<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Topics tagged with verification]]></title><description><![CDATA[A list of topics that have been tagged with verification]]></description><link>https://fusionauth.io/community/forum/tags/verification</link><generator>RSS for Node</generator><lastBuildDate>Thu, 16 Jul 2026 19:58:13 GMT</lastBuildDate><atom:link href="https://fusionauth.io/community/forum/tags/verification.rss" rel="self" type="application/rss+xml"/><pubDate>Invalid Date</pubDate><ttl>60</ttl><item><title><![CDATA[Does fusion auth supports es256k header for secp256k1 curve keys?]]></title><description><![CDATA[<p dir="auto">Hiya <a class="mention plugin-mentions-user plugin-mentions-a" href="https://fusionauth.io/community/forum/uid/2222">@benjamineroommen</a> ,</p>
<p dir="auto">I'm not sure what you mean? Are you talking about the JWT generated for a login event?</p>
]]></description><link>https://fusionauth.io/community/forum/topic/2337/does-fusion-auth-supports-es256k-header-for-secp256k1-curve-keys</link><guid isPermaLink="true">https://fusionauth.io/community/forum/topic/2337/does-fusion-auth-supports-es256k-header-for-secp256k1-curve-keys</guid><dc:creator><![CDATA[dan]]></dc:creator><pubDate>Invalid Date</pubDate></item><item><title><![CDATA[fusion auth versus jose4j library for jwt using secp256k]]></title><description><![CDATA[
ok main thing is, is it ok to use header ES256 for jwt created using secp256k1 keys?

<p dir="auto"><a href="https://datatracker.ietf.org/doc/html/rfc8812" rel="nofollow ugc">https://datatracker.ietf.org/doc/html/rfc8812</a> says, secp256k1 curve should only be used with ES256k header, but in authfusion even if we give k1 pair keys and then use sign and encode a JWT using EC, it will come as ES256 only, is that okay?</p>

Another doubt is, those jwt (k1 curve keys + ES256) created in authfusion is only able to verify in jose4j with .setRelaxVerificationKeyValidation() //needed if the key is smaller than 256 bits.

<p dir="auto">Without it we get the error:</p>
JWT processing failed. Additional details: &lsqb;&lsqb;17] Unable to process JOSE object (cause: org.jose4j.lang.InvalidKeyException: ES256/SHA256withECDSA expects a key using P-256 but was null):

<p dir="auto">Description inside <strong>setRelaxVerificationKeyValidation</strong> :</p>
Bypass the strict checks on the verification key. This might be needed, for example, if the JWT issuer is using 1024-bit RSA keys or HMAC secrets that are too small (smaller than the size of the hash output)

