Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Alternate step: configuring your proxy

Prev Next

If you replace the Digipass S3 API Server with your own proxy, you need to work around a limitation with how Android handles native FIDO2. Currently, FIDO2 on Android requires a non-empty allowCredentials during authentication, which means you need to supply the username of the person requesting authentication. See the W3 Web Authentication documentation for an explanation of allowCredentials.

A recommended solution is to pass the username when you initiate authentication. When you call the Digipass S3 Server’s INIT_AUTH or INIT_ADAPTIVE operations, send the user name in the payload using the attribute userName. The user must have existing registrations. The Auth Server automatically populates allowCredentials with the public key credentials for all the user’s registered authenticators. For more information about INIT_AUTH and INIT_ADAPTIVE operations, see Adaptive authentication in the reference to the REST API.