# Authentication nodes > AI agents should consult [Docs for Agents](https://developer.pingidentity.com/build-with-ai/docs-for-agents.md) > for guidance on navigating Ping Identity documentation. ## Auth Node Ref 8.1 - [Accept Terms and Conditions node](https://docs.pingidentity.com/auth-node-ref/8.1/accept-terms-and-conditions.md): Prompts users to accept the active terms and conditions during registration or sign-on journeys in PingAM. - [Account Active Decision node](https://docs.pingidentity.com/auth-node-ref/8.1/account-active-decision.md): Checks whether a user account is both active and unlocked, routing the journey along True or False outcome paths in PingAM. - [Account Lockout node](https://docs.pingidentity.com/auth-node-ref/8.1/account-lockout.md): Locks or unlocks a user account profile in PingAM, supporting both persistent and duration-based lockout. - [AD Decision node](https://docs.pingidentity.com/auth-node-ref/8.1/ad-decision.md): Verifies user credentials against an Active Directory data store and routes journeys based on account status, including locked, disabled, or expired accounts. - [Agent Data Store Decision node](https://docs.pingidentity.com/auth-node-ref/8.1/agent-data-store-decision.md): Authenticates agents such as PingGateway and Java or web agents against the agent profile data store in PingAM. - [Amster Jwt Decision node](https://docs.pingidentity.com/auth-node-ref/8.1/am-only/amster-jwt-decision.md): Configure the Amster JWT Decision node to authenticate Amster connections to PingAM using SSH key pairs stored in an authorized_keys file. - [Anonymous Session Upgrade node](https://docs.pingidentity.com/auth-node-ref/8.1/anonymous-session-upgrade.md): Upgrades an anonymous session to a non-anonymous session in PingAM journeys. - [Anonymous User Mapping node](https://docs.pingidentity.com/auth-node-ref/8.1/anonymous-user-mapping.md): Maps unauthenticated users to a named anonymous account in PingAM, enabling limited access without credentials. - [App Policy Decision node](https://docs.pingidentity.com/auth-node-ref/8.1/app-policy-decision.md): Evaluates application access policies automatically from journey context in PingAM, routing based on accept, reject, or error outcomes. - [Attribute Collector node](https://docs.pingidentity.com/auth-node-ref/8.1/attribute-collector.md): Collects user attribute values during a journey for use in registration or profile update flows in PingAM. - [Attribute Present Decision node](https://docs.pingidentity.com/auth-node-ref/8.1/attribute-present-decision.md): Checks whether a specified attribute, including private attributes such as password, is present on a user object in PingAM. - [Attribute Value Decision node](https://docs.pingidentity.com/auth-node-ref/8.1/attribute-value-decision.md): Verifies that a user attribute satisfies a configured condition, such as presence or equality, during journeys in PingAM. - [Auth Level Decision node](https://docs.pingidentity.com/auth-node-ref/8.1/auth-level-decision.md): Compares the current authentication level against a configured threshold to route journeys in PingAM. - [Authenticate Thing node](https://docs.pingidentity.com/auth-node-ref/8.1/self-managed/authenticate-thing.md): Use the Authenticate Thing node in PingAM to authenticate IoT devices and gateways using Proof of Possession JWT or Client Assertion. - [Authentication node reference](https://docs.pingidentity.com/auth-node-ref/8.1/overview.md): Reference index of all PingAM authentication nodes, organized by category including MFA, federation, identity management, and utility nodes. - [Backchannel Initialize node](https://docs.pingidentity.com/auth-node-ref/8.1/backchannel-initialize.md): Configure the Backchannel Initialize node to start an asynchronous journey for a different user or agent, enabling backchannel authentication in PingAM. - [Backchannel Notification node](https://docs.pingidentity.com/auth-node-ref/8.1/backchannel-notification.md): Configure the Backchannel Notification node to send real-time status updates from a backchannel journey to the main authentication journey in PingAM. - [Backchannel Status node](https://docs.pingidentity.com/auth-node-ref/8.1/backchannel-status.md): Configure the Backchannel Status node to check the status of an asynchronous backchannel authentication journey in PingAM. - [CAPTCHA node](https://docs.pingidentity.com/auth-node-ref/8.1/captcha.md): Configure the CAPTCHA node to verify CAPTCHA responses from providers such as Google reCAPTCHA v2, reCAPTCHA v3, and hCaptcha during PingAM authentication journeys. - [Certificate Collector node](https://docs.pingidentity.com/auth-node-ref/8.1/certificate-collector.md): Configure the Certificate Collector node to collect X.509 digital certificates from incoming requests for use as authentication credentials in PingAM journeys. - [Certificate User Extractor node](https://docs.pingidentity.com/auth-node-ref/8.1/certificate-user-extractor.md): Configure the Certificate User Extractor node to extract a user identifier from an X.509 certificate and match it against an identity in the identity store. - [Certificate Validation node](https://docs.pingidentity.com/auth-node-ref/8.1/certificate-validation.md): Configure the Certificate Validation node to validate X.509 digital certificates against LDAP stores, CRLs, and OCSP in PingAM authentication journeys. - [Choice Collector node](https://docs.pingidentity.com/auth-node-ref/8.1/choice-collector.md): Configure the Choice Collector node to present users with two or more selectable options during an authentication journey in PingAM. - [Combined MFA Registration node](https://docs.pingidentity.com/auth-node-ref/8.1/combined-mfa-registration.md): Configure the Combined MFA Registration node to register a device for both push notification and OATH one-time password multi-factor authentication in a single step. - [Configuration Provider node](https://docs.pingidentity.com/auth-node-ref/8.1/config-provider.md): Configure the Configuration Provider node to use a script to dynamically build the configuration of another node and replace it at runtime in an PingAM journey. - [Consent Collector node](https://docs.pingidentity.com/auth-node-ref/8.1/consent-collector.md): Configure the Consent Collector node to prompt users to consent to sharing their profile data during registration or progressive profile flows in PingAM. - [Cookie Presence Decision node](https://docs.pingidentity.com/auth-node-ref/8.1/cookie-presence-decision.md): Configure the Cookie Presence Decision node to check whether a named cookie exists in an incoming authentication request and route the journey accordingly. - [Create Object node](https://docs.pingidentity.com/auth-node-ref/8.1/create-object.md): Create a new managed object using attributes collected during an authentication journey, such as during user registration. - [Create Password node (deprecated)](https://docs.pingidentity.com/auth-node-ref/8.1/am-only/create-password.md): Deprecated. The Create Password node prompted users to create a password during social account provisioning in PingAM. - [Data Store Decision node](https://docs.pingidentity.com/auth-node-ref/8.1/data-store-decision.md): Authenticate users by verifying that their credentials match those stored in the configured data store for the realm. - [Debug node](https://docs.pingidentity.com/auth-node-ref/8.1/am-only/debug.md): Use the Debug node in PingAM to display shared node state, identity universalId, and transaction ID during authentication tree testing. - [Device Binding node](https://docs.pingidentity.com/auth-node-ref/8.1/device-binding.md): Register one or more devices to a user's account by generating a cryptographic key pair and storing the public key in the user's profile. - [Device Binding Storage node](https://docs.pingidentity.com/auth-node-ref/8.1/device-binding-storage.md): Persist collected device binding data, including the device public key, to a user's profile in the identity store. - [Device Geofencing node](https://docs.pingidentity.com/auth-node-ref/8.1/device-geofencing.md): Compare collected device location data against configured trusted locations to determine whether the user's device is within an allowed geofence. - [Device Location Match node](https://docs.pingidentity.com/auth-node-ref/8.1/device-location-match.md): Compare collected device location data against previously saved locations in the user's profile to verify the device is within an acceptable range. - [Device Match node](https://docs.pingidentity.com/auth-node-ref/8.1/device-match.md): Compare collected device metadata against saved trusted device profiles in a user's account using built-in or custom script matching. - [Device Profile Collector node](https://docs.pingidentity.com/auth-node-ref/8.1/device-profile-collector.md): Collect metadata about the user's device, including hardware details, OS information, and optionally location, for use in device profiling journeys. - [Device Profile Save node](https://docs.pingidentity.com/auth-node-ref/8.1/device-profile-save.md): Persist collected device metadata and location data to a user's profile in the identity store for use in future authentications. - [Device Signing Verifier node](https://docs.pingidentity.com/auth-node-ref/8.1/device-signing-verifier.md): Verify possession of a registered bound device by challenging it to sign a value with the private key paired to a stored public key. - [Device Tampering Verification node](https://docs.pingidentity.com/auth-node-ref/8.1/device-tampering-verification.md): Evaluate a device tampering score to determine whether a device has been rooted, jailbroken, or otherwise poses a security risk. - [Display Username node](https://docs.pingidentity.com/auth-node-ref/8.1/display-username.md): Look up and display a user's username based on a different identifying attribute, such as an email address, to support username recovery flows. - [Email Suspend node](https://docs.pingidentity.com/auth-node-ref/8.1/email-suspend.md): Sends an email using a template and suspends the authentication journey until the user clicks a resume link in that email. - [Email Template node](https://docs.pingidentity.com/auth-node-ref/8.1/email-template.md): Sends an email based on a configured template without suspending the authentication journey, for example to deliver a welcome message after registration. - [Enable Device Management node](https://docs.pingidentity.com/auth-node-ref/8.1/enable-device-management.md): Controls which MFA device types a user must authenticate with before they can remove a registered MFA device, allowing journeys to relax or remove this restriction. - [Failure node](https://docs.pingidentity.com/auth-node-ref/8.1/failure.md): Terminal node that ends an authentication journey in failure, redirecting the user to a failure URL and optionally incrementing the account lockout counter. - [Failure URL node](https://docs.pingidentity.com/auth-node-ref/8.1/failure-url.md): Specifies the URL to redirect end users to when authentication fails in a journey. - [Flow Control node](https://docs.pingidentity.com/auth-node-ref/8.1/flow-control.md): Randomly routes a configurable percentage of authentication requests between two journey paths, enabling controlled rollout and testing of new authentication flows. - [Get Authenticator App node](https://docs.pingidentity.com/auth-node-ref/8.1/get-authenticator-app.md): Displays a prompt with links to download an authenticator app from the Apple App Store or Google Play Store as part of a push authentication journey. - [Get Session Data node](https://docs.pingidentity.com/auth-node-ref/8.1/get-session-data.md): Retrieves a value from a user's existing session by key and stores it in the shared node state, for use during session upgrade journeys. - [HOTP Generator node](https://docs.pingidentity.com/auth-node-ref/8.1/hotp-generator.md): Generates a random numeric one-time passcode (OTP) of a specified length for use in authentication journeys, storing it in shared state for delivery by email or SMS. - [Identify Existing User node](https://docs.pingidentity.com/auth-node-ref/8.1/identify-existing-user.md): Looks up a user identity by a specified attribute such as email address and writes the matching identifier to shared node state, for use in forgotten password flows. - [Identity Assertion node](https://docs.pingidentity.com/auth-node-ref/8.1/identity-assertion-node.md): Integrates PingGateway into an authentication journey to support identity assertion with third-party services such as Windows Desktop SSO and Kerberos. - [Increment Login Count node](https://docs.pingidentity.com/auth-node-ref/8.1/increment-login-count.md): Increments the successful login count on a managed identity object, enabling journeys to track authentication frequency for use with the Login Count Decision node. - [Inner Tree Evaluator node](https://docs.pingidentity.com/auth-node-ref/8.1/inner-tree-evaluator.md): Configure the Inner Tree Evaluator node to nest authentication journeys as children within a parent journey in PingAM. - [JWT Password Replay node](https://docs.pingidentity.com/auth-node-ref/8.1/jwt-password-replay.md): Configure the JWT Password Replay node to store a user's password in an encrypted JWT session property for use with PingGateway credential replay scenarios. - [KBA Decision node](https://docs.pingidentity.com/auth-node-ref/8.1/kba-decision.md): Configure the KBA Decision node to check whether a user account has the minimum number of knowledge-based authentication security questions defined. - [KBA Definition node](https://docs.pingidentity.com/auth-node-ref/8.1/kba-definition.md): Configure the KBA Definition node to collect knowledge-based authentication questions and answers from users during registration or profile update. - [KBA Verification node](https://docs.pingidentity.com/auth-node-ref/8.1/kba-verification.md): Configure the KBA Verification node to present knowledge-based authentication questions to users and verify their answers against stored responses. - [Kerberos node](https://docs.pingidentity.com/auth-node-ref/8.1/self-managed/kerberos.md): Use the Kerberos node in PingAM to enable desktop single sign-on through SPNEGO, allowing users authenticated with a Kerberos KDC to sign on without re-entering credentials. - [LDAP Decision node](https://docs.pingidentity.com/auth-node-ref/8.1/ldap-decision.md): Configure the LDAP Decision node to verify a username and password against an LDAP user data store and check for expired or locked accounts. - [Legacy CAPTCHA node](https://docs.pingidentity.com/auth-node-ref/8.1/legacy-captcha.md): Configure the Legacy CAPTCHA node to verify a CAPTCHA response token and create a CAPTCHA callback. Superseded by the CAPTCHA node. - [Legacy Social Provider Handler node](https://docs.pingidentity.com/auth-node-ref/8.1/legacy-social-provider-handler.md): Configure the Legacy Social Provider Handler node to authenticate users with a social identity provider and collect profile attributes. Use the Social Provider Handler node for new journeys. - [Login Count Decision node](https://docs.pingidentity.com/auth-node-ref/8.1/login-count-decision.md): Configure the Login Count Decision node to trigger a journey action when a user's successful login count reaches a specified threshold. - [Message node](https://docs.pingidentity.com/auth-node-ref/8.1/message.md): Configure the Message node to present a custom, localized message with positive and negative response buttons that users must click to proceed through a journey. - [Meter node](https://docs.pingidentity.com/auth-node-ref/8.1/meter.md): Configure the Meter node to increment a custom metric key each time journey evaluation passes through the node, enabling trend monitoring with tools such as Prometheus. - [MFA Registration Options node](https://docs.pingidentity.com/auth-node-ref/8.1/mfa-registration-options.md): Configure the MFA Registration Options node to let users register a multi-factor authentication device or skip registration during a journey. - [Modify Auth Level node](https://docs.pingidentity.com/auth-node-ref/8.1/modify-auth-level.md): Configure the Modify Auth Level node to increase or decrease the authentication level value in the current session. - [OATH Device Storage node](https://docs.pingidentity.com/auth-node-ref/8.1/oath-device-storage.md): Configure the OATH Device Storage node to persist a registered OATH device profile from the shared state into the user's account. - [OATH Registration node](https://docs.pingidentity.com/auth-node-ref/8.1/oath-registration.md): Configure the OATH Registration node to let users register a device for OATH-based multi-factor authentication using a QR code scan. - [OATH Token Verifier node](https://docs.pingidentity.com/auth-node-ref/8.1/oath-token-verifier.md): Configure the OATH Token Verifier node to request and verify a one-time passcode generated by a registered OATH device using TOTP or HOTP. - [OAuth 2.0 node (deprecated)](https://docs.pingidentity.com/auth-node-ref/8.1/am-only/oauth2.md): Deprecated. The OAuth 2.0 node authenticated PingAM users against OAuth 2.0-compliant social identity providers using the authorization code grant. - [OIDC ID Token Validator node](https://docs.pingidentity.com/auth-node-ref/8.1/oidc-idtoken-validator.md): Configure the OIDC ID Token Validator node to authenticate users by validating an OpenID Connect ID token from an external identity provider. - [OpenID Connect node (deprecated)](https://docs.pingidentity.com/auth-node-ref/8.1/am-only/oidc.md): Deprecated. The OpenID Connect node authenticated PingAM users against OpenID Connect providers using the authorization code grant. - [Opt-out Multi-Factor Authentication node](https://docs.pingidentity.com/auth-node-ref/8.1/opt-out-multi-factor.md): Configure the Opt-out Multi-Factor Authentication node to record a user's decision to skip multi-factor authentication on their current device. - [OTP Collector Decision node](https://docs.pingidentity.com/auth-node-ref/8.1/otp-collector-decision.md): Configure the OTP Collector Decision node to prompt users to enter a one-time passcode and verify whether it is valid. - [OTP Email Sender node](https://docs.pingidentity.com/auth-node-ref/8.1/otp-email-sender.md): Configure the OTP Email Sender node to send a one-time passcode to a user's email address as part of an authentication journey. - [OTP SMS Sender node](https://docs.pingidentity.com/auth-node-ref/8.1/otp-sms-sender.md): Configure the OTP SMS Sender node to send a one-time passcode to a user's mobile phone through an email-to-SMS gateway. - [Page node](https://docs.pingidentity.com/auth-node-ref/8.1/page.md): Configure the Page node to combine multiple input-collecting nodes onto a single page displayed to users during an authentication journey. - [Passthrough Authentication node](https://docs.pingidentity.com/auth-node-ref/8.1/passthrough-authentication.md): Configure the Passthrough Authentication node to authenticate users against a third-party service through a connector, supporting password migration without forcing resets. - [Password Collector node](https://docs.pingidentity.com/auth-node-ref/8.1/am-only/password-collector.md): Use the Password Collector node in PingAM to prompt users to enter their password and write it to transient state for use later in the journey. - [Patch Object node](https://docs.pingidentity.com/auth-node-ref/8.1/patch-object.md): Configure the Patch Object node to update the attributes of an existing managed identity object. - [Persistent Cookie Decision node](https://docs.pingidentity.com/auth-node-ref/8.1/persistent-cookie-decision.md): Configure the Persistent Cookie Decision node to check for a persistent cookie, verify its JWT signature, and authenticate users without requiring them to log in again. - [PingOne Authorize node](https://docs.pingidentity.com/auth-node-ref/8.1/pingone/pingone-authorize.md): Configure the PingOne Authorize node to send policy decision requests to a PingOne Authorize environment and evaluate authorization levels in a journey. - [PingOne Create User node](https://docs.pingidentity.com/auth-node-ref/8.1/pingone/pingone-create-user.md): Configure the PingOne Create User node to create new users, including their profile data or as anonymized users, in the PingOne platform during a journey. - [PingOne Credentials Delete Wallet node](https://docs.pingidentity.com/auth-node-ref/8.1/pingone/pingone-cred-delete-wallet.md): Configure the PingOne Credentials Delete Wallet node to remove a paired digital wallet from a PingOne user during a journey. - [PingOne Credentials Find Wallets node](https://docs.pingidentity.com/auth-node-ref/8.1/pingone/pingone-cred-find-wallet.md): Configure the PingOne Credentials Find Wallets node to list all paired digital wallets for a PingOne user during a journey. - [PingOne Credentials Issue node](https://docs.pingidentity.com/auth-node-ref/8.1/pingone/pingone-cred-issue.md): Configure the PingOne Credentials Issue node to create and issue a PingOne digital credential to a user's paired wallet during a journey. - [PingOne Credentials nodes](https://docs.pingidentity.com/auth-node-ref/8.1/pingone/pingone-cred-overview.md): Overview of the PingOne Credentials nodes for implementing digital wallet pairing, credential management, and credential verification in PingAM journeys. - [PingOne Credentials Pair Wallet node](https://docs.pingidentity.com/auth-node-ref/8.1/pingone/pingone-cred-pair-wallet.md): Configure the PingOne Credentials Pair Wallet node to pair a PingOne digital wallet with a PingOne user ID during a journey. - [PingOne Credentials Revoke node](https://docs.pingidentity.com/auth-node-ref/8.1/pingone/pingone-cred-revoke.md): Configure the PingOne Credentials Revoke node to revoke existing PingOne credentials for a user during a journey. - [PingOne Credentials Update node](https://docs.pingidentity.com/auth-node-ref/8.1/pingone/pingone-cred-update.md): Configure the PingOne Credentials Update node to update an existing PingOne credential for a user during a journey. - [PingOne Credentials Verification node](https://docs.pingidentity.com/auth-node-ref/8.1/pingone/pingone-cred-verify.md): Configure the PingOne Credentials Verification node to initiate verification of PingOne credentials through QR code or push notification during a journey. - [PingOne DaVinci API