Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Out-of-band registration

Prev Next

URL: /nnlgateway/nnl/<tenant_id>/reg Method: POST


Although registration is triggered from a first device (usually a desktop browser) that starts OOB registration, it is actually completed on a second device (usually a cell phone). The second device sends the requests to initiate OOB registration and finish OOB registration. The second device can also cancel the OOB registration. There are also 2 status operations: one for registration and the other for cancellation.

The following operations are available:

OOB Registration Operation

Called by

START_OOB_REG

First device

INIT_OOB_REG

Second device

FINISH_OOB_REG

Second device

CANCEL_OOB_REG

Second device

STATUS_OOB_REG

First device

CANCEL_STATUS_OOB_REG

First device

Out-of-band registrations always use the FIDO protocol, which includes both UAF and FIDO2. In most cases you need to start the OOB registration process by calling INIT_ADAPTIVE_REG, but then you call the operations listed above instead of the corresponding operations in the section FIDO Registration. Once a FIDO OOB registration is completed, manage it just like any other FIDO registration, using the operations in Manage FIDO registrations.

You can choose one or more of the following mechanisms so the user can register an authenticator on the second device to use for future authentication. This document refers to these mechanisms as OOB mode.

  • Display a QR code on the first device that the user scans using the second device.

  • Use a custom mechanism that you implemented

Implementing a custom OOB mode is outside the scope of this documentation.

You can only register a FIDO authenticator by scanning a QR code or using your custom OOB mode. Any of the three OOB modes (QR code, push notification, or custom OOB) can be used to authenticate.

See FIDO Registration to understand how the API Server determines the FIDO policy to use for OOB registration. To perform OOB registration, the Authentication Server uses the FIDO registration policy to determine the valid UAF and FIDO2 authenticators that can be used. For UAF authenticators, the Auth Server refers to the allowed UAF authenticators specified by the FIDO policy and device information to create a list of permitted UAF authenticators from which an end user can select to verify their identity.

For FIDO2 authenticators, the Auth Server compares the authenticator's characteristics to the desired FIDO2 authenticator characteristics specified by the registration policy. The client uses these as hints to prompt the end user for the authenticator. The Auth Server enforces user verification and attestation preference during FINISH_OOB_REG based on the policy configuration.

Refer to Create FIDO Policies to create an authentication policy.

START_OOB_REG

Starts out-of-band registration from the first device.

Use the boolean attributes defined on the oobMode object to specify the OOB mode you want registration to use. You must specify at least one OOB mode.

  • oobMode.qr - to generate a QR code

  • oobMode.rawdata - to use your own custom OOB mode.

If successful, START_OOB_REG generates and returns a string for the QR code image that the first device displays to initiate registration.

Request

Attribute

Description

operation

Required. The string START_OOB_REG.

callerOrigin

Required if a web app is sending the request and that app has a different origin than the Digipass S3 API Server. A web origin is defined by the scheme (protocol), host (domain), and port of the URL used to access it.

The API Server checks if this origin is listed in its origin allow list, if not, the request is rejected. See My Web Apps Have a Different Origin.

id

Optional. The correlation ID, a unique identifier that associates START_OOB_REG, INIT_OOB_REG, and FINISH_OOB_REG operations for the same user. Use id to identify the desired OOB registration when you call STATUS_OOB_REG and CANCEL_OOB_REG. An alphanumeric string, maximum 255 characters. No special characters are allowed.

If not provided, the Server generates a unique id and returns it in the response.

oobMode

Required. Object with 4 attributes, which are listed below.

oobMode.qr

String. One of:

  • true: The Server generates a QR code image for initiating registration.

  • false: The Server does not generate a QR code image.

oobMode.qrType

Optional. String. Directs the Auth Server to generate the specified QR code. One of the values listed below, these are ordered by the size of the QR code they generate, from largest to smallest.

  • UNIVERSAL_ANY_RP: Generates a universal QR Code that can be scanned by web apps, native mobile apps, and camera apps capable of processing a QR code. These apps can be deployed by different organizations.

