Integrate provisioning via the SOAP API

Prev Next

The SOAP provisioning API provides the provisioningExecute SOAP command. This command can be used to execute different provisioning commands.

To use the provisioningExecute SOAP operation

  1. Create a SOAP request for the provisioningExecute command.

  2. Specify the correct SOAP provisioning operation (register or activate) to be executed in the SOAP request.

  3. Specify one or more provisioning attributes as parameters for the SOAP operation. Attributes are key/value pairs.

  4. Import the OneSpan Authentication Server SSL server certificate as trusted root certificate on the machine where your client application is running.

    This will allow your SOAP client application to connect to OneSpan Authentication Server securely via SSL.

  5. Send the SOAP request to OneSpan Authentication Server. By default, the SOAP request should be transmitted over HTTPS with the OneSpan Authentication Server.

    By default, OneSpan Authentication Server is configured to accept SOAP requests on port 8888.

  6. Receive the SOAP response.

  7. Process the SOAP response.

For more information about the structure of SOAP messages, see SOAP message structure.

provisioningExecute SOAP request structure

A provisioningExecute SOAP request typically uses the following format:

<SOAP-ENV:Envelope
    xmlns:SOAP-ENV="http://schemas.xmlsoap.org/soap/envelope/"
    xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
    xmlns:xsd="http://www.w3.org/2001/XMLSchema"
    xmlns:PROV-TYPES="http://www.vasco.com/IdentikeyServer/IdentikeyTypes/Provisioning">
    <SOAP-ENV:Body>
        <PROV-TYPES:provisioningExecute>
            <cmd>PROVISIONCMD_REGISTER</cmd>
            <attributeSet>
                <attributes>
                    <value xsi:type="xsd:string">DP4Mobile Provisioning Sample Client</value>
                    <attributeID>PROVFLD_COMPONENT_TYPE</attributeID>
                </attributes>
                <attributes>
                    <value xsi:type="xsd:string">testuser</value>
                    <attributeID>PROVFLD_USERID</attributeID>
                </attributes>
                <attributes>
                    <value xsi:type="xsd:string">master</value>
                    <attributeID>PROVFLD_DOMAIN</attributeID>
                </attributes>
                <attributes>
                    <value xsi:type="xsd:string">1.Password</value>
                    <attributeID>PROVFLD_STATIC_PASSWORD</attributeID>
                </attributes>
                <attributes>
                    <value xsi:type="xsd:string">336619</value>
                    <attributeID>PROVFLD_CUSTOM_ENCRYPT_PWD</attributeID>
                </attributes>
            </attributeSet>
        </PROV-TYPES:provisioningExecute>
    </SOAP-ENV:Body>
</SOAP-ENV:Envelope>

The SOAP body element should only contain a provisioningExecute element (line 7). This element is defined in the namespace prov. Therefore, the prov namespace needs to be declared in the Envelope element as an attribute.

A valid provisioningExecute request must follow these additional rules:

  • The provisioningExecute element should contain only one AttributeSet element.

  • The provisioningExecute element should contain only one cmd element.

  • The AttributeSet element should contain zero or more provisioning attributes elements.

Each attribute element should contain the following sub-elements:

  • attributeID (required). The attribute identifier. The supported credential attribute identifiers are listed in SOAP authentication (Overview).

  • value (required). The attribute value. This element also requires the specification of the value type using the following attribute definition xsi=type="xsd:<type>.

  • attributeOptions (optional). This element provides directive information about how OneSpan Authentication Server should handle the attribute value during request processing. Following options are supported for this element:

    • NULL. Indicates that the specified attribute should be set to zero.

    • NEGATIVE. Used for search criteria to say NO when searching for a specific attribute.

    • MASKED. Used to indicate OneSpan Authentication Server to mask the attribute value (e.g., when auditing the SOAP request).

To set an attribute option, add the option element in the attributeOptions element and give the option element the value true.

To set the MASKED option, add the following:

<attributeOptions><masked>true</masked></attributeOptions>

provisioningExecute SOAP response structure

A provisioningExecute SOAP response typically uses the following format:

<?xml version="1.0" encoding="UTF-8"?>
<SOAP-ENV:Envelope
    xmlns:SOAP-ENV="http://schemas.xmlsoap.org/soap/envelope/"
    xmlns:SOAP-ENC="http://schemas.xmlsoap.org/soap/encoding/"
    xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
    xmlns:xsd="http://www.w3.org/2001/XMLSchema"
    xmlns:xop="http://www.w3.org/2004/08/xop/include"
    xmlns:BASIC-TYPES="http://www.vasco.com/IdentikeyServer/IdentikeyTypes/BasicTypes.xsd"
    xmlns:PROVISIONING-TYPES="http://www.vasco.com/IdentikeyServer/IdentikeyTypes/ProvisioningTypes.xsd"
    xmlns:PROV-TYPES="http://www.vasco.com/IdentikeyServer/IdentikeyTypes/Provisioning">
    <SOAP-ENV:Body>
        <PROV-TYPES:provisioningExecuteResponse>
            <results>
                <resultCodes>
                    <returnCodeEnum>RET_SUCCESS</returnCodeEnum>
                    <statusCodeEnum>STAT_SUCCESS</statusCodeEnum>
                    <returnCode>0</returnCode>
                    <statusCode>0</statusCode>
                </resultCodes>
                <resultAttribute>
                    <attributes>
                        <value xsi:type="xsd:string">testuser</value>
                        <attributeID>PROVFLD_USERID</attributeID>
                    </attributes>
                    <attributes>
                        <value xsi:type="xsd:string">master</value>
                        <attributeID>PROVFLD_DOMAIN</attributeID>
                    </attributes>
                    <attributes>
                        <value xsi:type="xsd:string"/>
                        <attributeID>PROVFLD_ORGANIZATIONAL_UNIT</attributeID>
                    </attributes>
                    <attributes>
                        <value xsi:type="xsd:string">VDS1000140</value>
                        <attributeID>PROVFLD_SERIAL_NO</attributeID>
                    </attributes>
                    <attributes>
                        <attributeOptions>
                            <masked>true</masked>
                        </attributeOptions>
                        <value xsi:type="xsd:string">3808019401035644530210101...</value>
                        <attributeID>PROVFLD_ACTIVATION_CODE</attributeID>
                    </attributes>
                </resultAttribute>
                <errorStack/>
            </results>
        </PROV-TYPES:provisioningExecuteResponse>
    </SOAP-ENV:Body>
</SOAP-ENV:Envelope>

The SOAP body element should only contain a provisioningExecuteResponse element (line 12). The provisioningExecuteResponse element always contains a results element, which in turn contains the following sub-elements:

  • resultCodes (required). This element contains the following sub-elements:

    • returnCode. The operation return code indicating the overall result of the request processing.

    • statusCode. The operation status code indicating the reason for failure of any returnCode different from success (0).

    • returnCodeEnum. The identifier corresponding to the returnCode.

    • statusCodeEnum. The identifier corresponding to the statusCode.

  • resultAttribute (required). This element contains zero or more attributes elements.

  • errorStack (required). Contains zero or more errors elements.

    • errors. Each errors element contains the following sub-elements:

      • errorCode. The error code integer.

      • errorDesc. A string representation of the error code.

For a complete list of possible error codes, see Error codes and messages.

In this case, the resultattribute element is used to refer to provisioning attributes elements.