Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

FIDO registration

Prev Next

URL: /nnlgateway/nnl/<tenant_id>/reg Method: POST


Digipass S3 Authentication Software provides operations under the /nnlgateway/nnl/<tenant_id>/reg endpoint to manage user registrations that are performed entirely on one device, like a cell phone. Using these operations you can initiate registration, complete registration, and update a registration. The following operations are available:

API Server uses its policy plugin's configuration object, default_config, to determine the FIDO policy to use for a REST API operation that registers. An example default_config is shown below. For details about default_config, see Create a Policy Plugin.

{
    "registration_policy_name":"AcmeRegistration",
    "app_specified_policies":{
        "policy_type_mappings":{
            "VerySecurePolicy":"AcmeVerySecure",
            "QuickAuthPolicy":"AcmeQuickAuth"
        }
    }
}

To determine the FIDO policy to use for registration, the API Server does the following:

  1. IF the request contains a value for optionsData.policyType THEN use that to retrieve the FIDO policy name from default_config.app_specified_policies.policy_type_mappings.<policyType>.

    As an example, let's use the default_config above. If optionsData.policyType = "VerySecurePolicy" then the API Server passes the FIDO policy name "AcmeVerySecure" to the Authentication Server.

  2. ELSEIF there is a value for default_config.registration_policy_name, THEN retrieve use that as the FIDO policy.

    Using the example above, this is "AcmeRegistration".

  3. ELSE use the FIDO policy named "default".

To perform FIDO registration, the Authentication Server uses the registration policy to determine the valid UAF and FIDO2 authenticators that can be used. For UAF authenticators, the Auth Server refers to the allowed UAF authenticators specified by the FIDO policy and device information to create a list of permitted UAF authenticators that the user could register.

For FIDO2 authenticators, the Auth Server compares the authenticator's characteristics to the desired FIDO2 authenticator characteristics specified by the registration policy. The client uses these as hints to prompt the end user for the authenticator. The Auth Server enforces user verification and attestation preference during FINISH_REG based on the FIDO policy configuration. If you have not configured the registration policy for FIDO2 authenticators, then INIT_REG fails with a 4403 when a web app tries to register a FIDO2 authenticator.

Refer to Configure Adaptive Rulesets to see how to create a registration policy.

Because there can be many end users registering simultaneously, the Server needs to correlate INIT_REG and FINISH_REG with a particular user. It does this using the id attribute.

Depending on the operation, you can also get information about the device initiating the registration, the authentication protocol used by the Server, and the policy used to validate the operation.

INIT_REG

Initiates the registration process for a FIDO authenticator.

Request

Attribute

Description

operation

Required. The string INIT_REG.

callerOrigin

Required if a web app is sending the request and that app has a different origin than the Digipass S3 API Server. A web origin is defined by the scheme (protocol), host (domain), and port of the URL used to access it.

The API Server checks if this origin is listed in its origin allow list, if not, the request is rejected. See My Web Apps Have a Different Origin.

id

Optional. The correlation ID, a unique identifier that associates INIT_REG and FINISH_REG operations for the same user. An alphanumeric string, maximum 255 characters. No special characters are allowed.

If not provided, the Server generates a unique id and returns it in the response.

locale

Optional. Used by the Auth Server to retrieve the locale-specific name for the authenticator from its metadata statement. An IETF BCP 47 language tag string, like en-US.

message

Required. Generated by the App SDK on the client. This is an opaque value. The client app is responsible for sending message. This is a base64-URL encoded string.

optionsData

Optional. An object used to pass additional attributes to REST API operations. See OptionsData for a complete description.

sessionData

Required. An object containing the user's session information. See SessionData.

Response

The following attributes are always present in the JSON payload of the response.

Attribute

Description

id

The unique id that correlates INIT_REG and FINISH_REG operations for the same user.

If id was sent in the request, the same id is returned. If not, a server-generated ID is returned. If id was provided in the REST payload but the server was unable to parse the payload, the value is unknown.

statusCode

Server-specific status code that reports the success or failure of the requested operation. See Response Status Codes below for the codes.

The following attributes are present in the response upon a successful operation (Server status code 4000).

Attribute

Description

additionalInfo

An object containing information about the client app and device initiating registration. Contains the 4 attributes listed in the rows below.

In order for the API Server to return this information:

  1. The client app must have sent device, protocol, and extension information in the INIT_REG request message attribute.

  2. Update the response filter configuration so the API Server returns the elapsed time for the request, protocol, and payload extensions.

    By default, device information is automatically returned. Refer to Response Filter Configuration.

additionalInfo.device

A DeviceDetail object containing information about the device that issued the INIT_REG request, such as the device’s unique ID, model, and manufacturer.

additionalInfo.elapsedTime

Amount of time, in milliseconds, that has elapsed while processing the request.

additionalInfo.extensions

Information about the initiating device’s location and jailbreak status. List<Extension>.

additionalInfo.protocol

The protocol used by the Authentication Server based on information from the request. String. One of UAF or Web.

lifetimeMillis

Lifetime of message in milliseconds. Long.

