URL: /nnlgateway/nnl/<tenant_id>/reg Method: POST |
Although registration is triggered from a first device (usually a desktop browser) that starts OOB registration, it is actually completed on a second device (usually a cell phone). The second device sends the requests to initiate OOB registration and finish OOB registration. The second device can also cancel the OOB registration. There are also 2 status operations: one for registration and the other for cancellation.
The following operations are available:
OOB Registration Operation | Called by |
|---|---|
First device | |
Second device | |
Second device | |
Second device | |
First device | |
First device |
Out-of-band registrations always use the FIDO protocol, which includes both UAF and FIDO2. In most cases you need to start the OOB registration process by calling INIT_ADAPTIVE_REG, but then you call the operations listed above instead of the corresponding operations in the section FIDO Registration. Once a FIDO OOB registration is completed, manage it just like any other FIDO registration, using the operations in Manage FIDO registrations.
You can choose one or more of the following mechanisms so the user can register an authenticator on the second device to use for future authentication. This document refers to these mechanisms as OOB mode.
Display a QR code on the first device that the user scans using the second device.
Use a custom mechanism that you implemented
Implementing a custom OOB mode is outside the scope of this documentation.
You can only register a FIDO authenticator by scanning a QR code or using your custom OOB mode. Any of the three OOB modes (QR code, push notification, or custom OOB) can be used to authenticate.
See FIDO Registration to understand how the API Server determines the FIDO policy to use for OOB registration. To perform OOB registration, the Authentication Server uses the FIDO registration policy to determine the valid UAF and FIDO2 authenticators that can be used. For UAF authenticators, the Auth Server refers to the allowed UAF authenticators specified by the FIDO policy and device information to create a list of permitted UAF authenticators from which an end user can select to verify their identity.
For FIDO2 authenticators, the Auth Server compares the authenticator's characteristics to the desired FIDO2 authenticator characteristics specified by the registration policy. The client uses these as hints to prompt the end user for the authenticator. The Auth Server enforces user verification and attestation preference during FINISH_OOB_REG based on the policy configuration.
Refer to Create FIDO Policies to create an authentication policy.
START_OOB_REG
Starts out-of-band registration from the first device.
Use the boolean attributes defined on the oobMode object to specify the OOB mode you want registration to use. You must specify at least one OOB mode.
oobMode.qr - to generate a QR code
oobMode.rawdata - to use your own custom OOB mode.
If successful, START_OOB_REG generates and returns a string for the QR code image that the first device displays to initiate registration.
Request
Attribute | Description |
|---|---|
operation | Required. The string START_OOB_REG. |
callerOrigin | Required if a web app is sending the request and that app has a different origin than the Digipass S3 API Server. A web origin is defined by the scheme (protocol), host (domain), and port of the URL used to access it. The API Server checks if this origin is listed in its origin allow list, if not, the request is rejected. See My Web Apps Have a Different Origin. |
id | Optional. The correlation ID, a unique identifier that associates START_OOB_REG, INIT_OOB_REG, and FINISH_OOB_REG operations for the same user. Use id to identify the desired OOB registration when you call STATUS_OOB_REG and CANCEL_OOB_REG. An alphanumeric string, maximum 255 characters. No special characters are allowed. If not provided, the Server generates a unique id and returns it in the response. |
oobMode | Required. Object with 4 attributes, which are listed below. |
oobMode.qr | String. One of:
|
oobMode.qrType | Optional. String. Directs the Auth Server to generate the specified QR code. One of the values listed below, these are ordered by the size of the QR code they generate, from largest to smallest.
|
oobMode.rawData | String. One of:
|
oobMode.webUrl | Required if oobMode.qrType is either UNIVERSAL_RP_SPECIFIC or UNIVERSAL_ANY_RP. The web page URL that handles OOB registration. The Server encodes this web page URL in the generated QR code. String. |
oobRefId | Optional. ID provided by the RP app to retrieve contextual information from the RP server that can be displayed to the app user. This helps maintain continuity when a user is performing a transaction or task. The oobRefId sent in this request is packaged inside the oobData in the QR code displayed by the app running on the first device. The app running on the second device retrieves this when it scans the QR code. An alphanumeric string, maximum of 512 characters. |
optionsData | Optional. An object used to pass additional attributes to REST API operations. See OptionsData for a complete description. |
sessionData | Required. An object containing the user's session information. See SessionData. |
Response
The following attributes are always present in the JSON payload of the response.
Attribute | Description |
|---|---|
id | The unique id that correlates the START_OOB_REG, INIT_OOB_REG, and FINISH_OOB_REG operations. String. If id was sent in the request, the same id is returned. If not, a server-generated ID is returned. If id was provided in the REST payload but the server was unable to parse the payload, the value is unknown. |
statusCode | Server-specific status code that reports the success or failure of the requested operation. Integer. See Response Status Codes below for the status and error codes. |
The following attributes are present in the response upon a successful operation (Server status code 4000).
Attribute | Description |
|---|---|
additionalInfo | An object containing information returned by the Authentication Server. Contains the 2 attributes listed below. In order for the API Server to return this information:
|
additionalInfo.elapsedTime | The number of milliseconds to process the request. |
additionalInfo.oobRefId | ID provided by the RP app to retrieve contextual information from the RP server. Alphanumeric string. |
lifetimeMillis | Lifetime of the oobStatusHandle in milliseconds. Long. |
modeResult | An object containing the server-generated QR code and/or raw data needed for your custom OOB mode. Has 2 attributes: qrCode and rawData. |
modeResult.qrCode.qrImage | The server-generated QR Code. String (Base64-encoded PNG image). Returned if oobMode.qr is true. |
modeResult.rawData | Raw data to send to the second device when you are using your own mechanism in place of a QR code. String. Returned if oobMode.rawData is true. |
oobStatusHandle | Uniquely identifies this OOB registration operation. An alphanumeric string, maximum 4000 characters. Pass oobStatusHandle to STATUS_OOB_REG to get this OOB registration’s status. Any operations using oobStatusHandle must be completed within lifetimeMillis. |
Response status codes
The following are the descriptions of the Auth Server status codes returned by START_OOB_REG. Under certain circumstances, the API Server returns an unsuccessful HTTP status code. Examples include an invalid request or invalid session. You can find descriptions of these in API Server Status Codes.
