URL: /nnlgateway/nnl/<tenantID>/auth Method: POST |
Digipass S3 Authentication Software provides operations under the /nnl/v2/auth endpoint to initiate Adaptive Authentication, start verification with an authentication method, complete authentication for a method, or cancel verification for a specific method.
The following operations are available:
Start Adaptive Authentication by calling INIT_ADAPTIVE. If INIT_ADAPTIVE returns success and the succeeding Adaptive Rule's action is TRIGGER_AUTHENTICATION, then one or more authentication sequences are also returned in the response.
The calling app is responsible for interacting with the user to select an authentication sequence to use, then using each authentication method within that sequence to verify the user. To begin verification with an authentication method, call INIT_VERIFY. You can skip this call for FIDO or External authentication methods because Adaptive Authentication has been optimized for these methods. When the user successfully authenticates with a method, call VERIFY.
Users only get one chance to authenticate with a FIDO method. For non-FIDO methods, if the user failed authentication (for example, they mistyped the OTP for SMS OTP), then you can call VERIFY again. You can configure the number of allowed retries for OTP and FIDO OOB by using the Admin console.
Authentication Method | REST API operation(s) to call |
|---|---|
FIDO OOB, SMS OTP, Email OTP, Photo ID |
|
FIDO Authentication, External authentication | VERIFY: Complete authentication |
For example, the user selects an authentication sequence containing the following authentication methods:
FIDO fingerprint
FIDO2 security key
SMS OTP
Assuming the user successfully authenticates with all of these methods, the sequence of calls from the calling app to the Server would be as follows:
INIT_ADAPTIVE
VERIFY (FIDO fingerprint)
VERIFY (FIDO2 security key)
INIT_VERIFY (SMS OTP)
VERIFY (SMS OTP)
Let's consider an alternative authentication sequence that only contains FIDO OOB.
In this situation, two different client apps must be used to successfully complete FIDO OOB. The first could be a web app running on a browser on a laptop. The second would be a mobile app (like OneSpan's Passport app) running on a cell phone. The laptop is designated as the first device while the cell phone is the second device.
Assuming the user successfully authenticates with FIDO OOB, the sequence of calls from the client apps to the Server would be as follows:
From the web app running on the first device:
1. INIT_ADAPTIVE
2. INIT_VERIFY (Start FIDO OOB by displaying a QR code or sending a push notification)
3. VERIFY (The web app continues to call VERIFY to poll the Authentication Server until the mobile app has finished authenticating the user)
From the mobile app running on the second device:
4. INIT_OOB_AUTH (Called when the user scans the QR code or clicks the push notification)
5. FINISH_OOB_AUTH (Called after the user touches their finger on the fingerprint sensor)
From the web app running on the first device:
6. VERIFY (Final call that completes the FIDO OOB operation.)
To use Quick Authentication with Adaptive Authentication, you only need to call INIT_ADAPTIVE. The App SDK includes the Quick Authentication payload in the message attribute that you send in INIT_ADAPTIVE's request.
INIT_ADAPTIVE
The primary use case for INIT_ADAPTIVE is to initiate Adaptive Authentication by executing the Authentication Rules contained in a ruleset. It can also be used for Quick Authentication. The diagram below illustrates, at a high level, what happens between the client app and Server when INIT_ADAPTIVE is used for Adaptive Authentication. The diagram provides a specific example given for the succeeding rule's action and authentication sequences.
.png?sv=2026-02-06&spr=https&st=2026-09-30T02%3A10%3A58Z&se=2026-09-30T02%3A50%3A58Z&sr=c&sp=r&sig=26T95HvVkSNbRk124QjQpf1%2FDbXXjULAM%2BuqCXWb5ao%3D)
When the client app calls INIT_ADAPTIVE, it can send context data, signals, and an optional Adaptive Ruleset name in the request payload.
Prior to starting execution, the Server needs to determine which Adaptive Ruleset it should use.
That ruleset is determined using the following algorithm:
IF you configured the calling client app with an Adaptive Ruleset5, THEN use it.
ELSEIF there is an Adaptive Ruleset called default THEN use it.
ELSE authentication fails.
Each rule in the ruleset is evaluated in the order until one rule succeeds (its condition evaluates to true) or all the rules fail.
If a rule succeeds, then the Server returns the rule's action which is one of:
ALLOW: INIT_ADAPTIVE succeeds and returns 4000.
DENY: INIT_ADAPTIVE fails and returns 4403.
TRIGGER_AUTHENTICATION: INIT_ADAPTIVE succeeds and returns 4005. The Server returns the rule's authentication sequences in the authSequences attribute in the response. The client app uses these sequences to complete authentication.
If all the rules fail, INIT_ADAPTIVE fails with a 4403.
