URL: /nnlgateway/nnl/<tenant_id>/reg Method: POST |
Digipass S3 Authentication Software provides operations under the /nnlgateway/nnl/<tenant_id>/reg endpoint to manage user registrations that are performed entirely on one device, like a cell phone. Using these operations you can initiate registration, complete registration, and update a registration. The following operations are available:
API Server uses its policy plugin's configuration object, default_config, to determine the FIDO policy to use for a REST API operation that registers. An example default_config is shown below. For details about default_config, see Create a Policy Plugin.
{
"registration_policy_name":"AcmeRegistration",
"app_specified_policies":{
"policy_type_mappings":{
"VerySecurePolicy":"AcmeVerySecure",
"QuickAuthPolicy":"AcmeQuickAuth"
}
}
}To determine the FIDO policy to use for registration, the API Server does the following:
IF the request contains a value for optionsData.policyType THEN use that to retrieve the FIDO policy name from default_config.app_specified_policies.policy_type_mappings.<policyType>.
As an example, let's use the default_config above. If optionsData.policyType = "VerySecurePolicy" then the API Server passes the FIDO policy name "AcmeVerySecure" to the Authentication Server.ELSEIF there is a value for default_config.registration_policy_name, THEN retrieve use that as the FIDO policy.
Using the example above, this is "AcmeRegistration".ELSE use the FIDO policy named "default".
To perform FIDO registration, the Authentication Server uses the registration policy to determine the valid UAF and FIDO2 authenticators that can be used. For UAF authenticators, the Auth Server refers to the allowed UAF authenticators specified by the FIDO policy and device information to create a list of permitted UAF authenticators that the user could register.
For FIDO2 authenticators, the Auth Server compares the authenticator's characteristics to the desired FIDO2 authenticator characteristics specified by the registration policy. The client uses these as hints to prompt the end user for the authenticator. The Auth Server enforces user verification and attestation preference during FINISH_REG based on the FIDO policy configuration. If you have not configured the registration policy for FIDO2 authenticators, then INIT_REG fails with a 4403 when a web app tries to register a FIDO2 authenticator.
Refer to Configure Adaptive Rulesets to see how to create a registration policy.
Because there can be many end users registering simultaneously, the Server needs to correlate INIT_REG and FINISH_REG with a particular user. It does this using the id attribute.
Depending on the operation, you can also get information about the device initiating the registration, the authentication protocol used by the Server, and the policy used to validate the operation.
INIT_REG
Initiates the registration process for a FIDO authenticator.
Request
Attribute | Description |
|---|---|
operation | Required. The string INIT_REG. |
callerOrigin | Required if a web app is sending the request and that app has a different origin than the Digipass S3 API Server. A web origin is defined by the scheme (protocol), host (domain), and port of the URL used to access it. The API Server checks if this origin is listed in its origin allow list, if not, the request is rejected. See My Web Apps Have a Different Origin. |
id | Optional. The correlation ID, a unique identifier that associates INIT_REG and FINISH_REG operations for the same user. An alphanumeric string, maximum 255 characters. No special characters are allowed. If not provided, the Server generates a unique id and returns it in the response. |
locale | Optional. Used by the Auth Server to retrieve the locale-specific name for the authenticator from its metadata statement. An IETF BCP 47 language tag string, like en-US. |
message | Required. Generated by the App SDK on the client. This is an opaque value. The client app is responsible for sending message. This is a base64-URL encoded string. |
optionsData | Optional. An object used to pass additional attributes to REST API operations. See OptionsData for a complete description. |
sessionData | Required. An object containing the user's session information. See SessionData. |
Response
The following attributes are always present in the JSON payload of the response.
Attribute | Description |
|---|---|
id | The unique id that correlates INIT_REG and FINISH_REG operations for the same user. If id was sent in the request, the same id is returned. If not, a server-generated ID is returned. If id was provided in the REST payload but the server was unable to parse the payload, the value is unknown. |
statusCode | Server-specific status code that reports the success or failure of the requested operation. See Response Status Codes below for the codes. |
The following attributes are present in the response upon a successful operation (Server status code 4000).