Server Status Code | Description | Examples |
|---|---|---|
4000 | OK. Operation completed | Registration operation OOB started successfully. |
4404 | Internal Server Error | Internal server error. Failed to read from the database. Failed to connect to the database. Failed to read required properties. |
4406 | Payload Exception | An error occurred with one or more attributes. For example, oobMode is INVALID. |
Samples
Sample request URL
https://www.example.com:8443/nnlgateway/nnl/<tenant_id>/regSample request
{
"operation":"START_OOB_REG",
"sessionData":{
"sessionKey":"<session JWT>"
},
"id":"sample",
"oobRefId":"12345",
"oobMode":{
"qr":"true"
}
}Sample response
A developer updated the response filter configuration so the API Server returns the OOB Reference ID in additionalInfo.
{
"statusCode":4000,
"id":"sample",
"lifetimeMillis":180000,
"additionalInfo":{
"oobRefId":"12345"
},
"oobStatusHandle":"a2V5aGFuZGxlAAAAAj-qU25O-OOk3m308NX9CPlEVKJkR6q0447dLIszkI9uoln1U0TEi0DU1Arnc7CPNxDdNebgltEAHogj2DQ2yt2XNVPcVlclVV47-LzAV1aZyCUN38hA_Tof5O8",
"modeResult":{
"qrCode":{
"qrImage":"iVBORw0KGgoAAAANSUhEUgAAASwAAAEsAQAAAABRBrPYAAAC9ElEQVR4Xu2YUW4DIQxEuYHvf0vfgM4bSKvQSu1XZz/wRskufonA9hjaMf9iPc6RH+1ih13ssIsddrHDLnbYxQ7bWI8xZhWPLdsPaziO6aWxHl2zphg91CiG85iAWaNFzS5dkxWUh5+AMWuRTFqxHXoR6GdgjqTWoHR3EVvK4AkYZDN57kXx5i8+AGPeP9gpmQRmK1KuwK6ZK8BfriRmKW+Ue2DdlSyOKfF2FNJpiWVSloXC85ianqbOAug2WyvK++tXgpinK9b9xe2vXJDfspDAmDVy5lE36Hmyg6DvOOa2N2iD7dmv1K/vhTFpZDi29GWTrsntjmJbutYNAD1HiyDqcYyoIpBCMMa9oMFHGgNkiOiy7254cmiJY+5/mjNnASqTBwpzUVGM2dpBsuF4GyjozML/Y9w1MybjqgDHVtTePbIYgllemqC8n895DOfqMUxbq9g777GECIZC2NMAUY5yPng8lZXAercV2h93xRbCoWq7gxg9kCUsBRPVItBEPY7hkYtx6pIY77uXO4c1F0783JP1wed7R4pgJJztFqUMDlDcEPRlSYxFTJJP91uKRsvtUk1jVrN79Eq310CI948kscbheDLAk3shh4I05v7sJehC08R5xTiPDSJMb6Y0mXt7f6MI0hiNufGL4shuirftTmKruRQNZroFomXm/60jBbDVY9guiDLt0KXw0kwSY/cv/tmqVaAdd0SK8kx9AqOvsIpaCgagK+4VZDFRmjU1Sba1HnmoVBdDFtOHJQM1HGi6jajxXpYRjJaMlntBOJs/yb5+JogBkXtaM7Xoo9Qr81GMZ/ze39rC5qtceWxPuS3m4fHitHK0mgxGiNEHb2vbtaJPZQUwa5dhGGqRrkNhLsVkMV7sIQgZNwryEh6AMXHH1gkHZvNlXc/A6M3uNGy7VCVpX2uIYzTp8qbbvtiD37fdDGZy0qGRNccVFuG1xLHhPZaEczLgjm+OXZVR7De72GEXO+xih13ssIsddrHD/op9AHTt+9RovXr6AAAAAElFTkSuQmCC"
}
}
}Sample request with qrType=UNIVERSAL_ANY_RP
{
"operation":"START_OOB_REG",
"sessionData":{
"sessionKey":"<session JWT>"
},
"id":"sample",
"oobRefId":"12345",
"policyName":"default",
"oobMode":{
"qr":"true",
"qrType":"UNIVERSAL_ANY_RP",
"webUrl":"https://www.example.com:8443/"
}
}Sample response when qrType=UNIVERSAL_ANY_RP
A developer updated the response filter configuration so the API Server returns the OOB Reference ID in additionalInfo.
{
"statusCode":4000,
"id":"sample",
"lifetimeMillis":180000,
"additionalInfo":{
"oobRefId":"12345"
},
"oobStatusHandle":"a2V5aGFuZGxlAAAAApz53PPjA9gP61uUhwFZsseZ2q7po5LRzfIQz42Ci4CYO-NY5mTEUiz2JIejaE8l-DtIZpiE79Q76q2OzzAjge5nVc8iiTkGP75xLdUWQXAJ9xDjpHsMnh08HtQ",
"modeResult":{
"qrCode":{
"qrImage":"iVBORw0KGgoAAAANSUhEUgAAASwAAAEsAQAAAABRBrPYAAADS0lEQVR4Xu2XbW4bMQxEeQPe/5a8ATtvZBTZTYD0l8dAV3W8svQEiB9Dbmv/ZUzdV34cD3YbD3YbD3YbD3Yb/xs2VbW9zGf0rNa0dtobYYztqjHTw7Y2dJKNNKbl7S6P5t9qYThRn4DB9XGmJ/raT8G0plVN5ecG1c5HYJD6xgKtaEpuFrNvGfJ2rJyTPwzYLOYhhyoRm3yUU7VtUZ8RxLTIhMpit5KVeLsZYYwC6FUJmA9HOEjYv4Q+grkWU6MtEG7NIds1Xy2NYBIMFdkNRLLmo3MDeoAgttx3qcsyxn5eZyUFMY35oq5+WlACeMbxu+oTmP1YczQy/Oqzegl9CKPZct3ChKKridAyeZrF+gT6xB+vagUEN4cxwHPdpvW6BoK6KKYxqgwOtS3cXqfw9LXUZDBcu7yckJNYQfUhO2HDGEG3aMrRljX1ylNbkMQsGc1cXqh8be3IsjqaCWL8dhZydQJPr2NVLr6G/v0YWuHTzkqmJAKABR7F9PMVeXsW4fCKTPhJ0SgmraCRIvj42NXGJJMsBgdI4D315ZE3tTqMrb2piA/3P/WQLLU5YYx9+sZgjQu1l42HMRD+3De4OfLBFhl2ScsApge6JfLIxqF3ih4JZTGqDDlIacHFa9cur3rHxhw2/OfGl7dSGtpCPs6NYuv+gSPd4ViURbwcuI1EMZtQVL7BBv44wX+ALq0tgUkvNkEQfYTo84SyYVGMUoMznYSDU3V12prf3qMY3772cMB+dVPTmqkwxp0RDMqhJi5ubr+7pLFmG3/ScC0XZSgCOv0jiO1pIItLm9Y2LjUnV9OYXzx5ByAxHXVnJm7/mxsxzEWGB333+NZ6edXoIMa3Yiw75GV2oTDHxTGMLWXGluBYsPIh/B7Gli7BihOSNJAJxc+9RCGBIWPfG1VzwM2N1sH5MIYwcCwO5ZQlQ4q6CEUxT5yHi2QK2SxtpFBOHHvF+Ai5MYhKyOkwpqsWNlCoeRD6xRr9vkYhgPGhIp872ww8zIP9KObAE+yyPRayLo9pF2WlsGXDO85OtxO8/AkYwWeXSs31x5vf3Pt2DLLdQvCmGpqLDY0kj5Wb2qsoIxMSlKpDqc5iv44Hu40Hu40Hu40Hu40Hu435A9M32o5puUR1AAAAAElFTkSuQmCC"
}
}
}Sample request with qrType=UNIVERSAL_RP_SPECIFIC
{
"operation":"START_OOB_REG",
"sessionData":{
"sessionKey":"<session JWT>"
},
"id":"sample",
"oobRefId":"12345",
"oobMode":{
"qr":"true",
"rawData":"true",
"qrType":"UNIVERSAL_RP_SPECIFIC",
"webUrl":"https://www.example.com:8443/"
}
}Sample response when qrType=UNIVERSAL_RP_SPECIFIC
A developer updated the response filter configuration so the API Server returns the OOB Reference ID in additionalInfo.
