Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Adaptive authentication

Prev Next

URL: /nnlgateway/nnl/<tenantID>/auth Method: POST


Digipass S3 Authentication Software provides operations under the /nnl/v2/auth endpoint to initiate Adaptive Authentication, start verification with an authentication method, complete authentication for a method, or cancel verification for a specific method.

The following operations are available:

Start Adaptive Authentication by calling INIT_ADAPTIVE. If INIT_ADAPTIVE returns success and the succeeding Adaptive Rule's action is TRIGGER_AUTHENTICATION, then one or more authentication sequences are also returned in the response.

The calling app is responsible for interacting with the user to select an authentication sequence to use, then using each authentication method within that sequence to verify the user. To begin verification with an authentication method, call INIT_VERIFY. You can skip this call for FIDO or External authentication methods because Adaptive Authentication has been optimized for these methods. When the user successfully authenticates with a method, call VERIFY.

Users only get one chance to authenticate with a FIDO method. For non-FIDO methods, if the user failed authentication (for example, they mistyped the OTP for SMS OTP), then you can call VERIFY again. You can configure the number of allowed retries for OTP and FIDO OOB by using the Admin console.

Authentication Method

REST API operation(s) to call

FIDO OOB, SMS OTP, Email OTP, Photo ID

  1. INIT_VERIFY: Start authenticating with the specified method.

  2. VERIFY: Complete authentication.

FIDO Authentication, External authentication

VERIFY: Complete authentication

For example, the user selects an authentication sequence containing the following authentication methods:

  • FIDO fingerprint

  • FIDO2 security key

  • SMS OTP

Assuming the user successfully authenticates with all of these methods, the sequence of calls from the calling app to the Server would be as follows:

  1. INIT_ADAPTIVE

  2. VERIFY (FIDO fingerprint)

  3. VERIFY (FIDO2 security key)

  4. INIT_VERIFY (SMS OTP)

  5. VERIFY (SMS OTP)

Let's consider an alternative authentication sequence that only contains FIDO OOB.

In this situation, two different client apps must be used to successfully complete FIDO OOB. The first could be a web app running on a browser on a laptop. The second would be a mobile app (like OneSpan's Passport app) running on a cell phone. The laptop is designated as the first device while the cell phone is the second device.

Assuming the user successfully authenticates with FIDO OOB, the sequence of calls from the client apps to the Server would be as follows:

From the web app running on the first device:

1. INIT_ADAPTIVE

2. INIT_VERIFY (Start FIDO OOB by displaying a QR code or sending a push notification)

3. VERIFY (The web app continues to call VERIFY to poll the Authentication Server until the mobile app has finished authenticating the user)

From the mobile app running on the second device:

4. INIT_OOB_AUTH (Called when the user scans the QR code or clicks the push notification)

5. FINISH_OOB_AUTH (Called after the user touches their finger on the fingerprint sensor)

From the web app running on the first device:

6. VERIFY (Final call that completes the FIDO OOB operation.)

To use Quick Authentication with Adaptive Authentication, you only need to call INIT_ADAPTIVE. The App SDK includes the Quick Authentication payload in the message attribute that you send in INIT_ADAPTIVE's request.

INIT_ADAPTIVE

The primary use case for INIT_ADAPTIVE is to initiate Adaptive Authentication by executing the Authentication Rules contained in a ruleset. It can also be used for Quick Authentication. The diagram below illustrates, at a high level, what happens between the client app and Server when INIT_ADAPTIVE is used for Adaptive Authentication. The diagram provides a specific example given for the succeeding rule's action and authentication sequences.

When the client app calls INIT_ADAPTIVE, it can send context data, signals, and an optional Adaptive Ruleset name in the request payload.

Prior to starting execution, the Server needs to determine which Adaptive Ruleset it should use.

That ruleset is determined using the following algorithm:

  1. IF you configured the calling client app with an Adaptive Ruleset5, THEN use it.

  2. ELSEIF there is an Adaptive Ruleset called default THEN use it.

  3. ELSE authentication fails.

Each rule in the ruleset is evaluated in the order until one rule succeeds (its condition evaluates to true) or all the rules fail.

If a rule succeeds, then the Server returns the rule's action which is one of:

  • ALLOW: INIT_ADAPTIVE succeeds and returns 4000.

  • DENY: INIT_ADAPTIVE fails and returns 4403.

  • TRIGGER_AUTHENTICATION: INIT_ADAPTIVE succeeds and returns 4005. The Server returns the rule's authentication sequences in the authSequences attribute in the response. The client app uses these sequences to complete authentication.

If all the rules fail, INIT_ADAPTIVE fails with a 4403.

Quick Authentication

INIT_ADAPTIVE supports Quick Authentication for both FIDO and External Authentication methods. For FIDO authentication methods, the App SDK includes the Quick Authentication payload in the message attribute of the INIT_ADAPTIVE request.

For an External Authentication method, the App SDK sends information about the external authentication method and the JWT that it received from the RP server in the completedMethods attribute of the request.

For Quick Authentication, INIT_ADAPTIVE behaves like VERIFY. If the succeeding Authentication Rule has an authentication sequence containing one FIDO method, there is a Quick Auth payload for that method, and the user successfully verified themselves with that method, then INIT_ADAPTIVE returns 4000.