  • UNIVERSAL_RP_SPECIFIC: Generates a universal QR Code specific to apps deployed by one organization. The Server omits the API Server hostname from the QR code.

  • APP_ANY_RP (default): Generates a QR Code that works with native mobile apps deployed by different organizations. The Server omits the web page hostname from the QR code.

  • APP_RP_SPECIFIC: Generates a QR code that can only be scanned by native mobile apps deployed by one organization. The Server omits both the web page and API Server hostname from the QR code.

    Mobile apps that scan this QR code must hard code the registration and authentication endpoints as described in the Android Developer Guide or the iOS Developer Guide.

oobMode.rawData

String. One of:

  • false: You are using a QR code, so you don’t need raw data.

  • true: You are using your own mechanism to transfer information from the initiating device to a second device, so you need raw data to encode that information.

oobMode.webUrl

Required if oobMode.qrType is either UNIVERSAL_RP_SPECIFIC or UNIVERSAL_ANY_RP. The web page URL that handles OOB registration. The Server encodes this web page URL in the generated QR code. String.

oobRefId

Optional. ID provided by the RP app to retrieve contextual information from the RP server that can be displayed to the app user. This helps maintain continuity when a user is performing a transaction or task. The oobRefId sent in this request is packaged inside the oobData in the QR code displayed by the app running on the first device. The app running on the second device retrieves this when it scans the QR code.

An alphanumeric string, maximum of 512 characters.

optionsData

Optional. An object used to pass additional attributes to REST API operations. See OptionsData for a complete description.

sessionData

Required. An object containing the user's session information. See SessionData.

Response

The following attributes are always present in the JSON payload of the response.

Attribute

Description

id

The unique id that correlates the START_OOB_REG, INIT_OOB_REG, and FINISH_OOB_REG operations. String.

If id was sent in the request, the same id is returned. If not, a server-generated ID is returned. If id was provided in the REST payload but the server was unable to parse the payload, the value is unknown.

statusCode

Server-specific status code that reports the success or failure of the requested operation. Integer.

See Response Status Codes below for the status and error codes.

The following attributes are present in the response upon a successful operation (Server status code 4000).

Attribute

Description

additionalInfo

An object containing information returned by the Authentication Server. Contains the 2 attributes listed below.

In order for the API Server to return this information:

  1. Send oobRefID in START_OOB_REG's request

  2. Update the response filter configuration so the API Server returns elapsed time and the OOB reference ID. Refer to Response Filter Configuration.

additionalInfo.elapsedTime

The number of milliseconds to process the request.

additionalInfo.oobRefId

ID provided by the RP app to retrieve contextual information from the RP server. Alphanumeric string.

lifetimeMillis

Lifetime of the oobStatusHandle in milliseconds. Long.

modeResult

An object containing the server-generated QR code and/or raw data needed for your custom OOB mode. Has 2 attributes: qrCode and rawData.

modeResult.qrCode.qrImage

The server-generated QR Code. String (Base64-encoded PNG image).

Returned if oobMode.qr is true.

modeResult.rawData

Raw data to send to the second device when you are using your own mechanism in place of a QR code. String.

Returned if oobMode.rawData is true.

oobStatusHandle

Uniquely identifies this OOB registration operation. An alphanumeric string, maximum 4000 characters.

Pass oobStatusHandle to STATUS_OOB_REG to get this OOB registration’s status. Any operations using oobStatusHandle must be completed within lifetimeMillis.

Response status codes

The following are the descriptions of the Auth Server status codes returned by START_OOB_REG. Under certain circumstances, the API Server returns an unsuccessful HTTP status code. Examples include an invalid request or invalid session. You can find descriptions of these in API Server Status Codes.

Server Status Code

Description

Examples

4000

OK. Operation completed

Registration operation OOB started successfully.

4404

Internal Server Error

Internal server error.

Failed to read from the database.

Failed to connect to the database.