Your client or web app can use this to tell a user how much time they have to respond to the challenge or warn the user that the Server does not accept a response once lifetimeMillis has expired.

message

Opaque value that contains the challenge exchanged between the Server and the App SDK. A base64-URL encoded string.

message must be sent to the App SDK.

Response Status Codes

The following are the descriptions of the Auth Server status codes returned by INIT_REG. Under certain circumstances, the API Server returns an unsuccessful HTTP status code. Examples include an invalid request or invalid session. You can find descriptions of these in API Server Status Codes.

Server Status Code

Description

Examples

4000

OK. Operation completed

Request was successfully created.

4402

Security exception

policyName does not exist in the Server.

tenantID does not exist in the Server.

4403

PolicyVerificationException

Requested policy is not available on the Server.

4404

Internal Server Error

Internal server error.

Failed to read from the database.

Failed to connect to the database.

Failed to read required properties.

4406

Payload Exception

An error occurred with one or more attributes. For example, message is an invalid type.

4408

UnsupportedClient MessageException

The message attribute cannot be handled.
The client does not support the UAF/FIDO2 protocol. Or the protocol is missing.

4409

ClientMessageException

The message attribute is invalid (for example, a JSON syntax error). The message attribute from the App SDK is malformed (base64URL decode failed).

Samples

Sample Request URL

https://www.example.com:8443/nnlgateway/nnl/<tenant_id>/reg

Sample request

{
    "operation":"INIT_REG",
    "sessionData":{
        "sessionKey":"<session JWT>"
    },
    "id":"sample",
    "message":"<base64url-encoded-data>"
}

Sample UAF-protocol response

A developer updated the response filter configuration so the API Server returns the FIDO protocol and the elapsed time for the request in additionalInfo.

{
    "id":"dEgViadKjxcleujKbpfi6g",
    "statusCode":4000,
    "lifetimeMillis":300000,
    "message":"<base64url-encoded-data>",
    "additionalInfo":{
        "protocol":"uaf_1.0",
        "device":{
            "id":"123456789abcdef1234567890",
            "type":"android",
            "info":"OneSpan device"
        },
        "elapsedTime":38
    }
}

Sample FIDO2-protocol response

A developer updated the response filter configuration so the API Server returns the protocol and client app information in additionalInfo.

{
    "statusCode":4000,
    "additionalInfo":{
        "device":{
            "info":"my iPhone",
            "model":"iPhone 13 Pro",
            "os":"iOS 15",
            "manufacturer":"Apple",
            "id":"abcdef12345ghijkl",
            "type":"ios"
        },
        "app":{
            "name":"Passport",
            "id":"com.noknok.ios.passport"
        },
        "protocol":"web_1.0",
        "elapsedTime":38
    },
    "lifetimeMillis":300000,
    "message":
"eyJzZXJ2ZXIiOnsibm5sRGF0YSI6IlpkNVpxRjN2TTVzcHVfbE9BZ0M0MFNnNG5leDhqci1qNjJ3aDctRm9zTE5MejRuNDJoY2tFT2l3QjlJZ3pEUnFHUVdyZnB1VG9aT0h1blBheDZxU3Q4YVZIcXloWXFPeFRWRUxSaFRfVk9ySVRYLUNGS2dkemxaTDFUSm1kajQwWDZYdXNRQnZWMFgxczhWakFEU051S0I1ZUJxSFZaTzFVU2NhdWliS2J2QmNMNTcyNG0tZnBORU9jdyJ9LCJwcm90b2NvbE1lc3NhZ2UiOiJ7XCJvcHRpb25zXCI6e1wicnBcIjp7XCJpZFwiOlwicWEtaGVtYW50Lm5va25va3Rlc3QuY29tXCIsXCJuYW1lXCI6XCJERUZBVUxUX1RFTkFOVFwifSxcInVzZXJcIjp7XCJpZFwiOlwid2ViX1RDNjE2MVwiLFwiZGlzcGxheU5hbWVcIjpcIndlYl9UQzYxNjFcIixcIm5hbWVcIjpcIndlYl9UQzYxNjFcIn0sXCJjaGFsbGVuZ2VcIjpcIjgrYzNVeHJCa0FreGFaeURqSTlCQUV6TGNSQlI0ZHhXZkpYblVUTFhrQXNcXHUwMDNkXCIsXCJwdWJLZXlDcmVkUGFyYW1zXCI6W3tcImFsZ1wiOi03LFwidHlwZVwiOlwicHVibGljLWtleVwifSx7XCJhbGdcIjotMjU3LFwidHlwZVwiOlwicHVibGljLWtleVwifV0sXCJ0aW1lb3V0XCI6MzAwMDAwLFwiYXV0aGVudGljYXRvclNlbGVjdGlvblwiOnt9fSxcInNlcnZlckRhdGFcIjpcImtubGMwUkNMVjgyNlhBNnJyVzNmTEV0RXp1WEJ3UEtKaVlsWkNnOFFKbDJsT0htekdQUXRwQkFXMTk1bk5kWjJxTHB6RTRxSEVfa2pqQWxnSC1vOFVSSmxaUGRCLWpuYkdDMjRYOWtTLTlnb204NnMxUUxrOGhNTUU4MzI1dzA4RWFjQkNaNjJ2RE5yMzl4MWR2QVFCSENPSGt3eXpZQWVyRk1wc29QVFo3X3Y3eDVFajRPbk1BXCJ9IiwidmVyc2lvbiI6IjEuMCIsIm9wZXJhdGlvbiI6IklOSVRfUkVHIiwicHJvdG9jb2wiOiJ3ZWJfMS4wIn0",
    "id":"25XOAKx9BAWlF16iuki3VQ"
}

