Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Create an External Authentication Plugin

Prev Next

Introduction

When an end user needs to verify their identity with an External Authentication Method, one of your company servers, not the Nok Nok Authentication Server, authenticates the end user. This section refers to this company server as the RP Server.

When the App SDK receives a request for authentication using an External Authentication Method, your app sends the user verification data to your RP server. On successful user verification, your RP Server must return a credential. The Nok Nok JWT External Authentication plugin can validate this credential only if it is a JWT with standard claims. If your RP Server cannot return such a JWT, then Nok Nok's JWT External Authentication plugin won't work for you. If the user verification data is username and password, then you can use a Password External Authentication method. Otherwise, you must create a custom External Authentication plugin to validate the credential that your RP Server returns. The rest of this section describes how to create a custom External Authentication plugin.

Figure 10 External Authentication

Your custom External Authentication plugin is a class that implements Nok Nok's ISessionManager interface. Your ISessionManager class only needs to implement the onVerifyRequest() method. Your ISessionManager class can optionally implement the onResponse() method. Any other methods are ignored. The API Server calls your onVerifyRequest() method when it receives either a VERIFY or an INIT_ADAPTIVE request, then it calls your onResponse() method when the processing of the request is complete.

For information about building and deploying custom API Server plugins, see Create a plugin.