Failed to read required properties.

4406

Payload

Exception

An error occurred with one or more attributes. For example, oobMode is INVALID.

Samples

Sample request URL

https://www.example.com:8443/nnlgateway/nnl/<tenant_id>/reg

Sample request

{
    "operation":"START_OOB_REG",
    "sessionData":{
        "sessionKey":"<session JWT>"
    },
    "id":"sample",
    "oobRefId":"12345",
    "oobMode":{
        "qr":"true"
    }
}

Sample response

A developer updated the response filter configuration so the API Server returns the OOB Reference ID in additionalInfo.

{
  "statusCode":4000,
  "id":"sample",
  "lifetimeMillis":180000,
  "additionalInfo":{
    "oobRefId":"12345"
  },
  "oobStatusHandle":"a2V5aGFuZGxlAAAAAj-qU25O-OOk3m308NX9CPlEVKJkR6q0447dLIszkI9uoln1U0TEi0DU1Arnc7CPNxDdNebgltEAHogj2DQ2yt2XNVPcVlclVV47-LzAV1aZyCUN38hA_Tof5O8",
  "modeResult":{
    "qrCode":{
      "qrImage":"iVBORw0KGgoAAAANSUhEUgAAASwAAAEsAQAAAABRBrPYAAAC9ElEQVR4Xu2YUW4DIQxEuYHvf0vfgM4bSKvQSu1XZz/wRskufonA9hjaMf9iPc6RH+1ih13ssIsddrHDLnbYxQ7bWI8xZhWPLdsPaziO6aWxHl2zphg91CiG85iAWaNFzS5dkxWUh5+AMWuRTFqxHXoR6GdgjqTWoHR3EVvK4AkYZDN57kXx5i8+AGPeP9gpmQRmK1KuwK6ZK8BfriRmKW+Ue2DdlSyOKfF2FNJpiWVSloXC85ianqbOAug2WyvK++tXgpinK9b9xe2vXJDfspDAmDVy5lE36Hmyg6DvOOa2N2iD7dmv1K/vhTFpZDi29GWTrsntjmJbutYNAD1HiyDqcYyoIpBCMMa9oMFHGgNkiOiy7254cmiJY+5/mjNnASqTBwpzUVGM2dpBsuF4GyjozML/Y9w1MybjqgDHVtTePbIYgllemqC8n895DOfqMUxbq9g777GECIZC2NMAUY5yPng8lZXAercV2h93xRbCoWq7gxg9kCUsBRPVItBEPY7hkYtx6pIY77uXO4c1F0783JP1wed7R4pgJJztFqUMDlDcEPRlSYxFTJJP91uKRsvtUk1jVrN79Eq310CI948kscbheDLAk3shh4I05v7sJehC08R5xTiPDSJMb6Y0mXt7f6MI0hiNufGL4shuirftTmKruRQNZroFomXm/60jBbDVY9guiDLt0KXw0kwSY/cv/tmqVaAdd0SK8kx9AqOvsIpaCgagK+4VZDFRmjU1Sba1HnmoVBdDFtOHJQM1HGi6jajxXpYRjJaMlntBOJs/yb5+JogBkXtaM7Xoo9Qr81GMZ/ze39rC5qtceWxPuS3m4fHitHK0mgxGiNEHb2vbtaJPZQUwa5dhGGqRrkNhLsVkMV7sIQgZNwryEh6AMXHH1gkHZvNlXc/A6M3uNGy7VCVpX2uIYzTp8qbbvtiD37fdDGZy0qGRNccVFuG1xLHhPZaEczLgjm+OXZVR7De72GEXO+xih13ssIsddrHD/op9AHTt+9RovXr6AAAAAElFTkSuQmCC"
    }
  }
}

Sample request with qrType=UNIVERSAL_ANY_RP

{
    "operation":"START_OOB_REG",
    "sessionData":{
        "sessionKey":"<session JWT>"
    },
    "id":"sample",
    "oobRefId":"12345",
    "policyName":"default",
    "oobMode":{
        "qr":"true",
        "qrType":"UNIVERSAL_ANY_RP",
        "webUrl":"https://www.example.com:8443/"
    }
}

Sample response when qrType=UNIVERSAL_ANY_RP

A developer updated the response filter configuration so the API Server returns the OOB Reference ID in additionalInfo.

