Introduction
Out-of-band (OOB) authentication allows your users to use a mobile device to authenticate from other devices such as desktop applications, web browsers, Kiosk-PCs, IVR, or ATMs. The user binds the browser session or transaction to their mobile device by scanning a QR code using the mobile device or by triggering a push notification. The user then performs FIDO-based authentication on an out-of-band channel between the mobile device and the Digipass S3 Server.
Integrating OOB in your web app
Your web app initiates OOB by either displaying a QR code or sending a push notification. The Web App SDK supports FIDO authentication using either OOB or FIDO2, you make one assignment during initialization to select the mode. Registration and authentication automatically display a QR code.
To send a push notification, the App SDK saves the push handle returned after registration or authentication successfully completes. Your app then retrieves that push handle from the user cache and passes that push handle to send a push the next time it performs authentication.
The API Server can be configured to send a push notification without a push handle. In this situation, the push is sent to the user's most-recently-used device.
Integrating OOB in your mobile app
You can either implement OOB capability in your mobile app or use OneSpan's Passport app for Android or OneSpan’s Passport app for iOS.
QR code-based OOB requires implementing the UI for the scanning screen. The App SDK provides the scanning frame that can be embedded within your app. Once authentication is successful, the App SDK notifies your app, allowing it to display a success screen.
To enable push notification-based OOB, your app must register to receive the notifications. Push notification-based OOB requires server setup of the Apple Push Notification Service (APNS) for iOS and either Firebase Cloud Messaging (FCM) or Huawei Mobile Services (HMS) for Android.
Setting up the Digipass S3 Server
Push notification setup
Apple Push Notification Service (APNS): To enable your app to use APNS to send push notifications, you need the token signing key, the Key ID, and your Team ID. This information is available from your developer account on developer.apple.com. Once you have configured the Authentication Server with this information, your app can send push notifications.
Firebase Cloud Messaging (FCM): Use the Firebase Developers Console to obtain a sender ID and generate a new private key for your app. Configure the Authentication Server with the FCM sender id and private key so your app can send push notifications.
Huawei Mobile Services (HMS): To use push notifications, enable the Huawei Push Kit for your app. Obtain the App ID and App secret values from AppGallery Connect. Configure the Authentication Server with the App ID and App secret.
For more information about configuring out-of-band authentication, see Configure Out-of-band Authentication.