Introduction
DigipassONE authentication software enables secure, user-friendly authentication in your applications. Enabling your application requires both application-side and server-side development. OneSpan provides a number of resources for your development process. This page provides DigipassONE customers a high-level roadmap to successful integration with DigipassONE authentication software.
For an overview of DigipassONE authentication software and the integration process, see the Integration Overview.
Step 1: Deploy the DigipassONE Server
The DigipassONE Server determines the result of user authentication based on Adaptive Rulesets and FIDO Policies that you define. The DigipassONE API Server is the server-side Tomcat component that adds session and transaction management and enables UAF and FIDO2 integration. It also allows you to create your own user-written plugins to support custom session management schemes.
Configure these servers using either the Server Administration Console (Admin Console) or nnl-mgmt.sh. The Admin Console is a web-based service with an intuitive user interface used to perform both configuration and operational tasks. nnl-mgmt.sh is a command-line tool that serves the same purpose.
You can either use the DigipassONE Authenticate Cloud service to access predeployed Authentication and API Servers, or you can deploy them in your own datacenter. Logically, the Authentication Server sits behind your application server and offloads the authentication function. To learn more about the DigipassONE Authenticate Cloud service contact OneSpan Support.
Step 2: Test your installation and familiarize yourself with sample applications
DigipassONE provides a comprehensive sample application on all client platforms that demonstrates how to use key DigipassONE App SDK APIs. On Android and iOS, this is a mobile app called the Android Tutorial App and the iOS Tutorial App, respectively. For the web, this is a JavaScript web app called Web Tutorial App. Source code for these apps is available in the package you receive from DigipassONE authentication software. The code includes extensive comments that explain how the integration is performed.
Tutorial app implements:
Adaptive registration
Adaptive authentication
Transaction confirmation
Registration management
Passkey support
Out-of-band (OOB) authentication
Quick authentication
WebView integration
Device blessing
How to use the phone as a roaming authenticator
Tutorial web app implements:
Adaptive registration
Adaptive authentication
Transaction confirmation
Secure Payment Confirmation
Registration management
Passkey support
App-less QR OOB support
In addition to being useful implementation references, Tutorial App and Tutorial Web App enable you to verify that your installation and development environment are working properly. Successfully building Tutorial App or Tutorial Web App ensures that your development environment is set up correctly. After configuring your Authentication Server to work with Tutorial App or Tutorial Web App, test the configuration by using these apps. You should be able to successfully register and authenticate and use other functions. This confirms that your configuration works and allows you to focus on developing your own client app.
Step 3: Design the user interface
Before coding begins, you need to design the user interface for authentication operations in your app.
You can download the OneSpan BankAuth mobile app and use it to get a feel for how registration and authentication works. This mobile app provides example user interaction flows for an app that is integrated with the DigipassONE App SDK. BankAuth is available from the Google Play Store and the Apple App Store.
Step 4: Integrate with your application
Integrate with your mobile app
Using the DigipassONE App SDK for iOS and Android, you can embed strong authentication in your app. The embedded DigipassONE App SDK serves as a conduit between your mobile app and the DigipassONE Server. The App SDK processes authentication messages and communicates with the authenticators present on the device to register and authenticate a user. You can find detailed information on minimum requirements and integration within the following developer guides.
Further information can be found in the Client API documentation for iOS (generated by Doxygen), and for Android (generated by JavaDoc.) These client API docs are also included in the DigipassONE App SDK packages.
Integrate with your web app
Using the DigipassONE App SDK for Web, your web app can authenticate users with FIDO2/Web Authentication to replace passwords. Your app must run on a browser that supports the W3C Web Authentication API (WebAuthn). WebAuthn enables a user to authenticate with either a built-in authenticator or an external authenticator that can be connected to the device.
For browsers and platforms that don't support WebAuthn, your web app can request that the user authenticate using their mobile device. In this option, called out-of-band (OOB) authentication, the user scans a QR code or responds to a push notification with their mobile phone. In both scenarios, the user finishes by using a FIDO authenticator present on their mobile device.
The following document describes how to integrate your web app with FIDO2 and OOB authentication:
Further information can be found in the Client API documentation, generated by JSDoc, included in the DigipassONE App SDK package.
Use the OneSpan Passport app to evaluate OOB authentication. OneSpan Passport is available for download from Google Play Store and the Apple App Store. You can use Passport App as-is in your production deployment or customize it to create your own version.
Integrate with your application server
The DigipassONE Server handles the authentication functions for your existing infrastructure. When a user authenticates, the Authentication Server verifies the attempt and returns the result. A successful authentication generates a session token that is sent to the client device and can be used to access content. By default, the API Server generates a JSON Web Token (JWT) ,which can be used to get a more detailed authentication token from an Access Management (AM) server.
Troubleshooting
If you encounter problems during the integration process, you can find information on diagnosing and fixing problems in Troubleshoot your app and Troubleshoot the server.