SSO Authenticate Only

The SSO / Authenticate Only action sends the user to their tenant's identity provider to verify who they are, then returns to the flow without creating, updating, or signing in a Descope user. It also issues no session token. SAML attributes and OIDC claims from the IdP stay in flow context for later steps.

This page covers the flow action. If you want every login through a given connection to behave this way, regardless of which SSO action the flow uses, see Authentication-only connections.

For adding SSO to a flow in general, including the ordinary SSO action that does sign the user in, see SSO with Flows.

Why This Exists

Use it when you need to know who someone is without giving them access to your application. A typical case is verifying an external partner or contractor against their employer's directory.

A successful verification still appears in your audit trail like any other SSO login.

After the Action

Because there is no session, you cannot combine this action with step-up or MFA.

Therefore to end the flow, you can either:

  • End the flow with End without session so the flow returns its output and nothing else. See End Action.
  • Add Sign Up / Anonymous user with custom claims before the End step, so your application gets a signed token that carries the verified attributes without a user record behind it. See Anonymous Users.

Authentication-only Connections

Classifying an SSO connection as authentication only makes the ordinary SSO action behave like this one for that connection. A tenant administrator can make a connection verification-only without rebuilding the flow.

The rest of the flow still runs, so a later step can still issue a token. Branch on ssoAuthenticationOnly if you need to skip those steps when the connection was classified. Details are on Authentication-only connections.

Was this helpful?

On this page