Quick Authentication
INIT_ADAPTIVE supports Quick Authentication for both FIDO and External Authentication methods. For FIDO authentication methods, the App SDK includes the Quick Authentication payload in the message attribute of the INIT_ADAPTIVE request.
For an External Authentication method, the App SDK sends information about the external authentication method and the JWT that it received from the RP server in the completedMethods attribute of the request.
For Quick Authentication, INIT_ADAPTIVE behaves like VERIFY. If the succeeding Authentication Rule has an authentication sequence containing one FIDO method, there is a Quick Auth payload for that method, and the user successfully verified themselves with that method, then INIT_ADAPTIVE returns 4000.
When Quick Authentication succeeds, the Server populates the following attributes in INIT_ADAPTIVE's response:
userNames
completedMethods
ruleSetResult
claims
If there are additional methods in that authentication sequence then INIT_ADAPTIVE returns 4005. The Server returns the authentication sequence in the authSequences attribute in the response.
Request
Attribute | Description |
|---|---|
operation | Required. The string INIT_ADAPTIVE. |
callerOrigin | Required if a web app is sending the request and that app has a different origin than the Digipass S3 API Server. A web origin is defined by the scheme (protocol), host (domain), and port of the URL used to access it. The API Server checks if this origin is listed in its origin allow list, if not, the request is rejected. See My Web Apps Have a Different Origin. |
channelBinding | Optional. Channel binding data available from the TLS endpoint. A ChannelBinding object.
|
completedMethods | Optional. Used only when an External Authentication method is used for Quick Authentication. Set <Authentication Method>. Each Method object in the array must have the attributes listed below. |
completedMethods[n].data.credential | Required. The JWT sent by the RP server that verified the end user by performing the external authentication method. |
completedMethods[n].name | Required. The name of the external authentication method. |
completedMethods[n].type | Required. The string External Auth. |
contextData | Optional. A JSON object containing a set of name-value pairs for each context data item. Map<String, String>. Example: |
id | Optional. The correlation ID, a unique id that ties together different API requests that comprise a FIDO operation, like authentication. An alphanumeric string, maximum 255 characters. No special characters are allowed. If not provided, the Server generates a unique id and returns it. |
message | Required. Generated by the App SDK on the client. This is an opaque value. The client app is responsible for sending message. A base64-URL encoded string. |
option | Optional. Enables INIT_ADAPTIVE to be used for registration when option is getAllSequences. One of:
|
optionsData | Optional. An object used to pass additional attributes to REST API operations. The attribute below pertains to INIT_ADAPTIVE. See OptionsData. |
ruleSetName | Optional. The name of the Adaptive Ruleset that the Server could process. The ruleset contains all the information necessary to perform Adaptive Authentication. An alphanumeric string, maximum 255 characters.
|
sessionData | Optional. An object containing the user's session information. See SessionData. The 2 attributes listed below pertain to INIT_ADAPTIVE. |
sessionData.userName | Optional. For an improved authentication experience, provide the username so it is known up front. |
sessionData.sessionKey | Optional. To perform step-up authentication, assign a valid JWT session token to sessionData.sessionKey. |
transaction | This object applies only for FIDO Auth and FIDO OOB Auth using the UAF protocol. It has the 2 attributes listed below. |
transaction.id | Transaction ID provided by the client to track a transaction. It is mandatory if the request contains the optionsData.transactionText attribute. |
Response
The following attributes are always present in the JSON payload of the response.
Attribute | Description |
|---|---|
id | The unique id that correlates different requests comprising an operation. A Base64-URL encoded string. If id was sent in the request, the same id is returned. If not, a server-generated ID is returned. If id was provided in the REST payload but the server was unable to parse the payload, the value is unknown. |
statusCode | Server-specific status code that reports the success or failure of this operation. Integer. See Response Status Codes below for the status and error codes. |
The following attributes are present in the response upon a successful operation (Server status of 4000 or 4005).
