Decoupled Drupal with 2FA | Configure 2FA with Headless/ Decoupled Drupal

Decoupled Drupal with 2FA | Configure 2FA with Headless/ Decoupled Drupal


Secure your Headless/Decoupled Drupal with a robust Two Factor Authentication (2FA) using our Drupal 2FA (Two-Factor Authentication) module. This guide will help you to configure Two-Factor Authentication (2FA / MFA) for your Headless Drupal site.
Drupal 2FA module will add a second layer of authentication to your Drupal account to increase the security of your site from unwanted hacks and unauthorized login attempts. This module is compatible with all Drupal 7, 8 and Drupal 9 sites.
If you have any queries or if you need any sort of assistance in configuring the module, you can contact us at drupalsupport@xecurify.com. If you want, we can also schedule an online meeting to help you configure the Drupal 2FA (Two-Factor Authentication) module.

Pre-requisites: Download

Drupal Two-Factor Authentication (2FA) module. You can download the module from here.

Steps to configure 2FA method with Headless Drupal Using Drupal Two-Factor Authentication (2FA) module:

1. Setup Drupal as Headless 2FA

  • Navigate to the Headless 2FA Setup tab.
  • Click on Enable Headless Two-Factorcheckbox to activate the Headless/Decoupled 2FA service.
  • Drupal Headless 2FA - Enable headless 2FA
  • Select the authentication method of your choice from 2FA method dropdown.
  • Drupal Headless 2FA - Select 2FA Method
  • Enter the Machine Name of the phone number field. You can click the link in Note to check available fields on your Drupal site.
  • Drupal Headless 2FA Enter Machine Name
  • Click on the Save Settings button.

2. Steps to integrate Headless/ Decoupled 2FA:

  • Minimum requirement for integrating 2FA with Drupal :
    1. Login page : Having Username and Password fields
    2. OTP Page: Having OTP fields
Drupal Headless 2FA - Flow diagram

Authenticate users by sending Username and Password

  • The first step is to authenticate users by sending Username and Password to our /headless/authenticate endpoint (API) so they can authenticate against the Drupal database. Once the user is authenticated successfully, OTP will be sent to registered mobile/email (depending on the configuration).
  • API: POST {drupal-base-URL}/headless/authenticate.
    What you will send:
    {"username":"xxxxx","password":"xxxxx"}
    If successful, you will receive back the following response:
    {"username":"xxxxx","status":"SUCCESS","message":"xxxxx","transactionID":"xxxxx","authType":"xxxxx"}

  • With the following parameters:
  • PARAMETER TYPE REQUIRED? DESCRIPTION
    username string required Entered by the user on the login form.
    password string required Entered by the user on the login form.

Validate the user by sending OTP

  • The second step is to validate the user by sending OTP (One time passcode) to our /headless/login endpoint (API).
  • API: POST {drupal-base-URL}/headless/login
    What you will send:
    {"username":"xxxxx","transactionID":"xxxxx","authType":"xxxxx","otp":"xxxxx"}
    If successful, you will receive back the following response:
    {"username":"xxxxx","status":"SUCCESS","message":"xxxxx","userprofile":"xxxxx"}

  • With the following parameters:
  • PARAMETER TYPE REQUIRED? DESCRIPTION
    username string required You will get this in response to the first API call.
    transactionID string required You will get this in response to the first API call.
    authType string required You will get this in response to the first API call.
    otp string required You will get this in response to the first API call.

POSSIBLE ERRORS

    ERROR CODE DESCRIPTION
    404 Not Found Headless 2FA setting is not enabled. Please enable the same under the Headless 2FA Setup tab of the module.
    401 Unauthorized User has entered invalid credentials (username/password)
    403 Forbidden User has entered the incorrect OTP (One time passcode)
    500 Internal Server Error You will get 500 Internal Server Error due to various reasons, please check Drupal logs for more details.

24*7 Active Support

If you face any issues or if you have any questions, please feel free to reach out to us at drupalsupport@xecurify.com. In case you want some additional features to be included in the module, please get in touch with us, and we can get that custom-made for you. Also, If you want, we can also schedule an online meeting to help you configure the Drupal 2FA module.

Our Other modules

Hello there!

Need Help? We are right here!

support
Contact miniOrange Support
success

Thanks for your inquiry.

If you dont hear from us within 24 hours, please feel free to send a follow up email to info@xecurify.com