When Quick Authentication succeeds, the Server populates the following attributes in INIT_ADAPTIVE's response:

  • userNames

  • completedMethods

  • ruleSetResult

  • claims

If there are additional methods in that authentication sequence then INIT_ADAPTIVE returns 4005. The Server returns the authentication sequence in the authSequences attribute in the response.

Request

Attribute

Description

operation

Required. The string INIT_ADAPTIVE.

callerOrigin

Required if a web app is sending the request and that app has a different origin than the Digipass S3 API Server. A web origin is defined by the scheme (protocol), host (domain), and port of the URL used to access it.

The API Server checks if this origin is listed in its origin allow list, if not, the request is rejected. See My Web Apps Have a Different Origin.

channelBinding

Optional. Channel binding data available from the TLS endpoint. A ChannelBinding object.

This is relevant only if Quick Authentication is being processed during this operation.

completedMethods

Optional. Used only when an External Authentication method is used for Quick Authentication. Set <Authentication Method>. Each Method object in the array must have the attributes listed below.

completedMethods[n].data.credential

Required. The JWT sent by the RP server that verified the end user by performing the external authentication method.

completedMethods[n].name

Required. The name of the external authentication method.

completedMethods[n].type

Required. The string External Auth.

contextData

Optional. A JSON object containing a set of name-value pairs for each context data item. Map<String, String>.

Example:

"contextData" : {
    "transactionType" : "transfer",
    "amount" : "734.52",
    "orderNumber": "249038"
 }

id

Optional. The correlation ID, a unique id that ties together different API requests that comprise a FIDO operation, like authentication. An alphanumeric string, maximum 255 characters. No special characters are allowed.

If not provided, the Server generates a unique id and returns it.

message

Required. Generated by the App SDK on the client. This is an opaque value. The client app is responsible for sending message. A base64-URL encoded string.

option

Optional. Enables INIT_ADAPTIVE to be used for registration when option is getAllSequences.

One of:

  • default (default): Perform Adaptive Authentication.

  • getAllSequences: Do not perform Adaptive Authentication. Instead, the Server returns all sequences from all Registration and Authentication Rules contained in the Adaptive Ruleset in the authSequences attribute in the response.

optionsData

Optional. An object used to pass additional attributes to REST API operations. The attribute below pertains to INIT_ADAPTIVE. See OptionsData.

ruleSetName

Optional. The name of the Adaptive Ruleset that the Server could process. The ruleset contains all the information necessary to perform Adaptive Authentication. An alphanumeric string, maximum 255 characters.

The calling app cannot use ruleSetName to override what is configured in the Authentication Server.

  • The Server uses the value in ruleSetName if the calling app is not configured with a ruleset or if the calling app is configured with a ruleset named default.

  • The Server ignores this value if the calling app is configured with a ruleset that is not named default.

sessionData

Optional. An object containing the user's session information. See SessionData. The 2 attributes listed below pertain to INIT_ADAPTIVE.

sessionData.userName

Optional. For an improved authentication experience, provide the username so it is known up front.

sessionData.sessionKey

Optional. To perform step-up authentication, assign a valid JWT session token to sessionData.sessionKey.

transaction

This object applies only for FIDO Auth and FIDO OOB Auth using the UAF protocol. It has the 2 attributes listed below.

transaction.id

Transaction ID provided by the client to track a transaction. It is mandatory if the request contains the optionsData.transactionText attribute.

Response

The following attributes are always present in the JSON payload of the response.

Attribute

Description

id

The unique id that correlates different requests comprising an operation. A Base64-URL encoded string.

If id was sent in the request, the same id is returned. If not, a server-generated ID is returned. If id was provided in the REST payload but the server was unable to parse the payload, the value is unknown.

statusCode

Server-specific status code that reports the success or failure of this operation. Integer.

See Response Status Codes below for the status and error codes.

The following attributes are present in the response upon a successful operation (Server status of 4000 or 4005).

Attribute

Description

additionalInfo

An object containing information from the client app that is initiating authentication. Contains the 4 attributes listed in the rows below.

In order for the API Server to return this information,

  1. The client app must have sent this information in the INIT_ADAPTIVE request message attribute.

  2. Update the response filter configuration so the API Server returns the protocol, app information, transaction ID and payload extensions.

    By default, device information is automatically returned. Refer to Response Filter Configuration.

additionalInfo.app

App information received from the client. App.

additionalInfo.device

A DeviceDetail object containing information about the device that issued the INIT_ADAPTIVE request, such as the device’s unique ID, model, and manufacturer.

additionalInfo.extensions

Message payload extensions received by the Server in the INIT_ADAPTIVE request. List<Extension>.

additionalInfo.protocol

Protocol used by the Server. String. One of UAF or Web.

additionalInfo.transaction:id

Transaction ID provided by the client app to track a transaction. String.

The transaction ID is provided in the request payload of INIT_ADAPTIVE. Present only when the status is 4000.

authSequences

A list of authentication sequences, one of which a user must complete to be successfully authenticated. Only returned when the Action is TRIGGER_AUTHENTICATION.

