Events

Authelia sends a fixed set of notifications. Every notification is addressed to the email address recorded for the user in the authentication backend, is rendered from one of three templates, and is delivered by whichever notifier you have configured.

Authelia does not send marketing, digest, or administrative messages, and there is no per-event configuration option to enable or disable an individual notification.

Events

EventSubjectTemplate
Password reset requestedReset your passwordIdentityVerificationJWT
Session elevation requestedConfirm your identityIdentityVerificationOTC
Password reset completedPassword changed successfullyEvent
Password changedPassword changed successfullyEvent
Second factor registeredSecond Factor Method AddedEvent
Second factor removedSecond Factor Method RemovedEvent

The subject line is also used as the {{ .Title }} placeholder within the template.

Password reset requested

Sent when a user requests a password reset from the sign-in portal. The notification contains a single-use link which proves the recipient controls the mailbox, and a second link which revokes the request.

This notification is sent whether or not the requested user exists, from the perspective of the requester: the portal always responds identically in order to prevent user enumeration. No notification is sent when the user does not exist.

Session elevation requested

Sent when a user attempts an operation which requires an elevated session, such as managing their credentials, and identity validation requires them to confirm their identity. The notification contains a One-Time Code rather than a link, and a link which revokes the elevation request.

Password reset completed

Sent to the user after their password has been successfully changed via the password reset flow.

Password changed

Sent to the user after they have successfully changed their own password from the settings area.

Second factor registered

Sent when a user registers a new second factor method. The body names which method was registered, either a One-Time Password or a WebAuthn Credential, and in the case of a WebAuthn Credential the description the user gave it.

Second factor removed

Sent when a user removes a registered second factor method. As with registration, the body names the method and, for a WebAuthn Credential, its description.

Delivery

What a recipient actually receives depends on the configured notifier.

NotifierDelivery
SMTPA multipart message containing both the plaintext and HTML renderings.
SMTP with disable_html_emailsThe plaintext rendering only.
FilesystemThe plaintext rendering only, preceded by a header naming the date, recipient, and subject.

The filesystem notifier is intended for testing and development. It writes every notification to a single file rather than delivering it to the user, so a deployment using it sends the user nothing.

Customizing

The content of each notification is controlled by its template. To override one, set template_path and provide a file named after the template with either a .html or .txt extension.

See the Notification Templates reference guide for the available templates, the placeholder variables each one accepts, and the functions available within them.