Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Manage Personally Identifiable Information (PII)

Prev Next

URL: /nnlgateway/nnl/<tenant_id>/reg Method: POST


Use these calls to retrieve and delete sensitive user data. These can be used to meet regulatory requirements for the General Data Protection Regulation (GDPR) and California Consumer Privacy Act of 2018 (CCPA).

FETCH_USER_DATA

Fetches the active and deleted authentication methods for the specified user. Includes FIDO and non-FIDO authentication methods. If a FIDO2 authenticator is a synced passkey, its associated DPKs, if any, are also listed.

Request

Attribute

Description

operation

Required. The string FETCH_USER_DATA.

callerOrigin

Required if a web app is sending the request and that app has a different origin than the Digipass S3 API Server. A web origin is defined by the scheme (protocol), host (domain), and port of the URL used to access it.

The API Server checks if this origin is listed in its origin allow list, if not, the request is rejected. See My Web Apps Have a Different Origin.

sessionData

Required. An object containing the user's session information. See SessionData.

Response

The following attribute is always present in the JSON payload of the response.

Attribute

Description

statusCode

Server-specific status code that reports the success or failure of this operation. Integer.

See Response Status Codes below for the status and error codes.

The following attributes are present in the response upon a successful operation (Server status 4000).

Attribute

Description

methods

A list of the user's registered non-FIDO authentication methods.

List<Authentication Method>.

registrations

A list of the user's registered FIDO authenticators.

List<Registration>.

Response Status Codes

The following are the descriptions of the Auth Server status codes returned by FETCH_USER_DATA. Under certain circumstances, the API Server returns an unsuccessful HTTP status code. Examples include an invalid request or invalid session. You can find descriptions of these in API Server Status Codes.

Server Status Code

Description

Examples

4000

OK. Operation completed

Request was successfully created.

4404

InternalServer

Exception

Internal server error.

Failed to read from the database.

Failed to connect to the database.

4406

Payload

Exception

Parameter message has an invalid type.

4430

UserNotFound Exception

Failed to locate the user in the Server.

Samples

Sample Request URL

https://www.example.com:8443/nnlgateway/nnl/<tenant_id>/reg

Sample Request

{
    "operation": "FETCH_USER_DATA",
    "sessionData": {
        "sessionKey":"<session JWT>"
  },
}