FINISH_REG

Processes the registration response provided by the caller and completes the registration process. Assigns authenticatorName, if provided, as the registered authenticator's name.

The Server uses the allowed authenticators specified by the default registration policy and device information to verify whether the user's selected authenticator should be registered. If the registration policy has any optional post operation rules defined, these are also evaluated to allow or deny registration.

Request

Attribute

Description

operation

Required. The string FINISH_REG.

authenticatorName

Optional.The name of the authenticator. An alphanumeric string, max 128 characters.

callerOrigin

Required if a web app is sending the request and that app has a different origin than the Digipass S3 API Server. A web origin is defined by the scheme (protocol), host (domain), and port of the URL used to access it.

The API Server checks if this origin is listed in its origin allow list, if not, the request is rejected. See My Web Apps Have a Different Origin.

channelBinding

Optional. Channel binding data available from the TLS endpoint. A ChannelBinding object.

message

Required. Generated by the App SDK on the client. This is an opaque value. The client app is responsible for sending message. This is a base64-URL encoded string.

optionsData

Optional. An object used to pass additional attributes to REST API operations. See OptionsData for a complete description.

sessionData

Required. An object containing the user's session information. See SessionData.

Response

The following attributes are always present in the JSON payload of the response.

Attribute

Description

id

The unique id that correlates INIT_REG and FINISH_REG operations for the same user.

statusCode

Server-specific status code that reports the success or failure of the requested operation. See Response Status Codes below for the status and error codes. Integer.

The following attributes are present in the response upon a successful operation (Server status code 4000).

Attribute

Description

additionalInfo

An object containing information about the client app and device initiating the registration. Contains the attributes listed in the rows below.

In order for the API Server to return this information,

  1. The client app must have sent device, policy, and extension information in the FINISH_REG request’s message attribute

  2. Update the response filter configuration so the API Server returns additional authenticator details, elapsed time for the operation, extension information, policy name, the protocol, and/or post operation rule results.

    By default, the API Server automatically returns device information, authenticator handles, and authenticator attachment hints. Refer to Response Filter Configuration.

additionalInfo.authenticatorsResult

The authenticator (like fingerprint) that the user registered. If registration failed, this is the authenticator that failed. A List<AuthenticatorResult>. There is typically only one entry.

additionalInfo.device

A DeviceDetail object containing information about the device that issued the FINISH_REG request, such as the device’s unique ID, model, and manufacturer.

additionalInfo.elapsedTime

The number of milliseconds that has elapsed while processing the request.

additionalInfo.extensions

Information about a device’s location and jailbreak status. A List<Extension>.

additionalInfo.headerExtensions

Protocol-specific header extensions. List<HeaderExtension>

additionalInfo.policyName

FIDO registration policy name used for the operation. String.

additionalInfo.protocol

The protocol used by the Authentication Server based on information from the request. String. One of UAF or Web.

additionalInfo.rulesResult

RulesResult populated as a result of post operation rules processing giving out the matched rules details. RulesResult.

message

Information exchanged between the Server and the App SDK. A base64-URL encoded string.

Response status codes

The following are the descriptions of the Auth Server status codes returned by FINISH_REG. Under certain circumstances, the API Server returns an unsuccessful HTTP status code. Examples include an invalid request or invalid session. You can find descriptions of these in API Server Status Codes.

Server Status Code

Description

Examples

4000

OK. Operation completed

Registration completed successfully.

4002

  • OK. Optional security checks failed per lenient policy

  • U2F USB token is used and the token does not have an associated metadata of its own

This status code is returned in the response for a Lenient Web Authentication policy or failure to meet policy requirements, such as attestation, user verification, and so on.

4401

Challenge Expired

Exception

The INIT_REG request challenge expired.

