Events
Authelia sends a fixed set of notifications. Every notification is addressed to the email address recorded for the user in the authentication backend, is rendered from one of three templates, and is delivered by whichever notifier you have configured.
Authelia does not send marketing, digest, or administrative messages, and there is no per-event configuration option to enable or disable an individual notification.
Events
| Event | Subject | Template |
|---|---|---|
| Password reset requested | Reset your password | IdentityVerificationJWT |
| Session elevation requested | Confirm your identity | IdentityVerificationOTC |
| Password reset completed | Password changed successfully | Event |
| Password changed | Password changed successfully | Event |
| Second factor registered | Second Factor Method Added | Event |
| Second factor removed | Second Factor Method Removed | Event |
The subject line is also used as the {{ .Title }} placeholder within the template.
Password reset requested
Sent when a user requests a password reset from the sign-in portal. The notification contains a single-use link which proves the recipient controls the mailbox, and a second link which revokes the request.
This notification is sent whether or not the requested user exists, from the perspective of the requester: the portal always responds identically in order to prevent user enumeration. No notification is sent when the user does not exist.
Session elevation requested
Sent when a user attempts an operation which requires an elevated session, such as managing their credentials, and identity validation requires them to confirm their identity. The notification contains a One-Time Code rather than a link, and a link which revokes the elevation request.
Password reset completed
Sent to the user after their password has been successfully changed via the password reset flow.
Password changed
Sent to the user after they have successfully changed their own password from the settings area.
Second factor registered
Sent when a user registers a new second factor method. The body names which method was registered, either a One-Time Password or a WebAuthn Credential, and in the case of a WebAuthn Credential the description the user gave it.
Second factor removed
Sent when a user removes a registered second factor method. As with registration, the body names the method and, for a WebAuthn Credential, its description.
Delivery
What a recipient actually receives depends on the configured notifier.
| Notifier | Delivery |
|---|---|
| SMTP | A multipart message containing both the plaintext and HTML renderings. |
SMTP with disable_html_emails | The plaintext rendering only. |
| Filesystem | The plaintext rendering only, preceded by a header naming the date, recipient, and subject. |
The filesystem notifier is intended for testing and development. It writes every notification to a single file rather than delivering it to the user, so a deployment using it sends the user nothing.
Customizing
The content of each notification is controlled by its template. To override one, set
template_path and provide a file named after the template with either a .html or
.txt extension.
See the Notification Templates reference guide for the available templates, the placeholder variables each one accepts, and the functions available within them.