node](https://docs.pingidentity.com/auth-node-ref/8.1/pingone/pingone-davinci.md): Configure the PingOne DaVinci API node to trigger a PingOne DaVinci flow through API integration from within an PingAM authentication journey. - [PingOne Delete User node](https://docs.pingidentity.com/auth-node-ref/8.1/pingone/pingone-delete-user.md): Configure the PingOne Delete User node to delete a user from the PingOne platform during a journey using the PingOne user ID from shared state. - [PingOne Identity Match node](https://docs.pingidentity.com/auth-node-ref/8.1/pingone/pingone-identity-match.md): Configure the PingOne Identity Match node to verify that a user exists in both PingAM and PingOne, and populate shared state with the user's PingOne ID. - [PingOne node (deprecated)](https://docs.pingidentity.com/auth-node-ref/8.1/pingone/pingone.md): Deprecated. The PingOne node established a federated OIDC connection between PingOne and PingAM to delegate user flows to PingAM. - [PingOne Protect Evaluation node](https://docs.pingidentity.com/auth-node-ref/8.1/pingone/pingone-protect-evaluation.md): Configure the PingOne Protect Evaluation node to calculate a risk score and recommended actions for an authentication event using PingOne Protect risk policies. - [PingOne Protect Initialize node](https://docs.pingidentity.com/auth-node-ref/8.1/pingone/pingone-protect-initialize.md): Configure the PingOne Protect Initialize node to instruct the client to initialize the PingOne Protect SDK to gather device signals and contextual information for risk evaluation. - [PingOne Protect Result node](https://docs.pingidentity.com/auth-node-ref/8.1/pingone/pingone-protect-result.md): Configure the PingOne Protect Result node to update the risk evaluation configuration or completion status of a PingOne Protect risk evaluation in progress. - [PingOne Service](https://docs.pingidentity.com/auth-node-ref/8.1/pingone/pingone-service.md): Configure the PingOne Service to integrate PingOne Credentials and PingOne DaVinci nodes in PingAM authentication journeys. - [PingOne Verify Authentication node (deprecated)](https://docs.pingidentity.com/auth-node-ref/8.1/pingone/pingone-verify-authn.md): Deprecated. The PingOne Verify Authentication node integrated PingOne Verify biometric authentication into a journey by comparing a stored picture to a live selfie. - [PingOne Verify Completion Decision node](https://docs.pingidentity.com/auth-node-ref/8.1/pingone/pingone-verify-completion-decision.md): Configure the PingOne Verify Completion Decision node to check the status of a user's most recent PingOne Verify identity verification transaction and return an outcome. - [PingOne Verify Evaluation node](https://docs.pingidentity.com/auth-node-ref/8.1/pingone/pingone-verify-evaluation.md): Configure the PingOne Verify Evaluation node to initiate or continue an identity verification transaction using PingOne Verify, with delivery through QR code, email, or SMS. - [PingOne Verify Proofing node (deprecated)](https://docs.pingidentity.com/auth-node-ref/8.1/pingone/pingone-verify-proof.md): Deprecated. The PingOne Verify Proofing node integrated PingOne Verify for Government ID, Facial Comparison, and Liveness verification in a journey. - [PingOne Verify service (deprecated)](https://docs.pingidentity.com/auth-node-ref/8.1/pingone/pingone-verify-service.md): Deprecated. The PingOne Verify service configured PingOne Verify nodes to provide Government ID, Facial Comparison, and Liveness user verification in PingAM journeys. - [Platform Password node](https://docs.pingidentity.com/auth-node-ref/8.1/platform-password.md): Configure the Platform Password node to prompt users to enter their password, optionally validate it against password policies, and store it in the shared node state. - [Platform Username node](https://docs.pingidentity.com/auth-node-ref/8.1/platform-username.md): Configure the Platform Username node to prompt users to enter their username, optionally validate it against username policies, and store it in the shared node state. - [Policy Decision node](https://docs.pingidentity.com/auth-node-ref/8.1/policy-decision.md): Configure the Policy Decision node to evaluate authorization policies during an authentication journey based on identity attributes or environmental conditions such as time of day. - [Polling Wait node](https://docs.pingidentity.com/auth-node-ref/8.1/polling-wait.md): Configure the Polling Wait node to pause an authentication journey for a specified number of seconds, for example while waiting for a push notification response or external system. - [Profile Completeness Decision node](https://docs.pingidentity.com/auth-node-ref/8.1/profile-completeness-decision.md): Configure the Profile Completeness Decision node to check whether the percentage of completed user profile fields meets a configured threshold, for use in progressive profile flows. - [Provision Dynamic Account node](https://docs.pingidentity.com/auth-node-ref/8.1/am-only/provision-dynamic-account.md): Use the Provision Dynamic Account node in PingAM to create a user account after SAML2 or social authentication using attributes from the identity provider. - [Provision IDM Account node (deprecated)](https://docs.pingidentity.com/auth-node-ref/8.1/am-only/provision-IDM-account.md): Deprecated. The Provision IDM Account node redirected users to a PingIDM instance to provision an account after social authentication in PingAM. - [Push Registration node](https://docs.pingidentity.com/auth-node-ref/8.1/push-registration.md): Configure the Push Registration node to register a user's mobile device for multi-factor authentication using push notifications. - [Push Result Verifier node](https://docs.pingidentity.com/auth-node-ref/8.1/push-result-verifier.md): Configure the Push Result Verifier node to validate a user's response to a previously sent push notification message during multi-factor authentication. - [Push Sender node](https://docs.pingidentity.com/auth-node-ref/8.1/push-sender.md): Configure the Push Sender node to send push notification messages to a registered device for multi-factor authentication, supporting tap-to-accept, challenge code, and biometric options. - [Push Wait node](https://docs.pingidentity.com/auth-node-ref/8.1/push-wait.md): Configure the Push Wait node to pause authentication for a specified number of seconds while waiting for a user to respond to a push notification request. - [Query Filter Decision node](https://docs.pingidentity.com/auth-node-ref/8.1/query-filter-decision.md): Configure the Query Filter Decision node to check whether a user's profile attributes match a specified query filter, for use in progressive profile and conditional journey flows. - [Query Parameter node](https://docs.pingidentity.com/auth-node-ref/8.1/query-parameter.md): Configure the Query Parameter node to extract URL query parameter values into node state properties, enabling journey customization based on URL parameters. - [RADIUS Challenge Collector node](https://docs.pingidentity.com/auth-node-ref/8.1/radius-challenge-collector.md): Configure the RADIUS Challenge Collector node to present RADIUS server challenge messages to users and collect their responses, such as one-time passwords. - [RADIUS Decision node](https://docs.pingidentity.com/auth-node-ref/8.1/radius-decision.md): Configure the RADIUS Decision node to authenticate users against a RADIUS server, handling Access-Accept, Access-Reject, and Access-Challenge responses. - [reCAPTCHA Enterprise node](https://docs.pingidentity.com/auth-node-ref/8.1/recaptcha-enterprise.md): Configure the reCAPTCHA Enterprise node to add Google reCAPTCHA Enterprise bot detection and risk scoring to authentication journeys. - [Recovery Code Collector Decision node](https://docs.pingidentity.com/auth-node-ref/8.1/recovery-code-collector-decision.md): Configure the Recovery Code Collector Decision node to let users authenticate with a backup recovery code when they can't access their registered MFA device. - [Recovery Code Display node](https://docs.pingidentity.com/auth-node-ref/8.1/recovery-code-display.md): Configure the Recovery Code Display node to show generated MFA recovery codes to users during device registration so they can save them for future use. - [Register Logout Webhook node](https://docs.pingidentity.com/auth-node-ref/8.1/register-logout-webhook.md): Configure the Register Logout Webhook node to register a webhook that triggers when a user's session ends due to logout or session expiry. - [Register Thing node](https://docs.pingidentity.com/auth-node-ref/8.1/self-managed/register-thing.md): Use the Register Thing node in PingAM to register IoT devices and gateways by validating a JWT and creating or updating the thing identity with a confirmation key. - [Remove Session Properties node](https://docs.pingidentity.com/auth-node-ref/8.1/remove-session-properties.md): Configure the Remove Session Properties node to delete one or more named properties from the user session during an authentication journey. - [Request Header node](https://docs.pingidentity.com/auth-node-ref/8.1/request-header.md): Configure the Request Header node to extract HTTP request header values into node state properties, enabling journey customization based on incoming request headers. - [Required Attributes Present node](https://docs.pingidentity.com/auth-node-ref/8.1/required-attributes-present.md): Configure the Required Attributes Present node to check whether all attributes required to create an identity resource object exist in the shared node state. - [Retry Limit Decision node](https://docs.pingidentity.com/auth-node-ref/8.1/retry-limit-decision.md): Configure the Retry Limit Decision node to track failed authentication attempts and allow retries up to a configurable limit before rejecting the user. - [RSA SecurID node](https://docs.pingidentity.com/auth-node-ref/8.1/rsa-securid.md): Configure the RSA SecurID node to perform multi-factor authentication by integrating with RSA Cloud Access Service or RSA Authentication Manager. - [SAML2 Authentication node](https://docs.pingidentity.com/auth-node-ref/8.1/saml2.md): Configure the SAML2 Authentication node to integrate SAML 2.0 SP-initiated single sign-on into an PingAM authentication journey. - [Scripted Decision node](https://docs.pingidentity.com/auth-node-ref/8.1/scripted-decision.md): Configure the Scripted Decision node to run a custom server-side script in an PingAM authentication journey and set the node outcome. - [Select Identity Provider node](https://docs.pingidentity.com/auth-node-ref/8.1/select-identity-provider.md): Configure the Select Identity Provider node to present users with a list of enabled social identity providers to choose from during authentication. - [Set Custom Cookie node](https://docs.pingidentity.com/auth-node-ref/8.1/set-custom-cookie.md): Configure the Set Custom Cookie node to store a custom cookie on the client during an PingAM authentication journey, including in no-session journeys. - [Set Error Details node](https://docs.pingidentity.com/auth-node-ref/8.1/set-error-details.md): Configure the Set Error Details node to add a custom error message, extra key-value fields, and custom response headers to the JSON response when a journey ends in error. - [Set Failure Details node](https://docs.pingidentity.com/auth-node-ref/8.1/set-failure-details.md): Configure the Set Failure Details node to add a custom failure message, extra key-value fields, and custom response headers to the JSON response when a journey ends in failure. - [Set Logout Details node](https://docs.pingidentity.com/auth-node-ref/8.1/set-logout-details.md): Configure the Set Logout Details node to add extra key-value fields to the JSON response when a journey ends with the user logging out. - [Set Persistent Cookie node](https://docs.pingidentity.com/auth-node-ref/8.1/set-persistent-cookie.md): Configure the Set Persistent Cookie node to create a signed and encrypted persistent JWT cookie on the client after successful PingAM authentication. - [Set Session Properties node](https://docs.pingidentity.com/auth-node-ref/8.1/set-session-properties.md): Configure the Set Session Properties node to add key-value properties to the authenticated session or update session timeout settings during an PingAM journey. - [Set State node](https://docs.pingidentity.com/auth-node-ref/8.1/set-state.md): Configure the Set State node to set or overwrite attribute values in the shared state during an PingAM authentication journey. - [Set Success Details node](https://docs.pingidentity.com/auth-node-ref/8.1/set-success-details.md): Configure the Set Success Details node to add extra key-value fields and custom response headers to the JSON response on successful authentication. - [Social Facebook node (deprecated)](https://docs.pingidentity.com/auth-node-ref/8.1/am-only/social-facebook.md): Deprecated. The Social Facebook node authenticated PingAM users with Facebook using OAuth 2.0, preconfigured with Facebook endpoints. - [Social Google node (deprecated)](https://docs.pingidentity.com/auth-node-ref/8.1/am-only/social-google.md): Deprecated. The Social Google node authenticated PingAM users with Google using OAuth 2.0, preconfigured with Google endpoints. - [Social Ignore Profile node (deprecated)](https://docs.pingidentity.com/auth-node-ref/8.1/am-only/social-ignore-profile.md): Deprecated. The Social Ignore Profile node issued a PingAM SSO token after social authentication without checking for a local user profile. - [Social Provider Handler node](https://docs.pingidentity.com/auth-node-ref/8.1/social-provider-handler.md): Configure the Social Provider Handler node to authenticate users with a selected social identity provider, validate tokens, and match accounts in PingAM. - [State Metadata node](https://docs.pingidentity.com/auth-node-ref/8.1/state-metadata.md): Configure the State Metadata node to return selected shared node state attributes as metadata in the authentication response. - [Success node](https://docs.pingidentity.com/auth-node-ref/8.1/success.md): The Success node is a required terminal node that marks the end of a successful authentication journey in PingAM. - [Success URL node](https://docs.pingidentity.com/auth-node-ref/8.1/success-url.md): Configure the Success URL node to redirect users to a specified URL when authentication succeeds in an PingAM journey. - [Terms and Conditions Decision node](https://docs.pingidentity.com/auth-node-ref/8.1/terms-and-conditions-decision.md): Configure the Terms and Conditions Decision node to verify that a user has accepted the active terms and conditions before proceeding in a journey. - [Time Since Decision node](https://docs.pingidentity.com/auth-node-ref/8.1/time-since-decision.md): Configure the Time Since Decision node to check whether a specified amount of time has elapsed since a user's account was created, for use in progressive profile journeys. - [Timer Start node](https://docs.pingidentity.com/auth-node-ref/8.1/timer-start.md): Configure the Timer Start node to record the current time in a named property, enabling elapsed-time measurements with the Timer Stop node in a journey. - [Timer Stop node](https://docs.pingidentity.com/auth-node-ref/8.1/timer-stop.md): Configure the Timer Stop node to record the time elapsed since a corresponding Timer Start node and expose the result as a named metric. - [Update Journey Timeout node](https://docs.pingidentity.com/auth-node-ref/8.1/update-journey-timeout.md): Configure the Update Journey Timeout node to override or adjust the maximum duration of a journey session, for example to give users time to retrieve documents. - [Username Collector node](https://docs.pingidentity.com/auth-node-ref/8.1/am-only/username-collector.md): Use the Username Collector node in PingAM to prompt users to enter their username and write it to shared state for use later in the journey. - [WebAuthn Authentication node](https://docs.pingidentity.com/auth-node-ref/8.1/webauthn-authentication.md): Configure the WebAuthn Authentication node to let users authenticate with a registered FIDO device, including passkeys and hardware security keys, in PingAM. - [WebAuthn Device Storage node](https://docs.pingidentity.com/auth-node-ref/8.1/webauthn-device-storage.md): Configure the WebAuthn Device Storage node to write FIDO2 device data from transient state to a user's profile after registration. - [WebAuthn Registration node](https://docs.pingidentity.com/auth-node-ref/8.1/webauthn-registration.md): Configure the WebAuthn Registration node to let users register FIDO2 devices, such as fingerprint scanners or hardware security keys, for use during authentication. - [Write Federation Information node](https://docs.pingidentity.com/auth-node-ref/8.1/write-federation-information.md): Configure the Write Federation Information node to create a persistent SAML 2.0 account link between a remote identity provider and a local service provider account. - [Zero Page Login Collector node](https://docs.pingidentity.com/auth-node-ref/8.1/zero-page-login-collector.md): Configure the Zero Page Login Collector node to extract username and password credentials from HTTP headers in an incoming authentication request. ## Auth Node Ref 8 - [Accept Terms and Conditions node](https://docs.pingidentity.com/auth-node-ref/8/accept-terms-and-conditions.md): Prompts users to accept the active terms and conditions during registration or sign-on journeys in PingAM. - [Account Active Decision node](https://docs.pingidentity.com/auth-node-ref/8/account-active-decision.md): Checks whether a user account is both active and unlocked, routing the journey along True or False outcome paths in PingAM. - [Account Lockout node](https://docs.pingidentity.com/auth-node-ref/8/account-lockout.md): Locks or unlocks a user account profile in PingAM, supporting both persistent and duration-based lockout. - [Agent Data Store Decision node](https://docs.pingidentity.com/auth-node-ref/8/agent-data-store-decision.md): Authenticates agents such as PingGateway and Java or web agents against the agent profile data store in PingAM. - [Amster Jwt Decision node](https://docs.pingidentity.com/auth-node-ref/8/am-only/amster-jwt-decision.md): Configure the Amster JWT Decision node to authenticate Amster connections to PingAM using SSH key pairs stored in an authorized_keys file. - [Anonymous Session Upgrade node](https://docs.pingidentity.com/auth-node-ref/8/anonymous-session-upgrade.md): Upgrades an anonymous session to a non-anonymous session in PingAM journeys. - [Anonymous User Mapping node](https://docs.pingidentity.com/auth-node-ref/8/anonymous-user-mapping.md): Maps unauthenticated users to a named anonymous account in PingAM, enabling limited access without credentials. - [Attribute Collector node](https://docs.pingidentity.com/auth-node-ref/8/attribute-collector.md): Collects user attribute values during a journey for use in registration or profile update flows in PingAM. - [Attribute Present Decision node](https://docs.pingidentity.com/auth-node-ref/8/attribute-present-decision.md): Checks whether a specified attribute, including private attributes such as password, is present on a user object in PingAM. - [Attribute Value Decision node](https://docs.pingidentity.com/auth-node-ref/8/attribute-value-decision.md): Verifies that a user attribute satisfies a configured condition, such as presence or equality, during journeys in PingAM. - [Auth Level Decision node](https://docs.pingidentity.com/auth-node-ref/8/auth-level-decision.md): Compares the current authentication level against a configured threshold to route journeys in PingAM. - [Authenticate Thing node](https://docs.pingidentity.com/auth-node-ref/8/self-managed/authenticate-thing.md): Use the Authenticate Thing node in PingAM to authenticate IoT devices and gateways using Proof of Possession JWT or Client Assertion. - [Authentication node reference](https://docs.pingidentity.com/auth-node-ref/8/auth-nodes.md) - [CAPTCHA node](https://docs.pingidentity.com/auth-node-ref/8/captcha.md): Configure the CAPTCHA node to verify CAPTCHA responses from providers such as Google reCAPTCHA v2, reCAPTCHA v3, and hCaptcha during PingAM authentication journeys. - [Certificate Collector node](https://docs.pingidentity.com/auth-node-ref/8/certificate-collector.md): Configure the Certificate Collector node to collect X.509 digital certificates from incoming requests for use as authentication credentials in PingAM journeys. - [Certificate User Extractor node](https://docs.pingidentity.com/auth-node-ref/8/certificate-user-extractor.md): Configure the Certificate User Extractor node to extract a user identifier from an X.509 certificate and match it against an identity in the identity store. - [Certificate Validation node](https://docs.pingidentity.com/auth-node-ref/8/certificate-validation.md): Configure the Certificate Validation node to validate X.509 digital certificates against LDAP stores, CRLs, and OCSP in PingAM authentication journeys. - [Choice Collector node](https://docs.pingidentity.com/auth-node-ref/8/choice-collector.md): Configure the Choice Collector node to present users with two or more selectable options during an authentication journey in PingAM. - [Combined MFA Registration node](https://docs.pingidentity.com/auth-node-ref/8/combined-mfa-registration.md): Configure the Combined MFA Registration node to register a device for both push notification and OATH one-time password multi-factor authentication in a single step. - [Configuration Provider node](https://docs.pingidentity.com/auth-node-ref/8/config-provider.md): Configure the Configuration Provider node to use a script to dynamically build the configuration of another node and replace it at runtime in an PingAM journey. - [Consent Collector node](https://docs.pingidentity.com/auth-node-ref/8/consent-collector.md): Configure the Consent Collector node to prompt users to consent to sharing their profile data during registration or progressive profile flows in PingAM. - [Cookie Presence Decision node](https://docs.pingidentity.com/auth-node-ref/8/cookie-presence-decision.md): Configure the Cookie Presence Decision node to check whether a named cookie exists in an incoming authentication request and route the journey accordingly. - [Create Object node](https://docs.pingidentity.com/auth-node-ref/8/create-object.md): Create a new managed object using