The API Server acts like a gatekeeper on the amount of information that is returned from the Authentication Server to the App SDK. If your app specifically requests additional information, such as the user's device or the authenticator and authentication method that they used, then you also need to modify the API Server's response filter to allow that information to reach the App SDK.
Export an existing tenant-specific configuration object called Main and modify it to configure the response filter. The command below shows how to export this object from the database for the default tenant.
./nnl-mgmt.sh apiserver export -tenantid default -type Main -name Main -file Main.jsonEdit Main.json, the file's contents are similar to what's shown below.
{
"mfas_response_filter":{
"additionalInfo":{
"device":true,
"authenticatorsResult":[
{
"handle":true
}
]
}
},
"origin_allowlist":[
]
}Response filter configuration uses a JSON structure that specifies which data the API Server should allow through. This structure is assigned to an attribute called mfas_response_filter. See Response Filter Configuration to create a response filter configuration that you can assign using either the Admin Console or upload using nnl-mgmt.sh.
Main.json also contains the entry origin_allowlist that contains the URLs for trustworthy web client apps. Examine that to make sure those are web apps you want to allow. See My Web Client Apps Have a Different Origin than the API Server.
After you have made your modifications, use one of the instructions below to update the information.
Using the Admin Console
In the Admin Console, login and, if needed, switch to the desired tenant. Navigate to Configuration > API Server > Main.
.png?sv=2026-02-06&spr=https&st=2026-09-30T02%3A59%3A31Z&se=2026-09-30T03%3A10%3A31Z&sr=c&sp=r&sig=Vlu19al0AOe%2B4AG4I1B%2BheAN%2BbhGLB8S0LQgwPQvG0k%3D)
Click the value for Server response filter. Enter the JSON for mfas_response_filter.
Using nnl-mgmt.sh
The apiserver import command expects a file containing an API Server Main configuration object, this needs to contain both the mfas_response_filter and origin_allowlist fields. Below is an example using nnl-mgmt.sh's apiserver import command to import a modified Main.json for the finance tenant.
./nnl-mgmt.sh apiserver import -tenantid finance -type Main -name Main -file Main.jsonFor details on apiserver import command, refer to API Server Configuration Commands.