<p dir="auto">Is it the correct way to validate jwt created using ec in authfusion?</p>
]]></description><link>https://fusionauth.io/community/forum/topic/2315/fusion-auth-versus-jose4j-library-for-jwt-using-secp256k</link><guid isPermaLink="true">https://fusionauth.io/community/forum/topic/2315/fusion-auth-versus-jose4j-library-for-jwt-using-secp256k</guid><dc:creator><![CDATA[benjamineroommen]]></dc:creator><pubDate>Invalid Date</pubDate></item><item><title><![CDATA[Email Send exception while calling the &#x2F;registration API]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">We are calling the /api/user/registration API to create and register a new user. Our requirement is that we want to send an email verification first to the user, only after the user clicks on the link and verifies the email then we would like the user to be verified in FusioanAuth.</p>
<p dir="auto">Based on the API documentation it states that when we make a request to this API and if the "skipVerification" is set to default with is "false" it should send an email verification to the newly created user. And then the user should get an email.</p>
<p dir="auto">Though the call is successful we are getting the following error within the event logs  while sending the email.</p>
<p dir="auto">Async Email Send exception occurred.</p>
<p dir="auto">Template Id: 0e107c44-a3de-4607-b51c-cd797463ce3a<br />
Template Name: [FusionAuth Default] Email Verification<br />
Tenant Id: 07448f27-ca36-9612-8b9a-bce2e7137351<br />
Addressed to: <a href="mailto:apekshagb@gmail.com" rel="nofollow ugc">apekshagb@gmail.com</a></p>
<p dir="auto">Cause:<br />
javax.mail.MessagingException : Message: Could not connect to SMTP host: 127.0.0.1, port: 1025</p>
<p dir="auto">I did try to use an external SMTP server as mailcatcher but that didn't work either. Are we missing any configuration or we need to call a different API?</p>
<p dir="auto">Regards<br />
Apeksha</p>
]]></description><link>https://fusionauth.io/community/forum/topic/1587/email-send-exception-while-calling-the-registration-api</link><guid isPermaLink="true">https://fusionauth.io/community/forum/topic/1587/email-send-exception-while-calling-the-registration-api</guid><dc:creator><![CDATA[apeksha.barhanpur]]></dc:creator><pubDate>Invalid Date</pubDate></item><item><title><![CDATA[Verification of ID Token using RSA public key]]></title><description><![CDATA[<p dir="auto"><a class="mention plugin-mentions-user plugin-mentions-a" href="https://fusionauth.io/community/forum/uid/1401">@gokul-mahajan20</a></p>
<p dir="auto">Can you add ----BEGIN to the JWKS certs?</p>
]]></description><link>https://fusionauth.io/community/forum/topic/1519/verification-of-id-token-using-rsa-public-key</link><guid isPermaLink="true">https://fusionauth.io/community/forum/topic/1519/verification-of-id-token-using-rsa-public-key</guid><dc:creator><![CDATA[dan]]></dc:creator><pubDate>Invalid Date</pubDate></item><item><title><![CDATA[Link in Email verification not working first time]]></title><description><![CDATA[<p dir="auto">We have the exact same issue. If this was solved (hopefully) could you please provide a brief description on the fix?<br />
Thanks!</p>
]]></description><link>https://fusionauth.io/community/forum/topic/1406/link-in-email-verification-not-working-first-time</link><guid isPermaLink="true">https://fusionauth.io/community/forum/topic/1406/link-in-email-verification-not-working-first-time</guid><dc:creator><![CDATA[skelsec]]></dc:creator><pubDate>Invalid Date</pubDate></item><item><title><![CDATA[Email verification security hole?]]></title><description><![CDATA[<p dir="auto">If you are using email verification, you can check this user state within your own app. (So, don't allow the attacker to access anything until their email address has been verified.)</p>
<p dir="auto">In version 1.27.0 you can configure a gated login flow when the user is not verified (this is a 'reactor' feature requiring a paid license). This will enforce email verification before we even redirect to your app. You can then also configure FusionAuth to delete users after N number of days if the user has not verified their email address. This can assist with build up of accounts that are not actually in use.</p>
]]></description><link>https://fusionauth.io/community/forum/topic/1156/email-verification-security-hole</link><guid isPermaLink="true">https://fusionauth.io/community/forum/topic/1156/email-verification-security-hole</guid><dc:creator><![CDATA[dan]]></dc:creator><pubDate>Invalid Date</pubDate></item><item><title><![CDATA[Unable to invoke @ValidationMethod on the class [class io.fusionauth.app.action.oauth2.CompleteRegistrationAction]]]></title><description><![CDATA[<p dir="auto"><a class="mention plugin-mentions-user plugin-mentions-a" href="https://fusionauth.io/community/forum/uid/727">@alessandrojcm</a>,</p>
<p dir="auto">Sounds good.  I have logged a <a href="https://github.com/FusionAuth/fusionauth-issues/issues/1255" rel="nofollow ugc">bug report</a>; we should have this one squashed soon!</p>
<p dir="auto">Thanks,<br />
Josh</p>