Attribute | Description |
|---|---|
additionalInfo | An object containing information about the client app and device initiating registration. Contains the 4 attributes listed in the rows below. In order for the API Server to return this information:
|
additionalInfo.device | A DeviceDetail object containing information about the device that issued the INIT_REG request, such as the device’s unique ID, model, and manufacturer. |
additionalInfo.elapsedTime | Amount of time, in milliseconds, that has elapsed while processing the request. |
additionalInfo.extensions | Information about the initiating device’s location and jailbreak status. List<Extension>. |
additionalInfo.protocol | The protocol used by the Authentication Server based on information from the request. String. One of UAF or Web. |
lifetimeMillis | Lifetime of message in milliseconds. Long. Your client or web app can use this to tell a user how much time they have to respond to the challenge or warn the user that the Server does not accept a response once lifetimeMillis has expired. |
message | Opaque value that contains the challenge exchanged between the Server and the App SDK. A base64-URL encoded string. message must be sent to the App SDK. |
Response Status Codes
The following are the descriptions of the Auth Server status codes returned by INIT_REG. Under certain circumstances, the API Server returns an unsuccessful HTTP status code. Examples include an invalid request or invalid session. You can find descriptions of these in API Server Status Codes.
Server Status Code | Description | Examples |
|---|---|---|
4000 | OK. Operation completed | Request was successfully created. |
4402 | Security exception | policyName does not exist in the Server. tenantID does not exist in the Server. |
4403 | PolicyVerificationException | Requested policy is not available on the Server. |
4404 | Internal Server Error | Internal server error. Failed to read from the database. Failed to connect to the database. Failed to read required properties. |
4406 | Payload Exception | An error occurred with one or more attributes. For example, message is an invalid type. |
4408 | UnsupportedClient MessageException | The message attribute cannot be handled. |
4409 | ClientMessageException | The message attribute is invalid (for example, a JSON syntax error). The message attribute from the App SDK is malformed (base64URL decode failed). |
Samples
Sample Request URL
|
|---|
Sample request
{
"operation":"INIT_REG",
"sessionData":{
"sessionKey":"<session JWT>"
},
"id":"sample",
"message":"<base64url-encoded-data>"
}Sample UAF-protocol response
A developer updated the response filter configuration so the API Server returns the FIDO protocol and the elapsed time for the request in additionalInfo.
{
"id":"dEgViadKjxcleujKbpfi6g",
"statusCode":4000,
"lifetimeMillis":300000,
"message":"<base64url-encoded-data>",
"additionalInfo":{
"protocol":"uaf_1.0",
"device":{
"id":"123456789abcdef1234567890",
"type":"android",
"info":"OneSpan device"
},
"elapsedTime":38
}
}Sample FIDO2-protocol response
A developer updated the response filter configuration so the API Server returns the protocol and client app information in additionalInfo.
{
"statusCode":4000,
"additionalInfo":{
"device":{
"info":"my iPhone",
"model":"iPhone 13 Pro",
"os":"iOS 15",
"manufacturer":"Apple",
"id":"abcdef12345ghijkl",
"type":"ios"
},
"app":{
"name":"Passport",
"id":"com.noknok.ios.passport"
},
"protocol":"web_1.0",
"elapsedTime":38
},
"lifetimeMillis":300000,
"message":
"eyJzZXJ2ZXIiOnsibm5sRGF0YSI6IlpkNVpxRjN2TTVzcHVfbE9BZ0M0MFNnNG5leDhqci1qNjJ3aDctRm9zTE5MejRuNDJoY2tFT2l3QjlJZ3pEUnFHUVdyZnB1VG9aT0h1blBheDZxU3Q4YVZIcXloWXFPeFRWRUxSaFRfVk9ySVRYLUNGS2dkemxaTDFUSm1kajQwWDZYdXNRQnZWMFgxczhWakFEU051S0I1ZUJxSFZaTzFVU2NhdWliS2J2QmNMNTcyNG0tZnBORU9jdyJ9LCJwcm90b2NvbE1lc3NhZ2UiOiJ7XCJvcHRpb25zXCI6e1wicnBcIjp7XCJpZFwiOlwicWEtaGVtYW50Lm5va25va3Rlc3QuY29tXCIsXCJuYW1lXCI6XCJERUZBVUxUX1RFTkFOVFwifSxcInVzZXJcIjp7XCJpZFwiOlwid2ViX1RDNjE2MVwiLFwiZGlzcGxheU5hbWVcIjpcIndlYl9UQzYxNjFcIixcIm5hbWVcIjpcIndlYl9UQzYxNjFcIn0sXCJjaGFsbGVuZ2VcIjpcIjgrYzNVeHJCa0FreGFaeURqSTlCQUV6TGNSQlI0ZHhXZkpYblVUTFhrQXNcXHUwMDNkXCIsXCJwdWJLZXlDcmVkUGFyYW1zXCI6W3tcImFsZ1wiOi03LFwidHlwZVwiOlwicHVibGljLWtleVwifSx7XCJhbGdcIjotMjU3LFwidHlwZVwiOlwicHVibGljLWtleVwifV0sXCJ0aW1lb3V0XCI6MzAwMDAwLFwiYXV0aGVudGljYXRvclNlbGVjdGlvblwiOnt9fSxcInNlcnZlckRhdGFcIjpcImtubGMwUkNMVjgyNlhBNnJyVzNmTEV0RXp1WEJ3UEtKaVlsWkNnOFFKbDJsT0htekdQUXRwQkFXMTk1bk5kWjJxTHB6RTRxSEVfa2pqQWxnSC1vOFVSSmxaUGRCLWpuYkdDMjRYOWtTLTlnb204NnMxUUxrOGhNTUU4MzI1dzA4RWFjQkNaNjJ2RE5yMzl4MWR2QVFCSENPSGt3eXpZQWVyRk1wc29QVFo3X3Y3eDVFajRPbk1BXCJ9IiwidmVyc2lvbiI6IjEuMCIsIm9wZXJhdGlvbiI6IklOSVRfUkVHIiwicHJvdG9jb2wiOiJ3ZWJfMS4wIn0",
