Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

For authentication

Prev Next

Introduction

This article details the steps required to integrate Auth0 with the Digipass S3 Cloud to implement strong authentication when an end user signs into your web app. Your app integrates only with Auth0 - through a standard Open ID Connect (OIDC) flow - but it gains an additional layer of authentication assurance from the Digipass S3 Cloud.

An end user attempts to sign into your client web app. Your web app redirects the authentication request to Auth0. Auth0 forwards the request to the Digipass S3 Cloud. The Digipass S3 Cloud displays the Digipass S3 sign-in page specific to your cloud tenant. After the end user successfully authenticates using the sign-in page, the Digipass S3 Cloud returns a signed token to Auth0, where it is verified. Once the token is verified, Auth0 returns its own access token back to your web application.

Auth0 remains the primary identity provider (IdP), and Auth0 stores the user data. The Digipass S3 Cloud acts as a Federation Server that is responsible for authenticating the user.  

Prerequisites

  • Auth0 is your main CIAM and user store.

  • You are a Digipass S3 Cloud customer with an admin account.

  • Your Digipass S3 Cloud tenant is configured with FIDO policies and adaptive rulesets.

  • The end user already has an authentication method registered in the Digipass S3 Cloud.

Step 1. Configure the Digipass S3 Federation Server Client

  1. Sign into the Digipass S3 Cloud.

  2. Click the Authentication Cloud>Federation console.

  3. Click the Clients tab and then click Create client.

  4. Fill in the following properties:

    Property

    Value

    Client type

    OpenID Connect

    Client ID

    auth0

    Name

    External IDP for Auth0

    Description

    External IDP for Auth0

    Always display in UI

    Off


    Click Next.

  5. On the next page, select the following options and click Next again.

  6. On the following page, fill in the following properties:

    Property

    Value

    Valid redirect URIs

    https://YOUR_AUTH0_DOMAIN/login/callback

    Web origins

    https://YOUR_AUTH0_DOMAIN


    Click Save.

  7. In the newly created client, click Advanced at the top and scroll down to the Browser Flow section.

  8. Select Sign-in App Authentication Flow and click Save.

  9. In the newly created client, click Credentials at the top.

  10. Copy the Client Secret value—you will need this for the Auth0 configuration in the next step.

Step 2. Configure the Auth0 to OIDC connection

  1. In your Auth0 dashboard, select Authentication > Enterprise from the left menu.

  2. Click OpenID Connect.

  3. On the next page, click Create Connection.

  4. Fill in the following properties:  

    Property

    Value

    Purpose

    Authentication

    Connection name

    s3-federation-server

    OpenID Connect Discovery URL

    https://cloud.noknok.com/noknok/webapps/nnlfed/realms/YOUR_TENANT_ID/.well-known/openid-configuration

    ClientID

    auth0

    Communication Channel

    Back Channel

    Enable nonce for back channel OIDC requests

    Enable

    Authentication method

    Client Secret

    Client secret

    Your S3 Federation Server client secret

    Enable Demonstrating Proof of Possession (DPoP)

    Disable

    Sync User Profile Attributes at Login

    Enable

    Promote Connection to Domain Level

    Disable

  5. Click Create.

Step 3. Configure Auth0 Application

  1. In your Auth0 dashboard, select Applications > Applications from the left menu.

  2. Click Create Application.

  3. Enter an appropriate application name and click Create.

  4. In the newly created application, click the Settings tab at the top.

  5. Scroll down to the Application URIs section.

  6. In the Allowed Callback URLs field, enter the redirect URI that your client will use.

  7. Click Save. Click the Connections tab at the top.

  8. Enable the s3-federation-server connection. Disable all other connections.

Step 4. Configure your application to work with Auth0

Your client application needs to be configured as an OpenID Connect (OIDC) client. An example of how to configure your application to work with the Auth0 client:

Setting

What to enter

Client type

OAuth 2.0 / OpenID Connect

Grant type

Authorization code

Scopes

openid, profile

Authorization endpoint

https://YOUR_AUTH0_DOMAIN/authorize

Token endpoint

https://YOUR_AUTH0_DOMAIN/oauth/token

User info endpoint

https://YOUR_AUTH0_DOMAIN/userinfo

JWKS endpoint

https://YOUR_AUTH0_DOMAIN/.well-known/jwks.json

Logout endpoint

https://YOUR_AUTH0_DOMAIN/oidc/logout

Client ID

Your Auth0 application client ID

Client secret

Your Auth0 application client secret

Redirect URL

Your application's callback URL

Step 5. Test the Authentication Flow

Once your application is configured with the Auth0 OIDC settings, you can test the integration. When a user attempts to log in, your application will initiate a request to Auth0. Your browser network requests should look something like this:

Example Authentication Request:

https://YOUR_AUTH0_DOMAIN/authorize?  
response_type=code  
client_id= YOUR_AUTH0_APPLICATION_ID  
redirect_uri=YOUR_RED_URI_IN_AUTH0_APPLICATION  
scope=openid profile  
nonce=GENERATED  
state=GENERATED  
code_challenge= GENERATED  
code_challenge_method=S256  
connection= s3-federation-server

The connection=s3-federation-server parameter is critical because it forces Auth0 to route the authentication request through the Digipass S3 Federation Server instead of through other configured connections.

What Happens Next

When your application initiates this request to authenticate, the flow of control follows this path:

  1. Your Application → Redirects user to Auth0

  2. Auth0 → Validates the request and redirects to Digipass S3 Federation Server

  3. S3 Federation Server → Displays the Sign-in App

  4. Sign-in App → User enters their username and authenticates using an authentication method that they have previously registered in the Digipass S3 Cloud.

  5. S3 Federation Server → Returns authentication result to Auth0

  6. Auth0 → Issues authorization code and redirects back to your application

  7. Your Application → Receives authorization code and exchanges it for a session token.

Verification

The following steps test this flow:

  1. Click the login button in your application

  2. Verify that you are redirected to the Digipass S3 Sign-in App

  3. Successfully authenticate with your registered authentication method

  4. Your application resumes control with a valid session

If you do not see the Digipass S3 Sign-in App, verify that the connection=s3-federation-server parameter is included in your authorization request.