Introduction
This article details the steps required to integrate Auth0 with the Digipass S3 Cloud to implement strong authentication when an end user signs into your web app. Your app integrates only with Auth0 - through a standard Open ID Connect (OIDC) flow - but it gains an additional layer of authentication assurance from the Digipass S3 Cloud.
An end user attempts to sign into your client web app. Your web app redirects the authentication request to Auth0. Auth0 forwards the request to the Digipass S3 Cloud. The Digipass S3 Cloud displays the Digipass S3 sign-in page specific to your cloud tenant. After the end user successfully authenticates using the sign-in page, the Digipass S3 Cloud returns a signed token to Auth0, where it is verified. Once the token is verified, Auth0 returns its own access token back to your web application.
Auth0 remains the primary identity provider (IdP), and Auth0 stores the user data. The Digipass S3 Cloud acts as a Federation Server that is responsible for authenticating the user.
Prerequisites
Auth0 is your main CIAM and user store.
You are a Digipass S3 Cloud customer with an admin account.
Your Digipass S3 Cloud tenant is configured with FIDO policies and adaptive rulesets.
The end user already has an authentication method registered in the Digipass S3 Cloud.
Step 1. Configure the Digipass S3 Federation Server Client
Sign into the Digipass S3 Cloud.
Click the Authentication Cloud>Federation console.

Click the Clients tab and then click Create client.

Fill in the following properties:

Property
Value
Client type
OpenID Connect
Client ID
auth0
Name
External IDP for Auth0
Description
External IDP for Auth0
Always display in UI
Off
Click Next.On the next page, select the following options and click Next again.

On the following page, fill in the following properties:

Property
Value
Valid redirect URIs
https://YOUR_AUTH0_DOMAIN/login/callback
Web origins
https://YOUR_AUTH0_DOMAIN
Click Save.In the newly created client, click Advanced at the top and scroll down to the Browser Flow section.
Select Sign-in App Authentication Flow and click Save.

In the newly created client, click Credentials at the top.
Copy the Client Secret value—you will need this for the Auth0 configuration in the next step.

Step 2. Configure the Auth0 to OIDC connection
In your Auth0 dashboard, select Authentication > Enterprise from the left menu.
Click OpenID Connect.

On the next page, click Create Connection.

Fill in the following properties:

Property
Value
Purpose
Authentication
Connection name
s3-federation-server
OpenID Connect Discovery URL
https://cloud.noknok.com/noknok/webapps/nnlfed/realms/YOUR_TENANT_ID/.well-known/openid-configuration
ClientID
auth0
Communication Channel
Back Channel
Enable nonce for back channel OIDC requests
Enable
Authentication method
Client Secret
Client secret
Your S3 Federation Server client secret
Enable Demonstrating Proof of Possession (DPoP)
Disable
Sync User Profile Attributes at Login
Enable
Promote Connection to Domain Level
Disable
Click Create.
Step 3. Configure Auth0 Application
In your Auth0 dashboard, select Applications > Applications from the left menu.
Click Create Application.

Enter an appropriate application name and click Create.
In the newly created application, click the Settings tab at the top.
Scroll down to the Application URIs section.
In the Allowed Callback URLs field, enter the redirect URI that your client will use.

Click Save. Click the Connections tab at the top.
Enable the s3-federation-server connection. Disable all other connections.

Step 4. Configure your application to work with Auth0
Your client application needs to be configured as an OpenID Connect (OIDC) client. An example of how to configure your application to work with the Auth0 client:
Setting | What to enter |
|---|---|
Client type | OAuth 2.0 / OpenID Connect |
Grant type | Authorization code |
Scopes | openid, profile |
Authorization endpoint | https://YOUR_AUTH0_DOMAIN/authorize |
Token endpoint | https://YOUR_AUTH0_DOMAIN/oauth/token |
User info endpoint | https://YOUR_AUTH0_DOMAIN/userinfo |
JWKS endpoint | https://YOUR_AUTH0_DOMAIN/.well-known/jwks.json |
Logout endpoint | https://YOUR_AUTH0_DOMAIN/oidc/logout |
Client ID | Your Auth0 application client ID |
Client secret | Your Auth0 application client secret |
Redirect URL | Your application's callback URL |
Step 5. Test the Authentication Flow
Once your application is configured with the Auth0 OIDC settings, you can test the integration. When a user attempts to log in, your application will initiate a request to Auth0. Your browser network requests should look something like this:
Example Authentication Request:
https://YOUR_AUTH0_DOMAIN/authorize?
response_type=code
client_id= YOUR_AUTH0_APPLICATION_ID
redirect_uri=YOUR_RED_URI_IN_AUTH0_APPLICATION
scope=openid profile
nonce=GENERATED
state=GENERATED
code_challenge= GENERATED
code_challenge_method=S256
connection= s3-federation-serverThe connection=s3-federation-server parameter is critical because it forces Auth0 to route the authentication request through the Digipass S3 Federation Server instead of through other configured connections.
What Happens Next
When your application initiates this request to authenticate, the flow of control follows this path:
Your Application → Redirects user to Auth0
Auth0 → Validates the request and redirects to Digipass S3 Federation Server
S3 Federation Server → Displays the Sign-in App
Sign-in App → User enters their username and authenticates using an authentication method that they have previously registered in the Digipass S3 Cloud.
S3 Federation Server → Returns authentication result to Auth0
Auth0 → Issues authorization code and redirects back to your application
Your Application → Receives authorization code and exchanges it for a session token.
Verification
The following steps test this flow:
Click the login button in your application
Verify that you are redirected to the Digipass S3 Sign-in App
Successfully authenticate with your registered authentication method
Your application resumes control with a valid session
If you do not see the Digipass S3 Sign-in App, verify that the connection=s3-federation-server parameter is included in your authorization request.