentity federation

A trust arrangement where one identity provider's sign-in is accepted by other systems or organisations, using standards such as SAML or OpenID Connect.

Why it matters It lets partners sign in without you creating more accounts.

RelatedSSOIdP

Federation: one provider trusts another's sign-intrustPartnerproviderYourproviderYourapps

FIDO2

A set of specifications from the FIDO Alliance that lets websites use public-key credentials instead of passwords. It combines the W3C WebAuthn browser API with the CTAP protocol for authenticators.

Why it matters It is the standard behind passkeys, so it works across devices and browsers.

RelatedWebAuthnPasskey

FIDO2 = WebAuthn + CTAPWebAuthn(browser)FIDO2CTAP(device)

Grievance workflow

A route for people to raise concerns about their personal data, with an owner, a status and a response. AuthMantra includes a grievance workflow.

Why it matters A tracked route is easier to show than a shared mailbox.

RelatedDPDP ActData Principal

Hash

A fixed-size fingerprint of some data. Change one character of the input and the fingerprint changes completely. SHA-256 is a common one.

Why it matters It is the building block behind PKCE, signatures and tamper-evident logs.

RelatedHMACPKCE

HMACHash-based message authentication code

A fingerprint of a message made with a shared secret, so only holders of the secret can produce or check it. Used to sign webhooks.

Why it matters It proves a message is untouched and from a holder of the secret.

RelatedSigned webhookHash

ID token

A signed JWT issued in OpenID Connect that tells an application who just signed in, when and how. It is for the application; it is not an API credential.

Why it matters It tells the app who signed in; it is not for calling APIs.

RelatedOIDCJWTAccess token

ID token: who signed in, when, howProviderID tokensub, iat, acrApp

IdPIdentity provider

The system that authenticates users and vouches for them to other applications. AuthMantra acts as the identity provider for your workforce.

Why it matters One place to enforce sign-in rules for every app.

RelatedSPSSO

Identity provider vouches for people to appsprovesvouchesPersonIdPApps

iss (issuer)

The claim that names who issued a token. Compare it, exactly, with the issuer you trust before accepting the token.

Why it matters It stops a token from an untrusted source being accepted.

RelatedClaimJWKS

JIT provisioningJust-in-time provisioning

Creating a user account in an application the first time that person signs in through SSO. Simple, but it does not remove accounts when people leave, which is what SCIM is for.

Why it matters It saves setup, but it cannot remove accounts when someone leaves.

RelatedSCIMProvisioning

JIT provisioning: the account appears on first sign-increatesFirstsign-inIdentityproviderNew appaccount

JMLJoiner, mover, leaver

The three moments in an identity lifecycle: someone joins, changes role or team, or leaves. Most access problems come from doing the second and third by hand.

Why it matters Most access problems happen at one of these three moments.

RelatedProvisioningSCIM

Joiner, mover, leaverJoineraccess addedMoveraccess swappedLeaveraccess removed

JWKSJSON Web Key Set

A JSON document, defined with RFC 7517, that publishes the public keys an identity provider uses to sign tokens. Applications fetch it to verify signatures and cache it with a sensible expiry.

Why it matters It lets apps verify tokens and follow key rotation without manual copying.

RelatedJWTOIDC

JWKS: publish public keys, verify signaturespublishesfetchessigned tokenProvider(signs)/jwks.jsonpublic keysApp(verifies)

JWTJSON Web Token

A compact signed (and sometimes encrypted) token format defined in RFC 7519. Verify the signature, issuer, audience and expiry before trusting one.

Why it matters Readable by anyone, trustworthy only after the signature and claims check out.

RelatedJWKSID token

A JWT has three dot-separated partsheaderalg, kidpayloadclaimssignature..

Least privilege

Giving an identity only the access it needs for its task and nothing more. Applies to people, service accounts and API keys alike.

Why it matters Smaller access means a smaller blast radius when something goes wrong.

RelatedRBACAccess review

Least privilege: only what the task needsNeededaccessExcessaccesskeepremove

MFAMulti-factor authentication

Requiring two or more kinds of proof, such as something you know, something you have and something you are. Factors differ a lot in how well they resist phishing.

Why it matters A stolen password alone should not be enough.

RelatedTOTPPasskeyStep-up authentication

MFA: two different kinds of proof+Knowpassword/PINHavephone/keyAccess

nonce

A random value an application sends in an OpenID Connect request and checks in the returned ID token. It ties the token to the request and blocks replay.

Why it matters It ties an ID token to the request that asked for it.

RelatedOIDCID token

OAuth 2.0RFC 6749

A framework for letting an application get limited access to an API on a user's behalf, or its own. It is about delegated authorization; OpenID Connect adds sign-in on top.

Why it matters It is the base layer for delegated access and for OpenID Connect.

RelatedOIDCPKCEAccess token

OIDCOpenID Connect

An identity layer on top of OAuth 2.0 that gives applications a standard way to learn who signed in, using an ID token. Common for modern web and mobile applications.

