Custom Authentication

Creating a Custom Authentication scheme from scratch to have complete control over your authentication interface.

About Custom Authentication

Learn about Custom authentication.

Custom authentication is the best approach for applications when any of the following is true:

Tip: If you are planning on using the same authentication scheme for multiple applications, consider writing a custom authentication plug-in. See Implementing Plug-ins.

Setting Up Custom Authentication

Learn how to set up Custom authentication.

To create a custom authentication scheme:

  1. On the Workspace home page, click the App Builder icon.

  2. Select an application.

  3. On the Application home page, click Shared Components.

    The Shared Components page appears.

  4. Under Security, select Authentication Schemes.

  5. On the Authentication Schemes page, click Create.

  6. Select Based on a pre-configured scheme from the gallery and click Next.

  7. Under Name:

    1. Name - Enter the name used to reference the authentication scheme by other application developers.

    2. Scheme Type - Select Custom.

  8. Fill in the appropriate fields.

    To learn more about a specific field, see field-level Help.

  9. Click Create Authentication Scheme.

See Also: Viewing Field-Level and Page Designer Help

About Session Management Security

Learn about session management security.

When running custom authentication, APEX attempts to prevent two improper situations:

APEX checks that the user identity token set by the custom authentication function matches the user identity recorded when the application session was first created. If the user has not yet been authenticated and the user identity is not yet known, the session state being accessed does not belong to someone else. These checks determine whether the session ID in the request can be used. If not, the APEX engine redirects back the same page using an appropriate session ID.