attributes collected during an authentication journey, such as during user registration. - [Create Password node](https://docs.pingidentity.com/auth-node-ref/8/am-only/create-password.md): Deprecated. The Create Password node prompted users to create a password during social account provisioning in PingAM. - [Data Store Decision node](https://docs.pingidentity.com/auth-node-ref/8/data-store-decision.md): Authenticate users by verifying that their credentials match those stored in the configured data store for the realm. - [Debug node](https://docs.pingidentity.com/auth-node-ref/8/am-only/debug.md): Use the Debug node in PingAM to display shared node state, identity universalId, and transaction ID during authentication tree testing. - [Device Binding node](https://docs.pingidentity.com/auth-node-ref/8/device-binding.md): Register one or more devices to a user's account by generating a cryptographic key pair and storing the public key in the user's profile. - [Device Binding Storage node](https://docs.pingidentity.com/auth-node-ref/8/device-binding-storage.md): Persist collected device binding data, including the device public key, to a user's profile in the identity store. - [Device Geofencing node](https://docs.pingidentity.com/auth-node-ref/8/device-geofencing.md): Compare collected device location data against configured trusted locations to determine whether the user's device is within an allowed geofence. - [Device Location Match node](https://docs.pingidentity.com/auth-node-ref/8/device-location-match.md): Compare collected device location data against previously saved locations in the user's profile to verify the device is within an acceptable range. - [Device Match node](https://docs.pingidentity.com/auth-node-ref/8/device-match.md): Compare collected device metadata against saved trusted device profiles in a user's account using built-in or custom script matching. - [Device Profile Collector node](https://docs.pingidentity.com/auth-node-ref/8/device-profile-collector.md): Collect metadata about the user's device, including hardware details, OS information, and optionally location, for use in device profiling journeys. - [Device Profile Save node](https://docs.pingidentity.com/auth-node-ref/8/device-profile-save.md): Persist collected device metadata and location data to a user's profile in the identity store for use in future authentications. - [Device Signing Verifier node](https://docs.pingidentity.com/auth-node-ref/8/device-signing-verifier.md): Verify possession of a registered bound device by challenging it to sign a value with the private key paired to a stored public key. - [Device Tampering Verification node](https://docs.pingidentity.com/auth-node-ref/8/device-tampering-verification.md): Evaluate a device tampering score to determine whether a device has been rooted, jailbroken, or otherwise poses a security risk. - [Display Username node](https://docs.pingidentity.com/auth-node-ref/8/display-username.md): Look up and display a user's username based on a different identifying attribute, such as an email address, to support username recovery flows. - [Email Suspend node](https://docs.pingidentity.com/auth-node-ref/8/email-suspend.md): Sends an email using a template and suspends the authentication journey until the user clicks a resume link in that email. - [Email Template node](https://docs.pingidentity.com/auth-node-ref/8/email-template.md): Sends an email based on a configured template without suspending the authentication journey, for example to deliver a welcome message after registration. - [Enable Device Management node](https://docs.pingidentity.com/auth-node-ref/8/enable-device-management.md): Controls which MFA device types a user must authenticate with before they can remove a registered MFA device, allowing journeys to relax or remove this restriction. - [Failure node](https://docs.pingidentity.com/auth-node-ref/8/failure.md): Terminal node that ends an authentication journey in failure, redirecting the user to a failure URL and optionally incrementing the account lockout counter. - [Failure URL node](https://docs.pingidentity.com/auth-node-ref/8/failure-url.md): Specifies the URL to redirect end users to when authentication fails in a journey. - [Flow Control node](https://docs.pingidentity.com/auth-node-ref/8/flow-control.md): Randomly routes a configurable percentage of authentication requests between two journey paths, enabling controlled rollout and testing of new authentication flows. - [Get Authenticator App node](https://docs.pingidentity.com/auth-node-ref/8/get-authenticator-app.md): Displays a prompt with links to download an authenticator app from the Apple App Store or Google Play Store as part of a push authentication journey. - [Get Session Data node](https://docs.pingidentity.com/auth-node-ref/8/get-session-data.md): Retrieves a value from a user's existing session by key and stores it in the shared node state, for use during session upgrade journeys. - [HOTP Generator node](https://docs.pingidentity.com/auth-node-ref/8/hotp-generator.md): Generates a random numeric one-time passcode (OTP) of a specified length for use in authentication journeys, storing it in shared state for delivery by email or SMS. - [Identify Existing User node](https://docs.pingidentity.com/auth-node-ref/8/identify-existing-user.md): Looks up a user identity by a specified attribute such as email address and writes the matching identifier to shared node state, for use in forgotten password flows. - [Identity Assertion node](https://docs.pingidentity.com/auth-node-ref/8/identity-assertion-node.md): Integrates PingGateway into an authentication journey to support identity assertion with third-party services such as Windows Desktop SSO and Kerberos. - [Increment Login Count node](https://docs.pingidentity.com/auth-node-ref/8/increment-login-count.md): Increments the successful login count on a managed identity object, enabling journeys to track authentication frequency for use with the Login Count Decision node. - [Inner Tree Evaluator node](https://docs.pingidentity.com/auth-node-ref/8/inner-tree-evaluator.md): Configure the Inner Tree Evaluator node to nest authentication journeys as children within a parent journey in PingAM. - [KBA Decision node](https://docs.pingidentity.com/auth-node-ref/8/kba-decision.md): Configure the KBA Decision node to check whether a user account has the minimum number of knowledge-based authentication security questions defined. - [KBA Definition node](https://docs.pingidentity.com/auth-node-ref/8/kba-definition.md): Configure the KBA Definition node to collect knowledge-based authentication questions and answers from users during registration or profile update. - [KBA Verification node](https://docs.pingidentity.com/auth-node-ref/8/kba-verification.md): Configure the KBA Verification node to present knowledge-based authentication questions to users and verify their answers against stored responses. - [Kerberos node](https://docs.pingidentity.com/auth-node-ref/8/self-managed/kerberos.md): Use the Kerberos node in PingAM to enable desktop single sign-on through SPNEGO, allowing users authenticated with a Kerberos KDC to sign on without re-entering credentials. - [LDAP Decision node](https://docs.pingidentity.com/auth-node-ref/8/ldap-decision.md): Configure the LDAP Decision node to verify a username and password against an LDAP user data store and check for expired or locked accounts. - [Legacy CAPTCHA node](https://docs.pingidentity.com/auth-node-ref/8/legacy-captcha.md): Configure the Legacy CAPTCHA node to verify a CAPTCHA response token and create a CAPTCHA callback. Superseded by the CAPTCHA node. - [Legacy Social Provider Handler node](https://docs.pingidentity.com/auth-node-ref/8/legacy-social-provider-handler.md): Configure the Legacy Social Provider Handler node to authenticate users with a social identity provider and collect profile attributes. Use the Social Provider Handler node for new journeys. - [Login Count Decision node](https://docs.pingidentity.com/auth-node-ref/8/login-count-decision.md): Configure the Login Count Decision node to trigger a journey action when a user's successful login count reaches a specified threshold. - [Message node](https://docs.pingidentity.com/auth-node-ref/8/message.md): Configure the Message node to present a custom, localized message with positive and negative response buttons that users must click to proceed through a journey. - [Meter node](https://docs.pingidentity.com/auth-node-ref/8/meter.md): Configure the Meter node to increment a custom metric key each time journey evaluation passes through the node, enabling trend monitoring with tools such as Prometheus. - [MFA Registration Options node](https://docs.pingidentity.com/auth-node-ref/8/mfa-registration-options.md): Configure the MFA Registration Options node to let users register a multi-factor authentication device or skip registration during a journey. - [Modify Auth Level node](https://docs.pingidentity.com/auth-node-ref/8/modify-auth-level.md): Configure the Modify Auth Level node to increase or decrease the authentication level value in the current session. - [OATH Device Storage node](https://docs.pingidentity.com/auth-node-ref/8/oath-device-storage.md): Configure the OATH Device Storage node to persist a registered OATH device profile from the shared state into the user's account. - [OATH Registration node](https://docs.pingidentity.com/auth-node-ref/8/oath-registration.md): Configure the OATH Registration node to let users register a device for OATH-based multi-factor authentication using a QR code scan. - [OATH Token Verifier node](https://docs.pingidentity.com/auth-node-ref/8/oath-token-verifier.md): Configure the OATH Token Verifier node to request and verify a one-time passcode generated by a registered OATH device using TOTP or HOTP. - [OAuth 2.0 node](https://docs.pingidentity.com/auth-node-ref/8/am-only/oauth2.md): Deprecated. The OAuth 2.0 node authenticated PingAM users against OAuth 2.0-compliant social identity providers using the authorization code grant. - [OIDC ID Token Validator node](https://docs.pingidentity.com/auth-node-ref/8/oidc-idtoken-validator.md): Configure the OIDC ID Token Validator node to authenticate users by validating an OpenID Connect ID token from an external identity provider. - [OpenID Connect node](https://docs.pingidentity.com/auth-node-ref/8/am-only/oidc.md): Deprecated. The OpenID Connect node authenticated PingAM users against OpenID Connect providers using the authorization code grant. - [Opt-out Multi-Factor Authentication node](https://docs.pingidentity.com/auth-node-ref/8/opt-out-multi-factor.md): Configure the Opt-out Multi-Factor Authentication node to record a user's decision to skip multi-factor authentication on their current device. - [OTP Collector Decision node](https://docs.pingidentity.com/auth-node-ref/8/otp-collector-decision.md): Configure the OTP Collector Decision node to prompt users to enter a one-time passcode and verify whether it is valid. - [OTP Email Sender node](https://docs.pingidentity.com/auth-node-ref/8/otp-email-sender.md): Configure the OTP Email Sender node to send a one-time passcode to a user's email address as part of an authentication journey. - [OTP SMS Sender node](https://docs.pingidentity.com/auth-node-ref/8/otp-sms-sender.md): Configure the OTP SMS Sender node to send a one-time passcode to a user's mobile phone through an email-to-SMS gateway. - [Page node](https://docs.pingidentity.com/auth-node-ref/8/page.md): Configure the Page node to combine multiple input-collecting nodes onto a single page displayed to users during an authentication journey. - [Passthrough Authentication node](https://docs.pingidentity.com/auth-node-ref/8/passthrough-authentication.md): Configure the Pass-through Authentication node to authenticate users against a third-party service through a connector, supporting password migration without forcing resets. - [Password Collector node](https://docs.pingidentity.com/auth-node-ref/8/am-only/password-collector.md): Use the Password Collector node in PingAM to prompt users to enter their password and write it to transient state for use later in the journey. - [Patch Object node](https://docs.pingidentity.com/auth-node-ref/8/patch-object.md): Configure the Patch Object node to update the attributes of an existing managed identity object. - [Persistent Cookie Decision node](https://docs.pingidentity.com/auth-node-ref/8/persistent-cookie-decision.md): Configure the Persistent Cookie Decision node to check for a persistent cookie, verify its JWT signature, and authenticate users without requiring them to log in again. - [PingOne Create User node](https://docs.pingidentity.com/auth-node-ref/8/pingone-create-user.md) - [PingOne Delete User node](https://docs.pingidentity.com/auth-node-ref/8/pingone-delete-user.md) - [PingOne Identity Match node](https://docs.pingidentity.com/auth-node-ref/8/pingone-identity-match.md) - [PingOne Protect Evaluation node](https://docs.pingidentity.com/auth-node-ref/8/pingone-protect-evaluation.md) - [PingOne Protect Initialize node](https://docs.pingidentity.com/auth-node-ref/8/pingone-protect-initialize.md) - [PingOne Protect Result node](https://docs.pingidentity.com/auth-node-ref/8/pingone-protect-result.md) - [PingOne Verify Completion Decision node](https://docs.pingidentity.com/auth-node-ref/8/pingone-verify-completion-decision.md) - [PingOne Verify Evaluation node](https://docs.pingidentity.com/auth-node-ref/8/pingone-verify-evaluation.md) - [Platform Password node](https://docs.pingidentity.com/auth-node-ref/8/platform-password.md): Configure the Platform Password node to prompt users to enter their password, optionally validate it against password policies, and store it in the shared node state. - [Platform Username node](https://docs.pingidentity.com/auth-node-ref/8/platform-username.md): Configure the Platform Username node to prompt users to enter their username, optionally validate it against username policies, and store it in the shared node state. - [Polling Wait node](https://docs.pingidentity.com/auth-node-ref/8/polling-wait.md): Configure the Polling Wait node to pause an authentication journey for a specified number of seconds, for example while waiting for a push notification response or external system. - [Profile Completeness Decision node](https://docs.pingidentity.com/auth-node-ref/8/profile-completeness-decision.md): Configure the Profile Completeness Decision node to check whether the percentage of completed user profile fields meets a configured threshold, for use in progressive profile flows. - [Provision Dynamic Account node](https://docs.pingidentity.com/auth-node-ref/8/am-only/provision-dynamic-account.md): Use the Provision Dynamic Account node in PingAM to create a user account after SAML2 or social authentication using attributes from the identity provider. - [Provision IDM Account node](https://docs.pingidentity.com/auth-node-ref/8/am-only/provision-IDM-account.md): Deprecated. The Provision IDM Account node redirected users to a PingIDM instance to provision an account after social authentication in PingAM. - [Push Registration node](https://docs.pingidentity.com/auth-node-ref/8/push-registration.md): Configure the Push Registration node to register a user's mobile device for multi-factor authentication using push notifications. - [Push Result Verifier node](https://docs.pingidentity.com/auth-node-ref/8/push-result-verifier.md): Configure the Push Result Verifier node to validate a user's response to a previously sent push notification message during multi-factor authentication. - [Push Sender node](https://docs.pingidentity.com/auth-node-ref/8/push-sender.md): Configure the Push Sender node to send push notification messages to a registered device for multi-factor authentication, supporting tap-to-accept, challenge code, and biometric options. - [Push Wait node](https://docs.pingidentity.com/auth-node-ref/8/push-wait.md): Configure the Push Wait node to pause authentication for a specified number of seconds while waiting for a user to respond to a push notification request. - [Query Filter Decision node](https://docs.pingidentity.com/auth-node-ref/8/query-filter-decision.md): Configure the Query Filter Decision node to check whether a user's profile attributes match a specified query filter, for use in progressive profile and conditional journey flows. - [Query Parameter node](https://docs.pingidentity.com/auth-node-ref/8/query-parameter.md): Configure the Query Parameter node to extract URL query parameter values into node state properties, enabling journey customization based on URL parameters. - [reCAPTCHA Enterprise node](https://docs.pingidentity.com/auth-node-ref/8/recaptcha-enterprise.md): Configure the reCAPTCHA Enterprise node to add Google reCAPTCHA Enterprise bot detection and risk scoring to authentication journeys. - [Recovery Code Collector Decision node](https://docs.pingidentity.com/auth-node-ref/8/recovery-code-collector-decision.md): Configure the Recovery Code Collector Decision node to let users authenticate with a backup recovery code when they can't access their registered MFA device. - [Recovery Code Display node](https://docs.pingidentity.com/auth-node-ref/8/recovery-code-display.md): Configure the Recovery Code Display node to show generated MFA recovery codes to users during device registration so they can save them for future use. - [Register Logout Webhook node](https://docs.pingidentity.com/auth-node-ref/8/register-logout-webhook.md): Configure the Register Logout Webhook node to register a webhook that triggers when a user's session ends due to logout or session expiry. - [Register Thing node](https://docs.pingidentity.com/auth-node-ref/8/self-managed/register-thing.md): Use the Register Thing node in PingAM to register IoT devices and gateways by validating a JWT and creating or updating the thing identity with a confirmation key. - [Remove Session Properties node](https://docs.pingidentity.com/auth-node-ref/8/remove-session-properties.md): Configure the Remove Session Properties node to delete one or more named properties from the user session during an authentication journey. - [Request Header node](https://docs.pingidentity.com/auth-node-ref/8/request-header.md): Configure the Request Header node to extract HTTP request header values into node state properties, enabling journey customization based on incoming request headers. - [Required Attributes Present node](https://docs.pingidentity.com/auth-node-ref/8/required-attributes-present.md): Configure the Required Attributes Present node to check whether all attributes required to create an identity resource object exist in the shared node state. - [Retry Limit Decision node](https://docs.pingidentity.com/auth-node-ref/8/retry-limit-decision.md): Configure the Retry Limit Decision node to track failed authentication attempts and allow retries up to a configurable limit before rejecting the user. - [SAML2 Authentication node](https://docs.pingidentity.com/auth-node-ref/8/saml2.md): Configure the SAML2 Authentication node to integrate SAML 2.0 SP-initiated single sign-on into an PingAM authentication journey. - [Scripted Decision node](https://docs.pingidentity.com/auth-node-ref/8/scripted-decision.md): Configure the Scripted Decision node to run a custom server-side script in an PingAM authentication journey and set the node outcome. - [Select Identity Provider node](https://docs.pingidentity.com/auth-node-ref/8/select-identity-provider.md): Configure the Select Identity Provider node to present users with a list of enabled social identity providers to choose from during authentication. - [Set Custom Cookie node](https://docs.pingidentity.com/auth-node-ref/8/set-custom-cookie.md): Configure the Set Custom Cookie node to store a custom cookie on the client during an PingAM authentication journey, including in no-session journeys. - [Set Error Details node](https://docs.pingidentity.com/auth-node-ref/8/set-error-details.md): Configure the Set Error Details node to add a custom error message, extra key-value fields, and custom response headers to the JSON response when a journey ends in error. - [Set Failure Details node](https://docs.pingidentity.com/auth-node-ref/8/set-failure-details.md): Configure the Set Failure Details node to add a custom failure message, extra key-value fields, and custom response headers to the JSON response when a journey ends in failure. - [Set Persistent Cookie node](https://docs.pingidentity.com/auth-node-ref/8/set-persistent-cookie.md): Configure the Set Persistent Cookie node to create a signed and encrypted persistent JWT cookie on the client after successful PingAM authentication. - [Set Session Properties node](https://docs.pingidentity.com/auth-node-ref/8/set-session-properties.md): Configure the Set Session Properties node to add key-value properties to the authenticated session or update session timeout settings during an PingAM journey. - [Set State node](https://docs.pingidentity.com/auth-node-ref/8/set-state.md): Configure the Set State node to set or overwrite attribute values in the shared state during an PingAM authentication journey. - [Set Success Details node](https://docs.pingidentity.com/auth-node-ref/8/set-success-details.md): Configure the Set Success Details node to add extra key-value fields and custom response headers to the JSON response on successful authentication. - [Social Facebook node](https://docs.pingidentity.com/auth-node-ref/8/am-only/social-facebook.md): Deprecated. The Social Facebook node authenticated PingAM users with Facebook using OAuth 2.0, preconfigured with Facebook endpoints. - [Social Google node](https://docs.pingidentity.com/auth-node-ref/8/am-only/social-google.md): Deprecated. The Social Google node authenticated PingAM users with Google using OAuth 2.0, preconfigured with Google endpoints. - [Social Ignore Profile node](https://docs.pingidentity.com/auth-node-ref/8/am-only/social-ignore-profile.md): Deprecated. The Social Ignore Profile node issued a PingAM SSO token after social authentication without checking for a local user profile. - [Social Provider Handler node](https://docs.pingidentity.com/auth-node-ref/8/social-provider-handler.md): Configure the Social Provider Handler node to authenticate users with a selected social identity provider, validate tokens, and match accounts in