Map<String, AuthSequence>. String is the name of the authentication sequence.

claims

Contains a value when Quick Authentication is performed, authentication succeeds, and the rule was defined to return claims. Each claim is a name-value pair of arbitrary information that the client wants returned.

Map<String, String>.

completedMethods

Contains a value when Quick Authentication is performed. The set of completed authentication methods processed by INIT_ADAPTIVE. See FIDO Auth and FIDO OOB Auth for details.

Set <Authentication Method>

maxTimeAllowedInSeconds

Amount of time, in milliseconds, that the user has to complete an entire authentication sequence. This comes from the Authentication Rule's definition. Long.

Your client or web app can use this to tell a user how much time they have to complete the task or warn the user that the Server does not accept a response once maxTimeAllowedInSeconds has expired.

ruleSetResult

Contains a value when Quick Authentication is performed. ruleSetResult contains information about the Adaptive Rule that succeeded such as its name and its action. If ruleSetResult.action is TRIGGER_AUTHENTICATION, then a set of authentication sequences is also included. The user must satisfy one of these sequences in order to be authenticated.

AdaptiveRuleSetResult.

sessionData

An object representing the authenticated user's session information. See SessionData.

userNames

Contains a value when Quick Authentication is performed. The name(s) of the authenticated user(s).

Set<String>

Contains a single username when Quick Authentication is performed and authentication is completed. In the future, this could be a list of users, if required by a custom authentication method.

The following attribute can be present in the response when a failure occurs. For example, when there is an HTTP status 400 or server status code of 4430. The status code contains the reason for the failure.

Attribute

Description

failedMethods

Contains a FIDO authentication method when Quick Authentication payload processing fails.

If the server status code is 4400, then failedMethods contains registered methods were previously deleted on the Server but were not deleted from the client. The client app should delete these registrations.

Set <Authentication Method>

Response Status Codes

The following are the descriptions of the Auth Server status codes returned by INIT_ADAPTIVE. Under certain circumstances, the API Server returns an unsuccessful HTTP status code. Examples include an invalid request or invalid session. You can find descriptions of these in API Server Status Codes.

Server Status Code

Description

Examples

4000

Ok. Operation completed.

The operation completed successfully for one of the following situations:

  • Adaptive Authentication: The succeeding rule's action is ALLOW.

  • Quick Authentication: The succeeding rule's action is TRIGGER_AUTHENTICATION and one of its authentication sequences, containing a FIDO authentication method completed with Quick Auth, was completed.

  • Registration: INIT_ADAPTIVE was called with option = getAllSequences. The Server collects all the auth sequences for all rules in the ruleset. Rules are not evaluated.

4005

Ok. Operation in progress.

The succeeding rule's action is TRIGGER_AUTHENTICATION and it has authentication sequences.

4402

Security exception

The facet ID sent by the client doesn't match the valid facet IDs configured on the Authentication Server.

4403

Policy verification exception

One of the following occurred:

  • The requested ruleset is not available on Server.

  • The succeeding rule's action is DENY.

  • None of the rules in the ruleset matched.

  • One or more rules matched but the user has no registered authentication methods required to complete authentication.

4404

Internal Server Error

Internal server error.

Failed to read from the database.

Failed to connect to the database.

Failed to read required properties.

4406

Unacceptable content in the request

The mandatory attribute, message, is missing or empty.

4408

Unsupported client message exception

Invalid message attribute.

The client does not support the UAF/FIDO2 protocol. Or protocol information is missing.

4409

Client message exception

The message attribute is invalid (for example, there was a JSON syntax error). The message attribute from the App SDK is malformed (base64URL decode failed).

Samples

Sample Request URL

https://www.example.com:8443/nnlgateway/nnl/<tenantID>/auth

Sample Request

{
    "operation":"INIT_ADAPTIVE",
    "ruleSetName":"PaymentAuthorization",
    "id":"sample",
    "message":"<base64url-encoded-data>",
    "contextData":{
        "transactionType":"Payment",
        "paymentAmount":"30",
        "paymentVenue":"Contactless POS"
    }
}

Sample Request that Passes in an Adaptive Ruleset Name

{
    "operation": "INIT_ADAPTIVE",
    "ruleSetName": "adaptive",
    "sessionData": {
        "userName": "zsmith@noknok.com"
    },
    "contextData": {
        "transactionAmount": "3",
        "customString": "customValue"
    },
    "message": "<base64url-encoded-data>"
}

Sample Request Passing in the Result from an External Authentication Method that was Processed by an RP Server in the completedMethods Attribute

{
    "operation": "INIT_ADAPTIVE",
    "message": "<base64url-encoded-data>",
    "sessionData": {
        "userName": "zsmith@noknok.com"
    },
    "completedMethods": [
        {
            "type": "External Auth",
            "name": "Password-based External Auth",
            "data": {
                "credential": "<RP-generated JWT>"
            }
        }
    ],
    "contextData": {
        "scenario": "Default",
        "availableAuthenticationMethods": ""
    }
}

Sample Response When the Succeeding Rule's Action is TRIGGER_AUTHENTICATION

This sample response is for the UAF protocol. (FIDO Auth and Email OTP) OR (FIDO Auth and SMS OTP). A developer updated the response filter configuration so the API Server returns the protocol, app information, and payload extensions in additionalInfo.

