For the user to be able to activate their Mobile Authenticator Studio account and app, you must provide their credentials to them. The following workflow describes the steps a user must take to activate your application for the first time.
To activate an account offline
The user is presented with the authenticator home screen and taps Scan Code to initiate the activation process.
With the device camera, the user scans the QR code or Cronto image in your application to link their device and their account. A code appears.
The user is prompted to enter this code into your application.
The user scans a second QR code or Cronto image.
The user chooses a PIN.
The user confirms the PIN.
The user chooses their preferred authentication method for future access: biometric authentication with face or fingerprint recognition, or authentication via PIN.
If the user selects to skip setting up biometric authentication at this stage, they can enable this feature anytime later via the Mobile Authenticator Studio menu. For more information, see Biometric authentication.
The user gives Mobile Authenticator Studio permission to use face or fingerprint recognition.
The user's biometric data is collected.
The user enters a code into your application or web page to activate the account.
(Optional, if notifications are enabled in the app configuration) The user gives Mobile Authenticator Studio permission to send notifications from your application by tapping Allow notifications.
When the activation is successful, the user is redirected to the activated home screen, and the app is ready to be used for authentication.
If the process is interrupted, the user will see these screens:
If at any time the user taps Cancel they will see a cancel confirmation screen and can restart the activation process.
If something goes wrong, the user will be notified with an error message and tapping Start over will restart the activation procedure from the beginning.
Offline activation with DIGIPASS Gateway
In the DIGIPASS Gateway offline activation process, the user must provide additional information to complete the notification registration. This is required to receive push requests (Push and Sign or Push and Login) and to complete online actions such as approving Scan-and-Sign or Scan-and-Login workflows. After the user has tapped Allow Notifications, the app requests the user identifier from the credentials for the current account. Once the user provided this, the Done button is enabled. When the user taps this button, the notification registration and the activation flow are completed.
The rest of the workflow is identical to the regular offline activation process described in the procedure above.
If the user provides an invalid user identifier, an error will be displayed. The user can retry after verifying the information or dismiss the notification registration. If the user chooses not to enable notifications, the Allow Notifications screen will be displayed every time the app is launched until the user successfully completes the process.