PingAM. - [State Metadata node](https://docs.pingidentity.com/auth-node-ref/8/state-metadata.md): Configure the State Metadata node to return selected shared node state attributes as metadata in the authentication response. - [Success node](https://docs.pingidentity.com/auth-node-ref/8/success.md): The Success node is a required terminal node that marks the end of a successful authentication journey in PingAM. - [Success URL node](https://docs.pingidentity.com/auth-node-ref/8/success-url.md): Configure the Success URL node to redirect users to a specified URL when authentication succeeds in an PingAM journey. - [Terms and Conditions Decision node](https://docs.pingidentity.com/auth-node-ref/8/terms-and-conditions-decision.md): Configure the Terms and Conditions Decision node to verify that a user has accepted the active terms and conditions before proceeding in a journey. - [Time Since Decision node](https://docs.pingidentity.com/auth-node-ref/8/time-since-decision.md): Configure the Time Since Decision node to check whether a specified amount of time has elapsed since a user's account was created, for use in progressive profile journeys. - [Timer Start node](https://docs.pingidentity.com/auth-node-ref/8/timer-start.md): Configure the Timer Start node to record the current time in a named property, enabling elapsed-time measurements with the Timer Stop node in a journey. - [Timer Stop node](https://docs.pingidentity.com/auth-node-ref/8/timer-stop.md): Configure the Timer Stop node to record the time elapsed since a corresponding Timer Start node and expose the result as a named metric. - [Update Journey Timeout node](https://docs.pingidentity.com/auth-node-ref/8/update-journey-timeout.md): Configure the Update Journey Timeout node to override or adjust the maximum duration of a journey session, for example to give users time to retrieve documents. - [Username Collector node](https://docs.pingidentity.com/auth-node-ref/8/am-only/username-collector.md): Use the Username Collector node in PingAM to prompt users to enter their username and write it to shared state for use later in the journey. - [WebAuthn Authentication node](https://docs.pingidentity.com/auth-node-ref/8/webauthn-authentication.md): Configure the WebAuthn Authentication node to let users authenticate with a registered FIDO device, including passkeys and hardware security keys, in PingAM. - [WebAuthn Device Storage node](https://docs.pingidentity.com/auth-node-ref/8/webauthn-device-storage.md): Configure the WebAuthn Device Storage node to write FIDO2 device data from transient state to a user's profile after registration. - [WebAuthn Registration node](https://docs.pingidentity.com/auth-node-ref/8/webauthn-registration.md): Configure the WebAuthn Registration node to let users register FIDO2 devices, such as fingerprint scanners or hardware security keys, for use during authentication. - [Write Federation Information node](https://docs.pingidentity.com/auth-node-ref/8/write-federation-information.md): Configure the Write Federation Information node to create a persistent SAML 2.0 account link between a remote identity provider and a local service provider account. - [Zero Page Login Collector node](https://docs.pingidentity.com/auth-node-ref/8/zero-page-login-collector.md): Configure the Zero Page Login Collector node to extract username and password credentials from HTTP headers in an incoming authentication request. ## Auth Node Ref 7.5 - [Accept Terms and Conditions node](https://docs.pingidentity.com/auth-node-ref/7.5/accept-terms-and-conditions.md): Prompts users to accept the active terms and conditions during registration or sign-on journeys in PingAM. - [Account Active Decision node](https://docs.pingidentity.com/auth-node-ref/7.5/account-active-decision.md): Checks whether a user account is both active and unlocked, routing the journey along True or False outcome paths in PingAM. - [Account Lockout node](https://docs.pingidentity.com/auth-node-ref/7.5/account-lockout.md): Locks or unlocks a user account profile in PingAM, supporting both persistent and duration-based lockout. - [Agent Data Store Decision node](https://docs.pingidentity.com/auth-node-ref/7.5/agent-data-store-decision.md): Authenticates agents such as PingGateway and Java or web agents against the agent profile data store in PingAM. - [Anonymous Session Upgrade node](https://docs.pingidentity.com/auth-node-ref/7.5/anonymous-session-upgrade.md): Upgrades an anonymous session to a non-anonymous session in PingAM journeys. - [Anonymous User Mapping node](https://docs.pingidentity.com/auth-node-ref/7.5/anonymous-user-mapping.md): Maps unauthenticated users to a named anonymous account in PingAM, enabling limited access without credentials. - [Attribute Collector node](https://docs.pingidentity.com/auth-node-ref/7.5/attribute-collector.md): Collects user attribute values during a journey for use in registration or profile update flows in PingAM. - [Attribute Present Decision node](https://docs.pingidentity.com/auth-node-ref/7.5/attribute-present-decision.md): Checks whether a specified attribute, including private attributes such as password, is present on a user object in PingAM. - [Attribute Value Decision node](https://docs.pingidentity.com/auth-node-ref/7.5/attribute-value-decision.md): Verifies that a user attribute satisfies a configured condition, such as presence or equality, during journeys in PingAM. - [Auth Level Decision node](https://docs.pingidentity.com/auth-node-ref/7.5/auth-level-decision.md): Compares the current authentication level against a configured threshold to route journeys in PingAM. - [Authenticate Thing node](https://docs.pingidentity.com/auth-node-ref/7.5/self-managed/authenticate-thing.md): Use the Authenticate Thing node in PingAM to authenticate IoT devices and gateways using Proof of Possession JWT or Client Assertion. - [Authentication node reference](https://docs.pingidentity.com/auth-node-ref/7.5/auth-nodes.md) - [CAPTCHA node](https://docs.pingidentity.com/auth-node-ref/7.5/captcha.md): Configure the CAPTCHA node to verify CAPTCHA responses from providers such as Google reCAPTCHA v2, reCAPTCHA v3, and hCaptcha during PingAM authentication journeys. - [Certificate Collector node](https://docs.pingidentity.com/auth-node-ref/7.5/self-managed/certificate-collector.md): Configure the Certificate Collector node to collect X.509 digital certificates from incoming requests for use as authentication credentials in PingAM journeys. - [Certificate User Extractor node](https://docs.pingidentity.com/auth-node-ref/7.5/self-managed/certificate-user-extractor.md): Configure the Certificate User Extractor node to extract a user identifier from an X.509 certificate and match it against an identity in the identity store. - [Certificate Validation node](https://docs.pingidentity.com/auth-node-ref/7.5/self-managed/certificate-validation.md): Configure the Certificate Validation node to validate X.509 digital certificates against LDAP stores, CRLs, and OCSP in PingAM authentication journeys. - [Choice Collector node](https://docs.pingidentity.com/auth-node-ref/7.5/choice-collector.md): Configure the Choice Collector node to present users with two or more selectable options during an authentication journey in PingAM. - [Combined MFA Registration node](https://docs.pingidentity.com/auth-node-ref/7.5/combined-mfa-registration.md): Configure the Combined MFA Registration node to register a device for both push notification and OATH one-time password multi-factor authentication in a single step. - [Configuration Provider node](https://docs.pingidentity.com/auth-node-ref/7.5/config-provider.md): Configure the Configuration Provider node to use a script to dynamically build the configuration of another node and replace it at runtime in an PingAM journey. - [Consent Collector node](https://docs.pingidentity.com/auth-node-ref/7.5/consent-collector.md): Configure the Consent Collector node to prompt users to consent to sharing their profile data during registration or progressive profile flows in PingAM. - [Cookie Presence Decision node](https://docs.pingidentity.com/auth-node-ref/7.5/cookie-presence-decision.md): Configure the Cookie Presence Decision node to check whether a named cookie exists in an incoming authentication request and route the journey accordingly. - [Create Object node](https://docs.pingidentity.com/auth-node-ref/7.5/create-object.md): Create a new managed object using attributes collected during an authentication journey, such as during user registration. - [Create Password node](https://docs.pingidentity.com/auth-node-ref/7.5/am-only/create-password.md): Deprecated. The Create Password node prompted users to create a password during social account provisioning in PingAM. - [Data Store Decision node](https://docs.pingidentity.com/auth-node-ref/7.5/data-store-decision.md): Authenticate users by verifying that their credentials match those stored in the configured data store for the realm. - [Debug node](https://docs.pingidentity.com/auth-node-ref/7.5/am-only/debug.md): Use the Debug node in PingAM to display shared node state, identity universalId, and transaction ID during authentication tree testing. - [Device Binding node](https://docs.pingidentity.com/auth-node-ref/7.5/device-binding.md): Register one or more devices to a user's account by generating a cryptographic key pair and storing the public key in the user's profile. - [Device Binding Storage node](https://docs.pingidentity.com/auth-node-ref/7.5/device-binding-storage.md): Persist collected device binding data, including the device public key, to a user's profile in the identity store. - [Device Geofencing node](https://docs.pingidentity.com/auth-node-ref/7.5/device-geofencing.md): Compare collected device location data against configured trusted locations to determine whether the user's device is within an allowed geofence. - [Device Location Match node](https://docs.pingidentity.com/auth-node-ref/7.5/device-profile-location-match.md) - [Device Match node](https://docs.pingidentity.com/auth-node-ref/7.5/device-match.md): Compare collected device metadata against saved trusted device profiles in a user's account using built-in or custom script matching. - [Device Profile Collector node](https://docs.pingidentity.com/auth-node-ref/7.5/device-profile-collector.md): Collect metadata about the user's device, including hardware details, OS information, and optionally location, for use in device profiling journeys. - [Device Profile Save node](https://docs.pingidentity.com/auth-node-ref/7.5/device-profile-save.md): Persist collected device metadata and location data to a user's profile in the identity store for use in future authentications. - [Device Signing Verifier node](https://docs.pingidentity.com/auth-node-ref/7.5/device-signing-verifier.md): Verify possession of a registered bound device by challenging it to sign a value with the private key paired to a stored public key. - [Device Tampering Verification node](https://docs.pingidentity.com/auth-node-ref/7.5/device-tampering-verification.md): Evaluate a device tampering score to determine whether a device has been rooted, jailbroken, or otherwise poses a security risk. - [Display Username node](https://docs.pingidentity.com/auth-node-ref/7.5/display-username.md): Look up and display a user's username based on a different identifying attribute, such as an email address, to support username recovery flows. - [Email Suspend node](https://docs.pingidentity.com/auth-node-ref/7.5/email-suspend.md): Sends an email using a template and suspends the authentication journey until the user clicks a resume link in that email. - [Email Template node](https://docs.pingidentity.com/auth-node-ref/7.5/email-template.md): Sends an email based on a configured template without suspending the authentication journey, for example to deliver a welcome message after registration. - [Failure node](https://docs.pingidentity.com/auth-node-ref/7.5/failure.md): Terminal node that ends an authentication journey in failure, redirecting the user to a failure URL and optionally incrementing the account lockout counter. - [Failure URL node](https://docs.pingidentity.com/auth-node-ref/7.5/failure-url.md): Specifies the URL to redirect end users to when authentication fails in a journey. - [Get Authenticator App node](https://docs.pingidentity.com/auth-node-ref/7.5/get-authenticator-app.md): Displays a prompt with links to download an authenticator app from the Apple App Store or Google Play Store as part of a push authentication journey. - [Get Session Data node](https://docs.pingidentity.com/auth-node-ref/7.5/get-session-data.md): Retrieves a value from a user's existing session by key and stores it in the shared node state, for use during session upgrade journeys. - [HOTP Generator node](https://docs.pingidentity.com/auth-node-ref/7.5/hotp-generator.md): Generates a random numeric one-time passcode (OTP) of a specified length for use in authentication journeys, storing it in shared state for delivery by email or SMS. - [Identify Existing User node](https://docs.pingidentity.com/auth-node-ref/7.5/identify-existing-user.md): Looks up a user identity by a specified attribute such as email address and writes the matching identifier to shared node state, for use in forgotten password flows. - [Identity Assertion node](https://docs.pingidentity.com/auth-node-ref/7.5/identity-assertion-node.md): Integrates PingGateway into an authentication journey to support identity assertion with third-party services such as Windows Desktop SSO and Kerberos. - [Increment Login Count node](https://docs.pingidentity.com/auth-node-ref/7.5/increment-login-count.md): Increments the successful login count on a managed identity object, enabling journeys to track authentication frequency for use with the Login Count Decision node. - [Inner Tree Evaluator node](https://docs.pingidentity.com/auth-node-ref/7.5/inner-tree-evaluator.md): Configure the Inner Tree Evaluator node to nest authentication journeys as children within a parent journey in PingAM. - [KBA Decision node](https://docs.pingidentity.com/auth-node-ref/7.5/kba-decision.md): Configure the KBA Decision node to check whether a user account has the minimum number of knowledge-based authentication security questions defined. - [KBA Definition node](https://docs.pingidentity.com/auth-node-ref/7.5/kba-definition.md): Configure the KBA Definition node to collect knowledge-based authentication questions and answers from users during registration or profile update. - [KBA Verification node](https://docs.pingidentity.com/auth-node-ref/7.5/kba-verification.md): Configure the KBA Verification node to present knowledge-based authentication questions to users and verify their answers against stored responses. - [Kerberos node](https://docs.pingidentity.com/auth-node-ref/7.5/self-managed/kerberos.md): Use the Kerberos node in PingAM to enable desktop single sign-on through SPNEGO, allowing users authenticated with a Kerberos KDC to sign on without re-entering credentials. - [LDAP Decision node](https://docs.pingidentity.com/auth-node-ref/7.5/ldap-decision.md): Configure the LDAP Decision node to verify a username and password against an LDAP user data store and check for expired or locked accounts. - [Legacy CAPTCHA node](https://docs.pingidentity.com/auth-node-ref/7.5/legacy-captcha.md): Configure the Legacy CAPTCHA node to verify a CAPTCHA response token and create a CAPTCHA callback. Superseded by the CAPTCHA node. - [Legacy Social Provider Handler node](https://docs.pingidentity.com/auth-node-ref/7.5/legacy-social-provider-handler.md): Configure the Legacy Social Provider Handler node to authenticate users with a social identity provider and collect profile attributes. Use the Social Provider Handler node for new journeys. - [Login Count Decision node](https://docs.pingidentity.com/auth-node-ref/7.5/login-count-decision.md): Configure the Login Count Decision node to trigger a journey action when a user's successful login count reaches a specified threshold. - [Message node](https://docs.pingidentity.com/auth-node-ref/7.5/message.md): Configure the Message node to present a custom, localized message with positive and negative response buttons that users must click to proceed through a journey. - [Meter node](https://docs.pingidentity.com/auth-node-ref/7.5/meter.md): Configure the Meter node to increment a custom metric key each time journey evaluation passes through the node, enabling trend monitoring with tools such as Prometheus. - [MFA Registration Options node](https://docs.pingidentity.com/auth-node-ref/7.5/mfa-registration-options.md): Configure the MFA Registration Options node to let users register a multi-factor authentication device or skip registration during a journey. - [Modify Auth Level node](https://docs.pingidentity.com/auth-node-ref/7.5/modify-auth-level.md): Configure the Modify Auth Level node to increase or decrease the authentication level value in the current session. - [OATH Device Storage node](https://docs.pingidentity.com/auth-node-ref/7.5/oath-device-storage.md): Configure the OATH Device Storage node to persist a registered OATH device profile from the shared state into the user's account. - [OATH Registration node](https://docs.pingidentity.com/auth-node-ref/7.5/oath-registration.md): Configure the OATH Registration node to let users register a device for OATH-based multi-factor authentication using a QR code scan. - [OATH Token Verifier node](https://docs.pingidentity.com/auth-node-ref/7.5/oath-token-verifier.md): Configure the OATH Token Verifier node to request and verify a one-time passcode generated by a registered OATH device using TOTP or HOTP. - [OAuth 2.0 node](https://docs.pingidentity.com/auth-node-ref/7.5/am-only/oauth2.md): Deprecated. The OAuth 2.0 node authenticated PingAM users against OAuth 2.0-compliant social identity providers using the authorization code grant. - [OIDC ID Token Validator node](https://docs.pingidentity.com/auth-node-ref/7.5/oidc-idtoken-validator.md): Configure the OIDC ID Token Validator node to authenticate users by validating an OpenID Connect ID token from an external identity provider. - [OpenID Connect node](https://docs.pingidentity.com/auth-node-ref/7.5/am-only/oidc.md): Deprecated. The OpenID Connect node authenticated PingAM users against OpenID Connect providers using the authorization code grant. - [Opt-out Multi-Factor Authentication node](https://docs.pingidentity.com/auth-node-ref/7.5/opt-out-multi-factor.md): Configure the Opt-out Multi-Factor Authentication node to record a user's decision to skip multi-factor authentication on their current device. - [OTP Collector Decision node](https://docs.pingidentity.com/auth-node-ref/7.5/otp-collector-decision.md): Configure the OTP Collector Decision node to prompt users to enter a one-time passcode and verify whether it is valid. - [OTP Email Sender node](https://docs.pingidentity.com/auth-node-ref/7.5/otp-email-sender.md): Configure the OTP Email Sender node to send a one-time passcode to a user's email address as part of an authentication journey. - [OTP SMS Sender node](https://docs.pingidentity.com/auth-node-ref/7.5/otp-sms-sender.md): Configure the OTP SMS Sender node to send a one-time passcode to a user's mobile phone through an email-to-SMS gateway. - [Page node](https://docs.pingidentity.com/auth-node-ref/7.5/page.md): Configure the Page node to combine multiple input-collecting nodes onto a single page displayed to users during an authentication journey. - [Pass-through Authentication node](https://docs.pingidentity.com/auth-node-ref/7.5/passthrough-authentication.md): Configure the Pass-through Authentication node to authenticate users against a third-party service through a connector, supporting password migration without forcing resets. - [Password Collector node](https://docs.pingidentity.com/auth-node-ref/7.5/am-only/password-collector.md): Use the Password Collector node in PingAM to prompt users to enter their password and write it to transient state for use later in the journey. - [Patch Object node](https://docs.pingidentity.com/auth-node-ref/7.5/patch-object.md): Configure the Patch Object node to update the attributes of an existing managed identity object. - [Persistent Cookie Decision node](https://docs.pingidentity.com/auth-node-ref/7.5/persistent-cookie-decision.md): Configure the Persistent Cookie Decision node to check for a persistent cookie, verify its JWT signature, and authenticate users without requiring them to log in again. - [PingOne Protect Evaluation node](https://docs.pingidentity.com/auth-node-ref/7.5/pingone-protect-evaluation.md) - [PingOne Protect Initialization node](https://docs.pingidentity.com/auth-node-ref/7.5/pingone-protect-initialize.md) - [PingOne Protect Result node](https://docs.pingidentity.com/auth-node-ref/7.5/pingone-protect-result.md) - [Platform Password node](https://docs.pingidentity.com/auth-node-ref/7.5/platform-password.md): Configure the Platform Password node to prompt users to enter their password, optionally validate it against password policies, and store it in the shared node state. - [Platform Username node](https://docs.pingidentity.com/auth-node-ref/7.5/platform-username.md): Configure the Platform Username node to prompt users to enter their username, optionally validate it against username policies, and store it in the shared node state. - [Polling Wait node](https://docs.pingidentity.com/auth-node-ref/7.5/polling-wait.md): Configure the Polling Wait node to pause an authentication journey for a specified number of seconds, for example while waiting for a push notification response or external system. - [Profile Completeness Decision node](https://docs.pingidentity.com/auth-node-ref/7.5/profile-completeness-decision.md): Configure the Profile Completeness Decision node to check whether the percentage of completed user profile fields meets a configured threshold, for use in progressive profile flows. - [Provision Dynamic Account node](https://docs.pingidentity.com/auth-node-ref/7.5/am-only/provision-dynamic-account.md): Use the Provision Dynamic Account node in PingAM to create a user account after SAML2 or social authentication using attributes from the identity provider. - [Provision IDM Account node](https://docs.pingidentity.com/auth-node-ref/7.5/am-only/provision-IDM-account.md): Deprecated. The Provision IDM Account