{
  "statusCode":4005,
  "id":"t3w8UjmXK3HgJXi1vwoDdA",
  "additionalInfo":{
    "elapsedTime": 38,
    "device":{
      "id":"123456789abcdef1234567890",
      "type":"android",
      "info":"OneSpan's device",
      "model":"Galaxy S20",
      "os":"Android 12",
      "manufacturer":"Samsung"
    },
    "protocol":"uaf_1.0",
    "app":{
      "id":"com.noknok.ios.onramp",
      "name":"OnRamp",
      "qrSupported":true
    },
    "extensions":[
      {
        "id":"noknok.uaf.location",
        "data":"{\"status\":0,\"latitude\":37.46,\"longitude\":-122.143,\"accuracy\":99.2,\"countryCode\":\"US\"}",
        "operation":"INIT_ADAPTIVE"
      }
    ]
  },
  "authSequences":{
    "authSequence1":{
      "methods":[
        {
          "type":"FIDO Auth",
          "name":"default",
          "state":"PENDING",
          "data":{
            "message":"..."
          },
          "statusHandle":"a2V5aGFuZGxlAAAAAkJimA6d-mU-F34FVXt0OUXEWo0jkSZ6DytGEtKa3f6z4CNOnPIjaztJ0EMRyfZJ7QdIn1ASJXrvtdM3hugycA",
          "lifetimeMillis":3000000
        },
        {
          "statusHandle":"a2V5aGFuZGxlAAAAAkJimA6d-mU-F34FVXt0OUXEWo0jkSZ6DytGEtKa3f6z4CNOnPIjaztJ0EMRyfZJ7QdIn1ASJXrvtdM3hugycA",
          "type":"SMS OTP",
          "name":"OTP Using SMS"
        }
      ]
    },
    "authSequence2":{
      "methods":[
        {
          "type":"FIDO Auth",
          "name":"default",
          "state":"PENDING",
          "data":{
            "message":"..."
          },
          "statusHandle":"a2V5aGFuZGxlAAAAAkJimA6d-mU-F34FVXt0OUXEWo0jkSZ6DytGEtKa3f6z4CNOnPIjaztJ0EMRyfZJ7QdIn1ASJXrvtdM3hugycA",
          "lifetimeMillis":3000000
        },
        {
          "statusHandle":"a2V5aGFuZGxlAAAAAkJimA6d-mU-F34FVXt0OUXEWo0jkSZ6DytGEtKa3f6z4CNOnPIjaztJ0EMRyfZJ7QdIn1ASJXrvtdM3hugycA",
          "type":"Email OTP",
          "name":"OTP Using Email"
        }
      ]
    }
  },
  "ruleSetResult":{
    "action":"TRIGGER_AUTHENTICATION",
    "ruleSetName":"default",
    "ruleName":"defaultRule",
    "maxTimeAllowedInSeconds":900
  }
}

Sample Response When There is Quick Authentication and the Succeeding Rule's Action is TRIGGER_AUTHENTICATION

A developer updated the response filter configuration so the API Server returns app information and payload extensions.

{
  "statusCode": 4005,
  "id": "ST2A3S8hPLUTGWIx30lsLQ",
  "additionalInfo": {
    "elapsedTime": 38,
    "device": {
      "id": "123456789abcdef1234567890",
      "type": "android",
      "info": "NokNok Emulator",
      "model": "NokNok-AE 7.0",
      "os": "NokNokOS 7.0",
      "manufacturer": "NokNok",
      "supportsPlatformAuthenticator": true
    },
    "app": {
      "id": "android:apk-key-hash:rDQ4Tn60fAvxP8thtp6sOh5ococ",
      "name": "android:com.noknok.test.client",
      "qrSupported": false
    },
    "extensions": [
      {
        "id": "noknok.ipaddress",
        "data": "192.168.0.102",
        "operation": "INIT_ADAPTIVE"
      },
      {
        "id": "noknok.wifi.ssid",
        "data": "Oviya",
        "operation": "INIT_ADAPTIVE"
      },
      {
        "id": "noknok.uaf.location",
        "data": "{\"accuracy\":99.2,\"countryCode\":\"US\",\"latitude\":32.52,\"longitude\":-124.482,\"status\":0}",
        "operation": "INIT_ADAPTIVE"
      },
      {
        "id": "noknok.uaf.jailbreak",
        "data": "{\n  \"status\" : \"0\",\n  \"isJailbroken\" : \"false\"\n}",
        "operation": "INIT_ADAPTIVE"
      }
    ]
  },
  "authSequences": {
    "authenticationSequence_1": {
      "methods": [
        {
          "type": "FIDO Auth",
          "name": "default",
          "state": "PENDING",
          "data": {
            "message": "<base64url-encoded-data>",
            "additionalInfo": {
              "protocol": "uaf_1.0"
            }
          },
          "statusHandle": "a2V5aGFuZGxlAAAAAfVTOQKNgrsj4eIT4imaE9pCkg1zr8Sp7ob3d4gIxm9Tb6t1ahHB8UB9PJy7OoGhomB5ujYuLUUPaennuyJNKA",
          "lifetimeMillis": 300000
        }
      ]
    }
  },
  "ruleSetResult": {
    "action": "TRIGGER_AUTHENTICATION",
    "ruleSetName": "default",
    "ruleName": "defaultRule",
    "maxTimeAllowedInSeconds": 900
  }
}

Sample Response Where the Succeeding Rule Returned One Auth Sequence Containing the FIDO OOB Method

A developer updated the response filter configuration so the API Server returns client app information in additionalInfo.