{
"statusCode":4000,
"id":"sample",
"lifetimeMillis":180000,
"additionalInfo":{
"oobRefId":"12345"
},
"oobStatusHandle":"a2V5aGFuZGxlAAAAArEHCGN74lechjjgjamKXHHQKjiTujzmKNjpbWXihxTodTt32c-YSaAuLji2uw_TjV20ZXblcLlhiBWB7nZw2Xvh9KPSu4-IhjbiBSDfuH-4RFWIQ6wK5AUB2aY",
"modeResult":{
"qrCode":{
"qrImage":"iVBORw0KGgoAAAANSUhEUgAAASwAAAEsAQAAAABRBrPYAAADAElEQVR4Xu2XUW5rIQxEvQPvf5feAfUZk/cUGqn96twPUJsQODfCAx6TWL9pFefIx3axo13saBc72sWOdrGjXexoG6uIWJGZFVUrIxfdGbZj/VfMNlXZH3mvZNiP9dLpZ685erY0mxp+AoauLTHTmYBE8RAMaLWkRBGgMcN2DBJx+3OvvQ9BTvfDCflzrFeNmmcjGDemxqrJakXTWfN/xooVwvaKs3KyZrHneA/H1I31eWSjY+Y5lfrMixkjVVrSFhhz5qkOiKSZCKxYYczKZjY95dKt8zd5LdjUDdlgYjTKFY7pA7DQohcyS1t8WmOveSOG7UneEZbnZIgzbcX0rjsAtxYpnbq/vIdgwWTGiahkTHcRuFN5O7QXk5T4C56jI5nkTxyOZMFkLWjJ5mvx/Vlebcd6VF2WPwegH0RmHjJjSuFg0/nAY0TDw9O8WGI0lDSd0LnGp7bfjnEcERlRSRuomiyyY2t784AapU9UbkzrRdMOBHm5G0jod3ktWJEyC4QrQZHG2I7G/VhrWaw51ZHWdHeEVowiq2pLIhfVTUHJFN1YbzfJQkmjh+kkFn2kjANb84NH9gLPI2OLr68xYkHeBpc7PIZrsXxxZ7MV0/WTqYUj6t6SnNRULfFiiIs3N61fi8naJ4n8GEWNdbPfmCIhlA6AH8NeyI+YklEYDg/w78aSnxGSlQHBmOJhNSZs9n57Cx0uK/spO5YsGj17y/sAcAqwGz9WWM1EwNYnedO1owWfb7Fii1TZCpM+yd2YIPwYNTekZ5I7iIzprMluN7b2MO+s/HUE/slvw4hg7eNIVqt4LLJ8f4sRo1r0INUCRbmnUERQ249R0eZQLqUwjigf3CFasaUKAsgBYJTc+RaCASsEpZ6RyN0W9Zfytr/FivHHTmM6+idvCOEBGMvX0ll8yHDUU+I8ASNHZIF4dY8R0psNWjG8T0bd+57cEz6H8LeYSMyFo6nCyytq+zE2WemCuD1XZHWS0Xbsp3axo13saBc72sWOdrGjXexov8W+AOpfqVRc/KPFAAAAAElFTkSuQmCC"
},
"rawData":"https://www.example.com:8443/#nnl-oobdata=%7Cr%7Ca2V5aGFuZGxlAAAAAnxBifk3A8oCWCEH_CntrzNSkYtakM_UCHuVmW3FeKoZTtL8SmqkbFiyOewc3BN0sZ-gGWGKNr6hKsDXRG79hLRsXOSU6rOmMFO-Fv-N8C37gV2_krZvu6KZd7hQLM0%7C12345%7C"
}
}Sample request with qrType=APP_ANY_RP
{
"operation":"START_OOB_REG",
"sessionData":{
"sessionKey":"<session JWT>"
},
"id":"sample",
"oobRefId":"12345",
"policyName":"default",
"oobMode":{
"qr":"true",
"qrType":"APP_ANY_RP"
}
}Sample response when qrType=APP_ANY_RP
A developer updated the response filter configuration so the API Server returns the OOB Reference ID in additionalInfo.