"id":"25XOAKx9BAWlF16iuki3VQ"
}FINISH_REG
Processes the registration response provided by the caller and completes the registration process. Assigns authenticatorName, if provided, as the registered authenticator's name.
The Server uses the allowed authenticators specified by the default registration policy and device information to verify whether the user's selected authenticator should be registered. If the registration policy has any optional post operation rules defined, these are also evaluated to allow or deny registration.
Request
Attribute | Description |
|---|---|
operation | Required. The string FINISH_REG. |
authenticatorName | Optional.The name of the authenticator. An alphanumeric string, max 128 characters. |
callerOrigin | Required if a web app is sending the request and that app has a different origin than the Digipass S3 API Server. A web origin is defined by the scheme (protocol), host (domain), and port of the URL used to access it. The API Server checks if this origin is listed in its origin allow list, if not, the request is rejected. See My Web Apps Have a Different Origin. |
channelBinding | Optional. Channel binding data available from the TLS endpoint. A ChannelBinding object. |
message | Required. Generated by the App SDK on the client. This is an opaque value. The client app is responsible for sending message. This is a base64-URL encoded string. |
optionsData | Optional. An object used to pass additional attributes to REST API operations. See OptionsData for a complete description. |
sessionData | Required. An object containing the user's session information. See SessionData. |
Response
The following attributes are always present in the JSON payload of the response.
Attribute | Description |
|---|---|
id | The unique id that correlates INIT_REG and FINISH_REG operations for the same user. |
statusCode | Server-specific status code that reports the success or failure of the requested operation. See Response Status Codes below for the status and error codes. Integer. |
The following attributes are present in the response upon a successful operation (Server status code 4000).
Attribute | Description |
|---|---|
additionalInfo | An object containing information about the client app and device initiating the registration. Contains the attributes listed in the rows below. In order for the API Server to return this information,
|
additionalInfo.authenticatorsResult | The authenticator (like fingerprint) that the user registered. If registration failed, this is the authenticator that failed. A List<AuthenticatorResult>. There is typically only one entry. |
additionalInfo.device | A DeviceDetail object containing information about the device that issued the FINISH_REG request, such as the device’s unique ID, model, and manufacturer. |
additionalInfo.elapsedTime | The number of milliseconds that has elapsed while processing the request. |
additionalInfo.extensions | Information about a device’s location and jailbreak status. A List<Extension>. |
additionalInfo.headerExtensions | Protocol-specific header extensions. List<HeaderExtension> |
additionalInfo.policyName | FIDO registration policy name used for the operation. String. |
additionalInfo.protocol | The protocol used by the Authentication Server based on information from the request. String. One of UAF or Web. |
additionalInfo.rulesResult | RulesResult populated as a result of post operation rules processing giving out the matched rules details. RulesResult. |
message | Information exchanged between the Server and the App SDK. A base64-URL encoded string. |
Response status codes
The following are the descriptions of the Auth Server status codes returned by FINISH_REG. Under certain circumstances, the API Server returns an unsuccessful HTTP status code. Examples include an invalid request or invalid session. You can find descriptions of these in API Server Status Codes.