{
  "statusCode":4005,
  "id":"MNx4lXzXVIEg1D0dPOVopg",
  "additionalInfo":{
    "elapsedTime": 38,
    "device":{
      "id":"123456789abcdef1234567892",
      "type":"android",
      "info":"OneSpan's device",
      "model":"Galaxy S20",
      "os":"Android 12",
      "manufacturer":"Samsung"
    },
    "app":{
      "id":"com.noknok.android.Passport",
      "name":"Passport",
      "qrSupported":true
    }
  },
  "ruleSetResult":{
    "action":"TRIGGER_AUTHENTICATION",
    "ruleSetName":"adaptive",
    "ruleName":"transactionAmountSmallAndroid",
    "maxTimeAllowedInSeconds":900
  },
  "authSequences":{
    "authSequence1":{
      "methods":[
        {
          "statusHandle":"a2V5aGFuZGxlAAAAAkJimA6d-mU-F34FVXt0OUXEWo0jkSZ6DytGEtKa3f6z4CNOnPIjaztJ0EMRyfZJ7QdIn1ASJXrvtdM3hugycA",
          "type":"FIDO OOB Auth",
          "name":"default",
          "data":{
            "devices":[
              {
                "device":{
                  "id":"123456789abcdef1234567890",
                  "deviceType":"android",
                  "info":"OneSpan's device",
                  "model":"Galaxy S20",
                  "os":"Android 12",
                  "manufacturer":"Samsung"
                },
                "app":{
                  "id":"com.noknok.ios.onramp",
                  "name":"OnRamp"
                },
                "pushHandle":"a2V5aGFuZGxlAAAAAccdCXFL_ZRroPBDbleh_Tl_XDb5lybdJeccJdLvHmTrqLA6zfulWBzWZoReoyLg2xbIlYnIt1piOStyKLFWwb3umC7z6Iq-BKHXjIoOph39-WXWsvJ1"
              },
              {
                "device":{
                  "id":"123456789abcdef1234567891",
                  "deviceType":"android",
                  "info":"OneSpan's device",
                  "model":"Galaxy S20",
                  "os":"Android 12",
                  "manufacturer":"Samsung"
                },
                "app":{
                  "id":"com.noknok.android.onramp",
                  "name":"OnRamp"
                },
                "pushHandle":"a2V5aGFuZGxlAAAAAY-KcR32rwJVZCdN2SJv9qIr8aFJuwr5Ajsrgc2W7icgk6QURLU0u8kq8qRrLiqfEr5guQaQEdvZV8fgmfvSilGbBQJkH009ctgy0oGkrbWBQ-M-ZUe_"
              }
            ]
          }
        }
      ]
    }
  }
}

Sample Response Where the Succeeding Rule Returned One Auth Sequence Containing an External Authentication Method

{
    "statusCode": 4005,
    "id": "et1d3DD2uGL1BhfdkicnQw",
    "authSequences": {
        "authenticationSequence_1": {
            "methods": [
                {
                    "type": "External Auth",
                    "name": "Password-based External Auth",
                    "state": "PENDING",
                    "statusHandle": "a2V5aGFuZGxlAAAAARFVlWoXquFtS5v37"
                }
            ]
        }
    },
    "ruleSetResult": {
        "action": "TRIGGER_AUTHENTICATION",
        "ruleSetName": "Password-based External Auth",
        "ruleName": "ExternalAuthRule",
        "maxTimeAllowedInSeconds": 900
    },
    "additionalInfo": {}
}

Sample Response When Authentication Completed with Quick External Authentication

{
    "userNames": [
        "zsmith@noknok.com"
    ],
    "statusCode": 4000,
    "id": "ulhh_4vmSS1XCrcThHsQew",
    "completedMethods": [
        {
            "type": "External Auth",
            "name": "Password-based External Auth",
            "state": "SUCCEEDED",
            "data": {
                "userName": "zsmith@noknok.com"
            },
            "statusHandle": "a2V5aGFuZGxlAAAAARFVlWoXquFtS5v37"
        }
    ],
    "ruleSetResult": {
        "action": "TRIGGER_AUTHENTICATION",
        "ruleSetName": "Password-based External Auth",
        "ruleName": "ExternalAuthRule",
        "authSequenceId": "authenticationSequence_1",
        "riskScore": 0,
        "maxTimeAllowedInSeconds": 900
    },
    "claims": {
        "enable3DSBlob": "false"
    },
    "sessionData": {
        "sessionKey": "<session JWT>",
        "exp": 1660571778
    },
    "additionalInfo": {
    }
}

Sample Uaf Response Showing metadata when needDetails = 4. When the protocol is UAF, the response to a includes metadata-specific information in the additionalInfo.authenticatorsResult.metadata section.