Attribute | Description |
|---|---|
additionalInfo | An object containing information from the client app that is initiating authentication. Contains the 4 attributes listed in the rows below. In order for the API Server to return this information,
|
additionalInfo.app | App information received from the client. App. |
additionalInfo.device | A DeviceDetail object containing information about the device that issued the INIT_ADAPTIVE request, such as the device’s unique ID, model, and manufacturer. |
additionalInfo.extensions | Message payload extensions received by the Server in the INIT_ADAPTIVE request. List<Extension>. |
additionalInfo.protocol | Protocol used by the Server. String. One of UAF or Web. |
additionalInfo.transaction:id | Transaction ID provided by the client app to track a transaction. String. The transaction ID is provided in the request payload of INIT_ADAPTIVE. Present only when the status is 4000. |
authSequences | A list of authentication sequences, one of which a user must complete to be successfully authenticated. Only returned when the Action is TRIGGER_AUTHENTICATION. Map<String, AuthSequence>. String is the name of the authentication sequence. |
claims | Contains a value when Quick Authentication is performed, authentication succeeds, and the rule was defined to return claims. Each claim is a name-value pair of arbitrary information that the client wants returned. Map<String, String>. |
completedMethods | Contains a value when Quick Authentication is performed. The set of completed authentication methods processed by INIT_ADAPTIVE. See FIDO Auth and FIDO OOB Auth for details. Set <Authentication Method> |
maxTimeAllowedInSeconds | Amount of time, in milliseconds, that the user has to complete an entire authentication sequence. This comes from the Authentication Rule's definition. Long. Your client or web app can use this to tell a user how much time they have to complete the task or warn the user that the Server does not accept a response once maxTimeAllowedInSeconds has expired. |
ruleSetResult | Contains a value when Quick Authentication is performed. ruleSetResult contains information about the Adaptive Rule that succeeded such as its name and its action. If ruleSetResult.action is TRIGGER_AUTHENTICATION, then a set of authentication sequences is also included. The user must satisfy one of these sequences in order to be authenticated. |
sessionData | An object representing the authenticated user's session information. See SessionData. |
userNames | Contains a value when Quick Authentication is performed. The name(s) of the authenticated user(s). Set<String> Contains a single username when Quick Authentication is performed and authentication is completed. In the future, this could be a list of users, if required by a custom authentication method. |
The following attribute can be present in the response when a failure occurs. For example, when there is an HTTP status 400 or server status code of 4430. The status code contains the reason for the failure.
Attribute | Description |
|---|---|
failedMethods | Contains a FIDO authentication method when Quick Authentication payload processing fails. If the server status code is 4400, then failedMethods contains registered methods were previously deleted on the Server but were not deleted from the client. The client app should delete these registrations. Set <Authentication Method> |
Response Status Codes
The following are the descriptions of the Auth Server status codes returned by INIT_ADAPTIVE. Under certain circumstances, the API Server returns an unsuccessful HTTP status code. Examples include an invalid request or invalid session. You can find descriptions of these in API Server Status Codes.
Server Status Code | Description | Examples |
|---|---|---|
4000 | Ok. Operation completed. | The operation completed successfully for one of the following situations:
|
4005 | Ok. Operation in progress. | The succeeding rule's action is TRIGGER_AUTHENTICATION and it has authentication sequences. |
4402 | Security exception | The facet ID sent by the client doesn't match the valid facet IDs configured on the Authentication Server. |
4403 | Policy verification exception | One of the following occurred:
|
4404 | Internal Server Error | Internal server error. Failed to read from the database. Failed to connect to the database. Failed to read required properties. |
4406 | Unacceptable content in the request | The mandatory attribute, message, is missing or empty. |
4408 | Unsupported client message exception | Invalid message attribute. The client does not support the UAF/FIDO2 protocol. Or protocol information is missing. |
4409 | Client message exception | The message attribute is invalid (for example, there was a JSON syntax error). The message attribute from the App SDK is malformed (base64URL decode failed). |
Samples
Sample Request URL
https://www.example.com:8443/nnlgateway/nnl/<tenantID>/authSample Request
{
"operation":"INIT_ADAPTIVE",
"ruleSetName":"PaymentAuthorization",
"id":"sample",
"message":"<base64url-encoded-data>",
"contextData":{
"transactionType":"Payment",
"paymentAmount":"30",
"paymentVenue":"Contactless POS"
}
}Sample Request that Passes in an Adaptive Ruleset Name
{
"operation": "INIT_ADAPTIVE",
"ruleSetName": "adaptive",
"sessionData": {
"userName": "zsmith@noknok.com"
},
"contextData": {
"transactionAmount": "3",
"customString": "customValue"
},
"message": "<base64url-encoded-data>"
}Sample Request Passing in the Result from an External Authentication Method that was Processed by an RP Server in the completedMethods Attribute
{
"operation": "INIT_ADAPTIVE",
"message": "<base64url-encoded-data>",
"sessionData": {
"userName": "zsmith@noknok.com"
},
"completedMethods": [
{
"type": "External Auth",
"name": "Password-based External Auth",
"data": {
"credential": "<RP-generated JWT>"
}
}
],
"contextData": {
"scenario": "Default",
"availableAuthenticationMethods": ""
}
}Sample Response When the Succeeding Rule's Action is TRIGGER_AUTHENTICATION
This sample response is for the UAF protocol. (FIDO Auth and Email OTP) OR (FIDO Auth and SMS OTP). A developer updated the response filter configuration so the API Server returns the protocol, app information, and payload extensions in additionalInfo.