{
  "statusCode":4000,
  "id":"sample",
  "lifetimeMillis":180000,
  "additionalInfo":{
    "oobRefId":"12345"
  },
  "oobStatusHandle":"a2V5aGFuZGxlAAAAApz53PPjA9gP61uUhwFZsseZ2q7po5LRzfIQz42Ci4CYO-NY5mTEUiz2JIejaE8l-DtIZpiE79Q76q2OzzAjge5nVc8iiTkGP75xLdUWQXAJ9xDjpHsMnh08HtQ",
  "modeResult":{
    "qrCode":{
      "qrImage":"iVBORw0KGgoAAAANSUhEUgAAASwAAAEsAQAAAABRBrPYAAADS0lEQVR4Xu2XbW4bMQxEeQPe/5a8ATtvZBTZTYD0l8dAV3W8svQEiB9Dbmv/ZUzdV34cD3YbD3YbD3YbD3Yb/xs2VbW9zGf0rNa0dtobYYztqjHTw7Y2dJKNNKbl7S6P5t9qYThRn4DB9XGmJ/raT8G0plVN5ecG1c5HYJD6xgKtaEpuFrNvGfJ2rJyTPwzYLOYhhyoRm3yUU7VtUZ8RxLTIhMpit5KVeLsZYYwC6FUJmA9HOEjYv4Q+grkWU6MtEG7NIds1Xy2NYBIMFdkNRLLmo3MDeoAgttx3qcsyxn5eZyUFMY35oq5+WlACeMbxu+oTmP1YczQy/Oqzegl9CKPZct3ChKKridAyeZrF+gT6xB+vagUEN4cxwHPdpvW6BoK6KKYxqgwOtS3cXqfw9LXUZDBcu7yckJNYQfUhO2HDGEG3aMrRljX1ylNbkMQsGc1cXqh8be3IsjqaCWL8dhZydQJPr2NVLr6G/v0YWuHTzkqmJAKABR7F9PMVeXsW4fCKTPhJ0SgmraCRIvj42NXGJJMsBgdI4D315ZE3tTqMrb2piA/3P/WQLLU5YYx9+sZgjQu1l42HMRD+3De4OfLBFhl2ScsApge6JfLIxqF3ih4JZTGqDDlIacHFa9cur3rHxhw2/OfGl7dSGtpCPs6NYuv+gSPd4ViURbwcuI1EMZtQVL7BBv44wX+ALq0tgUkvNkEQfYTo84SyYVGMUoMznYSDU3V12prf3qMY3772cMB+dVPTmqkwxp0RDMqhJi5ubr+7pLFmG3/ScC0XZSgCOv0jiO1pIItLm9Y2LjUnV9OYXzx5ByAxHXVnJm7/mxsxzEWGB333+NZ6edXoIMa3Yiw75GV2oTDHxTGMLWXGluBYsPIh/B7Gli7BihOSNJAJxc+9RCGBIWPfG1VzwM2N1sH5MIYwcCwO5ZQlQ4q6CEUxT5yHi2QK2SxtpFBOHHvF+Ai5MYhKyOkwpqsWNlCoeRD6xRr9vkYhgPGhIp872ww8zIP9KObAE+yyPRayLo9pF2WlsGXDO85OtxO8/AkYwWeXSs31x5vf3Pt2DLLdQvCmGpqLDY0kj5Wb2qsoIxMSlKpDqc5iv44Hu40Hu40Hu40Hu40Hu435A9M32o5puUR1AAAAAElFTkSuQmCC"
    }
  }
}

Sample request with qrType=UNIVERSAL_RP_SPECIFIC

{
    "operation":"START_OOB_REG",
    "sessionData":{
        "sessionKey":"<session JWT>"
    },
    "id":"sample",
    "oobRefId":"12345",
    "oobMode":{
        "qr":"true",
        "rawData":"true",
        "qrType":"UNIVERSAL_RP_SPECIFIC",
        "webUrl":"https://www.example.com:8443/"
    }
}

Sample response when qrType=UNIVERSAL_RP_SPECIFIC

A developer updated the response filter configuration so the API Server returns the OOB Reference ID in additionalInfo.