]]></description><link>https://fusionauth.io/community/forum/topic/1076/unable-to-invoke-validationmethod-on-the-class-class-io-fusionauth-app-action-oauth2-completeregistrationaction</link><guid isPermaLink="true">https://fusionauth.io/community/forum/topic/1076/unable-to-invoke-validationmethod-on-the-class-class-io-fusionauth-app-action-oauth2-completeregistrationaction</guid><dc:creator><![CDATA[joshua]]></dc:creator><pubDate>Invalid Date</pubDate></item><item><title><![CDATA[Does FusionAuth support the ability to use codes for verification?]]></title><description><![CDATA[<p dir="auto">Yes. As of 1.27, you can use a verification strategy of FormField. This is configured on the tenant: <a href="https://fusionauth.io/docs/v1/tech/apis/tenants/" rel="nofollow ugc">https://fusionauth.io/docs/v1/tech/apis/tenants/</a></p>
<p dir="auto">You then provide the one time code in the oneTimeCode request body parameter. More about this in the email verification docs: <a href="https://fusionauth.io/docs/v1/tech/apis/users/#verify-a-users-email" rel="nofollow ugc">https://fusionauth.io/docs/v1/tech/apis/users/#verify-a-users-email</a></p>
<p dir="auto">Note that this feature only works with email gating at the current time, which is a reactor feature requiring a paid license.</p>
]]></description><link>https://fusionauth.io/community/forum/topic/1035/does-fusionauth-support-the-ability-to-use-codes-for-verification</link><guid isPermaLink="true">https://fusionauth.io/community/forum/topic/1035/does-fusionauth-support-the-ability-to-use-codes-for-verification</guid><dc:creator><![CDATA[dan]]></dc:creator><pubDate>Invalid Date</pubDate></item><item><title><![CDATA[Email verification email for &#x27;welcome message&#x27;]]></title><description><![CDATA[<p dir="auto">You are correct. The verified flag exists on the corresponding user and the registration. You could optionally use the "verify registration" templatefor this purpose.</p>
<p dir="auto">If you then ignored the verified: false flag on the registration in your code, it should not impact you.</p>
<p dir="auto">Another option would be to listen for the user.registration.create event and then fire off an email on your end, or call the Email Send API to send a pre-made FusionAuth email template as a welcome event: <a href="https://fusionauth.io/docs/v1/tech/apis/emails/#send-an-email" rel="nofollow ugc">https://fusionauth.io/docs/v1/tech/apis/emails/#send-an-email</a></p>
]]></description><link>https://fusionauth.io/community/forum/topic/746/email-verification-email-for-welcome-message</link><guid isPermaLink="true">https://fusionauth.io/community/forum/topic/746/email-verification-email-for-welcome-message</guid><dc:creator><![CDATA[dan]]></dc:creator><pubDate>Invalid Date</pubDate></item><item><title><![CDATA[Email verification without sending emails?]]></title><description><![CDATA[<p dir="auto">You could use the skipVerification parameter (set it to true) on the user or registration create statement, and then the <a href="https://fusionauth.io/docs/v1/tech/apis/users#resend-verification-email" rel="nofollow ugc">https://fusionauth.io/docs/v1/tech/apis/users#resend-verification-email</a> call with sendVerifyEmail set to false.</p>
<p dir="auto">This would give you a verificationId you could use with this API call: <a href="https://fusionauth.io/docs/v1/tech/apis/users#verify-a-users-email" rel="nofollow ugc">https://fusionauth.io/docs/v1/tech/apis/users#verify-a-users-email</a></p>
]]></description><link>https://fusionauth.io/community/forum/topic/353/email-verification-without-sending-emails</link><guid isPermaLink="true">https://fusionauth.io/community/forum/topic/353/email-verification-without-sending-emails</guid><dc:creator><![CDATA[dan]]></dc:creator><pubDate>Invalid Date</pubDate></item><item><title><![CDATA[The default templates are being marked as spam?]]></title><description><![CDATA[<p dir="auto">It looks like the issue was our mail server. We are using Mailgun SMTP service for our mail sending and this offers a tracking feature.</p>
<p dir="auto">This tracking feature adds a invisible image to the html code in order to get request for stats. If I deactivate this feature, the HTML_IMAGE_ONLY_12 error is gone and the mail are no longer marked as SPAM. We don't have any issues with our other applications because sent emails are bigger in text content.</p>
]]></description><link>https://fusionauth.io/community/forum/topic/313/the-default-templates-are-being-marked-as-spam</link><guid isPermaLink="true">https://fusionauth.io/community/forum/topic/313/the-default-templates-are-being-marked-as-spam</guid><dc:creator><![CDATA[dan]]></dc:creator><pubDate>Invalid Date</pubDate></item><item><title><![CDATA[Token difference when account hasn&#x27;t been verified]]></title><description><![CDATA[<p dir="auto">The JWT (id_token or access_token) will contain the email_verified claim with a value of true or false, so if you wish to limit privilege based upon this state, that would be a good way to do it.</p>
]]></description><link>https://fusionauth.io/community/forum/topic/282/token-difference-when-account-hasn-t-been-verified</link><guid isPermaLink="true">https://fusionauth.io/community/forum/topic/282/token-difference-when-account-hasn-t-been-verified</guid><dc:creator><![CDATA[dan]]></dc:creator><pubDate>Invalid Date</pubDate></item></channel></rss>