---
title: Passthrough Authentication node
description: Configure the Pass-through Authentication node to authenticate users against a third-party service through a connector, supporting password migration without forcing resets.
component: auth-node-ref
version: 8
page_id: auth-node-ref::passthrough-authentication
canonical_url: https://docs.pingidentity.com/auth-node-ref/latest/passthrough-authentication.html
llms_txt: https://docs.pingidentity.com/auth-node-ref/llms.txt
docs_for_agents: https://developer.pingidentity.com/build-with-ai/docs-for-agents.md
revdate: 2026-09-01T13:00:59Z
keywords: ["Nodes &amp; Trees", "Journeys", "Authentication", "User Profiles", "Migration", "Password", "Synchronization"]
page_aliases: ["auth-node-passthrough-authentication.adoc"]
superseded_by: https://docs.pingidentity.com/auth-node-ref/latest/passthrough-authentication.html
section_ids:
  example: Example
  availability: Availability
  inputs: Inputs
  dependencies: Dependencies
  connectors-support-pass-through-authentication: Connectors that support pass-through authentication
  configuration: Configuration
  outputs: Outputs
  callbacks: Callbacks
  outcomes: Outcomes
  errors: Errors
---

# Passthrough Authentication node

The Passthrough Authentication node authenticates users against a third-party service through a configured connector. This lets you migrate user profiles without forcing users to reset their passwords, or retain a third-party service indefinitely as the canonical store for authentication credentials.

Pass the credentials to this node to authenticate the identity against the service.

## Example

The following example shows a login flow that first attempts local authentication and then passes the credentials through to the third-party service if local authentication fails. After successful pass-through authentication, the flow verifies that the user's profile contains the required attributes and stores the password in the local profile.

Before trying this example, synchronize accounts from the third-party service.

![Passthrough Authentication that updates user credentials](_images/trees-node-passthrough-authentication-example-platform.png)

* The [Page node](page.html) containing the [Platform Username node](platform-username.html) and [Platform Password node](platform-password.html) prompts for credentials.

* The [Data Store Decision node](data-store-decision.html) validates the username-password credentials.

* If local authentication succeeds, the [Increment Login Count node](increment-login-count.html) increments the login count and the journey continues to an inner tree evaluator.

* If local authentication fails, the [Passthrough Authentication node](passthrough-authentication.html) authenticates the credentials against the third-party service.

* If third-party authentication succeeds, the [Identify Existing User node](identify-existing-user.html) checks for a matching user profile.

* The [Required Attributes Present node](required-attributes-present.html) checks whether the user profile contains the required attributes.

* The [Patch Object node](patch-object.html) updates the user profile with the successful password.

## Availability

| Product                                                                                                                                 | Available? |
| --------------------------------------------------------------------------------------------------------------------------------------- | ---------- |
| PingOne Advanced Identity Cloud                                                                                                         | Yes        |
| PingAM (self-managed)&#xA;&#xA;This functionality requires that you configure AM as part of a sample Ping Identity Platform deployment. | Yes        |
| Ping Identity Platform (self-managed)                                                                                                   | Yes        |

## Inputs

The node reads the username and password from shared state. It uses the configured Identity Attribute and Password Attribute values, falling back to the default username and password properties when necessary.

For standalone AM deployments, implement a [Username Collector node](am-only/username-collector.html) and a [Password Collector node](am-only/password-collector.html) earlier in the journey.

For Ping Identity Platform deployments, implement a [Platform Username node](platform-username.html) and a [Platform Password node](platform-password.html) earlier in the journey.

## Dependencies

Before you use the node:

* Configure the connector to the third-party service. The connector must [support pass-through authentication](#connectors-support-pass-through-authentication).

  Learn more in the [OpenICF documentation](https://docs.pingidentity.com/openicf/connector-reference/).

* If you plan to collect credentials in the identity repository for users, synchronize accounts from the third-party service.

  Learn more in [Synchronization](https://docs.pingidentity.com/pingidm/8/synchronization-guide/) in the IDM documentation.

### Connectors that support pass-through authentication

The following connectors support pass-through authentication using the [`AuthenticateOp` interface](https://docs.pingidentity.com/openicf/connector-dev-guide/operations/operation-authenticate.html) by default:

* [LDAP connector](https://docs.pingidentity.com/openicf/connector-reference/ldap.html)

* [CSV file connector](https://docs.pingidentity.com/openicf/connector-reference/csv.html)

* [Database Table connector](https://docs.pingidentity.com/openicf/connector-reference/dbtable.html)

* [Microsoft Graph API Java connector](https://docs.pingidentity.com/openicf/connector-reference/ms-graph-api.html)

|   |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| - | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|   | All [Scripted Groovy](https://docs.pingidentity.com/openicf/connector-reference/groovy.html)-based connectors are capable of pass-through authentication if the `AuthenticateScript.groovy` script is implemented, but the only default implementation is the ScriptedSQL connector. Learn more in [Authenticate script](https://docs.pingidentity.com/openicf/connector-dev-guide/scripts/script-authenticate.html) and [Authenticate operation](https://docs.pingidentity.com/openicf/connector-dev-guide/operations/operation-authenticate.html). |

## Configuration

| Property           | Usage                                                                                    |
| ------------------ | ---------------------------------------------------------------------------------------- |
| System Endpoint    | Required. Name of the connector to the third-party service that performs authentication. |
| Object Type        | The OpenICF object type for the object being authenticated.Default: `account`            |
| Identity Attribute | The username attribute for authentication.Default: `userName`                            |
| Password Attribute | The password attribute for authentication.Default: `password`                            |

## Outputs

The node preserves the shared and transient state and authenticates the supplied identity against the configured connector.

## Callbacks

This node doesn't send any callbacks.

## Outcomes

* `Authenticated`

  The connector successfully authenticated the supplied credentials.

* `Missing Input`

  The username or password isn't present in state, or the password is empty.

* `Failed`

  The connector rejected the supplied credentials or couldn't authenticate the identity. Check the connector configuration and service availability.

## Errors

This node doesn't log any error or warning messages of its own.