Sample Response that includes FIDO and non-FIDO Authentication Methods

{
  "statusCode":4000,
  "registrations":[
    {
      "device":{
        "id":"123456789abcdef1234567890",
        "deviceType":"android",
        "info":"NokNok Emulator",
        "model":"NokNok-AE 7.0",
        "os":"NokNokOS 7.0",
        "manufacturer":"NokNok"
      },
      "app":{
        "id":"android:apk-key-hash:rDQ4Tn60fAvxP8thtp6sOh5ococ",
        "name":"android:com.noknok.test.client",
        "qrSupported":true
      },
      "authenticators":[
        {
          "description":"ABCD#ABCD description",
          "createdTimeStamp":1667553400735,
          "handle":"WyJ1YWZfMS4wIiwiQUJDRCNBQkNEIiwiZUozWWpYdGpzdFhIR0dUN1A0NlkwRWFoVTlGVWJ4OTliLTVzUXZhTkI5WSJd",
          "status":1,
          "statusDesc":"ACTIVE",
          "lastUsedTimeStamp":1667553529221,
          "authCount":1,
          "protocolFamily":"UAF"
        }
      ]
    },
    {
      "device":{
        "id":"abcde12345fghij",
        "deviceType":"browser",
        "info":"NokNok Emulator",
        "model":"NokNok-AE 7.0",
        "os":"NokNokOS 7.0",
        "manufacturer":"NokNok"
      },
      "app":{
        "id":"android:apk-key-hash:rDQ4Tn60fAvxP8thtp6sOh5ococ",
        "name":"android:com.noknok.test.client",
        "qrSupported":true
      },
      "authenticators":[
        {
          "description":"Generic webauthn authenticator",
          "createdTimeStamp":1667550549975,
          "handle":"WyJ3ZWIiLCIwNjBiMmIwNi0wMTA0LTAxODItZTUxYy0wMTAxMDQwNDEyMDQiLCJOZVBVeWhTWVNmUW5peW9hQi1EdVRwUUR4WGQ4VFRjOXBJc1ZWWG81bm80Il0",
          "status":1,
          "statusDesc":"ACTIVE",
          "lastUsedTimeStamp":1667550664246,
          "authCount":1,
          "protocolFamily":"WEB",
            {
              "authenticatorName":"NokNok Emulator",
              "description":"Generic FIDO 2 Authenticator",
              "createdTimeStamp":1667550549985,
              "handle":"WyJ3ZWIiLCIwMDAwMDAwMC0wMDAwLTAwMDAtMDAwMC0wMDAwMDAwMDAwMDAiLCJOZVBVeWhTWVNmUW5peW9hQi1EdVRwUUR4WGQ4VFRjOXBJc1ZWWG81bm80OjQzQjExQzBEM0UxMjEyRUY5RTdFOTYyQ0Q0NEQzMUE0NTc4QTg4QzczNjdFOTk4NkEzQkQxNTkyNjk4RTA3Nzg6MCJd",
              "status":1,
              "lastUsedTimeStamp":1667550549905,
              "authCount":0,
              "scope":0
            }
          ]
        }
      ]
    }
  ],
  "methods":[
    {
      "type":"Email OTP",
      "name":"OTP Using Email",
      "data":{
        "identifier":"user@noknok.com",
        "status":1,
        "devices":[
          {
            "device":{
              "id":"123456789abcdef1234567890",
              "deviceType":"android",
              "info":"NokNok Emulator",
              "model":"NokNok-AE 7.0",
              "os":"NokNokOS 7.0",
              "manufacturer":"NokNok"
            },
            "app":{
              "id":"android:apk-key-hash:rDQ4Tn60fAvxP8thtp6sOh5ococ",
              "name":"android:com.noknok.test.client",
              "qrSupported":true
            }
          },
          {
            "device":{
              "id":"f307c6bd-deec-4609-83fd-0b5494d6c31c",
              "deviceType":"browser",
              "info":"Brave on macOS",
              "os":"macOS 13.5.0"
            },
            "app":{
              "id":"https://example.com",
              "name":"https://example.com/gwtutorial/",
              "qrSupported":true
            }
          },
          {
            "device":{
              "id":"New Device",
              "deviceType":"android",
              "info":"NokNok Emulator",
              "model":"NokNok-AE 7.0",
              "os":"NokNokOS 7.0",
              "manufacturer":"NokNok"
            },
            "app":{
              "id":"android:apk-key-hash:rDQ4Tn60fAvxP8thtp6sOh5ococ",
              "name":"android:com.noknok.test.client",
              "qrSupported":true
            }
          }
        ]
      }
    }
  ]
}

PURGE_USER_DATA

Hard deletes the specified user's PII such as their FIDO authenticators and non-FIDO authentication methods.

Request

Attribute

Description

operation

Required. The string PURGE_USER_DATA.

callerOrigin

Required if a web app is sending the request and that app has a different origin than the Digipass S3 API Server. A web origin is defined by the scheme (protocol), host (domain), and port of the URL used to access it.

The API Server checks if this origin is listed in its origin allow list, if not, the request is rejected. See My Web Apps Have a Different Origin.

sessionData

Required. An object containing the user's session information. See SessionData.

Response

The following attributes are always present in the JSON payload of the response.

Attribute

Description

stats

Deletion counts for the user's information. Object.

statusCode

Server-specific status code that reports the success or failure of this operation. Integer.

See Response Status Codes below for the status and error codes.

Response Status Codes

The following are the descriptions of the Auth Server status codes returned by PURGE_USER_DATA. Under certain circumstances, the API Server returns an unsuccessful HTTP status code. Examples include an invalid request or invalid session. You can find descriptions of these in API Server Status Codes.

Server Status Code

Description

Examples

4000

OK. Operation completed

Request was successfully created.

4404

InternalServer

Exception

Internal server error.

Failed to read from the database.

Failed to connect to the database.

4406

Payload

Exception

One or more mandatory attributes are invalid, missing, or empty. For example, the username extracted from sessionData.sessionKey has an invalid length.

4430

UserNotFound Exception

Failed to locate the user in the Server.

Samples

Sample Request URL

https://www.example.com:8443/nnlgateway/nnl/<tenant_id>/reg

Sample Request

{
    "operation"   : "PURGE_USER_DATA",
    "sessionData":{
        "sessionKey":"<session JWT>"
    }
}

Sample Response

{
    "statusCode": 4000,
    "stats": {
        "deletedAuthenticatorCount": 2,
        "deletedDeviceCount": 3,
        "deletedUserOperationsDataCount": 1,
        "deletedIdentityMethods": 1
    }
}