4402

Security Exception

Failed to validate the attestation.

Failed to validate Server challenge

Failed to validate the Server data.

Failed to locate authenticator metadata.

Challenge replay detected.

Failed due to revoked certificate.

Failed to validate Android Key Attestation extension.

Required Android Key Attestation extension is missing.

4403

Policy Exception

Failed to match policy.

Policy not supported.

Failed to register because the maximum number of configurable registrations for each user has been reached.

4404

Internal Server Error

Internal server error.

Failed to write to the database.

Failed to read from the database.

Failed to connect to the database.

Failed to read required properties.

4406

Payload Exception

An error occurred with one or more attributes. For example, message is an invalid type or the username extracted from sessionData.sessionKey has an invalid length.

4408

Unsupported ClientMessageException

The message attribute cannot be handled.

The client does not support UAF/FIDO2 protocol. Or the protocol is missing.

4409

ClientMessageException

The message attribute is invalid (for example, a JSON syntax error). The message attribute from the App SDK is malformed (base64URL decode failed).

Samples

Sample request URL

https://www.example.com:8443/nnlgateway/nnl/<tenant_id>/reg

Sample Request

{
    "operation":"FINISH_REG",
    "sessionData":{
        "sessionKey":"<session JWT>"
    },
    "message":"<base64url-encoded-data>"
}

Sample UAF-protocol response

A developer updated the response filter configuration so the API Server returns the protocol, the elapsed time for the request, FIDO policy used, additional authenticator details, and post operation rule results in additionalInfo.

{
  "message":"<base64url-encoded-data>",
  "id":"dEgViadKjxcleujKbpfi6g",
  "statusCode":4000,
  "additionalInfo":{
    "protocol":"uaf_1.0",
    "policyName":"reg_policy",
    "elapsedTime":25,
    "authenticatorsResult":[
      {
        "handle":
"WyJ1YWZfMS4wIiwiQUJDRCNBQkNEIiwiT1QzN2E5bUpkQ2s4Q0lBbG05eUFZNGJybXA1ME9nZGgyTXJEVWxTeUFjRSJd",
        "status":4000,
        "attestationType":15879,
        "uvi":"NwzJQXezm0gQeLn_kzaahxUGiC8FYqxYn-xqDSgyKyg",
        "uviStatus":4,
        "aaid":"ABCD#ABCD",
        "authenticatorVersion":1
      },
      {
        "handle":
"WyJ1YWZfMS4wIiwiQUJDRCMwMDEzIiwiSDhUM2t2cWFob1k1MWRwVEZFNzIwOUpyWDBZYWw3aDBBa0VPVkpPRXdOUSJd",
        "status":4000,
        "attestationType":15879,
        "uvi":"dVFPwbfp8fbcA2KK87yBsPm5fMX_hTulEFnnHrreKlY",
        "uviStatus":4,
        "aaid":"ABCD#0013",
        "authenticatorVersion":1
      }
    ],
    "device":{
      "id":"dID_91361a29-16ae-45f3-b0cc-922ba82e929e_16",
      "type":"android",
      "info":"OneSpan's device"
    },
    "rulesResult":{
      "matchedRules":[
        {
          "name":"LocationCheck",
          "template":"LocationCheck",
          "group":"location",
          "riskScore":60
        },
        {
          "name":"LocationUnknown",
          "template":"LocationUnknown",
          "group":"location",
          "riskScore":40
        }
      ],
      "riskThresholdRule":{
        "aboveThreshold":false,
        "riskScore":60,
        "threshold":80
      },
      "action":"ALLOW"
    }
  }
}

Sample Web-protocol response

A developer updated the response filter configuration so the API Server returns app information, additional authenticator details, protocol, and the elapsed time for the request in additionalInfo.

{
  "statusCode":4000,
  "additionalInfo":{
    "device":{
      "info":"Google Chrome on Windows",
      "os":"Windows 10",
      "id":"35da57bd-dcb6-4529-9f00-8eea5c0cea00",
      "type":"browser"
    },
    "app":{
      "name":"https://<server>.noknoktest.com/gwtutorial/",
      "id":"https://<server>.noknoktest.com",
      "qrSupported":true
    },
    "authenticatorsResult":[
      {
        "authenticatorVersion":0,
        "aaguid":"abcdef12-3456-7890-abcd-ef1234567890",
        "attestationFormat":"packed",
        "attachmentHints": ["internal"],
        "authenticatorAttachment": "platform",
        "credentialID":"RS3tw2_bsJFyMQMdMMk4pAKRgt_3voYyrRmm5ACzyhc",
        "status":4000,
        "handle":"WyJ3ZWIiLCJhYmNkZWYxMi0zNDU2LTc4OTAtYWJjZC1lZjEyMzQ1Njc4OTAiLCJSUzN0dzJfYnNKRnlNUU1kTU1rNHBBS1JndF8zdm9ZeXJSbW01QUN6eWhjIl0"
      }
    ],
    "protocol":"web_1.0",
    "elapsedTime":25
  },
  "message":"eyJzZXJ2ZXIiOnsiYXV0aGVudGljYXRvcnNSZXN1bHQiOlt7InN0YXR1cyI6NDAwMH1dLCJhcHBJRCI6InFhLXZqb3NoaS5ub2tub2t0ZXN0LmNvbSJ9LCJ2ZXJzaW9uIjoiMS4wIiwib3BlcmF0aW9uIjoiRklOSVNIX1JFRyIsInByb3RvY29sIjoid2ViXzEuMCJ9",
  "id":"4-_llfQ14DaBdeDIeWyVMw"
}