node redirected users to a PingIDM instance to provision an account after social authentication in PingAM. - [Push Registration node](https://docs.pingidentity.com/auth-node-ref/7.5/push-registration.md): Configure the Push Registration node to register a user's mobile device for multi-factor authentication using push notifications. - [Push Result Verifier node](https://docs.pingidentity.com/auth-node-ref/7.5/push-result-verifier.md): Configure the Push Result Verifier node to validate a user's response to a previously sent push notification message during multi-factor authentication. - [Push Sender node](https://docs.pingidentity.com/auth-node-ref/7.5/push-sender.md): Configure the Push Sender node to send push notification messages to a registered device for multi-factor authentication, supporting tap-to-accept, challenge code, and biometric options. - [Push Wait node](https://docs.pingidentity.com/auth-node-ref/7.5/push-wait.md): Configure the Push Wait node to pause authentication for a specified number of seconds while waiting for a user to respond to a push notification request. - [Query Filter Decision node](https://docs.pingidentity.com/auth-node-ref/7.5/query-filter-decision.md): Configure the Query Filter Decision node to check whether a user's profile attributes match a specified query filter, for use in progressive profile and conditional journey flows. - [Query Parameter node](https://docs.pingidentity.com/auth-node-ref/7.5/query-parameter.md): Configure the Query Parameter node to extract URL query parameter values into node state properties, enabling journey customization based on URL parameters. - [Recovery Code Collector Decision node](https://docs.pingidentity.com/auth-node-ref/7.5/recovery-code-collector-decision.md): Configure the Recovery Code Collector Decision node to let users authenticate with a backup recovery code when they can't access their registered MFA device. - [Recovery Code Display node](https://docs.pingidentity.com/auth-node-ref/7.5/recovery-code-display.md): Configure the Recovery Code Display node to show generated MFA recovery codes to users during device registration so they can save them for future use. - [Register Logout Webhook node](https://docs.pingidentity.com/auth-node-ref/7.5/register-logout-webhook.md): Configure the Register Logout Webhook node to register a webhook that triggers when a user's session ends due to logout or session expiry. - [Register Thing node](https://docs.pingidentity.com/auth-node-ref/7.5/self-managed/register-thing.md): Use the Register Thing node in PingAM to register IoT devices and gateways by validating a JWT and creating or updating the thing identity with a confirmation key. - [Remove Session Properties node](https://docs.pingidentity.com/auth-node-ref/7.5/remove-session-properties.md): Configure the Remove Session Properties node to delete one or more named properties from the user session during an authentication journey. - [Request Header node](https://docs.pingidentity.com/auth-node-ref/7.5/request-header.md): Configure the Request Header node to extract HTTP request header values into node state properties, enabling journey customization based on incoming request headers. - [Required Attributes Present node](https://docs.pingidentity.com/auth-node-ref/7.5/required-attributes-present.md): Configure the Required Attributes Present node to check whether all attributes required to create an identity resource object exist in the shared node state. - [Retry Limit Decision node](https://docs.pingidentity.com/auth-node-ref/7.5/retry-limit-decision.md): Configure the Retry Limit Decision node to track failed authentication attempts and allow retries up to a configurable limit before rejecting the user. - [SAML2 Authentication node](https://docs.pingidentity.com/auth-node-ref/7.5/saml2.md): Configure the SAML2 Authentication node to integrate SAML 2.0 SP-initiated single sign-on into an PingAM authentication journey. - [Scripted Decision node](https://docs.pingidentity.com/auth-node-ref/7.5/scripted-decision.md): Configure the Scripted Decision node to run a custom server-side script in an PingAM authentication journey and set the node outcome. - [Select Identity Provider node](https://docs.pingidentity.com/auth-node-ref/7.5/select-identity-provider.md): Configure the Select Identity Provider node to present users with a list of enabled social identity providers to choose from during authentication. - [Set Custom Cookie node](https://docs.pingidentity.com/auth-node-ref/7.5/set-custom-cookie.md): Configure the Set Custom Cookie node to store a custom cookie on the client during an PingAM authentication journey, including in no-session journeys. - [Set Persistent Cookie node](https://docs.pingidentity.com/auth-node-ref/7.5/set-persistent-cookie.md): Configure the Set Persistent Cookie node to create a signed and encrypted persistent JWT cookie on the client after successful PingAM authentication. - [Set Session Properties node](https://docs.pingidentity.com/auth-node-ref/7.5/set-session-properties.md): Configure the Set Session Properties node to add key-value properties to the authenticated session or update session timeout settings during an PingAM journey. - [Social Facebook node](https://docs.pingidentity.com/auth-node-ref/7.5/am-only/social-facebook.md): Deprecated. The Social Facebook node authenticated PingAM users with Facebook using OAuth 2.0, preconfigured with Facebook endpoints. - [Social Google node](https://docs.pingidentity.com/auth-node-ref/7.5/am-only/social-google.md): Deprecated. The Social Google node authenticated PingAM users with Google using OAuth 2.0, preconfigured with Google endpoints. - [Social Ignore Profile node](https://docs.pingidentity.com/auth-node-ref/7.5/am-only/social-ignore-profile.md): Deprecated. The Social Ignore Profile node issued a PingAM SSO token after social authentication without checking for a local user profile. - [Social Provider Handler node](https://docs.pingidentity.com/auth-node-ref/7.5/social-provider-handler.md): Configure the Social Provider Handler node to authenticate users with a selected social identity provider, validate tokens, and match accounts in PingAM. - [State Metadata node](https://docs.pingidentity.com/auth-node-ref/7.5/state-metadata.md): Configure the State Metadata node to return selected shared node state attributes as metadata in the authentication response. - [Success node](https://docs.pingidentity.com/auth-node-ref/7.5/success.md): The Success node is a required terminal node that marks the end of a successful authentication journey in PingAM. - [Success URL node](https://docs.pingidentity.com/auth-node-ref/7.5/success-url.md): Configure the Success URL node to redirect users to a specified URL when authentication succeeds in an PingAM journey. - [Terms and Conditions Decision node](https://docs.pingidentity.com/auth-node-ref/7.5/terms-and-conditions-decision.md): Configure the Terms and Conditions Decision node to verify that a user has accepted the active terms and conditions before proceeding in a journey. - [Time Since Decision node](https://docs.pingidentity.com/auth-node-ref/7.5/time-since-decision.md): Configure the Time Since Decision node to check whether a specified amount of time has elapsed since a user's account was created, for use in progressive profile journeys. - [Timer Start node](https://docs.pingidentity.com/auth-node-ref/7.5/timer-start.md): Configure the Timer Start node to record the current time in a named property, enabling elapsed-time measurements with the Timer Stop node in a journey. - [Timer Stop node](https://docs.pingidentity.com/auth-node-ref/7.5/timer-stop.md): Configure the Timer Stop node to record the time elapsed since a corresponding Timer Start node and expose the result as a named metric. - [Username Collector node](https://docs.pingidentity.com/auth-node-ref/7.5/am-only/username-collector.md): Use the Username Collector node in PingAM to prompt users to enter their username and write it to shared state for use later in the journey. - [WebAuthn Authentication node](https://docs.pingidentity.com/auth-node-ref/7.5/webauthn-authentication.md): Configure the WebAuthn Authentication node to let users authenticate with a registered FIDO device, including passkeys and hardware security keys, in PingAM. - [WebAuthn Device Storage node](https://docs.pingidentity.com/auth-node-ref/7.5/webauthn-device-storage.md): Configure the WebAuthn Device Storage node to write FIDO2 device data from transient state to a user's profile after registration. - [WebAuthn Registration node](https://docs.pingidentity.com/auth-node-ref/7.5/webauthn-registration.md): Configure the WebAuthn Registration node to let users register FIDO2 devices, such as fingerprint scanners or hardware security keys, for use during authentication. - [Write Federation Information node](https://docs.pingidentity.com/auth-node-ref/7.5/write-federation-information.md): Configure the Write Federation Information node to create a persistent SAML 2.0 account link between a remote identity provider and a local service provider account. - [Zero Page Login Collector node](https://docs.pingidentity.com/auth-node-ref/7.5/zero-page-login-collector.md): Configure the Zero Page Login Collector node to extract username and password credentials from HTTP headers in an incoming authentication request. ## Auth Node Ref 7.4 - [Accept Terms and Conditions node](https://docs.pingidentity.com/auth-node-ref/7.4/accept-terms-and-conditions.md) - [Account Active Decision node](https://docs.pingidentity.com/auth-node-ref/7.4/account-active-decision.md) - [Account Lockout node](https://docs.pingidentity.com/auth-node-ref/7.4/account-lockout.md) - [Agent Data Store Decision node](https://docs.pingidentity.com/auth-node-ref/7.4/agent-data-store-decision.md) - [Anonymous Session Upgrade node](https://docs.pingidentity.com/auth-node-ref/7.4/anonymous-session-upgrade.md) - [Anonymous User Mapping node](https://docs.pingidentity.com/auth-node-ref/7.4/anonymous-user-mapping.md) - [Attribute Collector node](https://docs.pingidentity.com/auth-node-ref/7.4/attribute-collector.md) - [Attribute Present Decision node](https://docs.pingidentity.com/auth-node-ref/7.4/attribute-present-decision.md) - [Attribute Value Decision node](https://docs.pingidentity.com/auth-node-ref/7.4/attribute-value-decision.md) - [Auth Level Decision node](https://docs.pingidentity.com/auth-node-ref/7.4/auth-level-decision.md) - [Authenticate Thing node](https://docs.pingidentity.com/auth-node-ref/7.4/self-managed/authenticate-thing.md) - [Authentication node reference](https://docs.pingidentity.com/auth-node-ref/7.4/auth-nodes.md) - [Authentication node reference](https://docs.pingidentity.com/auth-node-ref/7.4/overview.md) - [CAPTCHA node](https://docs.pingidentity.com/auth-node-ref/7.4/captcha.md) - [Certificate Collector node](https://docs.pingidentity.com/auth-node-ref/7.4/self-managed/certificate-collector.md) - [Certificate User Extractor node](https://docs.pingidentity.com/auth-node-ref/7.4/self-managed/certificate-user-extractor.md) - [Certificate Validation node](https://docs.pingidentity.com/auth-node-ref/7.4/self-managed/certificate-validation.md) - [Choice Collector node](https://docs.pingidentity.com/auth-node-ref/7.4/choice-collector.md) - [Combined MFA Registration node](https://docs.pingidentity.com/auth-node-ref/7.4/combined-mfa-registration.md) - [Configuration Provider node](https://docs.pingidentity.com/auth-node-ref/7.4/config-provider.md) - [Consent Collector node](https://docs.pingidentity.com/auth-node-ref/7.4/consent-collector.md) - [Cookie Presence Decision node](https://docs.pingidentity.com/auth-node-ref/7.4/cookie-presence-decision.md) - [Create Object node](https://docs.pingidentity.com/auth-node-ref/7.4/create-object.md) - [Create Password node](https://docs.pingidentity.com/auth-node-ref/7.4/am-only/create-password.md) - [Data Store Decision node](https://docs.pingidentity.com/auth-node-ref/7.4/data-store-decision.md) - [Debug node](https://docs.pingidentity.com/auth-node-ref/7.4/am-only/debug.md) - [Device Binding node](https://docs.pingidentity.com/auth-node-ref/7.4/device-binding.md) - [Device Binding Storage node](https://docs.pingidentity.com/auth-node-ref/7.4/device-binding-storage.md) - [Device Geofencing node](https://docs.pingidentity.com/auth-node-ref/7.4/device-geofencing.md) - [Device Location Match node](https://docs.pingidentity.com/auth-node-ref/7.4/device-profile-location-match.md) - [Device Match node](https://docs.pingidentity.com/auth-node-ref/7.4/device-match.md) - [Device Profile Collector node](https://docs.pingidentity.com/auth-node-ref/7.4/device-profile-collector.md) - [Device Profile Save node](https://docs.pingidentity.com/auth-node-ref/7.4/device-profile-save.md) - [Device Signing Verifier node](https://docs.pingidentity.com/auth-node-ref/7.4/device-signing-verifier.md) - [Device Tampering Verification node](https://docs.pingidentity.com/auth-node-ref/7.4/device-tampering-verification.md) - [Display Username node](https://docs.pingidentity.com/auth-node-ref/7.4/display-username.md) - [Email Suspend node](https://docs.pingidentity.com/auth-node-ref/7.4/email-suspend.md) - [Email Template node](https://docs.pingidentity.com/auth-node-ref/7.4/email-template.md) - [Failure node](https://docs.pingidentity.com/auth-node-ref/7.4/failure.md) - [Failure URL node](https://docs.pingidentity.com/auth-node-ref/7.4/failure-url.md) - [Get Authenticator App node](https://docs.pingidentity.com/auth-node-ref/7.4/get-authenticator-app.md) - [Get Session Data node](https://docs.pingidentity.com/auth-node-ref/7.4/get-session-data.md) - [HOTP Generator node](https://docs.pingidentity.com/auth-node-ref/7.4/hotp-generator.md) - [Identify Existing User node](https://docs.pingidentity.com/auth-node-ref/7.4/identify-existing-user.md) - [Increment Login Count node](https://docs.pingidentity.com/auth-node-ref/7.4/increment-login-count.md) - [Inner Tree Evaluator node](https://docs.pingidentity.com/auth-node-ref/7.4/inner-tree-evaluator.md) - [KBA Decision node](https://docs.pingidentity.com/auth-node-ref/7.4/kba-decision.md) - [KBA Definition node](https://docs.pingidentity.com/auth-node-ref/7.4/kba-definition.md) - [KBA Verification node](https://docs.pingidentity.com/auth-node-ref/7.4/kba-verification.md) - [Kerberos node](https://docs.pingidentity.com/auth-node-ref/7.4/self-managed/kerberos.md) - [LDAP Decision node](https://docs.pingidentity.com/auth-node-ref/7.4/ldap-decision.md) - [Legacy CAPTCHA node](https://docs.pingidentity.com/auth-node-ref/7.4/legacy-captcha.md) - [Login Count Decision node](https://docs.pingidentity.com/auth-node-ref/7.4/login-count-decision.md) - [Message node](https://docs.pingidentity.com/auth-node-ref/7.4/message.md) - [Meter node](https://docs.pingidentity.com/auth-node-ref/7.4/meter.md) - [MFA Registration Options node](https://docs.pingidentity.com/auth-node-ref/7.4/mfa-registration-options.md) - [Modify Auth Level node](https://docs.pingidentity.com/auth-node-ref/7.4/modify-auth-level.md) - [OATH Device Storage node](https://docs.pingidentity.com/auth-node-ref/7.4/oath-device-storage.md) - [OATH Registration node](https://docs.pingidentity.com/auth-node-ref/7.4/oath-registration.md) - [OATH Token Verifier node](https://docs.pingidentity.com/auth-node-ref/7.4/oath-token-verifier.md) - [OAuth 2.0 node](https://docs.pingidentity.com/auth-node-ref/7.4/am-only/oauth2.md) - [OIDC ID Token Validator node](https://docs.pingidentity.com/auth-node-ref/7.4/oidc-idtoken-validator.md) - [OpenID Connect node](https://docs.pingidentity.com/auth-node-ref/7.4/am-only/oidc.md) - [Opt-out Multi-Factor Authentication node](https://docs.pingidentity.com/auth-node-ref/7.4/opt-out-multi-factor.md) - [OTP Collector Decision node](https://docs.pingidentity.com/auth-node-ref/7.4/otp-collector-decision.md) - [OTP Email Sender node](https://docs.pingidentity.com/auth-node-ref/7.4/otp-email-sender.md) - [OTP SMS Sender node](https://docs.pingidentity.com/auth-node-ref/7.4/otp-sms-sender.md) - [Page node](https://docs.pingidentity.com/auth-node-ref/7.4/page.md) - [Pass-through Authentication node](https://docs.pingidentity.com/auth-node-ref/7.4/passthrough-authentication.md) - [Password Collector node](https://docs.pingidentity.com/auth-node-ref/7.4/am-only/password-collector.md) - [Patch Object node](https://docs.pingidentity.com/auth-node-ref/7.4/patch-object.md) - [Persistent Cookie Decision node](https://docs.pingidentity.com/auth-node-ref/7.4/persistent-cookie-decision.md) - [Platform Password node](https://docs.pingidentity.com/auth-node-ref/7.4/platform-password.md) - [Platform Username node](https://docs.pingidentity.com/auth-node-ref/7.4/platform-username.md) - [Polling Wait node](https://docs.pingidentity.com/auth-node-ref/7.4/polling-wait.md) - [Profile Completeness Decision node](https://docs.pingidentity.com/auth-node-ref/7.4/profile-completeness-decision.md) - [Provision Dynamic Account node](https://docs.pingidentity.com/auth-node-ref/7.4/am-only/provision-dynamic-account.md) - [Provision IDM Account node](https://docs.pingidentity.com/auth-node-ref/7.4/am-only/provision-IDM-account.md) - [Push Registration node](https://docs.pingidentity.com/auth-node-ref/7.4/push-registration.md) - [Push Result Verifier node](https://docs.pingidentity.com/auth-node-ref/7.4/push-result-verifier.md) - [Push Sender node](https://docs.pingidentity.com/auth-node-ref/7.4/push-sender.md) - [Push Wait node](https://docs.pingidentity.com/auth-node-ref/7.4/push-wait.md) - [Query Filter Decision node](https://docs.pingidentity.com/auth-node-ref/7.4/query-filter-decision.md) - [Query Parameter node](https://docs.pingidentity.com/auth-node-ref/7.4/query-parameter.md) - [Recovery Code Collector Decision node](https://docs.pingidentity.com/auth-node-ref/7.4/recovery-code-collector-decision.md) - [Recovery Code Display node](https://docs.pingidentity.com/auth-node-ref/7.4/recovery-code-display.md) - [Register Logout Webhook node](https://docs.pingidentity.com/auth-node-ref/7.4/register-logout-webhook.md) - [Register Thing node](https://docs.pingidentity.com/auth-node-ref/7.4/self-managed/register-thing.md) - [Remove Session Properties node](https://docs.pingidentity.com/auth-node-ref/7.4/remove-session-properties.md) - [Required Attributes Present node](https://docs.pingidentity.com/auth-node-ref/7.4/required-attributes-present.md) - [Retry Limit Decision node](https://docs.pingidentity.com/auth-node-ref/7.4/retry-limit-decision.md) - [SAML2 Authentication node](https://docs.pingidentity.com/auth-node-ref/7.4/saml2.md) - [Scripted Decision node](https://docs.pingidentity.com/auth-node-ref/7.4/scripted-decision.md) - [Select Identity Provider node](https://docs.pingidentity.com/auth-node-ref/7.4/select-identity-provider.md) - [Set Custom Cookie node](https://docs.pingidentity.com/auth-node-ref/7.4/set-custom-cookie.md) - [Set Persistent Cookie node](https://docs.pingidentity.com/auth-node-ref/7.4/set-persistent-cookie.md) - [Set Session Properties node](https://docs.pingidentity.com/auth-node-ref/7.4/set-session-properties.md) - [Social Facebook node](https://docs.pingidentity.com/auth-node-ref/7.4/am-only/social-facebook.md) - [Social Google node](https://docs.pingidentity.com/auth-node-ref/7.4/am-only/social-google.md) - [Social Ignore Profile node](https://docs.pingidentity.com/auth-node-ref/7.4/am-only/social-ignore-profile.md) - [Social Provider Handler node](https://docs.pingidentity.com/auth-node-ref/7.4/social-provider-handler.md) - [State Metadata node](https://docs.pingidentity.com/auth-node-ref/7.4/state-metadata.md) - [Success node](https://docs.pingidentity.com/auth-node-ref/7.4/success.md) - [Success URL node](https://docs.pingidentity.com/auth-node-ref/7.4/success-url.md) - [Terms and Conditions Decision node](https://docs.pingidentity.com/auth-node-ref/7.4/terms-and-conditions-decision.md) - [Time Since Decision node](https://docs.pingidentity.com/auth-node-ref/7.4/time-since-decision.md) - [Timer Start node](https://docs.pingidentity.com/auth-node-ref/7.4/timer-start.md) - [Timer Stop node](https://docs.pingidentity.com/auth-node-ref/7.4/timer-stop.md) - [Username Collector node](https://docs.pingidentity.com/auth-node-ref/7.4/am-only/username-collector.md) - [WebAuthn Authentication node](https://docs.pingidentity.com/auth-node-ref/7.4/webauthn-auth.md) - [WebAuthn Device Storage node](https://docs.pingidentity.com/auth-node-ref/7.4/webauthn-device-storage.md) - [WebAuthn Registration node](https://docs.pingidentity.com/auth-node-ref/7.4/webauthn-registration.md) - [Write Federation Information node](https://docs.pingidentity.com/auth-node-ref/7.4/write-federation-information.md) - [Zero Page Login Collector node](https://docs.pingidentity.com/auth-node-ref/7.4/zero-page-login-collector.md) ## Auth Node Ref 7.3 - [Accept Terms and Conditions node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-accept-terms-and-conditions.md) - [Account Active Decision node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-account-active-decision.md) - [Account Lockout node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-account-lockout.md) - [Agent Data Store Decision node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-agent-data-store-decision.md) - [Anonymous Session Upgrade node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-anonymous-session-upgrade.md) - [Anonymous User Mapping node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-anonymous-user-mapping.md) - [Attribute Collector node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-attribute-collector.md) - [Attribute Present Decision node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-attribute-present-decision.md) - [Attribute Value Decision node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-attribute-value-decision.md) - [Auth Level Decision node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-auth-level-decision.md) - [Authenticate Thing node](https://docs.pingidentity.com/auth-node-ref/7.3/self-managed/auth-node-authenticate-thing.md) - [Authentication node reference](https://docs.pingidentity.com/auth-node-ref/7.3/auth-nodes.md) - [CAPTCHA node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-captcha.md) - [Certificate Collector node](https://docs.pingidentity.com/auth-node-ref/7.3/self-managed/auth-node-certificate-collector.md) - [Certificate User