Unlock an Authenticator via API Call

Prev Next

The Unlock Device feature allows you to unlock an authenticator that has been locked after too many incorrect PIN entries. OneSpan Cloud Authentication supports unlocking the authenticator via the OneSpan Trusted Identity platform API. To unlock the authenticator, it is necessary to send an unlock challenge that will be generated when the authenticator is turned on the next time after it has been locked.

An authenticator can be unlocked via a POST call to the POST /authenticators/{serialNumber}/applications/{applName}/unlock endpoint. Depending on the type of authenticator, you can select either Plain Text Format for non-Cronto authenticators or Secure Channel Format for Cronto-based authenticators. The endpoint accepts outputFormat as payload and UnlockChallengeInput as input object. The created output depends on the chosen parameter: if you either do not use this field or enter “outputFormat”: “PlainText", the created output will contain the unlockCode field. If you enter “outputFormat”: “SecureChannel", the created output will contain the unlockRequestMessage field.

The responses include:

  • 200: Unlock completed successfully, unlock code generated and returned in response.

  • 400: The input is invalid.

  • 404: Authenticator or application not found.

  • 409: The authenticator unlock challenge is invalid.

  • 500: Internal error, sub-service failure, server crash.