Apple and Google both have services that certify the integrity of apps that attempt to use the Digipass S3 Server to authenticate. Use Apple’s App Attest service and/or Google’s Play Integrity service to provide assurance that client apps connecting to the Auth Server are valid instances of your iOS or Android app. Apple App Attest and Google Play Integrity assert that the authenticator has attestation and that the app is legitimate. The Auth Server uses these two app integrity services for both registration and authentication. For more information, see Apple's App Attest documentation or Google’s Play Integrity documentation.
When considering whether or not to use these app integrity services, weigh the security requirements of your app against the processing overhead of using the service. If the app integrity service is fielding too many requests, it could throttle incoming traffic. Older Apple devices do not support App Attest, and older Android devices do not support Google Play Integrity, so evaluate the devices used by your customers.
To configure the Server to use Apple’s App Attest service and/or Google’s Play Integrity service, you need to do two things using the Server Admin Console:
Update an existing or create a new FIDO policy that checks the integrity of an app when registering or authenticating.
Configure the Server for your apps by entering the information that is required by the Apple App Attest and Google Play Integrity services.