{
  "statusCode":4000,
  "id":"sample",
  "lifetimeMillis":180000,
  "additionalInfo":{
    "oobRefId":"12345"
  },
  "oobStatusHandle":"a2V5aGFuZGxlAAAAArEHCGN74lechjjgjamKXHHQKjiTujzmKNjpbWXihxTodTt32c-YSaAuLji2uw_TjV20ZXblcLlhiBWB7nZw2Xvh9KPSu4-IhjbiBSDfuH-4RFWIQ6wK5AUB2aY",
  "modeResult":{
    "qrCode":{
      "qrImage":"iVBORw0KGgoAAAANSUhEUgAAASwAAAEsAQAAAABRBrPYAAADAElEQVR4Xu2XUW5rIQxEvQPvf5feAfUZk/cUGqn96twPUJsQODfCAx6TWL9pFefIx3axo13saBc72sWOdrGjXexoG6uIWJGZFVUrIxfdGbZj/VfMNlXZH3mvZNiP9dLpZ685erY0mxp+AoauLTHTmYBE8RAMaLWkRBGgMcN2DBJx+3OvvQ9BTvfDCflzrFeNmmcjGDemxqrJakXTWfN/xooVwvaKs3KyZrHneA/H1I31eWSjY+Y5lfrMixkjVVrSFhhz5qkOiKSZCKxYYczKZjY95dKt8zd5LdjUDdlgYjTKFY7pA7DQohcyS1t8WmOveSOG7UneEZbnZIgzbcX0rjsAtxYpnbq/vIdgwWTGiahkTHcRuFN5O7QXk5T4C56jI5nkTxyOZMFkLWjJ5mvx/Vlebcd6VF2WPwegH0RmHjJjSuFg0/nAY0TDw9O8WGI0lDSd0LnGp7bfjnEcERlRSRuomiyyY2t784AapU9UbkzrRdMOBHm5G0jod3ktWJEyC4QrQZHG2I7G/VhrWaw51ZHWdHeEVowiq2pLIhfVTUHJFN1YbzfJQkmjh+kkFn2kjANb84NH9gLPI2OLr68xYkHeBpc7PIZrsXxxZ7MV0/WTqYUj6t6SnNRULfFiiIs3N61fi8naJ4n8GEWNdbPfmCIhlA6AH8NeyI+YklEYDg/w78aSnxGSlQHBmOJhNSZs9n57Cx0uK/spO5YsGj17y/sAcAqwGz9WWM1EwNYnedO1owWfb7Fii1TZCpM+yd2YIPwYNTekZ5I7iIzprMluN7b2MO+s/HUE/slvw4hg7eNIVqt4LLJ8f4sRo1r0INUCRbmnUERQ249R0eZQLqUwjigf3CFasaUKAsgBYJTc+RaCASsEpZ6RyN0W9Zfytr/FivHHTmM6+idvCOEBGMvX0ll8yHDUU+I8ASNHZIF4dY8R0psNWjG8T0bd+57cEz6H8LeYSMyFo6nCyytq+zE2WemCuD1XZHWS0Xbsp3axo13saBc72sWOdrGjXexov8W+AOpfqVRc/KPFAAAAAElFTkSuQmCC"
    },
    "rawData":"https://www.example.com:8443/#nnl-oobdata=%7Cr%7Ca2V5aGFuZGxlAAAAAnxBifk3A8oCWCEH_CntrzNSkYtakM_UCHuVmW3FeKoZTtL8SmqkbFiyOewc3BN0sZ-gGWGKNr6hKsDXRG79hLRsXOSU6rOmMFO-Fv-N8C37gV2_krZvu6KZd7hQLM0%7C12345%7C"
  }
}

