Skip to main content
Version: v45

PrivX Authorizer

PrivX Authorizer is a mobile app that allows PrivX users to:

  • Approve multi-factor authentication (MFA) requests when logging in to PrivX.
  • Approve or deny role requests assigned to them through PrivX workflows.

Mobile approval of role requests requires PrivX Authorizer 2.0.0 or later. PrivX Authorizer 1.7.x supports MFA login approval but does not support role request approval.

App VersionMFA Login ApprovalRole Request Approval
PrivX Authorizer 1.7.xSupportedNot supported
PrivX Authorizer 2.x.xSupportedSupported

PrivX Authorizer 1.7.x remains compatible with existing MFA functionality. We recommend users to upgrade to PrivX Authorizer 2.0.0 or later to approve role requests from the mobile app.

Prerequisites​

PrivX Authorizer requires:

  • A PrivX online license with the Mobile Gateway feature enabled.
  • Network access from the PrivX servers to the PrivX Mobile Gateway endpoint at https://mobilegw.privx.io:443.
  • A PrivX deployment registered with the Mobile Application Gateway.

Mobile approval of role requests additionally requires:

  • A PrivX online license with the Mobile Approval feature enabled.
  • A paired mobile device with PrivX Authorizer 2.0.0 or later installed.
  • An active mobile approval subscription for the paired device.
  • The required role to approve the workflow step.

To use PrivX Authorizer:

  1. Set up PrivX Mobile Gateway.
  2. Register PrivX with the Mobile Application Gateway.
  3. Install PrivX Authorizer and pair the mobile device with PrivX.
  4. Configure one or both of the following features depending on your PrivX Authorizer version:
    • Multi-factor authentication: Enable PrivX Authorizer as the MFA method for the required user directories.
    • Role request approval: Enable mobile approval for the required workflows. Approvers must also subscribe each paired device that they want to use for mobile approval.

After setup, users can verify login requests with PrivX Authorizer. Subscribed approvers also receive notifications about pending role requests and can approve or deny them in the app.


Setting Up Mobile Gateway​

MFA with PrivX Authorizer relies on the PrivX Mobile Gateway cloud service. The service is operated by SSH Communications Security.

The Mobile Gateway endpoint mobilegw.privx.io is hosted behind Amazon API Gateway and uses dynamic IP addresses. Before you begin, ensure that your PrivX servers can:

  • Resolve the Mobile Gateway IP addresses.
  • Complete TLS handshakes and validate the certificate for mobile.gateway.privx.io:443.

For environments that do not support dynamic IP addresses, configure your PrivX to a static Mobile Gateway endpoint in Administration → Settings → Global and under Mobile Gateway Endpoint enable the Use Static IPs setting.

When Use Static IPs is enabled, PrivX Servers use fixed.mobilegw.privx.io as the Mobile Gateway endpoint to resolves to the following two static IP addresses:

  • 34.246.145.86
  • 34.241.193.96

Restart PrivX to apply your changes. Ensure that your firewall rules allow the PrivX servers to access these IP addresses.

To minimize the storage of sensitive information, PrivX Mobile Gateway collects only the following data:

Data TypeDescriptionExample Value
PrivX product keyHash value of a public key per PrivX installationproduct-sha256-sS6ACFY-QF5MArxe2Twr9Gxm0ImED1_YdDca5bpAh60
PrivX user keyHash of a user ID in a PrivX Serverda313ca13cd81fcb04fc8a95d5edc05ae8010203
Mobile device keyHash value of public key of PrivX Authorizer appmobile-sha256-cKPwKD4IirMnXa_WDaixd4PKSZ4KlvkJhGTo4WTyduU
Device nameHardware model of the mobile deviceiPhone 14 Pro
Device OSDevice OS and versioniOS 17.2

Registering PrivX with Mobile Application Gateway​

PrivX Authorizer requires connectivity to the PrivX Mobile Gateway cloud service. The service is operated by SSH.

To register your PrivX deployment with the Mobile Application Gateway, go to Administration → Deployment → Mobile Application Gateway and select Register.

Setting Up Licensing for PrivX Authorizer​

Ensure that your PrivX online license includes Mobile Gateway. If you plan to use mobile approval of the Role Requests feature, the license must also include Mobile Approvals.

To view the enabled features, go to Administration → License. For more information, see Licensable Features.

Pairing PrivX Authorizer​

To pair a mobile device with PrivX:

  1. Download PrivX Authorizer from Google Play or the App Store.

  2. On first launch, enable notifications and select Continue to App. Allow camera access if prompted.

  3. In the PrivX Web UI, go to your Account page. Under Credentials → Paired Devices, select Pair New Device. PrivX displays a QR code. If MFA is required for the account, PrivX displays a pairing QR code the next time the user logs in.

    Two-Factor Authentication prompt
  4. Open PrivX Authorizer on your mobile device and select Scan QR Code. If the app already displays My Services, select Add New Service instead. Allow camera access if prompted, then scan the QR code displayed in the PrivX Web UI.

  5. On Pair This Device, verify that the service and account details are correct, then select Pair This Device.

  6. Keep PrivX Authorizer open while pairing completes. The app displays Pairing Complete, then shows the paired PrivX service under My Services:

Paired PrivX service in PrivX Authorizer

PrivX Authorizer lists paired PrivX services under My Services. Select a service to view its pending requests. Depending on your configuration, these can include sign-in requests and role requests.

Managing Paired Devices​

You can manage paired devices in the PrivX Web UI, on the Accounts page, under Credentials → Paired Devices:

  • Subscribe to/Unsubscribe from Role Requests
  • Unpair Device
  • Test Login

Unpairing a device removes its mobile approval subscriptions and request information. If the device is paired again by the same user or another user, information from the previous pairing is not available. Subscribe the new pairing separately to receive role approval requests.


The screenshots show PrivX Authorizer on Android. The interface may differ on iOS and between application versions.