{
"statusCode":4005,
"id":"t3w8UjmXK3HgJXi1vwoDdA",
"additionalInfo":{
"elapsedTime": 38,
"device":{
"id":"123456789abcdef1234567890",
"type":"android",
"info":"OneSpan's device",
"model":"Galaxy S20",
"os":"Android 12",
"manufacturer":"Samsung"
},
"protocol":"uaf_1.0",
"app":{
"id":"com.noknok.ios.onramp",
"name":"OnRamp",
"qrSupported":true
},
"extensions":[
{
"id":"noknok.uaf.location",
"data":"{\"status\":0,\"latitude\":37.46,\"longitude\":-122.143,\"accuracy\":99.2,\"countryCode\":\"US\"}",
"operation":"INIT_ADAPTIVE"
}
]
},
"authSequences":{
"authSequence1":{
"methods":[
{
"type":"FIDO Auth",
"name":"default",
"state":"PENDING",
"data":{
"message":"..."
},
"statusHandle":"a2V5aGFuZGxlAAAAAkJimA6d-mU-F34FVXt0OUXEWo0jkSZ6DytGEtKa3f6z4CNOnPIjaztJ0EMRyfZJ7QdIn1ASJXrvtdM3hugycA",
"lifetimeMillis":3000000
},
{
"statusHandle":"a2V5aGFuZGxlAAAAAkJimA6d-mU-F34FVXt0OUXEWo0jkSZ6DytGEtKa3f6z4CNOnPIjaztJ0EMRyfZJ7QdIn1ASJXrvtdM3hugycA",
"type":"SMS OTP",
"name":"OTP Using SMS"
}
]
},
"authSequence2":{
"methods":[
{
"type":"FIDO Auth",
"name":"default",
"state":"PENDING",
"data":{
"message":"..."
},
"statusHandle":"a2V5aGFuZGxlAAAAAkJimA6d-mU-F34FVXt0OUXEWo0jkSZ6DytGEtKa3f6z4CNOnPIjaztJ0EMRyfZJ7QdIn1ASJXrvtdM3hugycA",
"lifetimeMillis":3000000
},
{
"statusHandle":"a2V5aGFuZGxlAAAAAkJimA6d-mU-F34FVXt0OUXEWo0jkSZ6DytGEtKa3f6z4CNOnPIjaztJ0EMRyfZJ7QdIn1ASJXrvtdM3hugycA",
"type":"Email OTP",
"name":"OTP Using Email"
}
]
}
},
"ruleSetResult":{
"action":"TRIGGER_AUTHENTICATION",
"ruleSetName":"default",
"ruleName":"defaultRule",
"maxTimeAllowedInSeconds":900
}
}Sample Response When There is Quick Authentication and the Succeeding Rule's Action is TRIGGER_AUTHENTICATION
A developer updated the response filter configuration so the API Server returns app information and payload extensions.
{
"statusCode": 4005,
"id": "ST2A3S8hPLUTGWIx30lsLQ",
"additionalInfo": {
"elapsedTime": 38,
"device": {
"id": "123456789abcdef1234567890",
"type": "android",
"info": "NokNok Emulator",
"model": "NokNok-AE 7.0",
"os": "NokNokOS 7.0",
"manufacturer": "NokNok",
"supportsPlatformAuthenticator": true
},
"app": {
"id": "android:apk-key-hash:rDQ4Tn60fAvxP8thtp6sOh5ococ",
"name": "android:com.noknok.test.client",
"qrSupported": false
},
"extensions": [
{
"id": "noknok.ipaddress",
"data": "192.168.0.102",
"operation": "INIT_ADAPTIVE"
},
{
"id": "noknok.wifi.ssid",
"data": "Oviya",
"operation": "INIT_ADAPTIVE"
},
{
"id": "noknok.uaf.location",
"data": "{\"accuracy\":99.2,\"countryCode\":\"US\",\"latitude\":32.52,\"longitude\":-124.482,\"status\":0}",
"operation": "INIT_ADAPTIVE"
},
{
"id": "noknok.uaf.jailbreak",
"data": "{\n \"status\" : \"0\",\n \"isJailbroken\" : \"false\"\n}",
"operation": "INIT_ADAPTIVE"
}
]
},
"authSequences": {
"authenticationSequence_1": {
"methods": [
{
"type": "FIDO Auth",
"name": "default",
"state": "PENDING",
"data": {
"message": "<base64url-encoded-data>",
"additionalInfo": {
"protocol": "uaf_1.0"
}
},
"statusHandle": "a2V5aGFuZGxlAAAAAfVTOQKNgrsj4eIT4imaE9pCkg1zr8Sp7ob3d4gIxm9Tb6t1ahHB8UB9PJy7OoGhomB5ujYuLUUPaennuyJNKA",
"lifetimeMillis": 300000
}
]
}
},
"ruleSetResult": {
"action": "TRIGGER_AUTHENTICATION",
"ruleSetName": "default",
"ruleName": "defaultRule",
"maxTimeAllowedInSeconds": 900
}
}Sample Response Where the Succeeding Rule Returned One Auth Sequence Containing the FIDO OOB Method
A developer updated the response filter configuration so the API Server returns client app information in additionalInfo.