{
"statusCode":4000,
"id":"sample",
"lifetimeMillis":180000,
"additionalInfo":{
"oobRefId":"12345"
},
"oobStatusHandle":"a2V5aGFuZGxlAAAAAtddwMgKIA8ebPjirjDRm7haDH_uzmoKn4n26G_aSOHwKOqBWKEWG0310X5R0AoQ5qHaUAGFZRwlpkCzde0WgDCnE4bg37rjImoitIq1YqMCnb-Z1gBvMdKTK6Y",
"modeResult":{
"qrCode":{
"qrImage":"iVBORw0KGgoAAAANSUhEUgAAASwAAAEsAQAAAABRBrPYAAAC+klEQVR4Xu2XUa7rIAxEvQPvf5feAW/OmEo3qNK9X8/5gKYKgZMKBo+hsf5SKs6Wr+ViR7nYUS52lIsd5WJHudhRNlYRURnBc+QqPlVunse4MoqSK7PornTzOFZRGnuulR65ahnU4y2YJA7NQwrrJrHrPZgGv7z69KmBljdgvnJFg1p+BSnB+SVC/juGtF/KaZkJzFWvuiKAr+fxo28Q22JmpaKRpVdguu2QdwLTquNjSSxOqgrDMzhnHkPQJNX0K7ZP4ununcUKRGvfSQaBTR7yTmDYA2GTu1UmOJnI7p/EEBcxSXwkaj0Rms6I0xg7GU9tHKKgrDMaT2Pci+Ak8yG0dE0OLg/LzGBkFq8+BwHHpbMhITCN4WbLap2JSo5TVJ+pZgbzBBaHJ0zdVkncM45hYla6I9HTsbBb3VFssdpU4VAUZR2ez5lOYJLWa13orJkE64958NEwxhlFIy90DQcpWdEN85jugbZsuEyBrZdpPbePEQwpHZIo68hUriYcdlwOYyy/D+sdkGzARt+A9bB7AuxtbB+A4xh30qC/+pAQE+hw/QjGH/6wxp/pYBjCcx7TYvdNTWy3PMs8P2Y4hpWPKV5tTC0Cc5MRjwgZwHTnFKDM4pCkVS/gmM/PzGEEID30gfCIutvNsxhaLk514Oxx6vDVcTmKoSgSk5SxT5/4VgfrLEYj1fYNf8t8PCAKxjEGrS5lvUBaqrY0phnHkjNAJ8HcAGAcrp/AcAt9yZZGetYs4Oykaay8+gyZwOwdjffw9zTmpScGJXQwn+pz3841oxiq7s2XmOQsaqG7dxTzPsHAOUPxQJ5B9OfSj2DeM7qaNjRz8ZRegKml8ElnGwkb7GuI/QLMEhcBQLJmEq34POZh9xZSFM4Dru5fGcW4MC+cGknUfufY2kYw1jydcfSl7ntAvwLDyhiFGKCnLf0KDC018mT7aFe7Mo9B1v6z6OOAMyFCz2M04xFmEjZykQQ/Ak9iv5WLHeViR7nYUS52lIsd5WJH+Sv2D3cf0DyjkkAHAAAAAElFTkSuQmCC"
}
}
}Sample request with qrType=APP_RP_SPECIFIC
{
"operation":"START_OOB_REG",
"sessionData":{
"sessionKey":"<session JWT>"
},
"id":"sample",
"oobRefId":"12345",
"oobMode":{
"qr":"true",
"qrType":"APP_RP_SPECIFIC"
}
}Sample response with qrType=APP_RP_SPECIFIC
A developer updated the response filter configuration so the API Server returns the OOB Reference ID in additionalInfo.
{
"statusCode":4000,
"id":"sample",
"lifetimeMillis":180000,
"additionalInfo":{
"oobRefId":"12345"
},
"oobStatusHandle":"a2V5aGFuZGxlAAAAAj76lWNLqqmhXLgSBji1QS7dYV1T48L0shLGeFmEYoETrrvciKJ72NptgSozDm8KgJHwhLtQ-Zl0OglQHSxih7BE7J2XqsFBvwVaTEZPg8cQZxTx4uiquPmrOdo",
"modeResult":{
"qrCode":{
"qrImage":"iVBORw0KGgoAAAANSUhEUgAAASwAAAEsAQAAAABRBrPYAAADHUlEQVR4Xu2YPY6kMBCFCxEQcgTfpLlYSyBxMfomPgIhQatr33tmRotnpd1gA5dEBYwNn1uqqX+b/4vsVr/5o9xYJTdWyY1VcmOV3FglBTsM4h+zZNNuNmzYDi9fM/72QbDJPR+dvxNX7i9/m3X7nLFeg2AP6zPUnd0/49uwJQHssDES5hteHd3+tMGhM77xaCjsmOBqsNNi9hgXGz7SPgw20d8eo7tiBNuV7uew2E+3bBRj1ANbyf7+qKK+YUwCw1DnvZfTJW2/pH3sYJJCxu1drmbwMm2zPZgJQmD4kgaGOXd8jQMTF6+9smnDGJLtBtgZI4ZoAYZTLINBsM6XhIdercxjczb623DVtGFMSqJoLKUF0RaaPpOpKobAQCTUb5iIFRARBPf7GDCaLQSGdAV/o2FEsCC6jFVFfcMYG6jEdCVNE/sQdIOwHTNaDAylYmEFXOhnEOqnMELIRMEmvvpA04GtFIz1TM6Gtva3hjFqSgIfaSdWQOVePmJgrqbv5Z5pnYyAn5mAFfXKx+1j0hRaKeCtrHCAq/IjAbCOOYshgzm7P1vCibXwGvVNY2WO+JqHZKcyLV2M1TJ2zkPvNGwIfSYBKyv+C2JgSrtlFOKKZdDIqgyGwFC/VfdY8vBg/HPA8OJ5ITDaia6GkU7qsprg9VJ1gy1j6qJ0y3eOQmwJgaRr1DeOqY3VMMGbv7LyLLOFwKQVisbsGCtmJi4ofp6fg2AIj8wY4RWZVgujHj7oVeJqFtOVpbNqD2xGsF04KCkJSNrHsINWipuNXualD5lZAaNgzLO6tEf2Muq30t+UhdcYGGQFMaoPmRUtmWx1e9w0xvs+Xm+oCc88xZmVfchF04Yx1uqMXlaXl6aO5Ls30c+0j0lgmPdJdMzC3915CIzlw9jGlj6ESrJ+qzufg2CTMi7vBtSJn/V7paZRME5BakaKUD9pf70laB4rWkk/pitkLwxKiv8wGDTtlYBTmYzob/UA1TA2wd8QKLqthJKlkDBuJlERMLrWwbaJ4xEnil6JCxXwZ3JoE/ur3FglN1bJjVVyY5XcWCX/GfsFBmfXVddGKlMAAAAASUVORK5CYII="
}
}
}INIT_OOB_REG
Initiates out-of-band registration.
The Server uses the allowed UAF authenticators specified by the FIDO registration policy passed to START_OOB_REG and device information to create a list of permitted authenticators that the user could register.