Extractor node](https://docs.pingidentity.com/auth-node-ref/7.3/self-managed/auth-node-certificate-user-extractor.md) - [Certificate Validation node](https://docs.pingidentity.com/auth-node-ref/7.3/self-managed/auth-node-certificate-validation.md) - [Choice Collector node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-choice-collector.md) - [Combined MFA Registration node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-combined-mfa-registration.md) - [Configuration Provider node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-config-provider.md) - [Consent Collector node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-consent-collector.md) - [Cookie Presence Decision node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-cookie-presence-decision.md) - [Create Object node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-create-object.md) - [Create Password node](https://docs.pingidentity.com/auth-node-ref/7.3/am-only/auth-node-create-password.md) - [Data Store Decision node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-data-store-decision.md) - [Debug node](https://docs.pingidentity.com/auth-node-ref/7.3/am-only/auth-node-debug.md) - [Device Geofencing node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-device-geofencing.md) - [Device Location Match node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-device-profile-location-match.md) - [Device Match node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-device-match.md) - [Device Profile Collector node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-device-profile-collector.md) - [Device Profile Save node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-device-profile-save.md) - [Device Tampering Verification node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-device-tampering-verification.md) - [Display Username node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-display-username.md) - [Email Suspend node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-email-suspend.md) - [Email Template node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-email-template.md) - [Failure node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-failure.md) - [Failure URL node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-failure-url.md) - [Get Authenticator App node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-get-authenticator-app.md) - [Get Session Data node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-get-session-data.md) - [HOTP Generator node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-hotp-generator.md) - [Identify Existing User node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-identify-existing-user.md) - [Increment Login Count node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-increment-login-count.md) - [Inner Tree Evaluator node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-inner-tree-evaluator.md) - [KBA Decision node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-kba-decision.md) - [KBA Definition node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-kba-definition.md) - [KBA Verification node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-kba-verification.md) - [Kerberos node](https://docs.pingidentity.com/auth-node-ref/7.3/self-managed/auth-node-kerberos.md) - [LDAP Decision node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-ldap-decision.md) - [Legacy CAPTCHA node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-legacy-captcha.md) - [Login Count Decision node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-login-count-decision.md) - [Message node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-message.md) - [Meter node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-meter.md) - [MFA Registration Options node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-mfa-registration-options.md) - [Modify Auth Level node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-modify-auth-level.md) - [OATH Device Storage node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-oath-device-storage.md) - [OATH Registration node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-oath-registration.md) - [OATH Token Verifier node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-oath-token-verifier.md) - [OAuth 2.0 node](https://docs.pingidentity.com/auth-node-ref/7.3/am-only/auth-node-oauth2.md) - [OIDC ID Token Validator node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-oidc-idtoken-validator.md) - [OpenID Connect node](https://docs.pingidentity.com/auth-node-ref/7.3/am-only/auth-node-oidc.md) - [Opt-out Multi-Factor Authentication node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-opt-out-multi-factor.md) - [OTP Collector Decision node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-otp-collector-decision.md) - [OTP Email Sender node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-otp-email-sender.md) - [OTP SMS Sender node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-otp-sms-sender.md) - [Page node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-page.md) - [Passthrough Authentication node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-passthrough-authentication.md) - [Password Collector node](https://docs.pingidentity.com/auth-node-ref/7.3/am-only/auth-node-password-collector.md) - [Patch Object node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-patch-object.md) - [Persistent Cookie Decision node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-persistent-cookie-decision.md) - [Platform Password node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-platform-password.md) - [Platform Username node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-platform-username.md) - [Polling Wait node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-polling-wait.md) - [Profile Completeness Decision node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-profile-completeness-decision.md) - [Provision Dynamic Account node](https://docs.pingidentity.com/auth-node-ref/7.3/am-only/auth-node-provision-dynamic-account.md) - [Provision IDM Account node](https://docs.pingidentity.com/auth-node-ref/7.3/am-only/auth-node-provision-IDM-account.md) - [Push Registration node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-push-registration.md) - [Push Result Verifier node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-push-result-verifier.md) - [Push Sender node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-push-sender.md) - [Push Wait node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-push-wait.md) - [Query Filter Decision node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-query-filter-decision.md) - [Recovery Code Collector Decision node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-recovery-code-collector-decision.md) - [Recovery Code Display node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-recovery-code-display.md) - [Register Logout Webhook node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-register-logout-webhook.md) - [Register Thing node](https://docs.pingidentity.com/auth-node-ref/7.3/self-managed/auth-node-register-thing.md) - [Remove Session Properties node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-remove-session-properties.md) - [Required Attributes Present node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-required-attributes-present.md) - [Retry Limit Decision node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-retry-limit-decision.md) - [SAML2 Authentication node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-saml2.md) - [Scripted Decision node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-scripted-decision.md) - [Select Identity Provider node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-select-identity-provider.md) - [Set Custom Cookie node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-set-custom-cookie.md) - [Set Persistent Cookie node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-set-persistent-cookie.md) - [Set Session Properties node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-set-session-properties.md) - [Social Facebook node](https://docs.pingidentity.com/auth-node-ref/7.3/am-only/auth-node-social-facebook.md) - [Social Google node](https://docs.pingidentity.com/auth-node-ref/7.3/am-only/auth-node-social-google.md) - [Social Ignore Profile node](https://docs.pingidentity.com/auth-node-ref/7.3/am-only/auth-node-social-ignore-profile.md) - [Social Provider Handler node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-social-provider-handler.md) - [State Metadata node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-state-metadata.md) - [Success node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-success.md) - [Success URL node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-success-url.md) - [Terms and Conditions Decision node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-terms-and-conditions-decision.md) - [Time Since Decision node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-time-since-decision.md) - [Timer Start node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-timer-start.md) - [Timer Stop node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-timer-stop.md) - [Username Collector node](https://docs.pingidentity.com/auth-node-ref/7.3/am-only/auth-node-username-collector.md) - [WebAuthn Authentication node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-webauthn-auth.md) - [WebAuthn Device Storage node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-webauthn-device-storage.md) - [WebAuthn Registration node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-webauthn-registration.md) - [Write Federation Information node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-write-federation-information.md) - [Zero Page Login Collector node](https://docs.pingidentity.com/auth-node-ref/7.3/auth-node-zero-page-login-collector.md) ## Auth Node Ref latest - [Accept Terms and Conditions node](https://docs.pingidentity.com/auth-node-ref/latest/accept-terms-and-conditions.md): Prompts users to accept the active terms and conditions during registration or sign-on journeys in Advanced Identity Cloud. - [Account Active Decision node](https://docs.pingidentity.com/auth-node-ref/latest/account-active-decision.md): Checks whether a user account is both active and unlocked, routing the journey along True or False outcome paths in Advanced Identity Cloud. - [Account Lockout node](https://docs.pingidentity.com/auth-node-ref/latest/account-lockout.md): Locks or unlocks a user account profile in Advanced Identity Cloud, supporting both persistent and duration-based lockout. - [AD Decision node](https://docs.pingidentity.com/auth-node-ref/latest/ad-decision.md): Verifies user credentials against an Active Directory data store and routes journeys based on account status, including locked, disabled, or expired accounts. - [Agent Data Store Decision node](https://docs.pingidentity.com/auth-node-ref/latest/agent-data-store-decision.md): Authenticates agents such as PingGateway and Java or web agents against the agent profile data store in Advanced Identity Cloud. - [Amster Jwt Decision node](https://docs.pingidentity.com/auth-node-ref/latest/am-only/amster-jwt-decision.md): Configure the Amster JWT Decision node to authenticate Amster connections to PingAM using SSH key pairs stored in an authorized_keys file. - [Anonymous Session Upgrade node](https://docs.pingidentity.com/auth-node-ref/latest/anonymous-session-upgrade.md): Upgrades an anonymous session to a non-anonymous session in Advanced Identity Cloud journeys. - [Anonymous User Mapping node](https://docs.pingidentity.com/auth-node-ref/latest/anonymous-user-mapping.md): Maps unauthenticated users to a named anonymous account in Advanced Identity Cloud, enabling limited access without credentials. - [App Policy Decision node](https://docs.pingidentity.com/auth-node-ref/latest/app-policy-decision.md): Evaluates application access policies automatically from journey context in Advanced Identity Cloud, routing based on accept, reject, or error outcomes. - [Attribute Collector node](https://docs.pingidentity.com/auth-node-ref/latest/attribute-collector.md): Collects user attribute values during a journey for use in registration or profile update flows in Advanced Identity Cloud. - [Attribute Present Decision node](https://docs.pingidentity.com/auth-node-ref/latest/attribute-present-decision.md): Checks whether a specified attribute, including private attributes such as password, is present on a user object in Advanced Identity Cloud. - [Attribute Value Decision node](https://docs.pingidentity.com/auth-node-ref/latest/attribute-value-decision.md): Verifies that a user attribute satisfies a configured condition, such as presence or equality, during journeys in Advanced Identity Cloud. - [Auth Level Decision node](https://docs.pingidentity.com/auth-node-ref/latest/auth-level-decision.md): Compares the current authentication level against a configured threshold to route journeys in Advanced Identity Cloud. - [Authenticate Thing node](https://docs.pingidentity.com/auth-node-ref/latest/self-managed/authenticate-thing.md): Use the Authenticate Thing node in PingAM to authenticate IoT devices and gateways using Proof of Possession JWT or Client Assertion. - [Authentication node reference](https://docs.pingidentity.com/auth-node-ref/latest/overview.md): Reference index of all Advanced Identity Cloud authentication nodes, organized by category including MFA, federation, identity management, and utility nodes. - [Backchannel Initialize node](https://docs.pingidentity.com/auth-node-ref/latest/backchannel-initialize.md): Configure the Backchannel Initialize node to start an asynchronous journey for a different user or agent, enabling backchannel authentication in Advanced Identity Cloud. - [Backchannel Notification node](https://docs.pingidentity.com/auth-node-ref/latest/backchannel-notification.md): Configure the Backchannel Notification node to send real-time status updates from a backchannel journey to the main authentication journey in Advanced Identity Cloud. - [Backchannel Status node](https://docs.pingidentity.com/auth-node-ref/latest/backchannel-status.md): Configure the Backchannel Status node to check the status of an asynchronous backchannel authentication journey in Advanced Identity Cloud. - [BioCatch Session Collector node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/biocatch-session-collector.md): Collects the BioCatch unique session identifier (customerSessionID) from the user-agent during an Advanced Identity Cloud authentication journey. - [BioCatch Session node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/biocatch-session.md): Initializes a BioCatch scoring API session, associates it with the authenticating user, and links the session ID to the BioCatch server in an Advanced Identity Cloud journey. - [BioCatch Session Profiler node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/biocatch-session-profiler.md): Injects BioCatch JavaScript into the user-agent to set the unique session identifier (customerSessionID) during an Advanced Identity Cloud authentication journey. - [CAPTCHA node](https://docs.pingidentity.com/auth-node-ref/latest/captcha.md): Configure the CAPTCHA node to verify CAPTCHA responses from providers such as Google reCAPTCHA v2, reCAPTCHA v3, and hCaptcha during Advanced Identity Cloud authentication journeys. - [Certificate Collector node](https://docs.pingidentity.com/auth-node-ref/latest/certificate-collector.md): Configure the Certificate Collector node to collect X.509 digital certificates from incoming requests for use as authentication credentials in Advanced Identity Cloud journeys. - [Certificate User Extractor node](https://docs.pingidentity.com/auth-node-ref/latest/certificate-user-extractor.md): Configure the Certificate User Extractor node to extract a user identifier from an X.509 certificate and match it against an identity in the identity store. - [Certificate Validation node](https://docs.pingidentity.com/auth-node-ref/latest/certificate-validation.md): Configure the Certificate Validation node to validate X.509 digital certificates against LDAP stores, CRLs, and OCSP in Advanced Identity Cloud authentication journeys. - [Choice Collector node](https://docs.pingidentity.com/auth-node-ref/latest/choice-collector.md): Configure the Choice Collector node to present users with two or more selectable options during an authentication journey in Advanced Identity Cloud. - [Combined MFA Registration node](https://docs.pingidentity.com/auth-node-ref/latest/combined-mfa-registration.md): Configure the Combined MFA Registration node to register a device for both push notification and OATH one-time password multi-factor authentication in a single step. - [Configuration Provider node](https://docs.pingidentity.com/auth-node-ref/latest/config-provider.md): Configure the Configuration Provider node to use a script to dynamically build the configuration of another node and replace it at runtime in an Advanced Identity Cloud journey. - [Consent Collector node](https://docs.pingidentity.com/auth-node-ref/latest/consent-collector.md): Configure the Consent Collector node to prompt users to consent to sharing their profile data during registration or progressive profile flows in Advanced Identity Cloud. - [Cookie Presence Decision node](https://docs.pingidentity.com/auth-node-ref/latest/cookie-presence-decision.md): Configure the Cookie Presence Decision node to check whether a named cookie exists in an incoming authentication request and route the journey accordingly. - [Create Object node](https://docs.pingidentity.com/auth-node-ref/latest/create-object.md): Create a new managed object using attributes collected during an authentication journey, such as during user registration. - [Create Password node (deprecated)](https://docs.pingidentity.com/auth-node-ref/latest/am-only/create-password.md): Deprecated. The Create Password node prompted users to create a password during social account provisioning in PingAM. - [Data Store Decision node](https://docs.pingidentity.com/auth-node-ref/latest/data-store-decision.md): Authenticate users by verifying that their credentials match those stored in the configured data store for the realm. - [Debug node](https://docs.pingidentity.com/auth-node-ref/latest/am-only/debug.md): Use the Debug node in PingAM to display shared node state, identity universalId, and transaction ID during authentication tree testing. - [Device Binding node](https://docs.pingidentity.com/auth-node-ref/latest/device-binding.md): Register one or more devices to a user's account by generating a cryptographic key pair and storing the public key in the user's profile. - [Device Binding Storage node](https://docs.pingidentity.com/auth-node-ref/latest/device-binding-storage.md): Persist collected device binding data, including the device public key, to a user's profile in the identity store. - [Device Geofencing node](https://docs.pingidentity.com/auth-node-ref/latest/device-geofencing.md): Compare collected device location data against configured trusted locations to determine whether the user's device is within an allowed geofence. - [Device Location Match node](https://docs.pingidentity.com/auth-node-ref/latest/device-location-match.md): Compare collected device location data against previously saved locations in the user's profile to verify the device is within an acceptable range. - [Device Match node](https://docs.pingidentity.com/auth-node-ref/latest/device-match.md): Compare collected device metadata against saved trusted device profiles in a user's account using built-in or custom script matching. - [Device Profile Collector node](https://docs.pingidentity.com/auth-node-ref/latest/device-profile-collector.md): Collect metadata about the user's device, including hardware details, OS information, and optionally location, for use in device profiling journeys. - [Device Profile Save node](https://docs.pingidentity.com/auth-node-ref/latest/device-profile-save.md): Persist collected device metadata and location data to a user's profile in the identity store for use in future authentications. - [Device Signing Verifier node](https://docs.pingidentity.com/auth-node-ref/latest/device-signing-verifier.md): Verify possession of a registered bound device by challenging it to sign a value with the private key paired to a stored public key. - [Device Tampering Verification node](https://docs.pingidentity.com/auth-node-ref/latest/device-tampering-verification.md): Evaluate a device tampering score to determine whether a device has been rooted, jailbroken, or otherwise poses a security risk. - [Display Username node](https://docs.pingidentity.com/auth-node-ref/latest/display-username.md): Look up and display a user's username based on a different identifying attribute, such as an email address, to support username recovery flows. - [Duo node (deprecated)](https://docs.pingidentity.com/auth-node-ref/latest/cloud/duo.md): Deprecated. Integrates Duo as an additional authentication factor. Use the Duo Universal Prompt node instead, as Duo has deprecated the Traditional Duo Prompt used by this node. - [Duo Universal Prompt node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/duo-univ-prompt.md): Integrates Advanced Identity Cloud authentication journeys with Duo two-factor authentication using the Duo Universal Prompt interface and Web v4 SDK. - [Email Suspend node](https://docs.pingidentity.com/auth-node-ref/latest/email-suspend.md): Sends an email using a template and suspends the authentication journey until the user clicks a resume link in that email. - [Email Template node](https://docs.pingidentity.com/auth-node-ref/latest/email-template.md): Sends an email based on a configured template without suspending the authentication journey, for example to deliver a welcome message after registration. - [Enable Device Management node](https://docs.pingidentity.com/auth-node-ref/latest/enable-device-management.md): Controls which MFA device types a user must authenticate with before they can remove a registered MFA device, allowing journeys to relax or remove this restriction. - [Failure node](https://docs.pingidentity.com/auth-node-ref/latest/failure.md): Terminal node that ends an authentication journey in failure, redirecting the user to a failure URL and