Version 3.29 (September 2026)

Prev Next

New features and enhancements

Role-based administration  full-sdk 

You can now define administrator roles to group related administrative privileges into clearly defined responsibilities outlining the tasks an administrative user can perform within the system. Administrator roles can be assigned, modified, or revoked at any time to reflect organizational changes or security requirements.

The new adminRoleExecute and adminRoleQuery commands are provided to manage (create, modify, delete) administrator roles. To assign and revoke administrator roles, the following new commands are provided:

  • userExecute:USERCMD_ASSIGN_ADMIN_ROLES

  • userExecute:USERCMD_GET_ASSIGNED_ADMIN_ROLES

  • userExecute:USERCMD_REVOKE_ADMIN_ROLES

bulkCleanupDigipass command improvements  full-sdk 

The bulkCleanupDigipass command received a couple of enhancements:

  • New cleanup strategy. The new DigipassDisabledSince strategy identifies and processes all authenticators and authenticator instances that have been disabled for a specified number of days.

  • Configurable cleanup action. You can now specify a cleanup action that should be applied to the authenticators and authenticator instances that were determined by the cleanup strategy via the new cleanupaction parameter. You can either get a list of the matching items (default), delete them, or disable them (set the authenticator status). The new cleanupaction parameter replaces dryrun, which is now considered deprecated.

  • Safe default value. The minimum value for the age parameter (retention period) of the bulkCleanupDigipass command was increased to 30 days to prevent the unintentional deletion of authenticators or authenticator instances that were merely not used for a couple of days.

FIDO2 device binding support  full-sdk 

OneSpan Authentication Server now supports multi-device activation provisioning scenarios that require binding a FIDO2 instance of a FIDO2–capable authenticator with an authenticator instance. Such scenarios are used for authenticators that combine Cronto visual cryptography with FIDO2 hardware-bound credentials, such as DIGIPASS FX2.

The provisioningExecute:PROVISIONCMD_MDL_REGISTER command has been extended and now accepts an optional WebAuthn public key input attribute (PROVFLD_FIDO2_PUBLIC_KEY) to allow FIDO2 device binding via the SDK.

Corresponding wrapper functions are also available for Java and .NET.

Jakarta EE support (SDK sample website)  auth-sdk   full-sdk 

The Java sample website was updated to support Java Development Kit (JDK) 17 and the Jakarta EE 10 platform. This implies that the Java sample website now can be deployed to Apache Tomcat 10 (OAS-31955), Apache Tomcat 8 or 9 are no longer supported.

Changed behavior

Invalidate administrative sessions on password change  auth-sdk   full-sdk 

OneSpan Authentication Server 3.29 introduces the new Invalidate Sessions on Password Change option, which configures whether administrative sessions should expire automatically if the static password of the respective user account is changed. This option is enabled by default and influences the behavior of the following commands:

  • changeBackendPassword

  • updatePassword

  • userExecute:USERCMD_RESET_PASSWORD

  • userExecute:USERCMD_SET_PASSWAORD

  • userExecute:USERCMD_UPDATE

Fixes and other updates

Issue OAS-35422 (Support case CS0223257): Email address validation does not allow underscore characters (Administration)  full-sdk 

Description: When setting a user's email address, for example, with userExecute:USERCMD_UPDATE, the validation is overly strict and rejects underscore characters ("_") in the domain part.

Affects: OneSpan Authentication Server 3.27–3.28

Status: This issue has been fixed.

Issues OAS-34843, OAS-33345 (Support case CS0208970): Activation type input attribute broken and missing in SOAP wrapper (Provisioning)  full-sdk 

Description: When calling the dsappSRPRegister command as part of a provisioning workflow, the optional activationType input parameter, which was introduced in version 3.27  to determine whether to generate online or offline activation data, is not properly handled by the command.

Furthermore, the activation type parameter is not supported by the SOAP provisioning wrapper at all.

Affects: OneSpan Authentication Server 3.27–3.28

Status: This issue has been fixed. The dsappSRPRegister command was fixed, and the SOAP provisioning wrapper now correctly exposes the activation type parameter.

Issue OAS-32813 (Support case CS0208452): DIGIPASSCMD_VIEW ignores optional domain parameter (Administration)  full-sdk 

Description: When calling the digipassExecute:DIGIPASSCMD_VIEW command with the optional domain parameter (DIGIPASSFLD_DOMAIN) to limit the search scope, the command ignores the domain parameter and returns the authenticator attributes regardless of the authenticator’s domain (given that an authenticator with the specified serial number does exist within the administrative scope).

Affects: OneSpan Authentication Server 3.24–3.28

Status: This issue has been fixed.

Issue OAS-32510 (Support case CS0207784): DIGIPASSCMD_DECRYPT_INFORMATION_MESSAGE does not find authenticators in lower-level OU (Administration)  full-sdk 

Description: When the digipassExecute:DIGIPASSCMD_DECRYPT_INFORMATION_MESSAGE command is executed by an organizational unit administrator, it can find the respective authenticator only if it is located in the same organizational unit as the administrator. It does not find authenticators that are located in subordinate (lower-level) organizational units.

Affects: OneSpan Authentication Server 3.24–3.28

Status: This issue has been fixed.

Issue OAS-21699: Misleading audit message and status code when authenticator type limit is reached (Provisioning)  full-sdk 

Description: When an authenticator cannot be assigned during provisioning because the policy's assignment limit for this authenticator type has already been reached, the request fails. However, the corresponding audit message indicates a misleading reason (“Multiple DIGIPASS found where a single DIGIPASS was required”), and the SOAP command returns an inaccurate status code (STAT_TOO_MANY_DIGIPASS).

Affects: OneSpan Authentication Server 3.24–3.28

Status: This issue has been fixed. If provisioning fails because of the authenticator type limit, the audit message now provides a more meaningful reason (“The DIGIPASS type limit has been reached“).

Furthermore, the following commands return a new dedicated status code (STAT_DP_TYPE_LIMIT_REACHED) in this case:

  • digipassExecute:DIGIPASSCMD_ADD_DEVICE

  • digipassExecute:DIGIPASSCMD_ASSIGN

  • provisioningExecute:PROVISIONCMD_ASSIGN

  • provisioningExecute:PROVISIONCMD_DSAPPREGISTER

  • provisioningExecute:PROVISIONCMD_MDL_ADD_DEVICE

  • provisioningExecute:PROVISIONCMD_MDL_REGISTER

Known issues

None.