Sample web-protocol response that includes an AppAttest object

A developer updated the response filter configuration so the API Server returns the protocol, elapsed time, additional authenticator details, post operation rule results, and client app information in additionalInfo.

{
  "statusCode":4000,
  "id":"36AB3FD9-D5F7-40C1-9D9F-A11D1F9FFDFD",
  "message": "eyJzZXJ2ZXIiOnsiYXV0aGVudGljYXRvcnNSZXN1bHQiOlt7InN0YXR1cyI6NDAwMH1dLCJhcHBJRCI6InN0LW15c3FsLm5va25va3Rlc3QuY29tIn0sInZlcnNpb24iOiIxLjAiLCJvcGVyYXRpb24iOiJGSU5JU0hfUkVHIiwicHJvdG9jb2wiOiJ3ZWJfMS4wIn0",
  "additionalInfo":{
    "device":{
      "id": "AD5D2029-383A-47FE-BF80-DF133A9E0221",
      "type":"ios",
      "info":"iPhone",
      "model":"iPhone13,1",
      "os":"iOS 16.4.1",
      "manufacturer":"Apple",
      "supportsPlatformAuthenticator":true
    },
    "protocol":"web_1.0",
    "elapsedTime":30,
    "authenticatorsResult":[
      {
        "handle": "WyJ3ZWIiLCIwMDAwMDAwMC0wMDAwLTAwMDAtMDAwMC0wMDAwMDAwMDAwMDAiLCJJaUw2TzFEcDNZNTdLZlJXdzVVNHM4WDBNSW8iXQ",
        "authenticatorName":"iPhone authenticator",
        "status": 4000,
        "aaguid": "00000000-0000-0000-0000-000000000000",
        "attestationFormat":"none",
        "authenticatorAttachment":"cross-platform",
        "authenticatorVersion":0,
        "credentialID":"IiL6O1Dp3Y57KfRWw5U4s8X0MIo",
        "attestationStatus":"UNAVAILABLE",
        "userPresence":true,
        "userVerification":true,
        "backUpEligible":true,
        "backedUp":true,
        "dpk": {
          "state": "NOT_APPLICABLE"
        },
        "appAtt": {
          "state": "TRUSTED",
          "handle": "WyJ3ZWIiLCI2MTcwNzA2MS03NDc0LTY1NzMtNzQ2NC02NTc2NjU2YzZmNzAiLCJJdVJmRGUyWHRkYjVaaFBjNW9aU3lYalphRGJZUGZCS1dpaUJyaklMZEw0IiwiV3lKM1pXSWlMQ0l3TURBd01EQXdNQzB3TURBd0xUQXdNREF0TURBd01DMHdNREF3TURBd01EQXdNREFpTENKSmFVdzJUekZFY0ROWk5UZExabEpYZHpWVk5ITTRXREJOU1c4aVhRIl0",
          "authenticatorName": "iPhone",
          "aaguid": "61707061-7474-6573-7464-6576656c6f70",
          "attestationFormat": "apple-appattest",
          "authenticatorVersion": 0,
          "credentialID": "IuRfDe2Xtdb5ZhPc5oZSyXjZaDbYPfBKWiiBrjILdL4",
          "userPresence": false,
          "userVerification": false,
          "backUpEligible": false,
          "backedUp": false,
          "attachmentHints": [
            "internal"
          ]
        },
        "attachmentHints": [
          "internal"
        ]
      }
    ],
    "app": {
      "id":"ios:bundle-id:com.noknok.ios.tutorialappplus",
      "name":"ios:com.noknok.ios.tutorialappplus",
      "qrSupported":true
    }
  }
}

Sample request with authenticatorName

{
    "operation":"FINISH_REG",
    "sessionData":{
        "sessionKey":"<session JWT>"
    },
    "authenticatorName":"sampleAuthenticatorName",
    "message":"<base64url-encoded-data>"
}

