Introduction
Using the Digipass S3 App SDK for Android or iOS to create your own native mobile app offers the highest level of integration but incurs a longer development cycle. If you’re looking to easily add passwordless authentication to your web app, using the OneSpan Passport app is the quickest approach. If you don’t already have an app, the Digipass S3 App SDK plugin for Cordova allows you to create Android and iOS mobile apps with FIDO support.
Integration with the Digipass S3 App SDK involves initialization, request generation, and response processing. Before you initiate operations, you must first initialize the App SDK. Calling the appropriate App SDK method generates the request to register or authenticate a user. Finally, the authentication response from your mobile app and the application server are processed. An example implementation of this flow can be found in the source code for the Tutorial App. The source code includes extensive comments to assist you.
Mobile app integration model
Android and iOS devices provide strong security around key management and secure biometrics capabilities. The Digipass S3 App SDK leverages these device capabilities to provide FIDO Authentication using the scenario illustrated below.

Figure 1 Integration model supported by the Digipass S3 App SDK
A local client with embedded authenticators is the recommended model for application integration.
User experience
The Digipass S3 BankAuth and ShopAuth iOS and Android apps demonstrate example user experience flows for user registration, authentication, and transaction confirmation using fingerprint authentication. Though some customization is possible on the screen for selecting an authenticator, the authentication screen and interaction depend on the authenticator and platform. Figure 2 and Figure 3 show what can be controlled by your application for fingerprint authentication.
iOS
.png?sv=2026-02-06&spr=https&st=2026-09-30T03%3A52%3A00Z&se=2026-09-30T04%3A05%3A00Z&sr=c&sp=r&sig=EBiw2jSRDheVgzmtUJVQ8AMVkEi1fj7AGA%2B7nqxGXks%3D)
Solution Guide - iOS.png
Figure 2 Fingerprint Authentication UI on iOS
Android
.png?sv=2026-02-06&spr=https&st=2026-09-30T03%3A52%3A00Z&se=2026-09-30T04%3A05%3A00Z&sr=c&sp=r&sig=EBiw2jSRDheVgzmtUJVQ8AMVkEi1fj7AGA%2B7nqxGXks%3D)
Figure 3 Fingerprint Authentication UI on Android
Figure 4 and Figure 5 show the authentication flow for fingerprint authentication on iOS and Android respectively. Your mobile app displays the screen to trigger the authentication and the success screen after the authentication. Transaction confirmation follows a similar flow with the transaction content displayed within the fingerprint UI (and not by the app).
iOS
.png?sv=2026-02-06&spr=https&st=2026-09-30T03%3A52%3A00Z&se=2026-09-30T04%3A05%3A00Z&sr=c&sp=r&sig=EBiw2jSRDheVgzmtUJVQ8AMVkEi1fj7AGA%2B7nqxGXks%3D)
Figure 4 Fingerprint Authentication Flow on iOS
Android
.png?sv=2026-02-06&spr=https&st=2026-09-30T03%3A52%3A00Z&se=2026-09-30T04%3A05%3A00Z&sr=c&sp=r&sig=EBiw2jSRDheVgzmtUJVQ8AMVkEi1fj7AGA%2B7nqxGXks%3D)
Figure 5 Fingerprint Authentication Flow on Android
Integrating with authenticators
Authenticators are embedded within your app. The App SDK discovers the authenticators present and makes them available to your app. You can embed an authenticator by simply including the appropriate module or framework within your app. Newer fingerprint or other biometric-enabled Android devices (Android 6 and later) follow an embedded authenticator model similar to iOS.
Integrating with webview
WebView is a way to package browser functionality inside a native mobile app to implement certain functions. You can run any web application that was built with the Digipass S3 Web App SDK inside a WebView as is. In addition, a JavaScript API in the Digipass S3 Web App SDK provides support for FIDO authentication within a WebView. A sample implementation of WebView integration is provided in the Tutorial App.
Integrating with Passport app
Instead of developing your own custom mobile app, you can direct users to download OneSpan Passport from the Google Play Store or the Apple App Store. After you’ve integrated your web app with Digipass S3 Authentication Software (see Web App Integration), users can authenticate to your site from a mobile device. Your web app can display a QR code in a desktop browser or send a push notification to the mobile device. Using the Passport App, the user either scans the QR code displayed on the browser screen or activates the push notification to complete the authentication event. Digipass S3 Authentication Software also provides a rebrandable version of Passport App for customization. Multiple mobile apps can also use the Passport App as their authentication app. When the Passport App is used as the authentication app, FIDO credentials are shared between the apps. In this scenario the user will have to register once using Passport App and will not have to register into each app.
Authenticating multiple mobile apps
When you have multiple mobile apps, you can designate one of the apps to perform authentication for the related apps. FIDO credentials are shared between the apps. In this scenario the user registers once using the designated authentication app and does not have to register into each app. This app owns and manages the FIDO credentials for the related apps. Use the App SDK to enable this functionality and refer to Passport App as a guide for development. Instead of using the Passport App, it’s also possible to enable one of your apps to behave like the Passport App. See Using Passport App for Credential Sharing in Tutorial App for iOS or Android.