Why it matters It is the modern, JSON-based way to sign people in to web and mobile apps.

RelatedOAuth 2.0ID tokenSAML 2.0

OpenID Connect: code out, ID token backauthorize + PKCEAppProvider(OP)ID token

PAMPrivileged access management

Controls for powerful accounts: who may use them, when, with approval, and with session recording. A separate discipline from workforce SSO.

Why it matters A few powerful accounts deserve more care than thousands of ordinary ones.

RelatedLeast privilege

Passkey

A phishing-resistant credential based on WebAuthn, stored on a phone, computer or security key and unlocked with a biometric or device PIN. It replaces the password rather than adding to it.

Why it matters It removes the password, the thing attackers steal most.

RelatedWebAuthnFIDO2

Passkey: the device signs a challenge; only the public key is storedchallengesignatureDeviceprivate keyServicepublic keychallenge

Phishing

Tricking a person into giving secrets to a fake page or message. Codes and passwords can be handed over; a passkey cannot.

Why it matters It is how most real-world account takeovers begin.

RelatedPhishing-resistantPasskey

Phishing-resistant

A factor that cannot be handed to a fake site by the user. WebAuthn credentials qualify because they are bound to the real site's origin.

Why it matters It is the property that ends the most common account takeover.

RelatedWebAuthnPasskey

Phishing-resistant: the wrong site gets nothingsignsPasskeyreal sitefake siteno signature

PKCEProof Key for Code Exchange, RFC 7636

An extension to the authorization code flow where the client proves it is the same one that started the request, using a one-time secret. It stops a stolen authorization code from being redeemed.

Why it matters It stops a stolen authorization code from being useful.

RelatedAuthorization code flowOAuth 2.0

PKCE: the app proves it started the requesthashsent firstcode + verifierAppTokenendpointverifier(secret)challenge =SHA-256(verifier)

Prompt fatigue

When people approve prompts without reading because there are too many. It is why step-up should be selective.

Why it matters A check people click through protects nothing.

RelatedStep-up authenticationMFA

Provisioning

Creating, updating and removing user accounts in applications. Deprovisioning, removing access promptly, is the part that protects you.

Why it matters Accounts that are never removed are the quietest risk in most organisations.

RelatedSCIMJMLJIT provisioning

Provisioning: create, update, removechangescreate / update / removeSource oftruthIdentitysystemApps(accounts)

Public-key cryptography

Two linked keys: a private one that signs and stays secret, and a public one that anyone can use to check the signature.

Why it matters It lets you prove something without sharing the secret.

RelatedPasskeyJWKS

RBACRole-based access control

Granting access through roles such as admin, auditor or member, then assigning people to roles. Easy to explain to an auditor.

Why it matters Roles make access explainable and reviewable.

RelatedABACLeast privilege

RBAC: people get roles; roles hold permissionsassignedPersonRolePermissionPermission

Redirect URI

The address a provider sends the browser back to after sign-in. It must match a registered value exactly, or codes can be stolen.

Why it matters A loose match lets an attacker catch the code.

RelatedAuthorization code flowOIDC

Refresh token

A long-lived credential used to get new access tokens without asking the user to sign in again. Guard it closely.

Why it matters It is long-lived, so it needs the best protection.

RelatedRefresh token rotationAccess token

Refresh token: new access tokens without signing in againrefresh tokenAppTokenendpointNew accesstoken

Refresh token rotation

Issuing a new refresh token every time one is used and invalidating the old one. If an old token appears again, the server can treat it as theft and end the session.

Why it matters A stolen refresh token is noticed the moment it is reused.

RelatedRefresh token

Relying partyRP

The application that relies on an identity provider to sign people in. In OpenID Connect it is the client; in SAML it is the service provider.

Why it matters It is the app doing the verifying, so it carries the checks.

RelatedSPIdP

Replay attack

Reusing a captured valid request later. Defences are one-time values, short lifetimes and timestamp checks.

Why it matters A valid request is dangerous if it can be sent again.

RelatedHMACnonce

SAML 2.0Security Assertion Markup Language

An OASIS standard for exchanging signed sign-in statements between an identity provider and an application, widely supported by enterprise software.

Why it matters Many established business apps support only SAML for single sign-on.

RelatedAssertionIdPSP

SAML: the app redirects to the identity provider, which returns a signed assertion1 request2 redirect34 POSTBrowserApp (SP)IdentityproviderSigned assertion

SCIMSystem for Cross-domain Identity Management

A standard REST API for creating, updating and removing users and groups across systems, defined in RFC 7643 and RFC 7644. The usual way an HR system drives accounts in applications.

Why it matters It replaces CSV uploads and tickets with an automatic, standard feed.

RelatedProvisioningJML

SCIM: HR changes flow to appsPATCHHRsystemAuthMantraSCIMApp AApp B

Scope

A named slice of access an application asks for, such as openid or profile. Ask for the least you need.

Why it matters Narrow scopes limit what a leaked token can do.