For FIDO2 authenticators, the Server compares the authenticator's characteristics to the desired FIDO2 authenticator characteristics specified by the registration policy. The client uses these as hints to prompt the end user for the authenticator. The Server enforces user verification and attestation preference during FINISH_OOB_REG based on the policy configuration. If you have not configured the registration policy for FIDO2 authenticators, then INIT_OOB_REG fails with a 4403 when a web app tries to register a FIDO2 authenticator.
Request
Attribute | Description |
|---|---|
operation | Required. The string INIT_OOB_REG. |
callerOrigin | Required if a web app is sending the request and that app has a different origin than the Digipass S3 API Server. A web origin is defined by the scheme (protocol), host (domain), and port of the URL used to access it. The API Server checks if this origin is listed in its origin allow list, if not, the request is rejected. See My Web Apps Have a Different Origin. |
message | Required. Generated by the App SDK on the client. This is an opaque value. The client app is responsible for sending message. This is a base64-URL encoded string. |
optionsData | Optional. An object used to pass additional attributes to REST API operations. See OptionsData for a complete description. |
sessionData | Optional. An object containing the user's session information. See SessionData. This is for the user who is logged in on the second device. This person must be the same user logged in on the primary device. Omit if the user is not logged in on the second device. |
Response
The following attributes are always present in the JSON payload of the response.
Attribute | Description |
|---|---|
id | The unique id that correlates START_OOB_REG, INIT_OOB_REG, and FINISH_OOB_REG operations for the same user. String. If id was sent in the request, the same id is returned. If not, a server-generated ID is returned. If id was provided in the REST payload but the server was unable to parse the payload, the value is unknown. |
statusCode | Server-specific status code that reports the success or failure of the requested operation. Integer. See Response Status Codes below for the status and error codes. |
The following attributes are present in the response upon a successful operation (Server status code 4000).
Attribute | Description |
|---|---|
additionalInfo | An object containing information about the client app and device from the second device. Contains the 5 attributes listed in the rows below. In order for the API Server to return this information:
|
additionalInfo.device | A DeviceDetail object containing information about the second device such as the device’s unique ID, model, and manufacturer. |
additionalInfo.elapsedTime | The amount of time to process the request. |
additionalInfo.extensions | Information about a device’s location and jailbreak status. List<Extension>. |
additionalInfo.oobRefId | ID provided by the RP app to retrieve contextual information from the RP server that can be displayed to the app user. Only returned if oobRefId was included inside oobData in the scanned QR code. |
additionalInfo.protocol | The protocol used by the Authentication Server based on information from the request. String. One of UAF or Web. |
lifetimeMillis | Lifetime of message in milliseconds. Long. Your client or web app can use this to tell a user how much time they have to complete the operation or warn the user that the Server does not accept a response once lifetimeMillis has expired. |
message | An opaque value that contains the challenge exchanged between the Server and the App SDK. A base64-URL encoded string. message must be sent to the App SDK. |
Response status codes
The following are the descriptions of the Auth Server status codes returned by INIT_OOB_REG. Under certain circumstances, the API Server returns an unsuccessful HTTP status code. Examples include an invalid request or invalid session. You can find descriptions of these in API Server Status Codes.
Server Status Code | Description | Examples |
|---|---|---|
4000 | OK. Operation completed | Request created successfully. |
4403 | PolicyVerificationException | Requested policy is not available on Server. |
4404 | Internal Server Error | Internal server error. Failed to read from the database. Failed to connect to the database. Failed to read required properties. |
4406 | Payload Exception | An error occurred with one or more attributes. For example, message has an invalid type. |
4408 | UnsupportedClient MessageException | message cannot be handled. Unacceptable Client Capabilities - invalid protocol version. |
4409 | ClientMessageException | message is invalid JSON. |
4450 | UserCancelledException | The user canceled the registration operation. |
Samples
Sample request URL
https://www.example.com:8443/nnlgateway/nnl/<tenant_id>/regSample request
{
"operation":"INIT_OOB_REG",
"message":"<base64url-encoded-data>"
}Sample response
A developer updated the response filter configuration so the API Server returns the protocol and OOB Reference ID in additionalInfo.
{
"id": "INIT_OOB_REG_1439247650812",
"statusCode": 4000,
"message": "<base64url-encoded-data>",
"additionalInfo": {
"protocol":"uaf_1.0",
"oobRefId":"12345",
"device": {
"id": "123456789abcdef1234567890",
"type": "android",
"info": "OneSpan's device"
}
},
"lifetimeMillis": 300000
}FINISH_OOB_REG
Processes the registration response provided by the caller and completes the OOB registration process.
Request
Attribute | Description |
|---|---|
operation | Required. The string FINISH_OOB_REG. |
callerOrigin | Required if a web app is sending the request and that app has a different origin than the Digipass S3 API Server. A web origin is defined by the scheme (protocol), host (domain), and port of the URL used to access it. The API Server checks if this origin is listed in its origin allow list, if not, the request is rejected. See My Web Apps Have a Different Origin. |
channelBinding | Optional. Channel binding data available from the TLS endpoint. ChannelBinding object. |
message | Required. Generated by the App SDK on the client. This is an opaque value. The client app is responsible for sending message. This is a base64-URL encoded string. |
optionsData | Optional. An object used to pass additional attributes to REST API operations. See OptionsData for a complete description. |
sessionData | Optional. An object containing the user's session information. See SessionData. This is for the user who is logged in on the second device. This person must be the same user logged in on the primary device. Omit if the user is not logged in on the second device. |
Response
The following attributes are always present in the JSON payload of the response.
Attribute | Description |
|---|---|
id | The unique id that correlates START_OOB_REG, INIT_OOB_REG, and FINISH_OOB_REG operations for the same user. String. If id was sent in the request, the same id is returned. If not, a server-generated ID is returned. If id was provided in the REST payload but the server was unable to parse the payload, the value is unknown. |
statusCode | Server-specific status code that reports the success or failure of the requested operation. Integer. See Response Status Codes below for the status and error codes. |
The following attributes are present in the response upon a successful operation (Server status code 4000).
