Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

OIDC Federation support

Prev Next

The App SDK provides an interface to integrate FIDO authentication into an existing OIDC Federation infrastructure. Use this interface as an OIDC Federation client. After an end user authenticates and your app receives the AuthenticationData object from the App SDK, initiate the OIDC flow:

if let jwt = (authData?.sessionData.object(forKey: "sessionKey")) {
    let params = NNLOidcFederationParams(authFlow: URL(string: "<OIDC_AUTH_URL>"), jwToken: jwt)
    params.federationResumeUrl = URL(string: "<OIDC_RESUME_URL>")
    params.tokenUrl = URL(string: "<OIDC_TOKEN_URL>")
    let fedClient = NNLOidcFederationClient(params: params)
    let promise = fedClient.performCodeGrantFlow()
    promise.then({ result in
        if let result = result as? NNLOidcResult {
            print("ID Token = \(result.id_token ?? "nil")")
            print("Refresh Token = \(result.refresh_token ?? "nil")")
            return NSNull()
        }).error({ error in
            print("Code grant flow operation failed with an error. Reason: \((error as? NSError)?.localizedDescription ?? "unknown")")
            return NSNull()
        })
    }
}

Class NNLOidcFederationClient contains methods that support the following OIDC flows:

  • Authorization code grant

  • Implicit

  • Token refresh

Working example in Tutorial App

  • AppDelegate.swift shows how to initiate OIDC flows.