RelatedOAuth 2.0Least privilege

Separation of dutiesSoD

Splitting a sensitive process so no one person can complete it alone, for example the person who requests access is not the person who approves it.

Why it matters It stops one person, or one stolen account, finishing a risky task alone.

RelatedAccess reviewRBAC

Separation of duties: two people for one sensitive taskRequestsApprovesExecutes

Service accountNon-human identity

An identity used by software rather than a person. Often has broad rights, no owner and a secret nobody rotates, which makes it a common weak point.

Why it matters Often forgotten, widely trusted and rarely rotated: a favourite target.

RelatedClient credentials grantAPI key

Service account: software signs in as itselfclient secrettokenJob orserviceTokenendpointAPI

Session

The period during which a signed-in person stays recognised. Good session management means seeing active sessions and being able to revoke them.

Why it matters Its length decides how long a stolen cookie stays useful.

RelatedStep-up authentication

A session is the time a sign-in stays validSign inSessionactiveExpire orrevoke

SIEMSecurity information and event management

A platform that collects logs from many systems to detect and investigate threats. Identity logs, such as sign-ins and role changes, are among the most useful inputs.

Why it matters It lets a security team see identity events beside everything else.

RelatedAudit logSigned webhook

SIEM: logs from many systems, one place to investigateIdentityCloudEndpointsSIEMAlert

Signed webhook

An HTTP callback that carries an event to your system, with a signature you verify to be sure it came from the sender and was not altered.

Why it matters A signature is how the receiver knows an event is genuine.

RelatedSIEMAudit log

Signed webhook: sender signs, receiver recomputest.bodyX-...-SignaturePOSTSenderbody + timeReceiverrecomputes HMAC

SIM swap

An attack where someone gets a victim's mobile number moved to a SIM they control, so they receive the victim's text messages and codes.

Why it matters It is why SMS codes are a weaker choice for important accounts.

RelatedMFA

SIM swap: the number moves, the codes followswappedYour numberAttacker'sSIMCodesintercepted

Single logoutSLO

Ending sessions at the provider and at connected applications together. Support varies by application, so test it.

Why it matters Closing one tab is not the same as ending every session.

RelatedSessionSSO

SPService provider

In SAML, the application that consumes the identity provider's assertion. Everyday word: the app you are signing in to.

Why it matters It is the app side of a SAML trust, and it must check what it receives.

RelatedIdPSAML 2.0Relying party

SP-initiated sign-in

A SAML flow that starts at the application, which redirects the person to the identity provider. The most common start.

Why it matters It is the flow you will meet most often when setting up SAML apps.

RelatedSAML 2.0SPIdP

Splunk HECHTTP Event Collector

An HTTP endpoint on Splunk that accepts events with a token. AuthMantra can stream audit events to it.

Why it matters It lets Splunk users receive identity events directly.

RelatedSIEMSigned webhook

SSOSingle sign-on

Signing in once to reach many applications. The identity provider authenticates you and tells each app who you are, so you do not keep separate passwords.

Why it matters Fewer passwords, one place to enforce policy and one place to switch someone off.

RelatedIdPSAML 2.0OIDC

One sign-in at the identity provider reaches many appssigns in oncePersonIdentityproviderMailHR appTicketing

state

A random value an app sends with an authorization request and checks on return, to block forged callbacks.

Why it matters It blocks forged callbacks to your app.

RelatednonceRedirect URI

Step-up authenticationStep-up

Asking for stronger or fresher proof at the moment a sensitive action is attempted, instead of at every sign-in.

Why it matters It protects the sensitive moment without nagging people all day.

RelatedMFAacrSession

Step-up: ordinary work stays open; a sensitive action asks againno promptpromptSigned inOrdinaryworkSensitiveactionRe-verify

Suspend

An admin action that blocks an account and signs the person out everywhere. AuthMantra admins can suspend an account.

Why it matters It is the fast, complete stop when an account is at risk.

RelatedSessionJML

TOTPTime-based one-time password, RFC 6238

A six-digit code generated by an authenticator app from a shared secret and the current time. Better than a text message, but still phishable.

Why it matters It works offline and avoids the phone network.

RelatedMFAPasskey

TOTP: app and server share a secret and the clocksecret + timetypedAuthenticatorapp6-digit codechanges every 30 sServerchecks

WebAuthnWeb Authentication

The W3C browser API that lets a website register and use public-key credentials held by an authenticator. The credentials are scoped to the site, which is why they resist phishing.

Why it matters It is what lets a website ask your device for a passkey.

RelatedPasskeyFIDO2

WebAuthn: browser API between site and authenticatoroptionssignWebsiteBrowserWebAuthn APIAuthenticator

Zero trust

A design approach that does not trust a request because of where it comes from. Every request is checked for identity, context and authorisation.

Why it matters Network location is a weak signal; identity and context are better.

RelatedLeast privilegeMFA

Zero trust: verify every request, not the networkRequestVerifywho + what + contextAllow ordeny