Server Status Code | Description | Examples |
|---|---|---|
4000 | OK. Operation completed | Registration completed successfully. |
4002 |
| This status code is returned in the response for a Lenient Web Authentication policy or failure to meet policy requirements, such as attestation, user verification, and so on. |
4401 | Challenge Expired Exception | The INIT_REG request challenge expired. |
4402 | Security Exception | Failed to validate the attestation. Failed to validate Server challenge Failed to validate the Server data. Failed to locate authenticator metadata. Challenge replay detected. Failed due to revoked certificate. Failed to validate Android Key Attestation extension. Required Android Key Attestation extension is missing. |
4403 | Policy Exception | Failed to match policy. Policy not supported. Failed to register because the maximum number of configurable registrations for each user has been reached. |
4404 | Internal Server Error | Internal server error. Failed to write to the database. Failed to read from the database. Failed to connect to the database. Failed to read required properties. |
4406 | Payload Exception | An error occurred with one or more attributes. For example, message is an invalid type or the username extracted from sessionData.sessionKey has an invalid length. |
4408 | Unsupported ClientMessageException | The message attribute cannot be handled. The client does not support UAF/FIDO2 protocol. Or the protocol is missing. |
4409 | ClientMessageException | The message attribute is invalid (for example, a JSON syntax error). The message attribute from the App SDK is malformed (base64URL decode failed). |
Samples
Sample request URL
|
|---|
Sample Request
{
"operation":"FINISH_REG",
"sessionData":{
"sessionKey":"<session JWT>"
},
"message":"<base64url-encoded-data>"
}Sample UAF-protocol response
A developer updated the response filter configuration so the API Server returns the protocol, the elapsed time for the request, FIDO policy used, additional authenticator details, and post operation rule results in additionalInfo.
{
"message":"<base64url-encoded-data>",
"id":"dEgViadKjxcleujKbpfi6g",
"statusCode":4000,
"additionalInfo":{
"protocol":"uaf_1.0",
"policyName":"reg_policy",
"elapsedTime":25,
"authenticatorsResult":[
{
"handle":
"WyJ1YWZfMS4wIiwiQUJDRCNBQkNEIiwiT1QzN2E5bUpkQ2s4Q0lBbG05eUFZNGJybXA1ME9nZGgyTXJEVWxTeUFjRSJd",
"status":4000,
"attestationType":15879,
"uvi":"NwzJQXezm0gQeLn_kzaahxUGiC8FYqxYn-xqDSgyKyg",
"uviStatus":4,
"aaid":"ABCD#ABCD",
"authenticatorVersion":1
},
{
"handle":
"WyJ1YWZfMS4wIiwiQUJDRCMwMDEzIiwiSDhUM2t2cWFob1k1MWRwVEZFNzIwOUpyWDBZYWw3aDBBa0VPVkpPRXdOUSJd",
"status":4000,
"attestationType":15879,
"uvi":"dVFPwbfp8fbcA2KK87yBsPm5fMX_hTulEFnnHrreKlY",
"uviStatus":4,
"aaid":"ABCD#0013",
"authenticatorVersion":1
}
],
"device":{
"id":"dID_91361a29-16ae-45f3-b0cc-922ba82e929e_16",
"type":"android",
"info":"OneSpan's device"
},
"rulesResult":{
"matchedRules":[
{
"name":"LocationCheck",
"template":"LocationCheck",
"group":"location",
"riskScore":60
},
{
"name":"LocationUnknown",
"template":"LocationUnknown",
"group":"location",
"riskScore":40
}
],
"riskThresholdRule":{
"aboveThreshold":false,
"riskScore":60,
"threshold":80
},
"action":"ALLOW"
}
}
}Sample Web-protocol response
A developer updated the response filter configuration so the API Server returns app information, additional authenticator details, protocol, and the elapsed time for the request in additionalInfo.
