This documentation is for WSO2 Identity Server 5.1.0 . View documentation for the latest release.

Versions Compared


  • This line was added.
  • This line was removed.
  • Formatting was changed.


  1. Log in to the WSO2 Identity Server end user dashboard.
  2. Navigate to the My Profile section by clicking the associated View Details button.
  3. Click Manage U2F Authentication.
  4. You can add a new U2F device to your account and if needed you can remove it.


    Tip: You can have multiple devices associated to your account.

Configuring FIDO U2F as an authenticator

  1. Log in to the Management Console
  2. Navigate to the Main menu to access the Identity menu. Click Add under Service Providers.
  3. Fill in the Service Provider Name and provide a brief Description of the service provider. Only Service Provider Name is a required field.
  4. Click Register to add the new service provider.
  5. Access the service provider you just created and expand Local & Outbound Authentication Configuration.
  6. Select Advanced Configuration to configure multi-factor authentication.
  7. Click Add Authentication Step. Clicking this again will enable you to create another authentication step.
  8. Select whether this is a Subject StepAttribute Step or both. In the case of multiple steps, you can have only one step as the subject step and one as the attribute step.
  9. Click the plus button to add a Local Authenticator. You can choose the type of authenticator using the dropdown. Clicking the plus button again will enable you to add a second local authenticator. As an example of this scenario, basic and fido are used as the two authenticators. Basic authentication allows you to authenticate users from the enterprise user store while FIDO authenticates you externally.
  10. Click the Update button. This will return you to the previous screen with your newly configured authentication steps.