Using the Admin Console, you can configure the Digipass S3 API Server and Authentication Server, and perform operational tasks. It's important to control who has access to these critical functions. Admin Management enables you to create an administrative user and specify what they are permitted to do for major functions in the Admin Console.
This section covers:
Admin management concepts
There are four important concepts behind Admin Management that are described below.
Tenant
A Digipass S3 tenant is a logical concept that translates into an organization. It enables you to divide your customers into logical groups. For example, you could create tenants for subsidiaries in your global organization. Or you could create tenants based on geographic regions like Europe or North America.
When you configure Digipass S3 Software, you are configuring apps, authenticators, Adaptive Rules, FIDO policies, and so on for a specific tenant. As a result, you can tailor the authentication level and field different apps for different audiences using tenants. If your company doesn't need to define multiple tenants, you can use the default tenant that is automatically created when you install the Digipass S3 Server.
Resource
The work that you can perform using the Admin Console is divided into several logical categories called resources. These resources deal with product configuration, user management, and so on. You have the ability to control access to each resource.
The table below lists resources, their descriptions, and the navigation you use to reach their associated pages in the Admin Console.
Resource | Description & Admin Console Pages that Belong to the Resource |
|---|---|
Configuration | Includes configuration for the Authentication Server, API Server, and the Admin tenant. The permission for this resource controls whether you can import and export information from the Admin Console.
|
Configuration > Apps Configuration > Authentication Methods Configuration > Encryption Keys Configuration > API Server Configuration > Custom Configuration > Import/Export Configuration > Admin (Only visible in the Admin tenant.) | |
End User Management | View, deregister, suspend and/or resume a user's authenticators. You can also perform a wildcard username search to find end user records, and view registration and authentication history for end users. |
Administration > End Users | |
Metadata Management | Metadata for UAF, FIDO2/WebAuthn, and U2F authenticators that your apps support.
|
Configuration > Authenticator Metadata | |
Rulesets | Includes rulesets and all their supporting objects such as lists, FIDO policies, and so on. |
Authentication > Adaptive Rulesets Authentication > FIDO Policies Authentication > Authenticator Groups Authentication > Countries Authentication > Device Models Authentication > Geofences Authentication > IP Addresses Authentication > WiFi Networks |
Permission
A permission is the level of access that an administrative user has to a resource. You can only assign one permission to access an operation. Valid permissions include
None
Read
Write (includes delete, create, update, and read)
When an admin has no access to a resource, the Admin Console omits the associated menu items so an admin user cannot navigate to the resource's page or pages. Buttons are also disabled if those operations aren't permitted.
The permission for the Admin User Management resource is different. That permission specifies the type of Admin user you are, see the next section.
Administrative user
An administrative user manages the configuration and operation of Digipass S3 Authentication Software through the Admin Console and is different from an end user of client apps that your organization develops. There are 2 types of administrative users: Admins and Super Admins. These are described in the table below.
Admin User Category | What They Can Do | Scope of Their Authority |
|---|---|---|
Admin |
|
|
Super Admin |
| All tenants |
When you first assign a user to be an Admin, they are automatically assigned read access to all resources. You can promote an Admin to be a Super Admin. As soon as that happens, that Super Admin automatically gets write access to all editable resources. You can also demote a Super Admin to be an Admin.
You can create an operator by assigning write access for Rulesets and Configuration and no access for the remaining resources. You can create a customer service representative by granting write access to End User Management with no access to any other resource.
Create an administrative user
You must create administrative users in the Admin tenant so they can use the Admin Console. The Admin tenant is automatically created when you first install the Authentication Server. The Admin tenant is a special tenant that you use when controlling the admin console's authentication behavior. Both Admins and Super Admins can create Admins. Only a Super Admin can create other Super Admins.
Instructions
Creating a new administrative user is a 2-step process. A current administrator must create the user, assign their permissions to resources, and send them a registration code. Then, the new user must register using the code within 48 hours.
Using the Admin Console
Login and navigate to Administration > Admin Users.
On the Admin Users page, select User > New.
.png?sv=2026-02-06&spr=https&st=2026-09-30T02%3A13%3A26Z&se=2026-09-30T02%3A31%3A26Z&sr=c&sp=r&sig=zkkazE8XW5fdmhSHBBEA9u87bMn6yACRW%2FgYtVUt3qQ%3D)
Fill in the user's information on the Create New User dialog. Select the tenant from the Tenant dropdown and click Submit Request.
A dialog appears that confirms user creation as well as displays a user name, registration code, and the URL to the registration page. Copy this information to use in step 6 and click OK.
Important: Save the registration code, you cannot get it back.Set up the permissions for that user by clicking the checkbox in the first column and choosing User > Edit. On the ensuing dialog, click View/Edit Permissions. You can also specify whether the user is a Super Admin or Admin. See Assigning Permissions to Admin Console Resources.
Send the username, registration code, and the registration page's URL to the new user. The registration code is good for 48 hours. This time limit is not configurable.
If the person doesn't use their code in 48 hours, generate a new registration code for them.