{
"statusCode":4000,
"additionalInfo":{
"device":{
"info":"Google Chrome on Windows",
"os":"Windows 10",
"id":"35da57bd-dcb6-4529-9f00-8eea5c0cea00",
"type":"browser"
},
"app":{
"name":"https://<server>.noknoktest.com/gwtutorial/",
"id":"https://<server>.noknoktest.com",
"qrSupported":true
},
"authenticatorsResult":[
{
"authenticatorVersion":0,
"aaguid":"abcdef12-3456-7890-abcd-ef1234567890",
"attestationFormat":"packed",
"attachmentHints": ["internal"],
"authenticatorAttachment": "platform",
"credentialID":"RS3tw2_bsJFyMQMdMMk4pAKRgt_3voYyrRmm5ACzyhc",
"status":4000,
"handle":"WyJ3ZWIiLCJhYmNkZWYxMi0zNDU2LTc4OTAtYWJjZC1lZjEyMzQ1Njc4OTAiLCJSUzN0dzJfYnNKRnlNUU1kTU1rNHBBS1JndF8zdm9ZeXJSbW01QUN6eWhjIl0"
}
],
"protocol":"web_1.0",
"elapsedTime":25
},
"message":"eyJzZXJ2ZXIiOnsiYXV0aGVudGljYXRvcnNSZXN1bHQiOlt7InN0YXR1cyI6NDAwMH1dLCJhcHBJRCI6InFhLXZqb3NoaS5ub2tub2t0ZXN0LmNvbSJ9LCJ2ZXJzaW9uIjoiMS4wIiwib3BlcmF0aW9uIjoiRklOSVNIX1JFRyIsInByb3RvY29sIjoid2ViXzEuMCJ9",
"id":"4-_llfQ14DaBdeDIeWyVMw"
}Sample web-protocol response that includes an AppAttest object
A developer updated the response filter configuration so the API Server returns the protocol, elapsed time, additional authenticator details, post operation rule results, and client app information in additionalInfo.
{
"statusCode":4000,
"id":"36AB3FD9-D5F7-40C1-9D9F-A11D1F9FFDFD",
"message": "eyJzZXJ2ZXIiOnsiYXV0aGVudGljYXRvcnNSZXN1bHQiOlt7InN0YXR1cyI6NDAwMH1dLCJhcHBJRCI6InN0LW15c3FsLm5va25va3Rlc3QuY29tIn0sInZlcnNpb24iOiIxLjAiLCJvcGVyYXRpb24iOiJGSU5JU0hfUkVHIiwicHJvdG9jb2wiOiJ3ZWJfMS4wIn0",
"additionalInfo":{
"device":{
"id": "AD5D2029-383A-47FE-BF80-DF133A9E0221",
"type":"ios",
"info":"iPhone",
"model":"iPhone13,1",
"os":"iOS 16.4.1",
"manufacturer":"Apple",
"supportsPlatformAuthenticator":true
},
"protocol":"web_1.0",
"elapsedTime":30,
"authenticatorsResult":[
{
"handle": "WyJ3ZWIiLCIwMDAwMDAwMC0wMDAwLTAwMDAtMDAwMC0wMDAwMDAwMDAwMDAiLCJJaUw2TzFEcDNZNTdLZlJXdzVVNHM4WDBNSW8iXQ",
"authenticatorName":"iPhone authenticator",
"status": 4000,
"aaguid": "00000000-0000-0000-0000-000000000000",
"attestationFormat":"none",
"authenticatorAttachment":"cross-platform",
"authenticatorVersion":0,
"credentialID":"IiL6O1Dp3Y57KfRWw5U4s8X0MIo",
"attestationStatus":"UNAVAILABLE",
"userPresence":true,
"userVerification":true,
"backUpEligible":true,
"backedUp":true,
"dpk": {
"state": "NOT_APPLICABLE"
},
"appAtt": {
"state": "TRUSTED",
"handle": "WyJ3ZWIiLCI2MTcwNzA2MS03NDc0LTY1NzMtNzQ2NC02NTc2NjU2YzZmNzAiLCJJdVJmRGUyWHRkYjVaaFBjNW9aU3lYalphRGJZUGZCS1dpaUJyaklMZEw0IiwiV3lKM1pXSWlMQ0l3TURBd01EQXdNQzB3TURBd0xUQXdNREF0TURBd01DMHdNREF3TURBd01EQXdNREFpTENKSmFVdzJUekZFY0ROWk5UZExabEpYZHpWVk5ITTRXREJOU1c4aVhRIl0",
"authenticatorName": "iPhone",
"aaguid": "61707061-7474-6573-7464-6576656c6f70",
"attestationFormat": "apple-appattest",
"authenticatorVersion": 0,
"credentialID": "IuRfDe2Xtdb5ZhPc5oZSyXjZaDbYPfBKWiiBrjILdL4",