{
"statusCode":4005,
"id":"MNx4lXzXVIEg1D0dPOVopg",
"additionalInfo":{
"elapsedTime": 38,
"device":{
"id":"123456789abcdef1234567892",
"type":"android",
"info":"OneSpan's device",
"model":"Galaxy S20",
"os":"Android 12",
"manufacturer":"Samsung"
},
"app":{
"id":"com.noknok.android.Passport",
"name":"Passport",
"qrSupported":true
}
},
"ruleSetResult":{
"action":"TRIGGER_AUTHENTICATION",
"ruleSetName":"adaptive",
"ruleName":"transactionAmountSmallAndroid",
"maxTimeAllowedInSeconds":900
},
"authSequences":{
"authSequence1":{
"methods":[
{
"statusHandle":"a2V5aGFuZGxlAAAAAkJimA6d-mU-F34FVXt0OUXEWo0jkSZ6DytGEtKa3f6z4CNOnPIjaztJ0EMRyfZJ7QdIn1ASJXrvtdM3hugycA",
"type":"FIDO OOB Auth",
"name":"default",
"data":{
"devices":[
{
"device":{
"id":"123456789abcdef1234567890",
"deviceType":"android",
"info":"OneSpan's device",
"model":"Galaxy S20",
"os":"Android 12",
"manufacturer":"Samsung"
},
"app":{
"id":"com.noknok.ios.onramp",
"name":"OnRamp"
},
"pushHandle":"a2V5aGFuZGxlAAAAAccdCXFL_ZRroPBDbleh_Tl_XDb5lybdJeccJdLvHmTrqLA6zfulWBzWZoReoyLg2xbIlYnIt1piOStyKLFWwb3umC7z6Iq-BKHXjIoOph39-WXWsvJ1"
},
{
"device":{
"id":"123456789abcdef1234567891",
"deviceType":"android",
"info":"OneSpan's device",
"model":"Galaxy S20",
"os":"Android 12",
"manufacturer":"Samsung"
},
"app":{
"id":"com.noknok.android.onramp",
"name":"OnRamp"
},
"pushHandle":"a2V5aGFuZGxlAAAAAY-KcR32rwJVZCdN2SJv9qIr8aFJuwr5Ajsrgc2W7icgk6QURLU0u8kq8qRrLiqfEr5guQaQEdvZV8fgmfvSilGbBQJkH009ctgy0oGkrbWBQ-M-ZUe_"
}
]
}
}
]
}
}
}Sample Response Where the Succeeding Rule Returned One Auth Sequence Containing an External Authentication Method
{
"statusCode": 4005,
"id": "et1d3DD2uGL1BhfdkicnQw",
"authSequences": {
"authenticationSequence_1": {
"methods": [
{
"type": "External Auth",
"name": "Password-based External Auth",
"state": "PENDING",
"statusHandle": "a2V5aGFuZGxlAAAAARFVlWoXquFtS5v37"
}
]
}
},
"ruleSetResult": {
"action": "TRIGGER_AUTHENTICATION",
"ruleSetName": "Password-based External Auth",
"ruleName": "ExternalAuthRule",
"maxTimeAllowedInSeconds": 900
},
"additionalInfo": {}
}Sample Response When Authentication Completed with Quick External Authentication
{
"userNames": [
"zsmith@noknok.com"
],
"statusCode": 4000,
"id": "ulhh_4vmSS1XCrcThHsQew",
"completedMethods": [
{
"type": "External Auth",
"name": "Password-based External Auth",
"state": "SUCCEEDED",
"data": {
"userName": "zsmith@noknok.com"
},
"statusHandle": "a2V5aGFuZGxlAAAAARFVlWoXquFtS5v37"
}
],
"ruleSetResult": {
"action": "TRIGGER_AUTHENTICATION",
"ruleSetName": "Password-based External Auth",
"ruleName": "ExternalAuthRule",
"authSequenceId": "authenticationSequence_1",
"riskScore": 0,
"maxTimeAllowedInSeconds": 900
},
"claims": {
"enable3DSBlob": "false"
},
"sessionData": {
"sessionKey": "<session JWT>",
"exp": 1660571778
},
"additionalInfo": {
}
}Sample Uaf Response Showing metadata when needDetails = 4. When the protocol is UAF, the response to a includes metadata-specific information in the additionalInfo.authenticatorsResult.metadata section.
