How to secure a mobile App with sms otp and keycloak?

282 Views Asked by At

I have the requirement to secure a flutter mobile App with SMS otp as 2FA. We use keycloak as auth server and oidc. I already created a Sms auth spi that implements the flow for Browser flow. Is it also possible to use otp with another flow? I know that the otp flow is bound to a form based http challenge. Otherwise the Server looses the relation to Session. That is the reason why direct access grant is not possible afaik. We can't use an otp app Like google auth app or free otp. Is there another way to achieve it?

0

There are 0 best solutions below