Chrome Roads Identity Platform

AUTHENTICATION & INTENT SERVICES

Confirm identity.
Verify intent.

Know who is acting. Confirm what they intend to do. Bring authentication and approval of specific actions into your application with the standalone FIDO2 RP and mobile SDK.

MORE THAN A SUCCESSFUL LOGIN

What did you
actually approve?

Confirming identity tells you who is acting. Confirming intent asks whether they mean to approve this amount, this recipient or this scheduled call.

Show the exact details, give the person a chance to review them, and connect their verified decision to the action your system executes.

Follow a wire transfer through the business and customer views, or check an insurance call against recent outreach in the customer’s app. Explore the normal and attack cases.

CONFIRMING YOUR INTENTExplore the experience
WIRE TRANSFERSee demo

Approve the transfer you intended.

Follow a $25,000 wire from the banking website to the customer’s trusted device. Then see what changes when an attacker alters the request.

Normal caseAttack case

See the request, the device review and the bank’s response.

* Illustrative experiences. No account or device needed.

Choose the right friction
for the action.

Commerce keeps getting faster. Your application sets the level of confirmation, from a quick click to explicit approval of the exact transaction.

  1. 01 / ONE-CLICK

    Keep simple actions quick.

    Let routine actions proceed with a click when that is all your application requires.

  2. 02 / IDENTITY CONFIRMATION

    Confirm who is acting.

    Ask the person to verify their identity before your application proceeds.

  3. 03 / FULL TRANSACTION CONFIRMATION

    Confirm what they intend.

    Show the amount, recipient or requested change on the card or in your integrated mobile app. Ask for explicit approval of those exact details.

“Wire $10,000 to Alex Smith?” gives someone a specific action to review and approve. Confirming identity alone does not tell you whether they intended that transfer.

AUTHENTICATION & INTENT SERVICES

On the card.
In your app.

Use the Chrome Roads Card as a dedicated authenticator, or bring authentication and intent confirmation into your existing iOS or Android app with our mobile SDK.

The FIDO2 relying party (RP) verifies authentication and approval responses for your application. Your backend uses the verified result to complete the requested action.

Available standalone with the mobile SDK. The FIDO2 RP requires no other Chrome Roads Server component.

Discuss an RP and SDK integration
DEDICATED AUTHENTICATOR

Chrome Roads Card

Review and confirm on the card.

MOBILE SDK

Your existing app

iOS & Android

Through your application

AUTHENTICATION & INTENT SERVICES

FIDO2 relying party (RP)

Verify identity and confirmation of the specific action.

Your backend

Act on the verified result.

One authentication service for card and mobile integrations.

BUILD WITH THE RP & SDK

Build it into
your application.

Connect your application and backend to the FIDO2 RP. Use the mobile SDK for iOS and Android, or integrate the Chrome Roads Card. Keep the requested details, verified decision and resulting action connected throughout the flow.

  1. 01

    Request

    Your system submits the transaction or sensitive action, including the details that need approval.

  2. 02

    Review

    After identity validation, the person reviews the details on their enrolled phone or card. Is this the action they intended? They can approve or reject it.

  3. 03

    Verify

    The FIDO2 RP service verifies the approval against the exact action shown to the person.

  4. 04

    Execute

    Your integrated backend acts on the authorized request.

  5. 05

    Retain evidence

    Your application keeps the requested terms, verified decision and resulting action together for later review.

Changed terms? New approval.

The integration must connect the verified decision to the same action your system executes.

VERIFIED OUTREACH · INTEGRATION EXAMPLE

A trusted place
to check expected contact.

Explore Verified Outreach with the Authentication & Intent Services. Register the purpose, channel and expected time of contact for customers to check inside your authenticated application.

Check the notice.
Then verify the interaction.

A registered notice establishes what contact to expect. The application also needs a way to match the caller or session to that notice, such as returning to a conversation within the authenticated app.

If the interaction leads to a payment, account change or other sensitive action, ask for a separate approval of those exact details.

Discuss Verified Outreach

Ask about availability and integration requirements for your application.

EXAMPLE NOTICEExpected contact from your bank
Purpose
Review unusual account activity
Channel
Telephone
Expected time
Today, 2–3 p.m.
Reference
483921

Check the contact through your authenticated app. Acknowledging this notice does not authorize a transaction.

Illustration only. No outreach is registered or sent.

LET’S TALK ABOUT YOUR APPLICATION

Build your
approval flow.

Explore the standalone FIDO2 RP and mobile SDK,
or plan a card integration with our team.

Discuss your integration