# Conditional Authenticator

**URL:** <https://forum.keycloak.org/t/conditional-authenticator/149>\
**Category:** Getting advice\
**Created:** [October 16, 2019, 1:20pm UTC](https://forum.keycloak.org/t/conditional-authenticator/149 "2019-10-16T13:20:16Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ameckro](https://avatars.discourse-cdn.com/v4/letter/a/839c29/32.png) [@Ameckro](https://forum.keycloak.org/u/Ameckro)\
**Post date:** [October 16, 2019, 1:20pm UTC](https://forum.keycloak.org/t/conditional-authenticator/149/1 "2019-10-16T13:20:16Z")

</div>

Hi Team,  
I am trying to implement a new Authenticator based on the user’s browser fingerprint. The authentication flow should be the following:

 ![image](https://global.discourse-cdn.com/free1/uploads/keycloak/original/1X/bc06fb1f5ae551097556a5c5801a04af484f8cbb.png)

The _Username & Password_ authenticator and the _OTP_ authenticator are already provided by keycloak. I have developed an authenticator called _Fingerprint_ (or browser fingerprint). This authenticator works like this:

- The form submits a hash identifying many browser properties.
- The authenticator checks wheter the hash provided exists or not:
  - if it exists, then the authentication process ends successfully
  - if does not exist, the authenticator sets a required action to register the new fingerprint

But I’m not able to connect the fingerprint authentication with OTP

How should I perform the next step ?  
Is there a way to set a condition to an authenticator from Keycloak admin console ?  
Or is it posible to add an authenticator to a flow dynamically in Java (like required actions )?

Thanks,  
Haritz

---

<div class="post-metadata">

**Author:** ![khaianis](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/khaianis/32/1170_2.png) [@khaianis](https://forum.keycloak.org/u/khaianis)\
**Post date:** [June 13, 2020, 5:34pm UTC](https://forum.keycloak.org/t/conditional-authenticator/149/2 "2020-06-13T17:34:41Z")

</div>

Hi Hope u are well  
implement custom spi authenticator  
To verify fingerprint  
Without using required actions ( it will bé used once ) .  
Best regards

---

<div class="post-metadata">

**Author:** ![guenoledc](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/guenoledc/32/1076_2.png) [@guenoledc](https://forum.keycloak.org/u/guenoledc)\
**Post date:** [July 4, 2020, 5:47pm UTC](https://forum.keycloak.org/t/conditional-authenticator/149/3 "2020-07-04T17:47:55Z")

</div>

Hi

Have you been able to perform that function?

In my understanding, the Fingerprint authenticator should collect the browser information from the http request and possibly a form running some javascript. And this is passed to the fingerprint authenticator action function.

The action function will either find the fingerprint in its referential/database and accept the login, or trigger the registration of this new fingerprint by prompting the OTP form.

I think that if you create a new flow containing first your fingerprint authenticator (as alternative) and the OTP authenticator as alternative, it should trigger the OTP form only if the fingerprint is not found.

Alternatively, in your fingerprint authenticator, you can trigger yourself the otp form and handle the response from your authenticator.

Please let us know the result

---

<div class="post-metadata">

**Author:** ![avasconcelos](https://avatars.discourse-cdn.com/v4/letter/a/e95f7d/32.png) [@avasconcelos](https://forum.keycloak.org/u/avasconcelos)\
**Post date:** [October 30, 2020, 11:45am UTC](https://forum.keycloak.org/t/conditional-authenticator/149/4 "2020-10-30T11:45:21Z")

</div>

Did you manage to implement it? I’m trying to do the same using browser fingerprint to ask for OTP just if it is a new machine. But, so far I didn’t find a way to do it.