Attribute | Description |
|---|---|
additionalInfo | An object containing information about the client app and device from the second device. Contains the attributes listed in the rows below. In order for the API Server to return this information,
|
additionalInfo.authenticatorsResult | The authenticator that the user registered. Also, the status reflects the action for the App SDK. List<AuthenticatorResult>. |
additionalInfo.device | A DeviceDetail object containing information about the second device, such as the device’s unique ID, model, and manufacturer. |
additionalInfo.elapsedTime | The number of milliseconds to process the request. |
additionalInfo.extensions | Information about a device’s location and jailbreak status. Message payload extensions received by the Server in FINISH_OOB_REG and INIT_OOB_REG requests. List<Extension>. |
additionalInfo.headerExtensions | Protocol-specific header extensions. List<HeaderExtension> |
additionalInfo.oobRefId | ID provided by the RP app to retrieve contextual information from the RP server that can be displayed to the app user. Only returned if oobRefId was included inside oobData in the scanned QR code. |
additionalInfo.policyName | FIDO registration policy used for the operation. String. |
additionalInfo.protocol | The protocol used by the Authentication Server based on information from the request. String. One of UAF or Web. |
additionalInfo.rulesResult | RulesResult populated as a result of policy rules processing giving out the matched rules details. RulesResult. |
message | An opaque value that contains the challenge exchanged between the Server and the App SDK. A base64-URL encoded string. message must be sent to the App SDK. |
Response status codes
The following are the descriptions of the Auth Server status codes returned by FINISH_OOB_REG. Under certain circumstances, the API Server returns an unsuccessful HTTP status code. Examples include an invalid request or invalid session. You can find descriptions of these in API Server Status Codes.
Server Status Code | Description | Examples |
|---|---|---|
4000 | OK. Operation completed | Registration completed successfully. |
4002 | OK. Optional security checks failed | Failed to validate ChannelBinding. |
4401 | Challenge Expired Exception | The request challenge has expired. |
4402 | Security Exception | Failed to validate the attestation. Failed to validate Server challenge. Failed to validate the Server data. Failed to locate authenticator metadata. Challenge replay detected. Failed to validate extension data. |
4403 | Policy Exception | Failed to match policy. Policy not supported. Failed to register as configured max limit of registrations reached for the user. |
4404 | Internal Server Error | Internal server error. Failed to write to the database. Failed to read from the database. Failed to connect to the database. Failed to read properties. |
4406 | Payload Exception | An error occurred with one or more attributes. For example, message has an invalid type. |
4408 | Unsupported ClientMessageException | Attribute message cannot be handled. Unacceptable Client Capabilities - invalid protocol version. |
4409 | ClientMessageException | Attribute message has invalid JSON. The message attribute from the App SDK is malformed (unable to decode base64URL). |
4450 | UserCancelledException | The user canceled registration. |
Samples
Sample request URL
https://www.example.com:8443/nnlgateway/nnl/<tenant_id>/regSample request
{
"operation": "FINISH_OOB_REG",
"message": "<base64url-encoded-data>"
}Sample response
A developer updated the response filter configuration so the API Server returns the protocol, the elapsed time to process the request, additional authenticator details, FIDO policy used, post operation rule results, client app information, and payload extensions in additionalInfo.
{
"statusCode":4000,
"id":"rDRwiwww-m2CS3IWBbPuZw",
"message":
"eyJzZXJ2ZXIiOnsiYXV0aGVudGljYXRvcnNSZXN1bHQiOlt7ImFhaWQiOiJBQkNEI0FCQ0QiLCJrZXlJRCI6ImZaeVNBMDNoN3h1c1gxRFpLdS11MzJ1RV9sX25RSG1tTGtSVHFDTlZ1YkEiLCJzdGF0dXMiOjQwMDB9XSwiYXBwSUQiOiJodHRwczovLzEyNy4wLjAuMTo4NDQzL1NhbXBsZUFwcCJ9LCJ1c2VyTmFtZSI6Im8yIiwidmVyc2lvbiI6IjEuMCIsIm9wZXJhdGlvbiI6IkZJTklTSF9PT0JfUkVHIiwicHJvdG9jb2wiOiJ1YWZfMS4wIn0",
"additionalInfo":{
"device":{
"id":"123456789abcdef1234567890",
"type":"android",
"info":"NokNok Emulator",
"model":"NokNok-AE 8.0",
"os":"NokNokOS 8.0",
"manufacturer":"NokNok",
"supportsPlatformAuthenticator":true
},
"protocol":"uaf_1.0",
"elapsedTime":25,
"authenticatorsResult":[
{
"handle":
"WyJ1YWZfMS4wIiwiQUJDRCNBQkNEIiwiZlp5U0EwM2g3eHVzWDFEWkt1LXUzMnVFX2xfblFIbW1Ma1JUcUNOVnViQSJd",
"uvi":"VPAT7rKZAfKqGzGgnX1_qLzZZ9lF9FPPpO64SfufBEg",
"uviStatus":4,
"status":4000,
"aaid":"ABCD#ABCD",
"authenticatorVersion":1,
"attestationType":15879,
"attestationTypeName":"basic_full",
"attachmentHints":[
"internal"
]
}
],
"oobRefId":"12345",
"policyName":"default",
"rulesResult":{
"action":"ALLOW",
"matchedRules":[
{
"name":"LocationVelocity",
"riskScore":0,
"template":"DummyRule",
"group":"dummy group"
}
]
},
"app":{
"id":"android:apk-key-hash:rDQ4Tn60fAvxP8thtp6sOh5ococ",
"name":"android:com.noknok.test.client",
"qrSupported":false
},
"extensions":[
{
"id":"noknok.ipaddress",
"data":"192.168.0.102",
"operation":"FINISH_OOB_REG"
},
{
"id":"noknok.ipaddress",
"data":"192.168.0.102",
"operation":"INIT_OOB_REG"
},
{
"id":"noknok.wifi.ssid",
"data":"Oviya",
"operation":"FINISH_OOB_REG"
},
{
"id":"noknok.wifi.ssid",
"data":"Oviya",
"operation":"INIT_OOB_REG"
},
{
"id":"noknok.uaf.location",
"data":"{\"accuracy\":99.2,\"countryCode\":\"US\",\"latitude\":32.52,\"longitude\":-124.482,\"status\":0}",
"operation":"FINISH_OOB_REG"
},
{
"id":"noknok.uaf.location",
"data":"{\"accuracy\":99.2,\"countryCode\":\"US\",\"latitude\":32.52,\"longitude\":-124.482,\"status\":0}",
"operation":"INIT_OOB_REG"
},
{
"id":"noknok.uaf.jailbreak",
"data":"{\n \"status\" : \"0\",\n \"isJailbroken\" : \"false\"\n}",
"operation":"FINISH_OOB_REG"
},
{
"id":"noknok.uaf.jailbreak",
"data":"{\n \"status\" : \"0\",\n \"isJailbroken\" : \"false\"\n}",
"operation":"INIT_OOB_REG"
}
]
}
}STATUS_OOB_REG
Checks the OOB registration status on the device. This occurs on the device that starts the OOB registration operation.