optionally incrementing the account lockout counter. - [Failure URL node](https://docs.pingidentity.com/auth-node-ref/latest/failure-url.md): Specifies the URL to redirect end users to when authentication fails in a journey. - [Fingerprint nodes](https://docs.pingidentity.com/auth-node-ref/latest/cloud/fingerprint.md): Overview of the Fingerprint Profiler and Fingerprint Response nodes for integrating browser fingerprinting into Advanced Identity Cloud authentication journeys. - [Fingerprint Profiler node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/fingerprint-profiler.md): Injects client-side JavaScript required for Fingerprint browser fingerprinting into an authentication journey, optionally supporting Zero Trust Mode. - [Fingerprint Response node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/fingerprint-response.md): Fetches the Fingerprint server-side browser fingerprint and confidence score in Zero Trust Mode using the request ID from the Fingerprint Profiler node. - [Flow Control node](https://docs.pingidentity.com/auth-node-ref/latest/flow-control.md): Randomly routes a configurable percentage of authentication requests between two journey paths, enabling controlled rollout and testing of new authentication flows. - [Gateway Communication node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/gateway-communication.md): Establishes a secure JWT-based communication channel between Advanced Identity Cloud authentication journeys and PingGateway to extend journey capabilities with PingGateway features. - [Get Authenticator App node](https://docs.pingidentity.com/auth-node-ref/latest/get-authenticator-app.md): Displays a prompt with links to download an authenticator app from the Apple App Store or Google Play Store as part of a push authentication journey. - [Get Session Data node](https://docs.pingidentity.com/auth-node-ref/latest/get-session-data.md): Retrieves a value from a user's existing session by key and stores it in the shared node state, for use during session upgrade journeys. - [HOTP Generator node](https://docs.pingidentity.com/auth-node-ref/latest/hotp-generator.md): Generates a random numeric one-time passcode (OTP) of a specified length for use in authentication journeys, storing it in shared state for delivery by email or SMS. - [HTTP Client node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/http-client.md): Makes HTTP(S) requests to external APIs from within an authentication journey, supporting GET, POST, PUT, DELETE, PATCH, and HEAD methods with variable substitution and JSON response handling. - [Identify Existing User node](https://docs.pingidentity.com/auth-node-ref/latest/identify-existing-user.md): Looks up a user identity by a specified attribute such as email address and writes the matching identifier to shared node state, for use in forgotten password flows. - [Identity Assertion node](https://docs.pingidentity.com/auth-node-ref/latest/identity-assertion-node.md): Integrates PingGateway into an authentication journey to support identity assertion with third-party services such as Windows Desktop SSO and Kerberos. - [Identity Store Decision node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/identity-store-decision.md): Validates a username and password against the identity store, and handles locked accounts, expired passwords, and cancelled password change requests in Advanced Identity Cloud journeys. - [IdentityX Auth Request Decision node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/identityx-auth-request-decision.md): Checks the status of a Daon IdentityX out-of-band authentication request and routes the journey based on whether the request is pending, succeeded, failed, or expired. - [IdentityX Auth Request Initiator node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/identityx-auth-request-initiator.md): Generates and sends a Daon IdentityX authentication request for out-of-band authentication over a separate, secure channel, with optional push notification support. - [IdentityX Check Enrollment Status node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/identityx-check-enrollment-status.md): Verifies that a user is enrolled with the Daon IdentityX platform and configures the integration required by all IdentityX journey nodes. - [IdentityX Mobile Auth Request node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/identityx-mobile-auth-request.md): Generates and sends a Daon IdentityX authentication request for a user authenticating on a mobile device, with a configurable transaction description. - [IdentityX Mobile Auth Request Validate node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/identityx-mobile-auth-request-validate.md): Accepts a signed Daon IdentityX authentication request from a mobile device and validates the signature to confirm the authentication outcome. - [IdentityX Sponsor User node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/identityx-sponsor-user.md): Enrolls an end user with the Daon IdentityX platform using a QR code sponsorship flow, with configurable polling and display message settings. - [Increment Login Count node](https://docs.pingidentity.com/auth-node-ref/latest/increment-login-count.md): Increments the successful login count on a managed identity object, enabling journeys to track authentication frequency for use with the Login Count Decision node. - [Inner Tree Evaluator node](https://docs.pingidentity.com/auth-node-ref/latest/inner-tree-evaluator.md): Configure the Inner Tree Evaluator node to nest authentication journeys as children within a parent journey in Advanced Identity Cloud. - [iProov Authentication node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/iproov.md): Integrates Advanced Identity Cloud authentication journeys with iProov biometric face verification, supporting enrollment, liveness verification, and Genuine Presence Assurance. - [Jumio Decision node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/jumio-decision.md): Evaluates a Jumio NetVerify scan result, maps Jumio attributes to Advanced Identity Cloud properties, and routes the journey based on whether identity verification passed, failed, or is pending. - [Jumio identity verification](https://docs.pingidentity.com/auth-node-ref/latest/cloud/jumio-id-verify.md): Explains how to integrate Jumio identity verification with Advanced Identity Cloud using the Jumio Initiate and Jumio Decision nodes to verify government-issued IDs and selfies. - [Jumio Initiate node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/jumio-initiate.md): Triggers a Jumio transaction and redirects the user to the Netverify identity verification journey. - [JWT Password Replay node](https://docs.pingidentity.com/auth-node-ref/latest/jwt-password-replay.md): Configure the JWT Password Replay node to store a user's password in an encrypted JWT session property for use with PingGateway credential replay scenarios. - [KBA Decision node](https://docs.pingidentity.com/auth-node-ref/latest/kba-decision.md): Configure the KBA Decision node to check whether a user account has the minimum number of knowledge-based authentication security questions defined. - [KBA Definition node](https://docs.pingidentity.com/auth-node-ref/latest/kba-definition.md): Configure the KBA Definition node to collect knowledge-based authentication questions and answers from users during registration or profile update. - [KBA Verification node](https://docs.pingidentity.com/auth-node-ref/latest/kba-verification.md): Configure the KBA Verification node to present knowledge-based authentication questions to users and verify their answers against stored responses. - [Kerberos node](https://docs.pingidentity.com/auth-node-ref/latest/self-managed/kerberos.md): Use the Kerberos node in PingAM to enable desktop single sign-on through SPNEGO, allowing users authenticated with a Kerberos KDC to sign on without re-entering credentials. - [LDAP Decision node](https://docs.pingidentity.com/auth-node-ref/latest/ldap-decision.md): Configure the LDAP Decision node to verify a username and password against an LDAP user data store and check for expired or locked accounts. - [Legacy CAPTCHA node](https://docs.pingidentity.com/auth-node-ref/latest/legacy-captcha.md): Configure the Legacy CAPTCHA node to verify a CAPTCHA response token and create a CAPTCHA callback. Superseded by the CAPTCHA node. - [Legacy Social Provider Handler node](https://docs.pingidentity.com/auth-node-ref/latest/legacy-social-provider-handler.md): Configure the Legacy Social Provider Handler node to authenticate users with a social identity provider and collect profile attributes. Use the Social Provider Handler node for new journeys. - [LexisNexis One-Time Passcode (OTP)](https://docs.pingidentity.com/auth-node-ref/latest/cloud/lexis-otp.md): Overview of LexisNexis One-Time Passcode integration with Advanced Identity Cloud, including setup and sample journey configuration. - [LexisNexis OTP Collector node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/lexis-otp-collector.md): Collects the one-time passcode entered by the user during LexisNexis OTP authentication and allows resubmission or retry. - [LexisNexis OTP Decision node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/lexis-otp-decision.md): Validates the LexisNexis one-time passcode entered by the user against the value stored in shared state. - [LexisNexis OTP Sender node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/lexis-otp-sender.md): Sends a LexisNexis one-time passcode to the user through email, SMS, or voice during an Advanced Identity Cloud authentication journey. - [Login Count Decision node](https://docs.pingidentity.com/auth-node-ref/latest/login-count-decision.md): Configure the Login Count Decision node to trigger a journey action when a user's successful login count reaches a specified threshold. - [Message node](https://docs.pingidentity.com/auth-node-ref/latest/message.md): Configure the Message node to present a custom, localized message with positive and negative response buttons that users must click to proceed through a journey. - [Meter node](https://docs.pingidentity.com/auth-node-ref/latest/meter.md): Configure the Meter node to increment a custom metric key each time journey evaluation passes through the node, enabling trend monitoring with tools such as Prometheus. - [MFA Registration Options node](https://docs.pingidentity.com/auth-node-ref/latest/mfa-registration-options.md): Configure the MFA Registration Options node to let users register a multi-factor authentication device or skip registration during a journey. - [Microsoft Intune node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/microsoft-intune-about.md): Checks Microsoft Intune device compliance status during an Advanced Identity Cloud authentication journey using Microsoft Graph APIs. - [Modify Auth Level node](https://docs.pingidentity.com/auth-node-ref/latest/modify-auth-level.md): Configure the Modify Auth Level node to increase or decrease the authentication level value in the current session. - [OATH Device Storage node](https://docs.pingidentity.com/auth-node-ref/latest/oath-device-storage.md): Configure the OATH Device Storage node to persist a registered OATH device profile from the shared state into the user's account. - [OATH Registration node](https://docs.pingidentity.com/auth-node-ref/latest/oath-registration.md): Configure the OATH Registration node to let users register a device for OATH-based multi-factor authentication using a QR code scan. - [OATH Token Verifier node](https://docs.pingidentity.com/auth-node-ref/latest/oath-token-verifier.md): Configure the OATH Token Verifier node to request and verify a one-time passcode generated by a registered OATH device using TOTP or HOTP. - [OAuth 2.0 node (deprecated)](https://docs.pingidentity.com/auth-node-ref/latest/am-only/oauth2.md): Deprecated. The OAuth 2.0 node authenticated PingAM users against OAuth 2.0-compliant social identity providers using the authorization code grant. - [OIDC ID Token Validator node](https://docs.pingidentity.com/auth-node-ref/latest/oidc-idtoken-validator.md): Configure the OIDC ID Token Validator node to authenticate users by validating an OpenID Connect ID token from an external identity provider. - [OneSpan](https://docs.pingidentity.com/auth-node-ref/latest/cloud/onespan-about.md): Overview of integrating OneSpan Intelligent Adaptive Authentication and Risk Analytics with Advanced Identity Cloud. - [OneSpan Auth Activate Device node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/onespan-activate-device.md): Finalizes OneSpan device activation by prompting the user for the Digipass authenticator signature. - [OneSpan Auth Add Device node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/onespan-add-device.md): Prompts the user for a device code to add a new device for OneSpan authentication. - [OneSpan Auth Assign Authenticator node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/onespan-assign-authn.md): Assigns an available OneSpan VIR10 authenticator to a user who does not yet have one assigned. - [OneSpan Auth Check Activation node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/onespan-check-activation.md): Checks the status of a pending OneSpan device activation during an Advanced Identity Cloud journey. - [OneSpan Auth Check Session Status node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/onespan-check-session-status.md): Checks the status of an active OneSpan authentication request session, including step-up authentication results. - [OneSpan Auth Generate VOTP node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/onespan-generate-votp.md): Generates and delivers a OneSpan virtual one-time passcode to users assigned a VIR10 authenticator. - [OneSpan Auth VDP User Register node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/onespan-vdp-register.md): Registers a user for virtual one-time passcode delivery through SMS, email, or voice using OneSpan VDP. - [OneSpan Get User Authenticator node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/onespan-get-user-authenticator.md): Retrieves the OneSpan authenticators assigned to a user to direct the appropriate authentication flow. - [OneSpan Identity Verification node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/onespan-id-verify.md): Redirects users to OneSpan for document-based identity verification during an Advanced Identity Cloud journey. - [OneSpan nodes](https://docs.pingidentity.com/auth-node-ref/latest/cloud/onespan-nodes.md): Reference list of all OneSpan authentication nodes and sample nodes available in Advanced Identity Cloud. - [OneSpan Sample journeys](https://docs.pingidentity.com/auth-node-ref/latest/cloud/onespan-sample.md): Sample OneSpan authentication journeys for development and testing, covering user registration, login, and transaction validation. - [Onfido Check node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/onfido-check.md): Runs an Onfido identity verification check and returns the result for use in an Advanced Identity Cloud journey. - [Onfido Registration node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/onfido-registration.md): Registers a user with Onfido for identity verification, optionally collecting biometrics and provisioning the account from document data. - [OpenID Connect node (deprecated)](https://docs.pingidentity.com/auth-node-ref/latest/am-only/oidc.md): Deprecated. The OpenID Connect node authenticated PingAM users against OpenID Connect providers using the authorization code grant. - [Opt-out Multi-Factor Authentication node](https://docs.pingidentity.com/auth-node-ref/latest/opt-out-multi-factor.md): Configure the Opt-out Multi-Factor Authentication node to record a user's decision to skip multi-factor authentication on their current device. - [OTP Collector Decision node](https://docs.pingidentity.com/auth-node-ref/latest/otp-collector-decision.md): Configure the OTP Collector Decision node to prompt users to enter a one-time passcode and verify whether it is valid. - [OTP Email Sender node](https://docs.pingidentity.com/auth-node-ref/latest/otp-email-sender.md): Configure the OTP Email Sender node to send a one-time passcode to a user's email address as part of an authentication journey. - [OTP SMS Sender node](https://docs.pingidentity.com/auth-node-ref/latest/otp-sms-sender.md): Configure the OTP SMS Sender node to send a one-time passcode to a user's mobile phone through an email-to-SMS gateway. - [Page node](https://docs.pingidentity.com/auth-node-ref/latest/page.md): Configure the Page node to combine multiple input-collecting nodes onto a single page displayed to users during an authentication journey. - [Passthrough Authentication node](https://docs.pingidentity.com/auth-node-ref/latest/passthrough-authentication.md): Configure the Passthrough Authentication node to authenticate users against a third-party service through a connector, supporting password migration without forcing resets. - [Password Collector node](https://docs.pingidentity.com/auth-node-ref/latest/am-only/password-collector.md): Use the Password Collector node in PingAM to prompt users to enter their password and write it to transient state for use later in the journey. - [Patch Object node](https://docs.pingidentity.com/auth-node-ref/latest/patch-object.md): Configure the Patch Object node to update the attributes of an existing managed identity object. - [Persistent Cookie Decision node](https://docs.pingidentity.com/auth-node-ref/latest/persistent-cookie-decision.md): Configure the Persistent Cookie Decision node to check for a persistent cookie, verify its JWT signature, and authenticate users without requiring them to log in again. - [PingOne Authorize node](https://docs.pingidentity.com/auth-node-ref/latest/pingone/pingone-authorize.md): Configure the PingOne Authorize node to send policy decision requests to a PingOne Authorize environment and evaluate authorization levels in a journey. - [PingOne Create User node](https://docs.pingidentity.com/auth-node-ref/latest/pingone/pingone-create-user.md): Configure the PingOne Create User node to create new users, including their profile data or as anonymized users, in the PingOne platform during a journey. - [PingOne Credentials Delete Wallet node](https://docs.pingidentity.com/auth-node-ref/latest/pingone/pingone-cred-delete-wallet.md): Configure the PingOne Credentials Delete Wallet node to remove a paired digital wallet from a PingOne user during a journey. - [PingOne Credentials Find Wallets node](https://docs.pingidentity.com/auth-node-ref/latest/pingone/pingone-cred-find-wallet.md): Configure the PingOne Credentials Find Wallets node to list all paired digital wallets for a PingOne user during a journey. - [PingOne Credentials Issue node](https://docs.pingidentity.com/auth-node-ref/latest/pingone/pingone-cred-issue.md): Configure the PingOne Credentials Issue node to create and issue a PingOne digital credential to a user's paired wallet during a journey. - [PingOne Credentials nodes](https://docs.pingidentity.com/auth-node-ref/latest/pingone/pingone-cred-overview.md): Overview of the PingOne Credentials nodes for implementing digital wallet pairing, credential management, and credential verification in Advanced Identity Cloud journeys. - [PingOne Credentials Pair Wallet node](https://docs.pingidentity.com/auth-node-ref/latest/pingone/pingone-cred-pair-wallet.md): Configure the PingOne Credentials Pair Wallet node to pair a PingOne digital wallet with a PingOne user ID during a journey. - [PingOne Credentials Revoke node](https://docs.pingidentity.com/auth-node-ref/latest/pingone/pingone-cred-revoke.md): Configure the PingOne Credentials Revoke node to revoke existing PingOne credentials for a user during a journey. - [PingOne Credentials Update node](https://docs.pingidentity.com/auth-node-ref/latest/pingone/pingone-cred-update.md): Configure the PingOne Credentials Update node to update an existing PingOne credential for a user during a journey. - [PingOne Credentials Verification node](https://docs.pingidentity.com/auth-node-ref/latest/pingone/pingone-cred-verify.md): Configure the PingOne Credentials Verification node to initiate verification of PingOne credentials through QR code or push notification during a journey. - [PingOne DaVinci API node](https://docs.pingidentity.com/auth-node-ref/latest/pingone/pingone-davinci.md): Configure the PingOne DaVinci API node to trigger a PingOne DaVinci flow through API integration from within an Advanced Identity Cloud authentication journey. - [PingOne Delete User node](https://docs.pingidentity.com/auth-node-ref/latest/pingone/pingone-delete-user.md): Configure the PingOne Delete User node to delete a user from the PingOne platform during a journey using the PingOne user ID from shared state. - [PingOne Identity Match node](https://docs.pingidentity.com/auth-node-ref/latest/pingone/pingone-identity-match.md): Configure the PingOne Identity Match node to verify that a user exists in both Advanced Identity Cloud and PingOne, and populate shared state with the user's PingOne ID. - [PingOne node (deprecated)](https://docs.pingidentity.com/auth-node-ref/latest/pingone/pingone.md): Deprecated. The PingOne node established a federated OIDC connection between PingOne and Advanced Identity Cloud to delegate user flows to Advanced Identity Cloud. - [PingOne Protect Evaluation node](https://docs.pingidentity.com/auth-node-ref/latest/pingone/pingone-protect-evaluation.md): Configure the PingOne Protect Evaluation node to calculate a risk score and recommended actions for an authentication event using PingOne Protect risk policies. - [PingOne Protect Initialize node](https://docs.pingidentity.com/auth-node-ref/latest/pingone/pingone-protect-initialize.md): Configure the PingOne Protect Initialize node to instruct the client to initialize the PingOne Protect SDK to gather device signals and contextual information for risk evaluation. - [PingOne Protect Result node](https://docs.pingidentity.com/auth-node-ref/latest/pingone/pingone-protect-result.md): Configure the PingOne Protect Result node to update the risk evaluation configuration or completion status of a PingOne Protect risk evaluation in progress. - [PingOne Service](https://docs.pingidentity.com/auth-node-ref/latest/pingone/pingone-service.md): Configure the PingOne Service to integrate PingOne Credentials