Sample request with qrType=APP_ANY_RP

{
    "operation":"START_OOB_REG",
    "sessionData":{
        "sessionKey":"<session JWT>"
    },
    "id":"sample",
    "oobRefId":"12345",
    "policyName":"default",
    "oobMode":{
        "qr":"true",
        "qrType":"APP_ANY_RP"
    }
}

Sample response when qrType=APP_ANY_RP

A developer updated the response filter configuration so the API Server returns the OOB Reference ID in additionalInfo.

{
  "statusCode":4000,
  "id":"sample",
  "lifetimeMillis":180000,
  "additionalInfo":{
    "oobRefId":"12345"
  },
  "oobStatusHandle":"a2V5aGFuZGxlAAAAAtddwMgKIA8ebPjirjDRm7haDH_uzmoKn4n26G_aSOHwKOqBWKEWG0310X5R0AoQ5qHaUAGFZRwlpkCzde0WgDCnE4bg37rjImoitIq1YqMCnb-Z1gBvMdKTK6Y",
  "modeResult":{
    "qrCode":{
      "qrImage":"iVBORw0KGgoAAAANSUhEUgAAASwAAAEsAQAAAABRBrPYAAAC+klEQVR4Xu2XUa7rIAxEvQPvf5feAW/OmEo3qNK9X8/5gKYKgZMKBo+hsf5SKs6Wr+ViR7nYUS52lIsd5WJHudhRNlYRURnBc+QqPlVunse4MoqSK7PornTzOFZRGnuulR65ahnU4y2YJA7NQwrrJrHrPZgGv7z69KmBljdgvnJFg1p+BSnB+SVC/juGtF/KaZkJzFWvuiKAr+fxo28Q22JmpaKRpVdguu2QdwLTquNjSSxOqgrDMzhnHkPQJNX0K7ZP4ununcUKRGvfSQaBTR7yTmDYA2GTu1UmOJnI7p/EEBcxSXwkaj0Rms6I0xg7GU9tHKKgrDMaT2Pci+Ak8yG0dE0OLg/LzGBkFq8+BwHHpbMhITCN4WbLap2JSo5TVJ+pZgbzBBaHJ0zdVkncM45hYla6I9HTsbBb3VFssdpU4VAUZR2ez5lOYJLWa13orJkE64958NEwxhlFIy90DQcpWdEN85jugbZsuEyBrZdpPbePEQwpHZIo68hUriYcdlwOYyy/D+sdkGzARt+A9bB7AuxtbB+A4xh30qC/+pAQE+hw/QjGH/6wxp/pYBjCcx7TYvdNTWy3PMs8P2Y4hpWPKV5tTC0Cc5MRjwgZwHTnFKDM4pCkVS/gmM/PzGEEID30gfCIutvNsxhaLk514Oxx6vDVcTmKoSgSk5SxT5/4VgfrLEYj1fYNf8t8PCAKxjEGrS5lvUBaqrY0phnHkjNAJ8HcAGAcrp/AcAt9yZZGetYs4Oykaay8+gyZwOwdjffw9zTmpScGJXQwn+pz3841oxiq7s2XmOQsaqG7dxTzPsHAOUPxQJ5B9OfSj2DeM7qaNjRz8ZRegKml8ElnGwkb7GuI/QLMEhcBQLJmEq34POZh9xZSFM4Dru5fGcW4MC+cGknUfufY2kYw1jydcfSl7ntAvwLDyhiFGKCnLf0KDC018mT7aFe7Mo9B1v6z6OOAMyFCz2M04xFmEjZykQQ/Ak9iv5WLHeViR7nYUS52lIsd5WJH+Sv2D3cf0DyjkkAHAAAAAElFTkSuQmCC"
    }
  }
}

Sample request with qrType=APP_RP_SPECIFIC

{
    "operation":"START_OOB_REG",
    "sessionData":{
        "sessionKey":"<session JWT>"
    },
    "id":"sample",
    "oobRefId":"12345",
    "oobMode":{
        "qr":"true",
        "qrType":"APP_RP_SPECIFIC"
    }
}

Sample response with qrType=APP_RP_SPECIFIC

A developer updated the response filter configuration so the API Server returns the OOB Reference ID in additionalInfo.

