Web app & mobile app HSID OIDC authentication
For these cases, HSID OIDC Authentication is performed right before getting into the applications, therefore, the applications can check amr
(Authentication Method Reference) claim (array) in JWS payload of ID token. To satisfy AAL2, one of the following amrs is required:
- otp (Phone SMS / Call OTP)
- wa (WebAuthN – Passkey)
If none of them is included, the user’s authentication session is AAL1.