When an end user needs to verify their identity with a Password External Authentication Method, one of your company servers, not the Digipass S3 Server, authenticates the end user. This section refers to this company server as the RP Server.
How a password external authentication method works
Let's assume that you have implemented user ID and password as a Password External Authentication Method. Figure 7b illustrates how Digipass S3 Software interacts with your RP Server when an end user wants to authenticate.
.png?sv=2026-02-06&spr=https&st=2026-09-30T02%3A11%3A36Z&se=2026-09-30T02%3A23%3A36Z&sr=c&sp=r&sig=jFddREIlMqnqhjQS8VZf7ZO49oL1Knn4pA6B1fjA0aU%3D)
Figure 7b Digipass S3 Interaction with RP Server during Password External Authentication
Using your client app, the end user decides to login with their ID and password.
Your client app interacts with the Digipass S3 App SDK to send the ID and password to the Digipass S3 API Server.
The Digipass S3 API Server uses the Password External Authentication plugin to interact with the RP Server.
The RP Server authenticates the user and returns success to the Digipass S3 API Server.
The Digipass S3 API Server sends a request to the Auth Server for a response.
The Digipass S3 Auth Server creates a response intended for the App SDK and sends that to the API Server.
The API Server sends the response to the App SDK.
Configuration instructions
Implementing a Password External Authentication Method requires that you make changes to your client app, implement a REST API in your RP Server that verifies username and password, configure the Password External Authentication plugin to use that REST API, and configure the Password External Authentication method in the Auth Server so it can be used in an Adaptive Rule. This process is described in detail below.
Identify the RP Server that will authenticate the username and password.
Add support in your client app for the Password External Authentication Method by implementing specific classes. These classes in your client app display the UI if needed and send the username and password to the Password External Authentication plugin in the Digipass S3 API Server. See Using an External Authentication Method in the Developer Guide for Android, iOS or Web.
Implement a REST API in your RP Server to verify the username and password. The JSON payload for the password verification endpoint has the following attributes:
Request Attribute | Description |
|---|---|
userName | Required. The username to verify. |
password | Required. The password to verify. |
apikey | Optional. API Key to authenticate the caller. |
Response Attribute | Description |
|---|---|
status | Required. The verification status. Must be either "SUCCESS" or "FAILURE". |
message | Conditional. Must be present if the status is "FAILURE". The reason for the verification failure. |
Configure the Password External Authentication plugin to call the REST API in your RP Server to validate the username and password. See the Password External Authentication Plugin configuration for more details.
Define the External Authentication Method in the Authentication Server. See Add a New Non-FIDO Authentication Method. Digipass S3 Software ships with an External Authentication method that you can use.
To use an External Authentication Method during Adaptive Authentication, add the External Authentication Method to the sequence of a new or existing Adaptive Authentication rule. See Step 5D. Enter Sequences.
To use the method for Quick Authentication, modify how your client app performs registration and authentication. See Registering for FIDO Quick Authentication in the Developer Guide for Android, iOS or Web. Also see Implementing Quick Authentication in the Developer Guide for Android, iOS or Web.