The Server polls for the status of the registration operation identified by oobStatusHandle. Check if oobStatusHandle has expired since it has a lifetime.
Request
Attribute | Description |
|---|---|
operation | Required. The string STATUS_OOB_REG. |
callerOrigin | Required if a web app is sending the request and that app has a different origin than the Digipass S3 API Server. A web origin is defined by the scheme (protocol), host (domain), and port of the URL used to access it. The API Server checks if this origin is listed in its origin allow list, if not, the request is rejected. See My Web Apps Have a Different Origin. |
oobStatusHandle | Required. Identifies a specific OOB registration operation. An alphanumeric string, maximum 4000 characters. Use the oobStatusHandle returned in the response from a START_OOB_REG operation. |
optionsData | Optional. An object used to pass additional attributes to REST API operations. See OptionsData for a complete description. |
sessionData | Required. An object containing the user's session information. See SessionData. |
Response
The following attributes are always present in the JSON payload of the response.
Attribute | Description |
|---|---|
id | The unique id that correlates INIT_OOB_REG and FINISH_OOB_REG operations for the same user. Base64-URL encoded string. If id was sent in the request, the same id is returned. If not, a server-generated ID is returned. If id was provided in the REST payload but the server was unable to parse the payload, the value is unknown. |
statusCode | Server-specific status code that reports the success or failure of this operation. Integer. See Response Status Codes below for the status and error codes. |
The following attributes are present in the response upon a successful operation (Server status 4000).
Attribute | Description |
|---|---|
additionalInfo | An object containing information about the client app and device from the second device. Contains the attributes listed in the rows below. In order for the API Server to return this information,
|
additionalInfo.authenticatorsResult | Authenticators that succeeded or failed to complete the OOB registration. List<AuthenticatorResult>. The status reflects the action for App SDK. |
additionalInfo.device | A DeviceDetail object containing information about the client. |
additionalInfo.elapsedTime | The amount of time, in milliseconds, to process the request. |
additionalInfo.extensions | Message payload extensions received by the Server in FINISH_OOB_REG and INIT_OOB_REG requests. List<Extension>. |
additionalInfo.headerExtensions | Protocol-specific header extensions. List<HeaderExtension> . |
additionalInfo.oobRefId | ID provided by the RP app to retrieve contextual information from the RP server that can be displayed to the app user. Only returned if oobRefId was included inside oobData in the scanned QR code. String.
|
additionalInfo.policyName | FIDO registration policy used for the operation. String. |
additionalInfo.protocol | The protocol used by the Server based on information from the request. String. One of UAF or Web. |
push | If the client app is able to enroll for push notification with Apple Push Notification Service (APNS) or Firebase Cloud Messaging (FCM), then this object is returned. Contains the 4 attributes listed below. |
push.createdTimeStamp | Creation date and time of push handle in UTC format. String |
push.handleLifetimeDays | Remaining lifetime of push handle in days. Long. |
push.pushHandle | Identifies the device that receives a push notification and then initiates an OOB registration. A Base64-encoded string, maximum 4000 characters. |
push.status | Result of the push notification. Integer. Also indicates status when the Server is unable to generate a new pushHandle because the maximum number of push notifications has been reached. This could be due to delivery or processing failures. |
remainingTimeMillis | Lifetime of oobStatusHandle in milliseconds. If the lifetime has expired, the value is negative. |
Response status codes
The following are the descriptions of the Auth Server status codes returned by STATUS_OOB_REG. Under certain circumstances, the API Server returns an unsuccessful HTTP status code. Examples include an invalid request or invalid session. You can find descriptions of these in API Server Status Codes.
Server Status Code | Description | Examples |
|---|---|---|
4000 | OK. Operation completed | Registration has been completed successfully. |
4004 | OK. Operation in progress | The OOB Reg operation has started and is still in progress. |
4005 | OK. Operation Pending | The OOB Reg operation is pending. Also implies there is more info available when the statusCode is: 4004. |
4401 | Challenge Expired Exception | The request challenge has expired. |
4402 | Security exception | Failed to decrypt data. Failed to validate extension data. Failed to decode CodeP. Poll input validation has failed against data. CodeP has an invalid length. |
4404 | Internal Server Error | Internal server error. Failed to read from the database. Failed to connect to the database. Failed to read required properties. |
4406 | Payload Exception | An error occurred with one or more attributes. For example:
|
4450 | UserCancelledException | Operation is canceled. |
Samples
Sample request URL
https://www.example.com:8443/nnlgateway/nnl/<tenant_id>/regSample request
{
"operation": "STATUS_OOB_REG",
"sessionData":{
"sessionKey":"<session JWT>"
},
"oobStatusHandle": "AgAgUIh9AFHjsDU_mPp_DUsghnYn7kg3sl3z-keVqCtM09IDAAgAAAFPGdfXiwQAAQEBACCAcQ81Htjr69mhHEuluuT9Y9orXRfyRqZ_plbHpTNwRQ"
}Sample response
A developer updated the response filter configuration so the API Server returns the FIDO policy used, the elapsed time for processing the request, protocol, and additional authenticator details in additionalInfo.
{
"statusCode":4000,
"additionalInfo":{
"device":{
"info":"OneSpan's device",
"id":"dID_82b5799d-869a-4a9b-95c6-fdd36a6b61a1_1",
"type":"android"
},
"policyName":"reg_policy",
"elapsedTime":25,
"authenticatorsResult":[
{
"aaid":"ABCD#ABCD",
"uvi":"ZsGHbiYd6OgLVYW49G-qQHrwrgw83Wve5Ge5iQVYv8",
"uviStatus":4,
"authenticatorVersion":1,
"attestationType":15879,
"authenticatorExtensions":[
{
"id":"tag1",
"data":"extensionData1",
"fail_if_unknown":false
},
{
"id":"tag2",
"data":"extensionData2",
"fail_if_unknown":false
},
{
"id":"criticalTag1",
"data":"criticalExtensionData1",
"fail_if_unknown":true
},
{
"id":"criticalTag2",
"data":"criticalExtensionData2",
"fail_if_unknown":true
}
],
"status":4000,
"handle":
"WyJ1YWZfMS4wIiwiQUJDRCNBQkNEIiwiQnVKk5BQlVoVHZUeW1WY3FYMk9fRmhpRFY0aHA1OThxLTI0eWEzVlmUSJd"
}
],
"protocol":"uaf_1.0"
},
"push":{
"pushHandle":
"m3-ZrKasG_GhxK4IdEIyOIUysfOFcBhMkvm5BOyRZMWCMGozvHP3Fur9edF1mFLwI1iZpc0LuwCiY1ZLGqyWJea7zOp7kGJdHFSuLzd5vCOD7wLmPp2s5ciEtXRPUEaI4z5eZYlqGXKPPtW4s7H_Q5zBOaUiqNVueRoHx_ZBVEy-8A4",
"handleLifetimeDays":30,
"createdTimeStamp":"2020-09-08T06:18:08.904Z",
"status":4000
},
"id":"dEgViadKjxcleujKbpfi6g"
}CANCEL_OOB_REG
Cancels the OOB operation from the second device (authenticating device) on the Server.
