Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

For transaction confirmation

Prev Next

Introduction

This article details the steps required to integrate Auth0 with the Digipass S3 Cloud to implement strong authentication when an end user confirms a transaction with your web app. Your app integrates only with Auth0 - through a standard OpenID Connect (OIDC) flow - but it gains an additional layer of transaction assurance from the Digipass S3 Cloud.

An end user with an Auth0 session initiates the transaction using your web app. Your web app then sends all transaction details to Auth0, and Auth0 uses a Post-login Action to redirect to a confirmation page. This confirmation page is hosted on your application server and this page uses the Digipass S3 Web App SDK configured with the Digipass S3 Cloud endpoints for transaction confirmation. After the end user confirms the transaction, the Digipass S3 Cloud returns a signed token to the Auth0 Post-login Action, where it is verified. Upon successful verification, Auth0 shows its own transaction confirmation page and after the user's approval returns its own access token back to your web application.

Auth0 remains the primary identity provider (IdP), and Auth0 stores the user data. The Digipass S3 Cloud acts as an external service responsible for authenticating the transaction confirmation.

Prerequisites

  • Auth0 is your main CIAM and user store.

  • You are a Digipass S3 Cloud customer with an admin account.

  • Your Digipass S3 Cloud tenant is configured with FIDO policies, adaptive rulesets, and a transaction plugin.

Design diagram

Step 1. Allow an Auth0 Pushed Authorization Request(PAR)

  1. Using the Auth0 dashboard, log into your Auth0 account and click on your tenant ID in the left top corner. Click Settings.

  2. On the next page, click Advanced. 

  3. Scroll down and enable the Allow Pushed Authorization Requests (PAR). 

  4. Navigate to your Auth0 application that handles the transaction, and click on the Settings tab.

  5. Scroll down and turn on the Require Pushed Authorization Request (PAR).

  6. Auth0 requires a custom API to be registered as the audience for PAR-enabled applications. This ensures that issued access tokens are bound to a specific API and cannot be reused across other APIs. Select Application>APIs from the left navigation bar. Click Create API.

  7. Fill in the following properties and click Create.

    Property

    Value

    Name

    Anything

    Identifier

    Your API endpoint

    JSON Web Token (JWT) profile

    Auth0

    JSON Web Token(JWT) signing algorithm

    RS256

    Within user-delegated access

    Per-app authorization

    Within client access

    Per-app authorization

  8. In the newly created API, click the Application Access tab at the top, then find your transaction application in the list and click Edit.

  9. Click on Grant Access.

  10. Navigate to the Permissions tab of the same API and at the bottom, register the authorization details type that you are going to use in your request. For example, money_transfer.

Step 2. Configure your transaction page

The web page where the end user confirms a transaction makes calls to the Digipass S3 Web App SDK. This web page is hosted in your infrastructure.

  1. Load the Digipass S3 Cloud Web App SDK scripts. For more information, see Setting up the Web App SDK.

  2. In your web app, initialize AdaptiveUI with your Digipass S3 Cloud reg and auth endpoints:

    const mAdaptiveUI = new AdaptiveUI({
          regEndpoint:'https://cloud.noknok.com/<YOUR_TENANT>/webapps/nnlgateway/nnl/reg ',
          authEndpoint:'https://cloud.noknok.com/<YOUR_TENANT>/webapps/nnlgateway/nnl /auth'
    });
  3. Receive the redirect from Auth0.
    Auth0's Post-login Action redirects the user to your transaction page with the following URL parameters:

    1. state: Auth0 flow state, must be preserved and echoed back.

    2. email: The email address of the authenticated end user. This is used to identify the registered authenticator.

    3. transaction fields: txn_type, amount, currency, debtor_acc, creditor_acc, creditor_name, note

  4. Call AppSdk.setActiveUser(email) first, then invoke AdaptiveUI.transact() with the transaction text built from the URL parameters. The text format must exactly match what the Auth0 Post-login Action validates because any mismatch will deny the user.

  5. On success, AdaptiveUI.transact() returns a tcToken in result.sessionData.tcToken. Submit this tcToken to Auth0's /continue endpoint using a form POST. Preserve the state as parameter and the tcToken as the body.

Step 3. Configure your Digipass S3 Cloud tenant

Your transaction page needs to access the Digipass S3 Server.

