Introduction
This contains developer-focused technical details on incorporating strong authentication using the Nok Nok™ App SDK for iOS (hereafter referred to as the “App SDK”). By reading it, a developer learns how to integrate a mobile app with the Nok Nok S3 Authentication Suite.
This is intended for an intermediate iOS developer who already has strong working knowledge of Swift, Xcode, and the iOS APIs.
Overview
The major topics covered here fall into the following areas:
Getting Started - List of App SDK frameworks and bundles.
Setting Up the App SDK - Covers how to import the App SDK into your mobile app or watch app.
Using the App SDK - Discusses important points about the synchronous nature of the App SDK, the AppSessionData object, and error handling. Also lists the supported authenticators.
Implementing Authentication in Your App - Describes how to use the App SDK to implement Sign-in, OOB authentication, and Quick Authentication. You can find other useful topics like device blessing support, WebView integration, and more.
Packaging Options - Provides instructions on how to embed a local FIDO client, embed an authenticator, and more.
Getting started
To fully understand the materials presented here, we strongly urge you to read many of the pages on the Start menu first.
By using the App SDK for iOS, your app can take advantage of FIDO-enabled devices to perform strong authentication without relying on passwords. The App SDK performs authentication by using the adaptive policies, FIDO policies, authentication methods, and data lists configured on the Nok Nok Server.
The App SDK supports iOS/iPadOS devices as well as watchOS-based Apple Watch devices. Nok Nok recommends the following development approach:
Incorporate the App SDK into your mobile app and get Adaptive authentication working.
Incorporate the App SDK into your watch app.
Sample applications that you can build are described in Exploring Tutorial App and Exploring Tutorial Watch App
Prerequisites and Supported Platforms
See the App SDK for iOS Release Notes for details.
What’s in the SDK?
The App SDK package contains the following folders:
Folder Name | Description |
|---|---|
customize | Contains the necessary files for customizing the UI. |
docs | Contains generated documentation for the App SDK API |
Frameworks | Contains all required iOS xcframeworks for building fully functional FIDO-enabled mobile applications. |
FrameworksWatch | Contains all required watchOS xcframeworks for building fully functional FIDO-enabled watchOS applications. |
SwiftPackages | Contains local Swift packages for easy integration of frameworks into application targets. |
licenses | Contains license files of 3rd party software used in the Nok Nok SDKs |
metadata | Contains Authenticator Attestation ID (AAID) .json metadata files required for using iOS-specific Authenticators |
TutorialAppPlus | Contains the source files of Tutorial App. Demonstrates how to integrate the App SDK into a FIDO mobile app. |
TutorialWatchApp | Contains the source files for a Watch App containing the watch authenticator used by TutorialAppPlus. Demonstrates how to integrate the App SDK for watchOS into a Watch App. |
App SDK frameworks and bundles
Add the App SDK frameworks depending on the functionality you want in your app. Frameworks and bundles are in the Frameworks folder:
Framework / Bundle Name | Description | Category |
|---|---|---|
appsdkplus.xcframework nnl.appsdkplus.bundle | Framework for the APIs that handle FIDO registration, authentication, transaction confirmation, and deregistration. | Mandatory |
adaptiveSdk.xcframework nnl.AdaptiveSdk.bundle | Framework for using authentication that adapts to contextual information. Supports both FIDO and non-FIDO authentication methods. Non-FIDO authentication methods include SMS OTP, email OTP, and Photo ID. Not supported on Watch OS. | Mandatory |
watchKitAppExtension.xcframework | Contains the support code for the Apple Watch authenticator. Should be added to watch target. | Optional |
WatchASM.xcframework | Contains the Apple Watch Authenticator Specific Module (ASM) that runs on the phone. | Optional |
OOBSDK.xcframework | Contains the API for performing out-of-band (OOB) operations. Not supported on Watch OS. | Optional |
Ble.xcframework | Contains the API for using the BLE authenticator. This supports using the phone as a roaming authenticator. | Optional |
Ctap.xcframework | Allows an app to expose an authenticator using CTAP. | Optional |
PinASM.xcframework | Contains the PIN authenticator. Not supported on Watch OS. | Optional |
PresenceASM.xcframework | Contains the Presence authenticator. Not supported on Watch OS. | Optional |
SilentASM.xcframework nnl.SilentASM.bundle | Contains the Silent authenticator | Optional |
TouchIDASM.xcframework | Contains the Touch ID & Face ID authenticator. Not supported on Watch OS. | Optional |
Below are other frameworks that must always be included, independent of the framework you add from the above table.
Framework / Bundle Name | Description |
|---|---|
nnl_util.xcframework | Contains the utility functions used in other frameworks |
appsdk.xcframework nnl.appsdk.bundle | Contains the V2 APIs |
uaf_asm.xcframework nnl.uaf-asm.bundle | Contains the support code for the UAF ASMs |
uaf_extensions.xcframework | Contains the UAF extension processing |
uaf_engine_ios.xcframework | Contains utility functions used for UAF protocol handling. Not supported on Watch OS. |
uaf_engine.xcframework | Framework for UAF protocol. |