{
"userNames": [
"user1"
],
"statusCode": 4000,
"id": "6J-1l6oqz9jJiaz9E8afJQ",
"additionalInfo": {
"device": {
"id": "123456789abcdef1234567890",
"type": "android",
"info": "NokNok Emulator",
"model": "NokNok-AE 7.0",
"os": "NokNokOS 7.0",
"manufacturer": "NokNok",
"supportsPlatformAuthenticator": true
},
"app": {
"id": "android:apk-key-hash:rDQ4Tn60fAvxP8thtp6sOh5ococ",
"name": "android:com.noknok.test.client",
"qrSupported": true
},
"extensions": [
{
"id": "noknok.ipaddress",
"data": "192.168.0.102",
"operation": "INIT_ADAPTIVE"
},
{
"id": "noknok.wifi.ssid",
"data": "Oviya",
"operation": "INIT_ADAPTIVE"
},
{
"id": "noknok.uaf.location",
"data": "{\"accuracy\":99.2,\"countryCode\":\"US\",\"latitude\":32.52,\"longitude\":-124.482,\"status\":0}",
"operation": "INIT_ADAPTIVE"
},
{
"id": "noknok.uaf.jailbreak",
"data": "{\n "status" : "0",\n "isJailbroken" : "false"\n}",
"operation": "INIT_ADAPTIVE"
}
],
"statusMessage": "Ok"
},
"completedMethods": [
{
"type": "FIDO Auth",
"name": "default",
"state": "SUCCEEDED",
"data": {
"message": "eyJzZXJ2ZXIiOnsiYXV0aGVudGljYXRvcnNSZXN1bHQiOlt7ImFhaWQiOiJBQkNEI0FCQ0QiLCJrZXlJRCI6IldPWmF4d25vRHNRc3F2Y0VTMjd1dHdLVlRKbm5Dc3ZqWld6ek5zVmhKX1EiLCJzdGF0dXMiOjQwMDB9LHsiYWFpZCI6IkFCQ0QjMDAwMSIsImtleUlEIjoic2xUZEtBQ3pXQ2hLbTNrc1ZkWGk2aUdSY1hqU3hMd2xscTB3d0FiVXdYZyIsInN0YXR1cyI6NDQwMH0seyJhYWlkIjoiQUJDRCMwMDAyIiwia2V5SUQiOiJuVUh0cWFGblNNSG43RGgwcVpzUEdTRkF1Q1pyaDJsU2tTcTNtU21jcU1ZIiwic3RhdHVzIjo0NDAwfV0sInByb3RvY29sTWVzc2FnZSI6Ilt7XCJoZWFkZXJcIjp7XCJ1cHZcIjp7XCJtYWpvclwiOjEsXCJtaW5vclwiOjB9LFwib3BcIjpcIkRlcmVnXCIsXCJhcHBJRFwiOlwiaHR0cHM6Ly8xMjcuMC4wLjE6ODQ0My9TYW1wbGVBcHBcIn0sXCJhdXRoZW50aWNhdG9yc1wiOlt7XCJhYWlkXCI6XCJBQkNEIzAwMDJcIixcImtleUlEXCI6XCJuVUh0cWFGblNNSG43RGgwcVpzUEdTRkF1Q1pyaDJsU2tTcTNtU21jcU1ZXCJ9LHtcImFhaWRcIjpcIkFCQ0QjMDAwMVwiLFwia2V5SURcIjpcInNsVGRLQUN6V0NoS20za3NWZFhpNmlHUmNYalN4THdsbHEwd3dBYlV3WGdcIn1dfV0iLCJhcHBJRCI6Imh0dHBzOi8vMTI3LjAuMC4xOjg0NDMvU2FtcGxlQXBwIiwibmV3T3BlcmF0aW9uIjoiREVMRVRFX1JFRyIsInF1aWNrQXV0aERhdGEiOnsia2V5TGVuZ3RoIjoxMjgsInZhbGlkaXR5U2Vjb25kcyI6MzAwLCJzYWx0U3VmZml4IjoieGZzbG1VU3l3RHBGYzlqUXFVR1pNdyIsImFsZ29yaXRobSI6eyJuYW1lIjoicGJrZGYyIiwiaXRlcmF0aW9ucyI6IjEwMDAiLCJtaW5JdGVyYXRpb25zIjoiMTAwMCJ9fX0sInZlcnNpb24iOiIxLjAiLCJvcGVyYXRpb24iOiJGSU5JU0hfQVVUSCIsInByb3RvY29sIjoidWFmXzEuMCJ9",
"additionalInfo": {
"protocol": "uaf_1.0",
"authenticatorsResult": [
{
"handle": "WyJ1YWZfMS4wIiwiQUJDRCNBQkNEIiwiV09aYXh3bm9Ec1FzcXZjRVMyN3V0d0tWVEpubkNzdmpaV3p6TnNWaEpfUSJd",
"uvi": "jEw5SZNuD91hgRXtuVqVLsyngBa-kQg9FBkD_gQmUIE",
"uviStatus": 4,
"status": 4000,
"aaid": "ABCD#ABCD",
"authenticatorVersion": 1,
"appAtt": {
"state": "NOT_APPLICABLE"
},
"attachmentHints": [
"internal"
],
"metadata": {