{ 
    "userNames": [
        "user1"
    ],
    "statusCode": 4000,
    "id": "6J-1l6oqz9jJiaz9E8afJQ",
    "additionalInfo": {
        "device": {
            "id": "123456789abcdef1234567890",
            "type": "android",
            "info": "NokNok Emulator",
            "model": "NokNok-AE 7.0",
            "os": "NokNokOS 7.0",
            "manufacturer": "NokNok",
            "supportsPlatformAuthenticator": true
        },
        "app": {
            "id": "android:apk-key-hash:rDQ4Tn60fAvxP8thtp6sOh5ococ",
            "name": "android:com.noknok.test.client",
            "qrSupported": true
        },
        "extensions": [
            {
                "id": "noknok.ipaddress",
                "data": "192.168.0.102",
                "operation": "INIT_ADAPTIVE"
            },
            {
                "id": "noknok.wifi.ssid",
                "data": "Oviya",
                "operation": "INIT_ADAPTIVE"
            },
            {
                "id": "noknok.uaf.location",
                "data": "{\"accuracy\":99.2,\"countryCode\":\"US\",\"latitude\":32.52,\"longitude\":-124.482,\"status\":0}",
                "operation": "INIT_ADAPTIVE"
            },
            {
                "id": "noknok.uaf.jailbreak",
                "data": "{\n  "status" : "0",\n  "isJailbroken" : "false"\n}",
                "operation": "INIT_ADAPTIVE"
            }
        ],
        "statusMessage": "Ok"
    },
    "completedMethods": [
        {
            "type": "FIDO Auth",
            "name": "default",
            "state": "SUCCEEDED",
            "data": {
                "message": "eyJzZXJ2ZXIiOnsiYXV0aGVudGljYXRvcnNSZXN1bHQiOlt7ImFhaWQiOiJBQkNEI0FCQ0QiLCJrZXlJRCI6IldPWmF4d25vRHNRc3F2Y0VTMjd1dHdLVlRKbm5Dc3ZqWld6ek5zVmhKX1EiLCJzdGF0dXMiOjQwMDB9LHsiYWFpZCI6IkFCQ0QjMDAwMSIsImtleUlEIjoic2xUZEtBQ3pXQ2hLbTNrc1ZkWGk2aUdSY1hqU3hMd2xscTB3d0FiVXdYZyIsInN0YXR1cyI6NDQwMH0seyJhYWlkIjoiQUJDRCMwMDAyIiwia2V5SUQiOiJuVUh0cWFGblNNSG43RGgwcVpzUEdTRkF1Q1pyaDJsU2tTcTNtU21jcU1ZIiwic3RhdHVzIjo0NDAwfV0sInByb3RvY29sTWVzc2FnZSI6Ilt7XCJoZWFkZXJcIjp7XCJ1cHZcIjp7XCJtYWpvclwiOjEsXCJtaW5vclwiOjB9LFwib3BcIjpcIkRlcmVnXCIsXCJhcHBJRFwiOlwiaHR0cHM6Ly8xMjcuMC4wLjE6ODQ0My9TYW1wbGVBcHBcIn0sXCJhdXRoZW50aWNhdG9yc1wiOlt7XCJhYWlkXCI6XCJBQkNEIzAwMDJcIixcImtleUlEXCI6XCJuVUh0cWFGblNNSG43RGgwcVpzUEdTRkF1Q1pyaDJsU2tTcTNtU21jcU1ZXCJ9LHtcImFhaWRcIjpcIkFCQ0QjMDAwMVwiLFwia2V5SURcIjpcInNsVGRLQUN6V0NoS20za3NWZFhpNmlHUmNYalN4THdsbHEwd3dBYlV3WGdcIn1dfV0iLCJhcHBJRCI6Imh0dHBzOi8vMTI3LjAuMC4xOjg0NDMvU2FtcGxlQXBwIiwibmV3T3BlcmF0aW9uIjoiREVMRVRFX1JFRyIsInF1aWNrQXV0aERhdGEiOnsia2V5TGVuZ3RoIjoxMjgsInZhbGlkaXR5U2Vjb25kcyI6MzAwLCJzYWx0U3VmZml4IjoieGZzbG1VU3l3RHBGYzlqUXFVR1pNdyIsImFsZ29yaXRobSI6eyJuYW1lIjoicGJrZGYyIiwiaXRlcmF0aW9ucyI6IjEwMDAiLCJtaW5JdGVyYXRpb25zIjoiMTAwMCJ9fX0sInZlcnNpb24iOiIxLjAiLCJvcGVyYXRpb24iOiJGSU5JU0hfQVVUSCIsInByb3RvY29sIjoidWFmXzEuMCJ9",
                "additionalInfo": {
                    "protocol": "uaf_1.0",
                    "authenticatorsResult": [
                        {
                            "handle": "WyJ1YWZfMS4wIiwiQUJDRCNBQkNEIiwiV09aYXh3bm9Ec1FzcXZjRVMyN3V0d0tWVEpubkNzdmpaV3p6TnNWaEpfUSJd",
                            "uvi": "jEw5SZNuD91hgRXtuVqVLsyngBa-kQg9FBkD_gQmUIE",
                            "uviStatus": 4,