Sample UAF-protocol response with authenticatorName

{
  "statusCode":4000,
  "id":"OgpQAW37Blt7xtrAIwzheQ",
  "message":
"eyJzZXJ2ZXIiOnsiYXV0aGVudGljYXRvcnNSZXN1bHQiOlt7ImFhaWQiOiJBQkNEI0FCQ0QiLCJrZXlJRCI6IlNPcHdPb1NUN1BnX1hKZWo2RUtnc1NPOE5xVE01NGFkeF9Cdk83LXUteVEiLCJzdGF0dXMiOjQwMDB9XSwiYXBwSUQiOiJodHRwczovLzEyNy4wLjAuMTo4NDQzL1NhbXBsZUFwcCJ9LCJ2ZXJzaW9uIjoiMS4wIiwib3BlcmF0aW9uIjoiRklOSVNIX1JFRyIsInByb3RvY29sIjoidWFmXzEuMCJ9",
  "additionalInfo":{
    "device":{
      "id":"123456789abcdef1234567890",
      "type":"android",
      "info":"NokNok Emulator",
      "model":"iphone12",
      "os":"NokNokOS 8.0",
      "manufacturer":"NokNok"
    },
    "protocol":"uaf_1.0",
    "elapsedTime":25,
    "authenticatorsResult":[
      {
        "authenticatorName":"sampleAuthenticatorName",
        "handle":
"WyJ1YWZfMS4wIiwiQUJDRCNBQkNEIiwiU09wd09vU1Q3UGdfWEplajZFS2dzU084TnFUTTU0YWR4X0J2TzctdS15USJd",
        "uvi":"kHLOfu85VmwlUwj6XB8R8wt6HXyWTnzlcSDRUabKovA",
        "uviStatus":4,
        "status":4000,
        "aaid":"ABCD#ABCD",
        "authenticatorVersion":1,
        "attestationType":15879,
        "attestationTypeName":"full-basic-attestation"
      }
    ],
    "policyName":"default",
    "rulesResult":{
      "action":"ALLOW",
      "matchedRules":[
        {
          "name":"LocationVelocity",
          "riskScore":0,
          "template":"DummyRule",
          "group":"dummy group"
        }
      ]
    },
    "app":{
      "id":"android:apk-key-hash:rDQ4Tn60fAvxP8thtp6sOh5ococ",
      "name":"android:com.noknok.test.client"
    },
    "extensions":[
      {
        "id":"noknok.ipaddress",
        "data":"1.2.3.4",
        "operation":"FINISH_REG"
      },
      {
        "id":"noknok.wifi.ssid",
        "data":"Oviya",
        "operation":"FINISH_REG"
      },
      {
        "id":"noknok.wifi.ssid",
        "data":"Oviya",
        "operation":"INIT_REG"
      },
      {
        "id":"noknok.uaf.location",
        "data":
"{\"accuracy\":99.2,\"countryCode\":\"IN\",\"latitude\":32.52,\"longitude\":-124.482,\"status\":0}",
        "operation":"FINISH_REG"
      },
      {
        "id":"noknok.uaf.location",
        "data":
"{\"accuracy\":99.2,\"countryCode\":\"IN\",\"latitude\":32.52,\"longitude\":-124.482,\"status\":0}",
        "operation":"INIT_REG"
      },
      {
        "id":"noknok.ipaddress",
        "data":"1.2.3.4",
        "operation":"INIT_REG"
      },
      {
        "id":"noknok.uaf.jailbreak",
        "data":"{\n  \"status\" : \"0\",\n  \"isJailbroken\" : \"unknown\"\n}",
        "operation":"FINISH_REG"
      },
      {
        "id":"noknok.uaf.jailbreak",
        "data":"{\n  \"status\" : \"0\",\n  \"isJailbroken\" : \"unknown\"\n}",
        "operation":"INIT_REG"
      }
    ]
  }
}

Sample UAF-protocol Response showing metadata when needDetails = 4. When the protocol is UAF, the response includes metadata-specific information in the additionalInfo.authenticatorsResult.metadata section.