"aaid": "ABCD#ABCD",
"description": "ABCD#ABCD description",
"authenticatorVersion": 1,
"userVerificationMethods": [
[
{
"userVerificationMethod": "passcode_internal"
}
],
[
{
"userVerificationMethod": "fingerprint_internal"
}
]
],
"keyProtection": [
"KEY_PROTECTION_TEE"
],
"multiDeviceCredentialSupport": "unsupported",
"matcherProtection": [
"MATCHER_PROTECTION_TEE"
],
"tcDisplay": [
"SECURE_DISPLAY_ANY"
],
"isKeyRestricted": true,
"isFreshUserVerificationRequired": true,
"attestationTypes": [
"basic_full"
]
}
},
{
"handle": "WyJ1YWZfMS4wIiwiQUJDRCMwMDAxIiwic2xUZEtBQ3pXQ2hLbTNrc1ZkWGk2aUdSY1hqU3hMd2xscTB3d0FiVXdYZyJd",
"status": 4400,
"aaid": "ABCD#0001",
"authenticatorVersion": 1
},
{
"handle": "WyJ1YWZfMS4wIiwiQUJDRCMwMDAyIiwiblVIdHFhRm5TTUhuN0RoMHFac1BHU0ZBdUNacmgybFNrU3EzbVNtY3FNWSJd",
"status": 4400,
"aaid": "ABCD#0002",
"authenticatorVersion": 1
}
],
"policyName": "default"
},
"statusCode": 4000
},
"statusHandle": "AAAAAAAAAAG2uZ-2LcWSd4jUYunEaPQuCZgrLL7HRJxxH1KN754_0Hi2bqUt2Ox2dMrx73u7lvC9OTo6XS1VPdg8JXwzkT8"
}
],
"ruleSetResult": {
"action": "TRIGGER_AUTHENTICATION",
"ruleSetName": "default",
"ruleName": "defaultRule",
"authSequenceId": "authenticationSequence_1",
"maxTimeAllowedInSeconds": 180
}
}Sample Webauthn Response Showing metadata when needDetails = 4. When the protocol is web, the response from a Quick Auth request includes metadata-specific information in the additionalInfo.metadata section.
{
"userNames": [
"user1"
],
"statusCode": 4000,
"id": "6J-1l6oqz9jJiaz9E8afJQ",
"additionalInfo": {
"device": {
"id": "123456789abcdef1234567890",
"type": "android",
"info": "NokNok Emulator",
"model": "NokNok-AE 7.0",
"os": "NokNokOS 7.0",
"manufacturer": "NokNok",
"supportsPlatformAuthenticator": true
},
"app": {
"id": "android:apk-key-hash:rDQ4Tn60fAvxP8thtp6sOh5ococ",
"name": "android:com.noknok.test.client",
"qrSupported": true
},
"extensions": [
{
"id": "noknok.ipaddress",
"data": "192.168.0.102",
"operation": "INIT_ADAPTIVE"
},
{
"id": "noknok.wifi.ssid",
"data": "Oviya",
"operation": "INIT_ADAPTIVE"
},
{
"id": "noknok.web.location",
"data": "{\"accuracy\":99.2,\"countryCode\":\"US\",\"latitude\":32.52,\"longitude\":-124.482,\"status\":0}",
"operation": "INIT_ADAPTIVE"
},
{
"id": "noknok.web.jailbreak",
"data": "{\n "status" : "0",\n "isJailbroken" : "false"\n}",
"operation": "INIT_ADAPTIVE"
}
],
"statusMessage": "Ok"
},
"completedMethods": [
{
"type": "FIDO Auth",
"name": "default",
"state": "SUCCEEDED",
"data": {