                            "status": 4000,
                            "aaid": "ABCD#ABCD",
                            "authenticatorVersion": 1,
                            "appAtt": {
                                "state": "NOT_APPLICABLE"
                            },
                            "attachmentHints": [
                                "internal"
                            ],
                            "metadata": {
                                "aaid": "ABCD#ABCD",
                                "description": "ABCD#ABCD description",
                                "authenticatorVersion": 1,
                                "userVerificationMethods": [
                                    [
                                        {
                                            "userVerificationMethod": "passcode_internal"
                                        }
                                    ],
                                    [
                                        {
                                            "userVerificationMethod": "fingerprint_internal"
                                        }
                                    ]
                                ],
                                "keyProtection": [
                                    "KEY_PROTECTION_TEE"
                                ],
                                "multiDeviceCredentialSupport": "unsupported",
                                "matcherProtection": [
                                    "MATCHER_PROTECTION_TEE"
                                ],
                                "tcDisplay": [
                                    "SECURE_DISPLAY_ANY"
                                ],
                                "isKeyRestricted": true,
                                "isFreshUserVerificationRequired": true,
                                "attestationTypes": [
                                    "basic_full"
                                ]
                            }
                        },
                        {
                            "handle": "WyJ1YWZfMS4wIiwiQUJDRCMwMDAxIiwic2xUZEtBQ3pXQ2hLbTNrc1ZkWGk2aUdSY1hqU3hMd2xscTB3d0FiVXdYZyJd",
                            "status": 4400,
                            "aaid": "ABCD#0001",
                            "authenticatorVersion": 1
                        },
                        {
                            "handle": "WyJ1YWZfMS4wIiwiQUJDRCMwMDAyIiwiblVIdHFhRm5TTUhuN0RoMHFac1BHU0ZBdUNacmgybFNrU3EzbVNtY3FNWSJd",
                            "status": 4400,
                            "aaid": "ABCD#0002",
                            "authenticatorVersion": 1
                        }
                    ],
                    "policyName": "default"
                },
                "statusCode": 4000
            },
            "statusHandle": "AAAAAAAAAAG2uZ-2LcWSd4jUYunEaPQuCZgrLL7HRJxxH1KN754_0Hi2bqUt2Ox2dMrx73u7lvC9OTo6XS1VPdg8JXwzkT8"
        }
    ],
    "ruleSetResult": {
        "action": "TRIGGER_AUTHENTICATION",
        "ruleSetName": "default",
        "ruleName": "defaultRule",
        "authSequenceId": "authenticationSequence_1",
        "maxTimeAllowedInSeconds": 180
    }
}