{
    "statusCode": 4000,
    "id": "wVy6Rs-oGLoMI31Zw_oqOg",
    "message": "eyJzZXJ2ZXIiOnsiYXV0aGVudGljYXRvcnNSZXN1bHQiOlt7ImFhaWQiOiI0ZTRlI2FiY2QiLCJrZXlJRCI6IlFSLUZDNWRsbGE0eW1yRkE5d1FhVkY5MkFGZG5DeUp3dGhXcS1NOHlzNzgiLCJzdGF0dXMiOjQwMDB9XSwiYXBwSUQiOiJodHRwczovLzEyNy4wLjAuMTo4NDQzL1NhbXBsZUFwcCJ9LCJ2ZXJzaW9uIjoiMS4wIiwib3BlcmF0aW9uIjoiRklOSVNIX1JFRyIsInByb3RvY29sIjoidWFmXzEuMCJ9",
    "additionalInfo": {
        "device": {
            "id": "123456789abcdef1234567890",
            "type": "android",
            "info": "NokNok Emulator",
            "model": "NokNok-AE 7.0",
            "os": "NokNokOS 7.0",
            "manufacturer": "NokNok",
            "supportsPlatformAuthenticator": true
        },
        "protocol": "uaf_1.0",
        "authenticatorsResult": [
            {
                "handle": "WyJ1YWZfMS4wIiwiNGU0ZSNhYmNkIiwiUVItRkM1ZGxsYTR5bXJGQTl3UWFWRjkyQUZkbkN5Snd0aFdxLU04eXM3OCJd",
                "uvi": "UhGvpxuoi4eiLQ-RRyITTdDNg2_Vd5UcrHd0I04VE6w",
                "uviStatus": 4,
                "status": 4000,
                "aaid": "4e4e#abcd",
                "authenticatorVersion": 1,
                "attestationType": 15880,
                "attestationTypeName": "basic_surrogate",
                "appAtt": {
                    "state": "NOT_APPLICABLE"
                },
                "attachmentHints": [
                    "internal"
                ],
                "metadata": {
                    "aaid": "4e4e#abcd",
                    "description": "4e4e#abcd description",
                    "authenticatorVersion": 1,
                    "userVerificationMethods": [
                        [
                            {
                                "userVerification": 4,
                                "userVerificationMethod": "passcode_internal"
                            }
                        ],
                        [
                            {
                                "userVerification": 2,
                                "userVerificationMethod": "fingerprint_internal"
                            }
                        ]
                    ],
                    "matcherProtection": [
                        "MATCHER_PROTECTION_ON_CHIP"
                    ],
                    "tcDisplay": {
                        "schema": 1,
                        "secureDisplayList": [
                            "SECURE_DISPLAY_ANY"
                        ]
                    },
                    "isKeyRestricted": true,
                    "isFreshUserVerificationRequired": true,
                    "attestationType": [
                        "basic_surrogate"
                    ],
                    "keyProtection": [
                        "KEY_PROTECTION_TEE"
                    ],
                     "authenticatorSpecCustomAttributes": {
                    "authenticatorFidoCertificationLevel": "FIDO_CERTIFIED_L1",
                    "authenticatorFipsCertificationLevel": "FIPS140_CERTIFIED_L1_PHY_2"
  }
                }
            }
        ],
        "policyName": "default",
        "rulesResult": {
            "action": "ALLOW",
            "matchedRules": [
                {
                    "name": "LocationVelocity",
                    "riskScore": 0,
                    "template": "DummyRule",
                    "group": "dummy group"
                }
            ]
        },
        "app": {
            "id": "android:apk-key-hash:rDQ4Tn60fAvxP8thtp6sOh5ococ",
            "name": "android:com.noknok.test.client",
            "qrSupported": true
        },
        "extensions": [
            {
                "id": "noknok.ipaddress",
                "data": "192.168.0.102",
                "operation": "FINISH_REG"
            },
            {
                "id": "noknok.ipaddress",
                "data": "192.168.0.102",
                "operation": "INIT_REG"
            },
            {
                "id": "noknok.wifi.ssid",
                "data": "Oviya",
                "operation": "FINISH_REG"
            },
            {
                "id": "noknok.wifi.ssid",
                "data": "Oviya",
                "operation": "INIT_REG"
            },
            {
                "id": "noknok.uaf.location",
                "data": "{\"accuracy\":99.2,\"countryCode\":\"US\",\"latitude\":32.52,\"longitude\":-124.482,\"status\":0}",
                "operation": "FINISH_REG"
            },
            {
                "id": "noknok.uaf.location",
                "data": "{\"accuracy\":99.2,\"countryCode\":\"US\",\"latitude\":32.52,\"longitude\":-124.482,\"status\":0}",
                "operation": "INIT_REG"
            },
            {
                "id": "noknok.uaf.jailbreak",
                "data": "{\n  \"status\" : \"0\",\n  \"isJailbroken\" : \"false\"\n}",
                "operation": "FINISH_REG"
            },
            {
                "id": "noknok.uaf.jailbreak",
                "data": "{\n  \"status\" : \"0\",\n  \"isJailbroken\" : \"false\"\n}",
                "operation": "INIT_REG"
            }
        ],
        "statusMessage": "Ok"
    }
}

Sample Webauthn Response Showing metadata when needDetails = 4. When the protocol is web, the response includes metadata-specific information in the additionalInfo.authenticatorsResult.metadata section.

