MDL user registration

Prev Next

The multi-device licensing (MDL) user registration operation enables a user to register an authenticator (license) compliant with the MDL model for provisioning.

The MDL user registration operation can involve the following optional processes:

  • Creating a user account in OneSpan Authentication Server after successful back-end authentication.

  • Assigning a new authenticator license to the user if this user does not yet have an authenticator license matching the assigned policy limits.

  • Generating the challenge for Activation Message 1.

  • Binding a FIDO2  instance of a FIDO2–capable authenticator, such as DIGIPASS FX2, with an authenticator instance (see Multi-device activation with FIDO2 device binding). In that case, you need also to specify the respective WebAuthn public key.

    For more information, refer to the Web Authentication specification, available at: https://w3c.github.io/webauthn/ (last accessed on September 2, 2026).

The user registration operation is the first step in the MDL provisioning process. This operation returns Activation Message 1, which allows activating an authenticator license in the device. This operation is followed by the MDL device registration operation, to create authenticator instances based on the authenticator license.

Activation Message 1 must be transferred to the authenticator to generate a device code. This can be done encoded as a QR code or a color QR code, which the user scans with the device's camera. To generate such QR codes, you can use the Image Generator SDK.

OneSpan Authentication Server requires a successful user authentication before generating Activation Message 1 for the assigned authenticator license.

The following registration types are supported, based on the type of user authentication:

Local authentication with historical shared secrets

For this operation to succeed, the following administrative tasks should be performed in OneSpan Authentication Server:

To configure OneSpan Authentication Server for multi-device licensing (MDL) user registration using local authentication with a historical shared secret

  1. Define a policy with the following settings:

    • Policy > Local Authentication: DIGIPASS/Password during Grace Period or DIGIPASS or Password

    • Policy > Back-End Authentication: None

    • DIGIPASS > Assignment Mode: Auto-Assignment

    • DP Control Parameters > Challenge Check Mode: 0 - No Challenge Check

  2. Register the client component.

  3. Assign the policy previously defined to the registered client component.

  4. Import an authenticator compliant with MDL.

  5. Pre-load the user accounts and include static passwords.

For more information about performing these tasks, refer to the OneSpan Authentication Server Administrator Guide.

To execute this operation, the registered client application needs to send a provisioningExecute SOAP command to OneSpan Authentication Server, where the value for the cmd element is PROVISIONCMD_MDL_REGISTER.

At a minimum, this SOAP command requires the following set of field attributes to perform this operation:

  • PROVFLD_STATIC_PASSWORD

  • PROVFLD_USERID

  • PROVFLD_COMPONENT_TYPE

For more information about the required and optional attributes for this command, see SOAP provisioning.

Dynamic user registration (DUR) using a back-end system for authentication

For this operation to succeed, the following administrative tasks should be performed in OneSpan Authentication Server:

To configure OneSpan Authentication Server for multi-device licensing (MDL) user registration with Dynamic User Registration (DUR) using a back-end system for authentication

  1. Register a back-end server for authentication (not required for a local Windows backend).

  2. Define a policy with the following settings:

    • Policy > Local Authentication: DIGIPASS/Password during Grace Period or DIGIPASS or Password

    • Policy > Back-End Authentication: If Needed

    • Policy > Back-End Protocol: Set to the chosen back-end system (effectively, the setting must not be None)

    • User > Dynamic User Registration: Enabled

    • DIGIPASS > Assignment Mode: Auto-Assignment

    • DP Control Parameters > Challenge Check Mode: 0 - No Challenge Check

  3. Register the client component.

  4. Assign the policy previously defined to the registered client component.

  5. Import an authenticator compliant with MDL.

For more information about performing these tasks, see the OneSpan Authentication Server Administrator Guide.

To execute this operation, the registered client application needs to send a provisioningExecute SOAP command to OneSpan Authentication Server, where the value for the cmd element is PROVISIONCMD_MDL_REGISTER.

At a minimum, this SOAP command requires the following set of field attributes to perform this operation:

  • PROVFLD_STATIC_PASSWORD

  • PROVFLD_USERID

  • PROVFLD_COMPONENT_TYPE

For more information about the required and optional attributes for this command, see SOAP provisioning.