Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

My web client apps have a different origin than the API server

Prev Next

The Digipass S3 API Server handles all communication between the App SDK and Authentication Server. By default, the Digipass S3 API Server rejects requests from URLs that are different from its URL. If your web client apps have a different origin than the API Server, you must add those URLs to an allow list. To do this, use either the Admin Console or nnl-mgmt.sh.

Using the Admin Console

  1. In the Admin Console, login and, if needed, switch to the desired tenant. Navigate to Configuration > API Server > Main.

  2. Click Add an origin. A textbox appears under the last list item. Enter your client web app's URL.

Using nnl-mgmt.sh

Export an existing tenant-specific configuration file, called Main.json, and modify it to include your trustworthy web apps. The command below shows how to export this file from the default tenant.

./nnl-mgmt.sh apiserver export -tenantid default -type Main -name Main 
-file Main.json

Edit Main.json, the file's contents are similar to what's shown below.

{
    "mfas_response_filter":{
        "additionalInfo":{
            "device":true,
            "authenticatorsResult":[
                {
                    "handle":true
                }
            ]
        }       
    },
    "origin_allowlist":[
    ]
}

Add the trusted URLs to "origin_allowlist", as shown below.

    "origin_allowlist": [
        "https://example1.com", 
        "https://example2.com"
    ]

Main.json also contains an entry (mfas_response_filter) that configures the API Server's response filter. Examine that to make sure that is the behavior you want. For details on specifying the API Server's Main configuration object, see Main in API Server Configuration Objects.

After modifying Main.json, you can import it. Below is an example using nnl-mgmt.sh's apiserver import command to import Main.json for the investment tenant.

./nnl-mgmt.sh apiserver import -tenantid investment -type Main -name Main -file Main.json

For details on the apiserver import command, refer to API Server Configuration Commands in the command line interface.