Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Configuring an iOS App

Prev Next

Use the Admin Console to configure your iOS App. The Admin Console also updates the trusted facets list at the same time.

Step 1. Login to the Admin Console and, if needed, switch to the desired tenant. Navigate to Configuration > Apps.

The Apps page appears. Find your app in the list and either click its name or the Modify icon at the end of its row. If your app is not in the list yet, click the blue Add App button, select the iOS radio button and click Add.

The App page appears.

Step 2. Enter the app’s package name in Package Name/URL. This name cannot be changed later. Also enter the App Name which is used for display purposes here in the Admin Console.

Step 3. If you want your app to use the FIDO UAF protocol, make sure that you have already completed the UAF Configuration on the Server. Then you need to find and enter the UAF facet ID.

Find the facet ID which is the URI that contains the bundle ID of the app. This is written as ios:bundle-id:<ios-bundle-id-of-app>. A bundle ID uniquely identifies an app in Apple’s ecosystems. For example, the facet ID for the included Tutorial App is ios:bundle-id:com.noknok.ios.tutorialappplus.

  1. On the App page in the Admin console, toggle on FIDO UAF and enter its facet ID in FIDO UAF Facet ID.

  2. If your implementation uses a remote, standalone UAF FIDO client, then update facets.uaf.

Step 4. If you want your app to use the FIDO2/WebAuthn protocol, first complete the FIDO2 Configuration on the Server. Then you need to find and enter the FIDO2 facet ID, which is the same as the UAF facet ID.

Find the facet ID which is the URI that contains the bundle ID of the app. This is written as ios:bundle-id:<ios-bundle-id-of-app>. A bundle ID uniquely identifies an app in Apple’s ecosystems. For example, the facet ID for the included Tutorial App is ios:bundle-id:com.noknok.ios.tutorialappplus.

  1. On the App page in the Admin console, toggle on FIDO2/WebAuthn.

  2. Enter the app’s facet ID in FIDO2 Facet ID.

  3. Make sure that your app is listed in your associated domain file: apple-app-site-association. See Apple's documentation on supporting associated domains for more information.

Step 5. If your app uses Apple App Attest, enter your Team ID. For more information about App Attest, see Support app integrity.

Step 6. You can optionally assign an Adaptive Ruleset that this app uses. Select the ruleset's name from the Adaptive Ruleset dropdown. For more information, see Configure Adaptive Rulesets.

Step 7. If your app uses OOB authentication, you can set this up now. For more information, see Configuring Out-of-band Authentication.

Step 8. If the package name changed, enter the previous package name into Old Package Names. If the package name changed multiple times, enter all previous package names separated by commas.

The Auth Server uses the package name to uniquely identify an app. The Server uses Old Package Names to consolidate what would otherwise be duplicate information for the app.

Step 9. Save your changes. Verify that the facet ID was added correctly to the server database by performing a client registration operation using the protocols that you configured. If the application facet ID was not correctly added to the database, user registration fails with error 4402.