  1. Sign into your Digipass S3 Cloud account at cloud.noknok.com. Select your tenant and choose Authentication Cloud > Configure server.

  2. Use the top horizontal menu bar to navigate to Configuration > API Server.

  3. Navigate to API Server > Authentication API > Main > Web Client origin allow list. Select Add an origin and add the origin of your transaction page.

  4. Select API Server > Authentication API > Transaction Plugin. Click the edit icon next to the JWT Transaction Processor. Review the jwt_config object, and make sure that it uses asymetric keys.

  5. Use the top horizontal menu bar to navigate to Configuration > Authentication Methods. In the section FIDO2/WebAuthn, the RP ID must match the domain of the transaction page.

  6. Use the top horizontal menu bar to navigate to Configuration > Apps and click Add App. Add the web application that contains your transaction page. For more information, see the article Operate>Configure apps>Configuring a Web App in the OneSpan Documentation Portal.

Step 4. Create an Auth0 Post-Login Custom Action

  1. Using the Auth0 dashboard, log into your Auth0 account and choose Actions > Library from the left navigation bar. Select Create Action > Create Custom Action.

  2. Fill in the following properties and click Create.

    Property

    Value

    Name

    Anything

    Trigger

    Login/Post Login

    Runtime

    Node 22

  3. Below is a code example of how to configure your Login/Post Login custom action. Set YOUR_SIGNING_APP_URL to the transaction page that makes calls to the Digipass S3 Web App SDK for transaction confirmation. Set the TC_TOKEN_AUDIENCE  to your Digipass S3 Cloud tenant ID.

    const YOUR_SIGNING_APP_URL = "https://your-signing-app.example.com/sign";    
    const TC_TOKEN_ISSUER = "https://cloud.noknok.com";    
    const TC_TOKEN_AUDIENCE = "YOUR_S3_CLOUD_TENANT_ID";    
    const TC_TOKEN_JWKS_URL = "https://cloud.noknok.com/YOUR_S3_CLOUD_TENANT_ID/webapps/nnlgateway/jwks/transaction/";   
    // ─── STEP 1: Redirect to signing page   
    exports.onExecutePostLogin = async (event, api) => {  
         const details = 
             event.transaction?.requested_authorization_details?.[0] ?? {};  
         const params = new URLSearchParams(); 
         if (event.user?.email)  
              params.set("email", event.user.email);  
         if (details.type)  
              params.set("txn_type", details.type);  
         if (details.instructedAmount?.amount)  
              params.set("amount", details.instructedAmount.amount);  
         if (details.instructedAmount?.currency) 
              params.set("currency",details.instructedAmount.currency);  
         // Add more fields as needed (source/destination accounts, beneficiary, etc.)   
         // Auth0 automatically appends ?state=… — do not add it manually 
         api.redirect.sendUserTo(${YOUR_SIGNING_APP_URL}?${params.toString()});  
    };  
    
    // ─── STEP 2: Validate the tcToken returned by your signing app  
    exports.onContinuePostLogin = async (event, api) => {  
         const tcToken = event.request?.body?.tcToken;  
         if (!tcToken) { 
              api.access.deny("Transaction signing failed: tcToken not received");   
              return;  
         }   
         try {  
              const parsed = parseJwt(tcToken);   
              // Fetch the public key from your FIDO server's JWKS endpoint  
              const keys = await fetchJwks(TC_TOKEN_JWKS_URL);   
              const jwk  = selectJwk(keys, parsed.header);   
              // Verify RS256 signature using Node crypto against the JWK public key   
              verifySignature(parsed, jwk);   
              // Validate exp/iss/aud claims and that the signed transaction text exactly matches event.transaction.requested_authorization_details 
              validateClaims(parsed.payload, event, { issuer: TC_TOKEN_ISSUER,audience: TC_TOKEN_AUDIENCE });   
         } catch (err) {   
             api.access.deny(Transaction signing failed: ${err.message 
         });   
         return;   
    }}; 
  4. In the newly created custom action, paste your modified code and click Deploy.

Step 5. Test

Verify the integration by completing an end‑to‑end transaction flow using your app. The test is successful if:

  1. Your app redirects the user to your transaction page.

  2. The user completes the transaction confirmation.

  3. Your app returns to Auth0 without errors.

  4. Auth0 logs show successful execution of the Post‑login Action with no tcToken validation failures.

  5. Your app displays transaction details to the user that match the original authorization request.