---
title: Authentication session allowlisting
description: Enable authentication session allowlisting to protect authentication sessions from replay attacks by validating key-value pairs at each authentication node
component: pingam
version: 7.5
page_id: pingam:security:auth-session-whitelist
canonical_url: https://docs.pingidentity.com/pingam/8.1/security/auth-session-whitelist.html
llms_txt: https://docs.pingidentity.com/pingam/llms.txt
docs_for_agents: https://developer.pingidentity.com/build-with-ai/docs-for-agents.md
keywords: ["Security", "Sessions", "Authentication", "Setup &amp; Configuration"]
page_aliases: ["security-guide:auth-session-whitelist.adoc"]
superseded_by: https://docs.pingidentity.com/pingam/8.1/security/auth-session-whitelist.html
section_ids:
  proc-configure-auth-session-whitelisting: Configure authentication session allowlisting
---

# Authentication session allowlisting

Enable authentication session allowlisting to protect authentication sessions from replay attacks.

When authentication session allowlisting is enabled, AM generates a key-value pair for each authentication session and stores it for the length of the authentication flow in the following ways:

* For client-side authentication sessions, AM stores the key-value pair in the CTS token store.

* For server-side authentication sessions, AM creates the key-value pair as a session property in the authentication session.

* For in-memory sessions, AM creates the key-value pair as a session property in the authentication session.

Each time the authentication flow reaches an authentication node, AM modifies the value of the stored key-value pair and sends it to the user or client that it is authenticating. The next request to AM to continue the authentication flow must contain the key-value pair and must match the value expected by AM.

If the authenticating user or client cannot provide the key-value pair with the values AM expects, AM would not continue the authentication flow, therefore protecting the authentication flow against malicious users wanting to rewind the authentication flow to a previous node.

Perform the following steps to configure authentication session allowlisting:

## Configure authentication session allowlisting

1. Go to Realms > *realm name* > Authentication > Settings > Trees.

2. Choose Enable Allowlisting.

3. Click Save.