{
    "statusCode": 4000,
    "id": "ss_lcK2VYEkDxdPwToDqGw",
    "message": "eyJzZXJ2ZXIiOnsiYXV0aGVudGljYXRvcnNSZXN1bHQiOlt7InN0YXR1cyI6NDAwMH1dfSwidmVyc2lvbiI6IjEuMCIsIm9wZXJhdGlvbiI6IkZJTklTSF9SRUciLCJwcm90b2NvbCI6IndlYl8xLjAifQ",
    "additionalInfo": {
        "device": {
            "id": "abcde12345fghij",
            "type": "browser",
            "info": "NokNok Emulator",
            "model": "NokNok-AE 7.0",
            "os": "NokNokOS 7.0",
            "manufacturer": "NokNok",
            "supportsPlatformAuthenticator": true
        },
        "protocol": "web_1.0",
        "authenticatorsResult": [
            {
                "handle": "WyJ3ZWIiLCIwNjBiMmIwNi0wMTA0LTAxODItZTUxYy0wMTAxMDQwNDEyMDQiLCJIajdIWWpzcmxuS0ZnNFNCdWtlWXd4RGJhaDZsekhLbUtsNUFRc2NzZW9VIl0",
                "status": 4000,
                "aaguid": "060b2b06-0104-0182-e51c-010104041204",
                "attestationFormat": "packed",
                "authenticatorVersion": 0,
                "attestationType": 15880,
                "credentialID": "Hj7HYjsrlnKFg4SBukeYwxDbah6lzHKmKl5AQscseoU",
                "attestationTypeName": "Self",
                "attestationStatus": "SUCCESS",
                "userPresence": true,
                "userVerification": false,
                "backUpEligible": true,
                "backedUp": false,
                "dpk": {
                    "state": "UNAVAILABLE"
                },
                "appAtt": {
                    "state": "NOT_APPLICABLE"
                },
                "attachmentHints": [
                    "internal"
                ],
                "authenticatorAttachment": "platform",
                "metadata": {
                    "aaguid": "060b2b0601040182e51c010104041204",
                    "description": "Generic webauthn authenticator",
                    "authenticatorVersion": 0,
                    "userVerificationMethods": [
                        [
                            {
                                "userVerification": 1,
                                "userVerificationMethod": "presence_internal"
                            }
                        ]
                    ],
                    "matcherProtection": [
                        "MATCHER_PROTECTION_TEE",
                        "MATCHER_PROTECTION_ON_CHIP"
                    ],
                    "tcDisplay": {
                        "schema": 1,
                        "secureDisplayList": [
                            "SECURE_DISPLAY_ANY"
                        ]
                    },
                    "isKeyRestricted": true,
                    "isFreshUserVerificationRequired": true,
                    "attestationType": [
                        "Self"
                    ],
                    "keyProtection": [
                        "KEY_PROTECTION_HARDWARE",
                        "KEY_PROTECTION_TEE"
                    ],
                    "authenticatorSpecCustomAttributes": {
                    "authenticatorFidoCertificationLevel": "FIDO_CERTIFIED_L1",
                    "authenticatorFipsCertificationLevel": "FIPS140_CERTIFIED_L1_PHY_2"
  }
                }
            }
        ],
        "policyName": "default",
        "rulesResult": {
            "action": "ALLOW",
            "matchedRules": [
                {
                    "name": "LocationVelocity",
                    "riskScore": 0,
                    "template": "DummyRule",
                    "group": "dummy group"
                }
            ]
        },
        "app": {
            "id": "android:apk-key-hash:rDQ4Tn60fAvxP8thtp6sOh5ococ",
            "name": "android:com.noknok.test.client",
            "qrSupported": true
        },
        "extensions": [
            {
                "id": "noknok.ipaddress",
                "data": "192.168.0.102",
                "operation": "FINISH_REG"
            },
            {
                "id": "noknok.ipaddress",
                "data": "192.168.0.102",
                "operation": "INIT_REG"
            },
            {
                "id": "noknok.wifi.ssid",
                "data": "Oviya",
                "operation": "FINISH_REG"
            },
            {
                "id": "noknok.wifi.ssid",
                "data": "Oviya",
                "operation": "INIT_REG"
            },
            {
                "id": "noknok.uaf.location",
                "data": "{\"accuracy\":99.2,\"countryCode\":\"US\",\"latitude\":32.52,\"longitude\":-124.482,\"status\":0}",
                "operation": "FINISH_REG"
            },
            {
                "id": "noknok.uaf.location",
                "data": "{\"accuracy\":99.2,\"countryCode\":\"US\",\"latitude\":32.52,\"longitude\":-124.482,\"status\":0}",
                "operation": "INIT_REG"
            },
            {
                "id": "noknok.uaf.jailbreak",
                "data": "{\n  \"status\" : \"0\",\n  \"isJailbroken\" : \"false\"\n}",
                "operation": "FINISH_REG"
            },
            {
                "id": "noknok.uaf.jailbreak",
                "data": "{\n  \"status\" : \"0\",\n  \"isJailbroken\" : \"false\"\n}",
                "operation": "INIT_REG"
            }
        ],
        "statusMessage": "Ok"
    }
}