Integration Model

Prev Next

The OneSpan Identity Verification integration model is geared towards simplicity and security. System-to-system integration is done via the OneSpan Identity Verification REST API. For more information, see OneSpan Identity Verification REST API.

Authentication

Authentication for access to the OneSpan Identity Verification REST API happens via two-legged OAuth2 with a JSON Web Token (JWT). OneSpan support provides a JWT to OneSpan Identity Verification customers. This token is used to restrict access to resources that are authorized for a given tenant, such as transactions, providers, or data sources. Effectively, the JWT Bearer schema is used as client credentials for API requests.

PUT /api/transaction/ HTTP1.1
Host: onespan.com
Accept: application/json, text/javascript
Authorization: Bearer xxxxxx\!
 xxxxx...

{
 "tenant_id":"12345678-1234-5678-901234567",
 "workflow_id":"12345678-1234-5678-901234567",
 "urlSetKey":"default",
 "brand_id:"12345678-1234-5678-901234567",
 "language":"english",
 "users": [...],
 "documents": [...]
}

JSON Web Tokens

The OneSpan Professional Services Team provides the access token, which will be used by the client when creating transactions.

  • Scopes: tenant_access

Access token

Header: Algorithm and token type

{
 "alg":"A1234"
 "typ":"JWT"
}

Payload: Data

{
 "scope": [
 "tenant_access"
 ],
 "exp": 3698071610,
 "jti": "12345678-1234-5678-901234567"
 "client_id": "onespan"
}

Token

<token key>

Session token

Header: Algorithm and token type

{
 "alg":"A12345"
 "typ":"JWT"
}

Payload: Data

{
 "session": {
 "role": "Borrower"
},
 "scope": [
 "session_creation_authorization_code"
],
 "transaction_uuid": "12345678-1234-5678-901234567,
 "exp": 1550591677,
 "jti": "12345678-1234-5678-901234567",
 "client_id": "onespan"
}

Token

<token key>