"message": "eyJzZXJ2ZXIiOnsiYXV0aGVudGljYXRvcnNSZXN1bHQiOlt7ImFhaWQiOiJBQkNEI0FCQ0QiLCJrZXlJRCI6IldPWmF4d25vRHNRc3F2Y0VTMjd1dHdLVlRKbm5Dc3ZqWld6ek5zVmhKX1EiLCJzdGF0dXMiOjQwMDB9LHsiYWFpZCI6IkFCQ0QjMDAwMSIsImtleUlEIjoic2xUZEtBQ3pXQ2hLbTNrc1ZkWGk2aUdSY1hqU3hMd2xscTB3d0FiVXdYZyIsInN0YXR1cyI6NDQwMH0seyJhYWlkIjoiQUJDRCMwMDAyIiwia2V5SUQiOiJuVUh0cWFGblNNSG43RGgwcVpzUEdTRkF1Q1pyaDJsU2tTcTNtU21jcU1ZIiwic3RhdHVzIjo0NDAwfV0sInByb3RvY29sTWVzc2FnZSI6Ilt7XCJoZWFkZXJcIjp7XCJ1cHZcIjp7XCJtYWpvclwiOjEsXCJtaW5vclwiOjB9LFwib3BcIjpcIkRlcmVnXCIsXCJhcHBJRFwiOlwiaHR0cHM6Ly8xMjcuMC4wLjE6ODQ0My9TYW1wbGVBcHBcIn0sXCJhdXRoZW50aWNhdG9yc1wiOlt7XCJhYWlkXCI6XCJBQkNEIzAwMDJcIixcImtleUlEXCI6XCJuVUh0cWFGblNNSG43RGgwcVpzUEdTRkF1Q1pyaDJsU2tTcTNtU21jcU1ZXCJ9LHtcImFhaWRcIjpcIkFCQ0QjMDAwMVwiLFwia2V5SURcIjpcInNsVGRLQUN6V0NoS20za3NWZFhpNmlHUmNYalN4THdsbHEwd3dBYlV3WGdcIn1dfV0iLCJhcHBJRCI6Imh0dHBzOi8vMTI3LjAuMC4xOjg0NDMvU2FtcGxlQXBwIiwibmV3T3BlcmF0aW9uIjoiREVMRVRFX1JFRyIsInF1aWNrQXV0aERhdGEiOnsia2V5TGVuZ3RoIjoxMjgsInZhbGlkaXR5U2Vjb25kcyI6MzAwLCJzYWx0U3VmZml4IjoieGZzbG1VU3l3RHBGYzlqUXFVR1pNdyIsImFsZ29yaXRobSI6eyJuYW1lIjoicGJrZGYyIiwiaXRlcmF0aW9ucyI6IjEwMDAiLCJtaW5JdGVyYXRpb25zIjoiMTAwMCJ9fX0sInZlcnNpb24iOiIxLjAiLCJvcGVyYXRpb24iOiJGSU5JU0hfQVVUSCIsInByb3RvY29sIjoidWFmXzEuMCJ9",
"additionalInfo": {
"protocol": "web_1.0",
"authenticatorsResult": [
{
"handle": "WyJ3ZWIiLCIwNjBiMmIwNi0wMTA0LTAxODItZTUxYy0wMTAxMDQwNDEyMDQiLCJOQThzOGQ3aHJ2NE9wdE5KSXJxY1pkR0Zkb3l4MUFZaDNqX3NRMWtLVFg4Il0",
"status": 4000,
"aaguid": "060b2b06-0104-0182-e51c-010104041204",
"attestationFormat": "packed",
"authenticatorVersion": 0,
"attestationType": 15880,
"credentialID": "NA8s8d7hrv4OptNJIrqcZdGFdoyx1AYh3j_sQ1kKTX8",
"attestationTypeName": "Self",
"attestationStatus": "SUCCESS",
"userPresence": true,
"userVerification": true,
"backUpEligible": true,
"backedUp": false,
"dpk": {
"state": "NOT_APPLICABLE"
},
"appAtt": {
"state": "NOT_APPLICABLE"
},
"attachmentHints": [
"internal"
],
"authenticatorAttachment": "platform",
"metadata": {
"aaguid": "060b2b0601040182e51c010104041204",
"description": "Generic webauthn authenticator",
"authenticatorVersion": 0,
"userVerificationMethods": [
[
{
"userVerification": 1,
"userVerificationMethod": "presence_internal"
}
]
],
"keyProtection": [
"KEY_PROTECTION_HARDWARE",
"KEY_PROTECTION_TEE"
],
"multiDeviceCredentialSupport": "unsupported",
"matcherProtection": [
"MATCHER_PROTECTION_TEE"
],
"tcDisplay": [
"SECURE_DISPLAY_ANY"
],
"isKeyRestricted": true,
"isFreshUserVerificationRequired": true,
"attestationType": [
"basic_full"
]
}
}
],
"policyName": "default"
},
"statusCode": 4000
},
"statusHandle": "AAAAAAAAAAG2uZ-2LcWSd4jUYunEaPQuCZgrLL7HRJxxH1KN754_0Hi2bqUt2Ox2dMrx73u7lvC9OTo6XS1VPdg8JXwzkT8"
}
],
"ruleSetResult": {
"action": "TRIGGER_AUTHENTICATION",
"ruleSetName": "default",
"ruleName": "defaultRule",
"authSequenceId": "authenticationSequence_1",
"maxTimeAllowedInSeconds": 180
}
}