Registering
New administrative users must register using the following instructions. They can verify their identity using either a FIDO2 authenticator or by scanning a QR code using the OneSpan Passport app on their mobile device.
Open the URL to the Register page. Enter the registration code and click Register.
.png?sv=2026-02-06&spr=https&st=2026-09-30T02%3A13%3A26Z&se=2026-09-30T02%3A31%3A26Z&sr=c&sp=r&sig=zkkazE8XW5fdmhSHBBEA9u87bMn6yACRW%2FgYtVUt3qQ%3D)
Next, the Admin Console displays the Authenticators page.
.png?sv=2026-02-06&spr=https&st=2026-09-30T02%3A13%3A26Z&se=2026-09-30T02%3A31%3A26Z&sr=c&sp=r&sig=zkkazE8XW5fdmhSHBBEA9u87bMn6yACRW%2FgYtVUt3qQ%3D)
Register one or more FIDO2 authenticators and/or native authenticators on your iOS/Android mobile device.
FIDO2 authenticator: To use a built-in authenticator on your device/computer, click the toggle next to Platform Authenticator. To use a FIDO2 security key, click the "+" next to Security Key.
iOS or Android mobile device: Make sure that you have already installed the OneSpan Passport app on your mobile device from the App Store or Google Play store. Click Register OOB Authenticator Using OneSpan Passport App.
The Admin Console displays a QR code.
Launch Passport on your mobile device and scan the QR code.
Select the authenticator on your mobile phone that you want to use to complete login in the future.
You are returned to the Authenticators page. Your new credential appears in section Manage Authenticators.
Generate a new registration code
If the user wasn't able to use their registration code and it expired, you can use either the Admin Console or nnl-mgmt.sh to create a new one.
Using the Admin Console
Login and navigate to Administration > Admin Users.
On the Admin Users page, select a user by clicking the checkbox in the first column. Select User > Generate Reg Code.
.png?sv=2026-02-06&spr=https&st=2026-09-30T02%3A13%3A26Z&se=2026-09-30T02%3A31%3A26Z&sr=c&sp=r&sig=zkkazE8XW5fdmhSHBBEA9u87bMn6yACRW%2FgYtVUt3qQ%3D)
A modal dialog appears with registration code for the selected user and the URL for the registration page. Copy and send to the user.
Using nnl-mgmt.sh
The example below shows how to generate a new registration code for the user jsmith.
./nnl-mgmt.sh admin generate-reg-code -userid jsmithAssign permissions to Admin console resources
The table below lists the default permissions when you create an Admin or Super Admin.
Resource | New Administrative User Permissions | Default Super Admin Permissions |
|---|---|---|
Admin User Management | None | Super Admin |
Configuration | Read | Write |
End User Management | Read | Write |
Metadata Management | Read | Write |
Rulesets | Read | Write |
You cannot change a Super Admin's access to any resource.
Admins cannot modify their own permissions. In addition, Admins can only grant permission to resources that they can access at a level equal to or less than their own.
For example, Sally Smith is an Admin who has read access to Configuration. She cannot grant write access to Configuration to another Admin because she only has read access. Likewise, if Sally has no access to Metadata Management, then she cannot grant read or write access to Metadata Management for another Admin. This prevents an Admin from circumventing security by creating a super user.
Instructions
Use the Admin Console to modify permissions for Admins by performing the steps below.
Login and navigate to Administration > Admin Users.
On the Admin Users page, select a user by clicking the checkbox in the first column. Select User > Edit.
When the User Information dialog appears:
If the new admin is a Super Admin, select super admin from the Admin User Management dropdown list. The permissions for the resources are automatically set for a Super Admin.
If the new admin user is an Admin, select admin from the Admin User Management dropdown list.
To set an Admin's permissions for the resources, click View/Edit Permissions. The Permissions dialog appears. Modify the permissions for the resources to match the access you want to give to this user. Click Back.
Save your changes by clicking Update on the User Information page.
Switching tenants
If you are an administrative user who can manage several tenants, you can easily switch to a different tenant.
Under the Admin Console's navigation bar, there is an informational bar showing your user name and the tenant. Click Switch, located next to the tenant name.

The Switch Tenant dialog appears, select the tenant name from the dropdown list and click Switch.
Adding an Admin to a tenant
When you create an Admin, they automatically can manage the tenant that they were created in. You can add an Admin to a different tenant using the following instructions. Note: Super Admins can automatically manage all tenants so this function doesn't apply to them.
Use the Admin Console to add an Admin to a Tenant:
Login and navigate to Administration > Admin Users.
In the Admin Users page, select one or more Admins by clicking the checkbox in the first column.
Select User > Add to Tenant. Select the tenant name.
Deleting an Admin from a tenant
Use the Admin Console to remove an Admin from a tenant. If you remove the Admin from all tenants, the Admin is deleted from the database and their FIDO registrations are removed.
Login and navigate to Administration > Admin Users.
In the Admin Users page, click the checkbox in the first column to select one or more Admins.
Select User >Delete.