# Reauthentication for Sensitive functionality ( Step-up authentication)

**URL:** <https://forum.keycloak.org/t/reauthentication-for-sensitive-functionality-step-up-authentication/11740>\
**Category:** Securing applications\
**Tags:** authentication, oidc\
**Created:** [October 27, 2021, 9:00am UTC](https://forum.keycloak.org/t/reauthentication-for-sensitive-functionality-step-up-authentication/11740 "2021-10-27T09:00:16Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sachithra](https://avatars.discourse-cdn.com/v4/letter/s/94ad74/32.png) [@sachithra](https://forum.keycloak.org/u/sachithra)\
**Post date:** [October 27, 2021, 9:00am UTC](https://forum.keycloak.org/t/reauthentication-for-sensitive-functionality-step-up-authentication/11740/1 "2021-10-27T09:00:16Z")

</div>

In my application, there are some sensitive functionalities that could perform by all types of users. What I wanted is whether the user has an active keycloak session to access the application to perform the above sensitive functionalities, verify the user again using their password. By authenticating what I expect is to ensure that mentioned sensitive functionality is performed by the legitimate user. Does keycloak has such reauthenticate functionality built-in?

reference: Require Re-authentication for Sensitive Features of [Authentication - OWASP Cheat Sheet Series](https://cheatsheetseries.owasp.org/cheatsheets/Authentication_Cheat_Sheet.html)

---

<div class="post-metadata">

**Author:** ![xgp](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/xgp/32/2589_2.png) [@xgp](https://forum.keycloak.org/u/xgp)\
**Post date:** [October 27, 2021, 9:08am UTC](https://forum.keycloak.org/t/reauthentication-for-sensitive-functionality-step-up-authentication/11740/2 "2021-10-27T09:08:02Z")

</div>

Assuming you’re using OIDC, you can do a redirect to the login with `prompt=login` set, which will force the user to re-authenticate.

---

<div class="post-metadata">

**Author:** ![dasniko](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/dasniko/32/2969_2.png) [@dasniko](https://forum.keycloak.org/u/dasniko)\
**Post date:** [October 27, 2021, 9:41am UTC](https://forum.keycloak.org/t/reauthentication-for-sensitive-functionality-step-up-authentication/11740/3 "2021-10-27T09:41:40Z")

</div>

The step-up auth feature is currently under discussion and will hopefully be integrated soon. There are a lot of people waiting for this:

Issue: [[KEYCLOAK-847] Step-up Authentication - Red Hat Issue Tracker](https://issues.redhat.com/browse/KEYCLOAK-847)  
PR + current discussions: [KEYCLOAK-847 Add support for step up authentication by CorneliaLahnsteiner · Pull Request #7897 · keycloak/keycloak · GitHub](https://github.com/keycloak/keycloak/pull/7897)
