Your app can receive an OOB request either by scanning a QR code or by receiving a push notification. This section describes how to customize the processing of this OOB request.
Customizing the appearance of a push notification
You can customize the appearance of the push notification that is sent for OOB authentication. The default appearance of the push notification is shown below.
New notification on an unlocked device |
New notification on a locked device |
The following image calls out the UI elements that you can modify. Modify the resources in the following table to update the icons and text shown.
.png?sv=2026-02-06&spr=https&st=2026-09-30T02%3A16%3A23Z&se=2026-09-30T02%3A30%3A23Z&sr=c&sp=r&sig=g%2FVnmd99CD312Qov%2FYJ3Ggs0CkJYPCnhuphUEJJZl5A%3D)
UI Element | Resource ID | Type |
|---|---|---|
Small icon | nnl_oobsdk_fido_icon_trans, nnl_oobsdk_fido_icon | Drawable resource |
Title | nnl_appsdk_plus_notification_default_title | String resource |
Message | nnl_appsdk_plus_notification_message | String resource |
Large icon | nnl_oobsdk_fido_lock_screen_notification_icon_trans | Drawable resource |
Customizing the behavior of OOB registration and authentication
You can customize the behavior of OOB registration and authentication. For example, you may need to log the fact that a user registers or authenticates using OOB. The AppSDK allows you to add code inside the start listener and the completion listener.
The start listener is called when an OOB message is received, before the SDK starts processing the OOB message. The start listener returns false to indicate that no further processing of the OOB message is required. The start listener returns true to continue message processing.
The completion listener is called when the OOB message processing is completed.
Working Example in Tutorial App
Refer to the definition of setStartListener and the definition of setCompletionListener inside the file TutorialAppPlus.kt.
Configuring push notification processing
You can configure how your app responds when it receives a push notification. The default behavior is described in the table below.
Circumstance | Default Processing |
|---|---|
App receives the notification when it is in the foreground | OOB processing is started immediately without posting notification. |
App receives the notification when it is in the background |
|
App receives the notification when it is in the foreground and the device is locked | OOB processing is started immediately after the user unlocks the device, even if the user did not click on the notification on the lock screen. |
App receives the notification when it is in the background and the device is locked |
|
The app's response to a push notification is controlled by the flag startOnNotification in the client configuration file, mfac_config.json. By default, this flag is true.
When you set startOnNotification to false in mfac_config.json, as shown below, the push notification is displayed in all 4 cases listed in the table above. This applies even when the app is in foreground. OOB authentication is started immediately, as described in rows 3 and 4, regardless of the value of this flag.
"startOnNotification": falseAny alternative response to a push notification requires implementing your own StartListener which could post a notification, silently start, or whatever it is needed. Contact Support if you need assistance.
Granting or denying camera permission
During QR code scanning, your app can display customized error messages or perform other functions to grant or deny a permission to use the camera. To accomplish this, implement your own onRequestPermissionsResult() method in your activity. An example onRequestPermissionsResult() is shown below:
/**
* This function needs to handle permission requesting callback
*/
@Override
public void onRequestPermissionsResult (int requestCode, String[] permissions,
int[] grantResults(){
// Check if the user granted the requested permission. Since only one permission
// is requested, only check the first element of the grantResults array.
if (grantResults.length > 0
&& grantResults[0] == PackageManager.PERMISSION_GRANTED) {
// Permission granted by the user, need to initialize ScannerFragment.
// Add your code here.
} else {
// Permission denied by the user.
// You could show an error screen or do any other UI change
// in this case finishing activity
}
}Customizing QR code scanner messages
You can customize the informational messages that are displayed when the camera that is used to scan a QR code turns on or off.
Implement the OobReceiver class's IScannerStateChangeListener to show informational messages or make other UI changes during QR code scanning. This interface has two functions:
switchOn(): Called when the device's camera is turned on to scan a QR code.
switchOff(): Called when the device's camera is turned off after the user scans the QR code or cancels scanning.
Working example in Tutorial app
Refer to file ScanCodeFragment.kt.
Enabling OOB authentication from the lock screen
When a device is locked, all authenticator UI screens are blocked by default. Because this could potentially interfere with a user’s ability to complete an OOB operation, Digipass S3 provides an option allowing the authenticator UI screens to be displayed on the lock screen.
In your activity’s onCreate() method, check if the device is already locked:
// Check whether the keyguard is currently locked.
KeyguardManager keyguardManager = (KeyguardManager) getSystemService(KEYGUARD_SERVICE);
if (keyguardManager.isKeyguardLocked()) { ... }If it is locked, then add the flags to display the authenticator UI on the lock screen:
// Set the flag when the lock screen is displayed.
final Window win = getWindow();
win.addFlags(WindowManager.LayoutParams.FLAG_SHOW_WHEN_LOCKED
|WindowManager.LayoutParams.FLAG_DISMISS_KEYGUARD);.png?sv=2026-02-06&spr=https&st=2026-09-30T02%3A16%3A23Z&se=2026-09-30T02%3A30%3A23Z&sr=c&sp=r&sig=g%2FVnmd99CD312Qov%2FYJ3Ggs0CkJYPCnhuphUEJJZl5A%3D)
.png?sv=2026-02-06&spr=https&st=2026-09-30T02%3A16%3A23Z&se=2026-09-30T02%3A30%3A23Z&sr=c&sp=r&sig=g%2FVnmd99CD312Qov%2FYJ3Ggs0CkJYPCnhuphUEJJZl5A%3D)