Request
Attribute | Description |
|---|---|
operation | Required. The string CANCEL_OOB_REG. |
callerOrigin | Required if a web app is sending the request and that app has a different origin than the Digipass S3 API Server. A web origin is defined by the scheme (protocol), host (domain), and port of the URL used to access it. The API Server checks if this origin is listed in its origin allow list, if not, the request is rejected. See My Web Apps Have a Different Origin. |
nnlData | Required. Required to cancel the operation from the second device used to perform the OOB registration. You can get nnlData from the response message of INIT_OOB_REG. String. |
optionsData | Optional. An object used to pass additional attributes to REST API operations. See OptionsData for a complete description. |
sessionData | Optional. An object containing the user's session information. See SessionData. This is for the person logged in on the second device. Must be the same as the sessionData passed into INIT_OOB_REG. Omit if the user is not logged in on the second device. |
Response
The following attributes are always present in the JSON payload of the response.
Attribute | Description |
|---|---|
id | The unique id that correlates INIT_OOB_REG and FINISH_OOB_REG operations for the same user. String. |
statusCode | Server-specific status code that reports the success or failure of this operation. Integer. See Response Status Codes below for the status and error codes. |
The following attributes are present in the response upon a successful operation (Server status code 4000).
Attribute | Description |
|---|---|
additionalInfo | An object containing information returned by the Authentication Server. Contains the 2 attributes listed below. In order for the API Server to return this information:
|
additionalInfo.elapsedTime | The amount of time, in milliseconds, to process the request. |
additionalInfo.oobRefId | ID provided by the RP app to retrieve contextual information from the RP server. Alphanumeric string. The API Server only returns this attribute if you sent oobRefID in START_OOB_REG's request. |
Response status codes
The following are the descriptions of the Auth Server status codes returned by CANCEL_OOB_REG. Under certain circumstances, the API Server returns an unsuccessful HTTP status code. Examples include an invalid request or invalid session. You can find descriptions of these in API Server Status Codes.
Server Status Code | Description | Examples |
|---|---|---|
4000 | OK. Operation completed | Authentication Request created successfully. |
4401 | Challenge Expired Exception | The request challenge has expired. |
4402 | Security Exception | Cancel input validation has failed against DB. Username mismatch. NNLData validation failed. |
4404 | Internal Server Error | Internal server error. Failed to read from the database. Failed to connect to the database. Failed to read required properties. |
4406 | Payload Exception | Parameter nnlData is empty. |
4453 | Operation already completed | Unable to cancel because registration has completed. |
Samples
Sample request URL
https://www.example.com:8443/nnlgateway/nnl/<tenant_id>/regSample request
{
"operation":"CANCEL_OOB_REG",
"nnlData":"giltFqT8g5CblHqnzXLrrYoxG6nmseHYWGSdWUxBW6hHVJ9RHj9WgmYxbLE8C98YSizqHqUlqzkeVZ7F_5GzigU8X67qyg"
}Sample Response
{
"id":"CANCEL_OOB_REG_1439247762691",
"statusCode":4000
}CANCEL_STATUS_OOB_REG
Checks the OOB cancel registration status on the second device.
Request
Attribute | Description |
|---|---|
Operation | Required. The string CANCEL_STATUS_OOB_REG. |
callerOrigin | Required if a web app is sending the request and that app has a different origin than the Digipass S3 API Server. A web origin is defined by the scheme (protocol), host (domain), and port of the URL used to access it. The API Server checks if this origin is listed in its origin allow list, if not, the request is rejected. See My Web Apps Have a Different Origin. |
oobStatusHandle | Required. Identifies the specific OOB registration operation that you want to cancel on the initiating device. An alphanumeric string, maximum 4000 characters. Use the oobStatusHandle returned in the response from a START_OOB_REG operation. |
optionsData | Optional. An object used to pass additional attributes to REST API operations. See OptionsData for a complete description. |
sessionData | Required. An object containing the user's session information. See SessionData. |
Response
The following attributes are always present in the JSON payload of the response.
Attribute | Description |
|---|---|
id | The unique id that correlates INIT_OOB_REG and FINISH_OOB_REG operations for the same user. Base64-URL encoded string. |
statusCode | Server-specific status code that reports the success or failure of this operation. Integer. See Response Status Codes below for the status and error codes. |
Response status codes
The following are the descriptions of the Auth Server status codes returned by CANCEL_STATUS_OOB_REG. Under certain circumstances, the API Server returns an unsuccessful HTTP status code. Examples include an invalid request or invalid session. You can find descriptions of these in API Server Status Codes.
Server Status Code | Description | Examples |
|---|---|---|
4000 | OK. Operation completed | Registration request canceled successfully. |
4402 | Security Exception | Failed to validate extension data. |
4404 | Internal Server Error | Internal server error. Failed to read required properties. |
4406 | Payload Exception | An error occurred with one or more attributes. For example, attribute oobStatusHandle is empty. |
4453 | OperationAlreadyCompleted | Unable to cancel even if the operation is completed. |
Samples
Sample Request URL
https://www.example.com:8443/nnlgateway/nnl/<tenant_id>/regSample request
{
"operation":"CANCEL_STATUS_OOB_REG",
"sessionData":{
"sessionKey":"<session JWT>"
},
"oobStatusHandle":"AgAgCcIuezLxWhezpTS7Le3-lGQsTmO7TqJ7IYspDote_gsDAAgAAAFPcv9jhwQAAQEBACCCp9fGEPR4GC-S57z1UCTtCXbPYBlhu5acflIHXMyUvA"
}Sample response
{
"id":"dEgViadKjxcleujKbpfi6g",
"statusCode":"4000"
}