"userPresence": false,
"userVerification": false,
"backUpEligible": false,
"backedUp": false,
"attachmentHints": [
"internal"
]
},
"attachmentHints": [
"internal"
]
}
],
"app": {
"id":"ios:bundle-id:com.noknok.ios.tutorialappplus",
"name":"ios:com.noknok.ios.tutorialappplus",
"qrSupported":true
}
}
}Sample request with authenticatorName
{
"operation":"FINISH_REG",
"sessionData":{
"sessionKey":"<session JWT>"
},
"authenticatorName":"sampleAuthenticatorName",
"message":"<base64url-encoded-data>"
}Sample UAF-protocol response with authenticatorName
{
"statusCode":4000,
"id":"OgpQAW37Blt7xtrAIwzheQ",
"message":
"eyJzZXJ2ZXIiOnsiYXV0aGVudGljYXRvcnNSZXN1bHQiOlt7ImFhaWQiOiJBQkNEI0FCQ0QiLCJrZXlJRCI6IlNPcHdPb1NUN1BnX1hKZWo2RUtnc1NPOE5xVE01NGFkeF9Cdk83LXUteVEiLCJzdGF0dXMiOjQwMDB9XSwiYXBwSUQiOiJodHRwczovLzEyNy4wLjAuMTo4NDQzL1NhbXBsZUFwcCJ9LCJ2ZXJzaW9uIjoiMS4wIiwib3BlcmF0aW9uIjoiRklOSVNIX1JFRyIsInByb3RvY29sIjoidWFmXzEuMCJ9",
"additionalInfo":{
"device":{
"id":"123456789abcdef1234567890",
"type":"android",
"info":"NokNok Emulator",
"model":"iphone12",
"os":"NokNokOS 8.0",
"manufacturer":"NokNok"
},
"protocol":"uaf_1.0",
"elapsedTime":25,
"authenticatorsResult":[
{
"authenticatorName":"sampleAuthenticatorName",
"handle":
"WyJ1YWZfMS4wIiwiQUJDRCNBQkNEIiwiU09wd09vU1Q3UGdfWEplajZFS2dzU084TnFUTTU0YWR4X0J2TzctdS15USJd",
"uvi":"kHLOfu85VmwlUwj6XB8R8wt6HXyWTnzlcSDRUabKovA",
"uviStatus":4,
"status":4000,
"aaid":"ABCD#ABCD",
"authenticatorVersion":1,
"attestationType":15879,
"attestationTypeName":"full-basic-attestation"
}
],
"policyName":"default",
"rulesResult":{
"action":"ALLOW",
"matchedRules":[
{
"name":"LocationVelocity",
"riskScore":0,
"template":"DummyRule",
"group":"dummy group"
}
]
},
"app":{
"id":"android:apk-key-hash:rDQ4Tn60fAvxP8thtp6sOh5ococ",
"name":"android:com.noknok.test.client"
},
"extensions":[
{
"id":"noknok.ipaddress",
"data":"1.2.3.4",
"operation":"FINISH_REG"
},
{
"id":"noknok.wifi.ssid",
"data":"Oviya",
"operation":"FINISH_REG"
},
{
"id":"noknok.wifi.ssid",
"data":"Oviya",
"operation":"INIT_REG"
},
{
"id":"noknok.uaf.location",
"data":
"{\"accuracy\":99.2,\"countryCode\":\"IN\",\"latitude\":32.52,\"longitude\":-124.482,\"status\":0}",
"operation":"FINISH_REG"
},
{
"id":"noknok.uaf.location",
"data":
"{\"accuracy\":99.2,\"countryCode\":\"IN\",\"latitude\":32.52,\"longitude\":-124.482,\"status\":0}",
"operation":"INIT_REG"
},
{
"id":"noknok.ipaddress",
"data":"1.2.3.4",
"operation":"INIT_REG"
},
{
"id":"noknok.uaf.jailbreak",
"data":"{\n \"status\" : \"0\",\n \"isJailbroken\" : \"unknown\"\n}",
"operation":"FINISH_REG"
},
{
"id":"noknok.uaf.jailbreak",
"data":"{\n \"status\" : \"0\",\n \"isJailbroken\" : \"unknown\"\n}",
"operation":"INIT_REG"
}
]
}
}Sample UAF-protocol Response showing metadata when needDetails = 4. When the protocol is UAF, the response includes metadata-specific information in the additionalInfo.authenticatorsResult.metadata section.