Sample Webauthn Response Showing metadata when needDetails = 4.  When the protocol is web, the response from a Quick Auth request includes metadata-specific information in the additionalInfo.metadata section.

{
    "userNames": [
        "user1"
    ],
    "statusCode": 4000,
    "id": "6J-1l6oqz9jJiaz9E8afJQ",
    "additionalInfo": {
        "device": {
            "id": "123456789abcdef1234567890",
            "type": "android",
            "info": "NokNok Emulator",
            "model": "NokNok-AE 7.0",
            "os": "NokNokOS 7.0",
            "manufacturer": "NokNok",
            "supportsPlatformAuthenticator": true
        },
        "app": {
            "id": "android:apk-key-hash:rDQ4Tn60fAvxP8thtp6sOh5ococ",
            "name": "android:com.noknok.test.client",
            "qrSupported": true
        },
        "extensions": [
            {
                "id": "noknok.ipaddress",
                "data": "192.168.0.102",
                "operation": "INIT_ADAPTIVE"
            },
            {
                "id": "noknok.wifi.ssid",
                "data": "Oviya",
                "operation": "INIT_ADAPTIVE"
            },
            {
                "id": "noknok.web.location",
                "data": "{\"accuracy\":99.2,\"countryCode\":\"US\",\"latitude\":32.52,\"longitude\":-124.482,\"status\":0}",
                "operation": "INIT_ADAPTIVE"
            },
            {
                "id": "noknok.web.jailbreak",
                "data": "{\n  "status" : "0",\n  "isJailbroken" : "false"\n}",
                "operation": "INIT_ADAPTIVE"
            }
        ],
        "statusMessage": "Ok"
    },
    "completedMethods": [
        {
            "type": "FIDO Auth",
            "name": "default",
            "state": "SUCCEEDED",
            "data": {
                "message": "eyJzZXJ2ZXIiOnsiYXV0aGVudGljYXRvcnNSZXN1bHQiOlt7ImFhaWQiOiJBQkNEI0FCQ0QiLCJrZXlJRCI6IldPWmF4d25vRHNRc3F2Y0VTMjd1dHdLVlRKbm5Dc3ZqWld6ek5zVmhKX1EiLCJzdGF0dXMiOjQwMDB9LHsiYWFpZCI6IkFCQ0QjMDAwMSIsImtleUlEIjoic2xUZEtBQ3pXQ2hLbTNrc1ZkWGk2aUdSY1hqU3hMd2xscTB3d0FiVXdYZyIsInN0YXR1cyI6NDQwMH0seyJhYWlkIjoiQUJDRCMwMDAyIiwia2V5SUQiOiJuVUh0cWFGblNNSG43RGgwcVpzUEdTRkF1Q1pyaDJsU2tTcTNtU21jcU1ZIiwic3RhdHVzIjo0NDAwfV0sInByb3RvY29sTWVzc2FnZSI6Ilt7XCJoZWFkZXJcIjp7XCJ1cHZcIjp7XCJtYWpvclwiOjEsXCJtaW5vclwiOjB9LFwib3BcIjpcIkRlcmVnXCIsXCJhcHBJRFwiOlwiaHR0cHM6Ly8xMjcuMC4wLjE6ODQ0My9TYW1wbGVBcHBcIn0sXCJhdXRoZW50aWNhdG9yc1wiOlt7XCJhYWlkXCI6XCJBQkNEIzAwMDJcIixcImtleUlEXCI6XCJuVUh0cWFGblNNSG43RGgwcVpzUEdTRkF1Q1pyaDJsU2tTcTNtU21jcU1ZXCJ9LHtcImFhaWRcIjpcIkFCQ0QjMDAwMVwiLFwia2V5SURcIjpcInNsVGRLQUN6V0NoS20za3NWZFhpNmlHUmNYalN4THdsbHEwd3dBYlV3WGdcIn1dfV0iLCJhcHBJRCI6Imh0dHBzOi8vMTI3LjAuMC4xOjg0NDMvU2FtcGxlQXBwIiwibmV3T3BlcmF0aW9uIjoiREVMRVRFX1JFRyIsInF1aWNrQXV0aERhdGEiOnsia2V5TGVuZ3RoIjoxMjgsInZhbGlkaXR5U2Vjb25kcyI6MzAwLCJzYWx0U3VmZml4IjoieGZzbG1VU3l3RHBGYzlqUXFVR1pNdyIsImFsZ29yaXRobSI6eyJuYW1lIjoicGJrZGYyIiwiaXRlcmF0aW9ucyI6IjEwMDAiLCJtaW5JdGVyYXRpb25zIjoiMTAwMCJ9fX0sInZlcnNpb24iOiIxLjAiLCJvcGVyYXRpb24iOiJGSU5JU0hfQVVUSCIsInByb3RvY29sIjoidWFmXzEuMCJ9",
                "additionalInfo": {
                    "protocol": "web_1.0",
                    "authenticatorsResult": [
                        {
                "handle": "WyJ3ZWIiLCIwNjBiMmIwNi0wMTA0LTAxODItZTUxYy0wMTAxMDQwNDEyMDQiLCJOQThzOGQ3aHJ2NE9wdE5KSXJxY1pkR0Zkb3l4MUFZaDNqX3NRMWtLVFg4Il0",
                "status": 4000,
                "aaguid": "060b2b06-0104-0182-e51c-010104041204",
                "attestationFormat": "packed",
                "authenticatorVersion": 0,
                "attestationType": 15880,
                "credentialID": "NA8s8d7hrv4OptNJIrqcZdGFdoyx1AYh3j_sQ1kKTX8",
                "attestationTypeName": "Self",
                "attestationStatus": "SUCCESS",
                "userPresence": true,
                "userVerification": true,
                "backUpEligible": true,
                "backedUp": false,
                "dpk": {
                    "state": "NOT_APPLICABLE"
                },
                "appAtt": {
                    "state": "NOT_APPLICABLE"
                },
                "attachmentHints": [
                    "internal"
                ],
                "authenticatorAttachment": "platform",
                "metadata": {
                    "aaguid": "060b2b0601040182e51c010104041204",
                    "description": "Generic webauthn authenticator",
                    "authenticatorVersion": 0,
                    "userVerificationMethods": [
                        [
                            {
                                "userVerification": 1,
                                "userVerificationMethod": "presence_internal"
                            }
                        ]
                    ],
                    "keyProtection": [
                        "KEY_PROTECTION_HARDWARE",
                        "KEY_PROTECTION_TEE"
                    ],
                    "multiDeviceCredentialSupport": "unsupported",
                    "matcherProtection": [
                        "MATCHER_PROTECTION_TEE"
                    ],
                    "tcDisplay": [
                        "SECURE_DISPLAY_ANY"
                    ],
                    "isKeyRestricted": true,
                    "isFreshUserVerificationRequired": true,
                    "attestationType": [
                        "basic_full"
                    ]
                }
            }
                    ],
                    "policyName": "default"
                },
                "statusCode": 4000
            },
            "statusHandle": "AAAAAAAAAAG2uZ-2LcWSd4jUYunEaPQuCZgrLL7HRJxxH1KN754_0Hi2bqUt2Ox2dMrx73u7lvC9OTo6XS1VPdg8JXwzkT8"
        }
    ],
    "ruleSetResult": {
        "action": "TRIGGER_AUTHENTICATION",
        "ruleSetName": "default",
        "ruleName": "defaultRule",
        "authSequenceId": "authenticationSequence_1",
        "maxTimeAllowedInSeconds": 180
    }
}