and PingOne DaVinci nodes in Advanced Identity Cloud authentication journeys. - [PingOne Verify Authentication node (deprecated)](https://docs.pingidentity.com/auth-node-ref/latest/pingone/pingone-verify-authn.md): Deprecated. The PingOne Verify Authentication node integrated PingOne Verify biometric authentication into a journey by comparing a stored picture to a live selfie. - [PingOne Verify Completion Decision node](https://docs.pingidentity.com/auth-node-ref/latest/pingone/pingone-verify-completion-decision.md): Configure the PingOne Verify Completion Decision node to check the status of a user's most recent PingOne Verify identity verification transaction and return an outcome. - [PingOne Verify Evaluation node](https://docs.pingidentity.com/auth-node-ref/latest/pingone/pingone-verify-evaluation.md): Configure the PingOne Verify Evaluation node to initiate or continue an identity verification transaction using PingOne Verify, with delivery through QR code, email, or SMS. - [PingOne Verify Proofing node (deprecated)](https://docs.pingidentity.com/auth-node-ref/latest/pingone/pingone-verify-proof.md): Deprecated. The PingOne Verify Proofing node integrated PingOne Verify for Government ID, Facial Comparison, and Liveness verification in a journey. - [PingOne Verify service (deprecated)](https://docs.pingidentity.com/auth-node-ref/latest/pingone/pingone-verify-service.md): Deprecated. The PingOne Verify service configured PingOne Verify nodes to provide Government ID, Facial Comparison, and Liveness user verification in Advanced Identity Cloud journeys. - [Platform Password node](https://docs.pingidentity.com/auth-node-ref/latest/platform-password.md): Configure the Platform Password node to prompt users to enter their password, optionally validate it against password policies, and store it in the shared node state. - [Platform Username node](https://docs.pingidentity.com/auth-node-ref/latest/platform-username.md): Configure the Platform Username node to prompt users to enter their username, optionally validate it against username policies, and store it in the shared node state. - [Policy Decision node](https://docs.pingidentity.com/auth-node-ref/latest/policy-decision.md): Configure the Policy Decision node to evaluate authorization policies during an authentication journey based on identity attributes or environmental conditions such as time of day. - [Polling Wait node](https://docs.pingidentity.com/auth-node-ref/latest/polling-wait.md): Configure the Polling Wait node to pause an authentication journey for a specified number of seconds, for example while waiting for a push notification response or external system. - [Profile Completeness Decision node](https://docs.pingidentity.com/auth-node-ref/latest/profile-completeness-decision.md): Configure the Profile Completeness Decision node to check whether the percentage of completed user profile fields meets a configured threshold, for use in progressive profile flows. - [Provision Dynamic Account node](https://docs.pingidentity.com/auth-node-ref/latest/am-only/provision-dynamic-account.md): Use the Provision Dynamic Account node in PingAM to create a user account after SAML2 or social authentication using attributes from the identity provider. - [Provision IDM Account node (deprecated)](https://docs.pingidentity.com/auth-node-ref/latest/am-only/provision-IDM-account.md): Deprecated. The Provision IDM Account node redirected users to a PingIDM instance to provision an account after social authentication in PingAM. - [Push Registration node](https://docs.pingidentity.com/auth-node-ref/latest/push-registration.md): Configure the Push Registration node to register a user's mobile device for multi-factor authentication using push notifications. - [Push Result Verifier node](https://docs.pingidentity.com/auth-node-ref/latest/push-result-verifier.md): Configure the Push Result Verifier node to validate a user's response to a previously sent push notification message during multi-factor authentication. - [Push Sender node](https://docs.pingidentity.com/auth-node-ref/latest/push-sender.md): Configure the Push Sender node to send push notification messages to a registered device for multi-factor authentication, supporting tap-to-accept, challenge code, and biometric options. - [Push Wait node](https://docs.pingidentity.com/auth-node-ref/latest/push-wait.md): Configure the Push Wait node to pause authentication for a specified number of seconds while waiting for a user to respond to a push notification request. - [Query Filter Decision node](https://docs.pingidentity.com/auth-node-ref/latest/query-filter-decision.md): Configure the Query Filter Decision node to check whether a user's profile attributes match a specified query filter, for use in progressive profile and conditional journey flows. - [Query Parameter node](https://docs.pingidentity.com/auth-node-ref/latest/query-parameter.md): Configure the Query Parameter node to extract URL query parameter values into node state properties, enabling journey customization based on URL parameters. - [RADIUS Challenge Collector node](https://docs.pingidentity.com/auth-node-ref/latest/radius-challenge-collector.md): Configure the RADIUS Challenge Collector node to present RADIUS server challenge messages to users and collect their responses, such as one-time passwords. - [RADIUS Decision node](https://docs.pingidentity.com/auth-node-ref/latest/radius-decision.md): Configure the RADIUS Decision node to authenticate users against a RADIUS server, handling Access-Accept, Access-Reject, and Access-Challenge responses. - [reCAPTCHA Enterprise node](https://docs.pingidentity.com/auth-node-ref/latest/recaptcha-enterprise.md): Configure the reCAPTCHA Enterprise node to add Google reCAPTCHA Enterprise bot detection and risk scoring to authentication journeys. - [Recovery Code Collector Decision node](https://docs.pingidentity.com/auth-node-ref/latest/recovery-code-collector-decision.md): Configure the Recovery Code Collector Decision node to let users authenticate with a backup recovery code when they can't access their registered MFA device. - [Recovery Code Display node](https://docs.pingidentity.com/auth-node-ref/latest/recovery-code-display.md): Configure the Recovery Code Display node to show generated MFA recovery codes to users during device registration so they can save them for future use. - [Register Logout Webhook node](https://docs.pingidentity.com/auth-node-ref/latest/register-logout-webhook.md): Configure the Register Logout Webhook node to register a webhook that triggers when a user's session ends due to logout or session expiry. - [Register Thing node](https://docs.pingidentity.com/auth-node-ref/latest/self-managed/register-thing.md): Use the Register Thing node in PingAM to register IoT devices and gateways by validating a JWT and creating or updating the thing identity with a confirmation key. - [Remove Session Properties node](https://docs.pingidentity.com/auth-node-ref/latest/remove-session-properties.md): Configure the Remove Session Properties node to delete one or more named properties from the user session during an authentication journey. - [Request Header node](https://docs.pingidentity.com/auth-node-ref/latest/request-header.md): Configure the Request Header node to extract HTTP request header values into node state properties, enabling journey customization based on incoming request headers. - [Required Attributes Present node](https://docs.pingidentity.com/auth-node-ref/latest/required-attributes-present.md): Configure the Required Attributes Present node to check whether all attributes required to create an identity resource object exist in the shared node state. - [Retry Limit Decision node](https://docs.pingidentity.com/auth-node-ref/latest/retry-limit-decision.md): Configure the Retry Limit Decision node to track failed authentication attempts and allow retries up to a configurable limit before rejecting the user. - [RSA SecurID node](https://docs.pingidentity.com/auth-node-ref/latest/rsa-securid.md): Configure the RSA SecurID node to perform multi-factor authentication by integrating with RSA Cloud Access Service or RSA Authentication Manager. - [RSA SecurID node (deprecated)](https://docs.pingidentity.com/auth-node-ref/latest/cloud/rsa-securid.md): Deprecated. The RSA SecurID node integrated RSA Cloud Authentication Service or RSA Authentication Manager into Advanced Identity Cloud journeys. Use the replacement RSA SecurID node instead. - [SAML2 Authentication node](https://docs.pingidentity.com/auth-node-ref/latest/saml2.md): Configure the SAML2 Authentication node to integrate SAML 2.0 SP-initiated single sign-on into an Advanced Identity Cloud authentication journey. - [Scripted Decision node](https://docs.pingidentity.com/auth-node-ref/latest/scripted-decision.md): Configure the Scripted Decision node to run a custom server-side script in an Advanced Identity Cloud authentication journey and set the node outcome. - [Secret Double Octopus (SDO) nodes](https://docs.pingidentity.com/auth-node-ref/latest/cloud/secret-double-octopus.md): Configure the Secret Double Octopus (SDO) Octopus and Octopus Return nodes to enable high-assurance, passwordless authentication in Advanced Identity Cloud journeys. - [Select Identity Provider node](https://docs.pingidentity.com/auth-node-ref/latest/select-identity-provider.md): Configure the Select Identity Provider node to present users with a list of enabled social identity providers to choose from during authentication. - [Set Custom Cookie node](https://docs.pingidentity.com/auth-node-ref/latest/set-custom-cookie.md): Configure the Set Custom Cookie node to store a custom cookie on the client during an Advanced Identity Cloud authentication journey, including in no-session journeys. - [Set Error Details node](https://docs.pingidentity.com/auth-node-ref/latest/set-error-details.md): Configure the Set Error Details node to add a custom error message, extra key-value fields, and custom response headers to the JSON response when a journey ends in error. - [Set Failure Details node](https://docs.pingidentity.com/auth-node-ref/latest/set-failure-details.md): Configure the Set Failure Details node to add a custom failure message, extra key-value fields, and custom response headers to the JSON response when a journey ends in failure. - [Set Logout Details node](https://docs.pingidentity.com/auth-node-ref/latest/set-logout-details.md): Configure the Set Logout Details node to add extra key-value fields to the JSON response when a journey ends with the user logging out. - [Set Persistent Cookie node](https://docs.pingidentity.com/auth-node-ref/latest/set-persistent-cookie.md): Configure the Set Persistent Cookie node to create a signed and encrypted persistent JWT cookie on the client after successful Advanced Identity Cloud authentication. - [Set Session Properties node](https://docs.pingidentity.com/auth-node-ref/latest/set-session-properties.md): Configure the Set Session Properties node to add key-value properties to the authenticated session or update session timeout settings during an Advanced Identity Cloud journey. - [Set State node](https://docs.pingidentity.com/auth-node-ref/latest/set-state.md): Configure the Set State node to set or overwrite attribute values in the shared state during an Advanced Identity Cloud authentication journey. - [Set Success Details node](https://docs.pingidentity.com/auth-node-ref/latest/set-success-details.md): Configure the Set Success Details node to add extra key-value fields and custom response headers to the JSON response on successful authentication. - [Set up OneSpan](https://docs.pingidentity.com/auth-node-ref/latest/cloud/onespan-setup.md): Set up OneSpan tenant configuration and the OneSpan Configuration service in Advanced Identity Cloud before using OneSpan nodes. - [Setup](https://docs.pingidentity.com/auth-node-ref/latest/cloud/fingerprint-setup.md): Describes the prerequisite steps to configure a Fingerprint account, application, and API keys before using Fingerprint nodes in Advanced Identity Cloud. - [Social Facebook node (deprecated)](https://docs.pingidentity.com/auth-node-ref/latest/am-only/social-facebook.md): Deprecated. The Social Facebook node authenticated PingAM users with Facebook using OAuth 2.0, preconfigured with Facebook endpoints. - [Social Google node (deprecated)](https://docs.pingidentity.com/auth-node-ref/latest/am-only/social-google.md): Deprecated. The Social Google node authenticated PingAM users with Google using OAuth 2.0, preconfigured with Google endpoints. - [Social Ignore Profile node (deprecated)](https://docs.pingidentity.com/auth-node-ref/latest/am-only/social-ignore-profile.md): Deprecated. The Social Ignore Profile node issued a PingAM SSO token after social authentication without checking for a local user profile. - [Social Provider Handler node](https://docs.pingidentity.com/auth-node-ref/latest/social-provider-handler.md): Configure the Social Provider Handler node to authenticate users with a selected social identity provider, validate tokens, and match accounts in Advanced Identity Cloud. - [Socure](https://docs.pingidentity.com/auth-node-ref/latest/cloud/socure.md): Overview of Socure integration with Advanced Identity Cloud, covering the DeviceId Collector, ID+, and Predictive DocV nodes for real-time identity verification and fraud prevention. - [Socure DeviceId Collector node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/socure-deviceid-collector.md): The Socure DeviceId Collector node collects device fingerprint data and creates a device identifier for use with the Socure ID+ API in Advanced Identity Cloud journeys. - [Socure ID+ node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/socure-id.md): The Socure ID+ node verifies user attributes using the Socure ID+ API and returns an identity verification decision such as Accept, Refer, or Reject in Advanced Identity Cloud journeys. - [Socure Predictive DocV node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/socure-predictive-docv.md): The Socure Predictive DocV node verifies a user's identity by authenticating government-issued documents using image capture and facial recognition in Advanced Identity Cloud journeys. - [SpyCloud Auth Node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/spycloud-auth.md): The SpyCloud Auth node checks whether a user's password has been compromised using the SpyCloud service, enabling remediation such as forced password reset in Advanced Identity Cloud journeys. - [State Metadata node](https://docs.pingidentity.com/auth-node-ref/latest/state-metadata.md): Configure the State Metadata node to return selected shared node state attributes as metadata in the authentication response. - [Success node](https://docs.pingidentity.com/auth-node-ref/latest/success.md): The Success node is a required terminal node that marks the end of a successful authentication journey in Advanced Identity Cloud. - [Success URL node](https://docs.pingidentity.com/auth-node-ref/latest/success-url.md): Configure the Success URL node to redirect users to a specified URL when authentication succeeds in an Advanced Identity Cloud journey. - [Terms and Conditions Decision node](https://docs.pingidentity.com/auth-node-ref/latest/terms-and-conditions-decision.md): Configure the Terms and Conditions Decision node to verify that a user has accepted the active terms and conditions before proceeding in a journey. - [ThreatMetrix Authentication nodes](https://docs.pingidentity.com/auth-node-ref/latest/cloud/threat-metrix.md): Overview of ThreatMetrix authentication nodes for Advanced Identity Cloud, enabling device intelligence and fraud risk assessment using LexisNexis ThreatMetrix decision tools. - [ThreatMetrix Profiler node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/threat-metrix-profiler.md): The ThreatMetrix Profiler node tags the Advanced Identity Cloud login page with ThreatMetrix JavaScript to collect device intelligence and session data for fraud risk assessment. - [ThreatMetrix Reason Code node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/threat-metrix-reason-code.md): The ThreatMetrix Reason Code node analyzes the ThreatMetrix Session Query response and routes the journey based on configured LexisNexis Dynamic Decision Platform rule reason codes. - [ThreatMetrix Review Status node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/threat-metrix-review-status.md): The ThreatMetrix Review Status node analyzes the ThreatMetrix Session Query response and routes the journey based on the review status: Pass, Challenge, Review, or Reject. - [ThreatMetrix Session Query node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/threat-metrix-session-query.md): The ThreatMetrix Session Query node queries the LexisNexis Dynamic Decision Platform to retrieve a policy decision about a user session for fraud risk assessment in Advanced Identity Cloud. - [ThreatMetrix Update Review node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/threat-metrix-update-review.md): The ThreatMetrix Update Review node sends retrospective truth data from an authentication event back to ThreatMetrix to improve policy tuning and fraud detection accuracy. - [Time Since Decision node](https://docs.pingidentity.com/auth-node-ref/latest/time-since-decision.md): Configure the Time Since Decision node to check whether a specified amount of time has elapsed since a user's account was created, for use in progressive profile journeys. - [Timer Start node](https://docs.pingidentity.com/auth-node-ref/latest/timer-start.md): Configure the Timer Start node to record the current time in a named property, enabling elapsed-time measurements with the Timer Stop node in a journey. - [Timer Stop node](https://docs.pingidentity.com/auth-node-ref/latest/timer-stop.md): Configure the Timer Stop node to record the time elapsed since a corresponding Timer Start node and expose the result as a named metric. - [Twilio Identifier node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/twilio-identifier.md): The Twilio Identifier node retrieves a telephone number or email address from the user profile and stores it in shared state for use by Twilio Verify nodes in Advanced Identity Cloud journeys. - [Twilio Verify Collector Decision node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/twilio-verify-collector-decision.md): The Twilio Verify Collector Decision node collects a one-time passcode from the user and validates it against the Twilio Verify service in Advanced Identity Cloud journeys. - [Twilio Verify Lookup node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/twilio-verify-lookup.md): The Twilio Verify Lookup node checks whether a phone number belongs to a mobile carrier using the Twilio Verify service in Advanced Identity Cloud journeys. - [Twilio Verify Sender node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/twilio-verify-sender.md): The Twilio Verify Sender node initiates a Twilio Verify request to send a one-time passcode to the user by SMS, call, email, or WhatsApp as an additional authentication factor. - [TypingDNA](https://docs.pingidentity.com/auth-node-ref/latest/cloud/tdna-set.md): Overview of TypingDNA integration with Advanced Identity Cloud, covering the Recorder, Short Phrase Collector, Decision, and Reset Profile nodes for AI-based typing biometric authentication. - [TypingDNA Decision node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/tdna-decision.md): The TypingDNA Decision node communicates with the TypingDNA Authentication API to enroll, verify, or reject users based on their typing patterns in Advanced Identity Cloud journeys. - [TypingDNA Recorder node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/tdna-recorder.md): The TypingDNA Recorder node collects end user typing behaviors and transforms them into typing patterns for biometric authentication in Advanced Identity Cloud journeys. - [TypingDNA Reset Profile node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/tdna-reset-profile.md): The TypingDNA Reset Profile node deletes all stored typing patterns for an end user, forcing re-enrollment the next time they sign on in Advanced Identity Cloud journeys. - [TypingDNA Short Phrase Collector node](https://docs.pingidentity.com/auth-node-ref/latest/cloud/tdna-short-phrase-collector.md): The TypingDNA Short Phrase Collector node prompts end users to type a short phrase so that their keystroke patterns can be collected for biometric authentication in Advanced Identity Cloud journeys. - [Update Journey Timeout node](https://docs.pingidentity.com/auth-node-ref/latest/update-journey-timeout.md): Configure the Update Journey Timeout node to override or adjust the maximum duration of a journey session, for example to give users time to retrieve documents. - [Username Collector node](https://docs.pingidentity.com/auth-node-ref/latest/am-only/username-collector.md): Use the Username Collector node in PingAM to prompt users to enter their username and write it to shared state for use later in the journey. - [WebAuthn Authentication node](https://docs.pingidentity.com/auth-node-ref/latest/webauthn-authentication.md): Configure the WebAuthn Authentication node to let users authenticate with a registered FIDO device, including passkeys and hardware security keys, in Advanced Identity Cloud. - [WebAuthn Device Storage node](https://docs.pingidentity.com/auth-node-ref/latest/webauthn-device-storage.md): Configure the WebAuthn Device Storage node to write FIDO2 device data from transient state to a user's profile after registration. - [WebAuthn Registration node](https://docs.pingidentity.com/auth-node-ref/latest/webauthn-registration.md): Configure the WebAuthn Registration node to let users register FIDO2 devices, such as fingerprint scanners or hardware security keys, for use during authentication. - [Write Federation Information node](https://docs.pingidentity.com/auth-node-ref/latest/write-federation-information.md): Configure the Write Federation Information node to create a persistent SAML 2.0 account link between a remote identity provider and a local service provider account. - [Zero Page Login Collector node](https://docs.pingidentity.com/auth-node-ref/latest/zero-page-login-collector.md): Configure the Zero Page Login Collector node to extract username and password credentials from HTTP headers in an incoming authentication request.