{
"statusCode": 4000,
"id": "wVy6Rs-oGLoMI31Zw_oqOg",
"message": "eyJzZXJ2ZXIiOnsiYXV0aGVudGljYXRvcnNSZXN1bHQiOlt7ImFhaWQiOiI0ZTRlI2FiY2QiLCJrZXlJRCI6IlFSLUZDNWRsbGE0eW1yRkE5d1FhVkY5MkFGZG5DeUp3dGhXcS1NOHlzNzgiLCJzdGF0dXMiOjQwMDB9XSwiYXBwSUQiOiJodHRwczovLzEyNy4wLjAuMTo4NDQzL1NhbXBsZUFwcCJ9LCJ2ZXJzaW9uIjoiMS4wIiwib3BlcmF0aW9uIjoiRklOSVNIX1JFRyIsInByb3RvY29sIjoidWFmXzEuMCJ9",
"additionalInfo": {
"device": {
"id": "123456789abcdef1234567890",
"type": "android",
"info": "NokNok Emulator",
"model": "NokNok-AE 7.0",
"os": "NokNokOS 7.0",
"manufacturer": "NokNok",
"supportsPlatformAuthenticator": true
},
"protocol": "uaf_1.0",
"authenticatorsResult": [
{
"handle": "WyJ1YWZfMS4wIiwiNGU0ZSNhYmNkIiwiUVItRkM1ZGxsYTR5bXJGQTl3UWFWRjkyQUZkbkN5Snd0aFdxLU04eXM3OCJd",
"uvi": "UhGvpxuoi4eiLQ-RRyITTdDNg2_Vd5UcrHd0I04VE6w",
"uviStatus": 4,
"status": 4000,
"aaid": "4e4e#abcd",
"authenticatorVersion": 1,
"attestationType": 15880,
"attestationTypeName": "basic_surrogate",
"appAtt": {
"state": "NOT_APPLICABLE"
},
"attachmentHints": [
"internal"
],
"metadata": {
"aaid": "4e4e#abcd",
"description": "4e4e#abcd description",
"authenticatorVersion": 1,
"userVerificationMethods": [
[
{
"userVerification": 4,
"userVerificationMethod": "passcode_internal"
}
],
[
{
"userVerification": 2,
"userVerificationMethod": "fingerprint_internal"
}
]
],
"matcherProtection": [
"MATCHER_PROTECTION_ON_CHIP"
],
"tcDisplay": {
"schema": 1,
"secureDisplayList": [
"SECURE_DISPLAY_ANY"
]
},
"isKeyRestricted": true,
"isFreshUserVerificationRequired": true,
"attestationType": [
"basic_surrogate"
],
"keyProtection": [
"KEY_PROTECTION_TEE"
],
"authenticatorSpecCustomAttributes": {
"authenticatorFidoCertificationLevel": "FIDO_CERTIFIED_L1",
"authenticatorFipsCertificationLevel": "FIPS140_CERTIFIED_L1_PHY_2"
}
}
}
],
"policyName": "default",
"rulesResult": {
"action": "ALLOW",
"matchedRules": [
{
"name": "LocationVelocity",
"riskScore": 0,
"template": "DummyRule",
"group": "dummy group"
}
]
},
"app": {
"id": "android:apk-key-hash:rDQ4Tn60fAvxP8thtp6sOh5ococ",
"name": "android:com.noknok.test.client",
"qrSupported": true
},
"extensions": [
{
"id": "noknok.ipaddress",
"data": "192.168.0.102",
"operation": "FINISH_REG"
},
{
"id": "noknok.ipaddress",
"data": "192.168.0.102",
"operation": "INIT_REG"
},
{
"id": "noknok.wifi.ssid",
"data": "Oviya",
"operation": "FINISH_REG"
},
{
"id": "noknok.wifi.ssid",
"data": "Oviya",
"operation": "INIT_REG"
},
{
"id": "noknok.uaf.location",
"data": "{\"accuracy\":99.2,\"countryCode\":\"US\",\"latitude\":32.52,\"longitude\":-124.482,\"status\":0}",
"operation": "FINISH_REG"
},
{
"id": "noknok.uaf.location",
"data": "{\"accuracy\":99.2,\"countryCode\":\"US\",\"latitude\":32.52,\"longitude\":-124.482,\"status\":0}",
"operation": "INIT_REG"
},
{
"id": "noknok.uaf.jailbreak",
"data": "{\n \"status\" : \"0\",\n \"isJailbroken\" : \"false\"\n}",
"operation": "FINISH_REG"
},
{
"id": "noknok.uaf.jailbreak",
"data": "{\n \"status\" : \"0\",\n \"isJailbroken\" : \"false\"\n}",
"operation": "INIT_REG"
}
],
"statusMessage": "Ok"
}
}
Sample Webauthn Response Showing metadata when needDetails = 4. When the protocol is web, the response includes metadata-specific information in the additionalInfo.authenticatorsResult.metadata section.
{
"statusCode": 4000,
"id": "ss_lcK2VYEkDxdPwToDqGw",
"message": "eyJzZXJ2ZXIiOnsiYXV0aGVudGljYXRvcnNSZXN1bHQiOlt7InN0YXR1cyI6NDAwMH1dfSwidmVyc2lvbiI6IjEuMCIsIm9wZXJhdGlvbiI6IkZJTklTSF9SRUciLCJwcm90b2NvbCI6IndlYl8xLjAifQ",
"additionalInfo": {
"device": {
"id": "abcde12345fghij",
"type": "browser",
"info": "NokNok Emulator",
"model": "NokNok-AE 7.0",
"os": "NokNokOS 7.0",
"manufacturer": "NokNok",
"supportsPlatformAuthenticator": true
},
"protocol": "web_1.0",
"authenticatorsResult": [
{
"handle": "WyJ3ZWIiLCIwNjBiMmIwNi0wMTA0LTAxODItZTUxYy0wMTAxMDQwNDEyMDQiLCJIajdIWWpzcmxuS0ZnNFNCdWtlWXd4RGJhaDZsekhLbUtsNUFRc2NzZW9VIl0",
"status": 4000,
"aaguid": "060b2b06-0104-0182-e51c-010104041204",
"attestationFormat": "packed",
"authenticatorVersion": 0,
"attestationType": 15880,
"credentialID": "Hj7HYjsrlnKFg4SBukeYwxDbah6lzHKmKl5AQscseoU",
"attestationTypeName": "Self",
"attestationStatus": "SUCCESS",
"userPresence": true,
"userVerification": false,
"backUpEligible": true,
"backedUp": false,
"dpk": {
"state": "UNAVAILABLE"
},
"appAtt": {
"state": "NOT_APPLICABLE"
},
"attachmentHints": [
"internal"
],
"authenticatorAttachment": "platform",
"metadata": {
"aaguid": "060b2b0601040182e51c010104041204",
"description": "Generic webauthn authenticator",
"authenticatorVersion": 0,
"userVerificationMethods": [
[
{
"userVerification": 1,
"userVerificationMethod": "presence_internal"
}
]
],
"matcherProtection": [
"MATCHER_PROTECTION_TEE",
"MATCHER_PROTECTION_ON_CHIP"
],
"tcDisplay": {
"schema": 1,
"secureDisplayList": [
"SECURE_DISPLAY_ANY"
]
},
"isKeyRestricted": true,
"isFreshUserVerificationRequired": true,
"attestationType": [
"Self"
],
"keyProtection": [
"KEY_PROTECTION_HARDWARE",
"KEY_PROTECTION_TEE"
],
"authenticatorSpecCustomAttributes": {
"authenticatorFidoCertificationLevel": "FIDO_CERTIFIED_L1",
"authenticatorFipsCertificationLevel": "FIPS140_CERTIFIED_L1_PHY_2"
}
}
}
],
"policyName": "default",
"rulesResult": {
"action": "ALLOW",
"matchedRules": [
{
"name": "LocationVelocity",
"riskScore": 0,
"template": "DummyRule",
"group": "dummy group"
}
]
},
"app": {
"id": "android:apk-key-hash:rDQ4Tn60fAvxP8thtp6sOh5ococ",
"name": "android:com.noknok.test.client",
"qrSupported": true
},
"extensions": [
{
"id": "noknok.ipaddress",
"data": "192.168.0.102",
"operation": "FINISH_REG"
},
{
"id": "noknok.ipaddress",
"data": "192.168.0.102",
"operation": "INIT_REG"
},
{
"id": "noknok.wifi.ssid",
"data": "Oviya",
"operation": "FINISH_REG"
},
{
"id": "noknok.wifi.ssid",
"data": "Oviya",
"operation": "INIT_REG"
},
{
"id": "noknok.uaf.location",
"data": "{\"accuracy\":99.2,\"countryCode\":\"US\",\"latitude\":32.52,\"longitude\":-124.482,\"status\":0}",
"operation": "FINISH_REG"
},
{
"id": "noknok.uaf.location",
"data": "{\"accuracy\":99.2,\"countryCode\":\"US\",\"latitude\":32.52,\"longitude\":-124.482,\"status\":0}",
"operation": "INIT_REG"
},
{
"id": "noknok.uaf.jailbreak",
"data": "{\n \"status\" : \"0\",\n \"isJailbroken\" : \"false\"\n}",
"operation": "FINISH_REG"
},
{
"id": "noknok.uaf.jailbreak",
"data": "{\n \"status\" : \"0\",\n \"isJailbroken\" : \"false\"\n}",
"operation": "INIT_REG"
}
],
"statusMessage": "Ok"
}
}