{
  "statusCode":4000,
  "id":"sample",
  "lifetimeMillis":180000,
  "additionalInfo":{
    "oobRefId":"12345"
  },
  "oobStatusHandle":"a2V5aGFuZGxlAAAAAj76lWNLqqmhXLgSBji1QS7dYV1T48L0shLGeFmEYoETrrvciKJ72NptgSozDm8KgJHwhLtQ-Zl0OglQHSxih7BE7J2XqsFBvwVaTEZPg8cQZxTx4uiquPmrOdo",
  "modeResult":{
    "qrCode":{
      "qrImage":"iVBORw0KGgoAAAANSUhEUgAAASwAAAEsAQAAAABRBrPYAAADHUlEQVR4Xu2YPY6kMBCFCxEQcgTfpLlYSyBxMfomPgIhQatr33tmRotnpd1gA5dEBYwNn1uqqX+b/4vsVr/5o9xYJTdWyY1VcmOV3FglBTsM4h+zZNNuNmzYDi9fM/72QbDJPR+dvxNX7i9/m3X7nLFeg2AP6zPUnd0/49uwJQHssDES5hteHd3+tMGhM77xaCjsmOBqsNNi9hgXGz7SPgw20d8eo7tiBNuV7uew2E+3bBRj1ANbyf7+qKK+YUwCw1DnvZfTJW2/pH3sYJJCxu1drmbwMm2zPZgJQmD4kgaGOXd8jQMTF6+9smnDGJLtBtgZI4ZoAYZTLINBsM6XhIdercxjczb623DVtGFMSqJoLKUF0RaaPpOpKobAQCTUb5iIFRARBPf7GDCaLQSGdAV/o2FEsCC6jFVFfcMYG6jEdCVNE/sQdIOwHTNaDAylYmEFXOhnEOqnMELIRMEmvvpA04GtFIz1TM6Gtva3hjFqSgIfaSdWQOVePmJgrqbv5Z5pnYyAn5mAFfXKx+1j0hRaKeCtrHCAq/IjAbCOOYshgzm7P1vCibXwGvVNY2WO+JqHZKcyLV2M1TJ2zkPvNGwIfSYBKyv+C2JgSrtlFOKKZdDIqgyGwFC/VfdY8vBg/HPA8OJ5ITDaia6GkU7qsprg9VJ1gy1j6qJ0y3eOQmwJgaRr1DeOqY3VMMGbv7LyLLOFwKQVisbsGCtmJi4ofp6fg2AIj8wY4RWZVgujHj7oVeJqFtOVpbNqD2xGsF04KCkJSNrHsINWipuNXualD5lZAaNgzLO6tEf2Muq30t+UhdcYGGQFMaoPmRUtmWx1e9w0xvs+Xm+oCc88xZmVfchF04Yx1uqMXlaXl6aO5Ls30c+0j0lgmPdJdMzC3915CIzlw9jGlj6ESrJ+qzufg2CTMi7vBtSJn/V7paZRME5BakaKUD9pf70laB4rWkk/pitkLwxKiv8wGDTtlYBTmYzob/UA1TA2wd8QKLqthJKlkDBuJlERMLrWwbaJ4xEnil6JCxXwZ3JoE/ur3FglN1bJjVVyY5XcWCX/GfsFBmfXVddGKlMAAAAASUVORK5CYII="
    }
  }
}

INIT_OOB_REG

Initiates out-of-band registration.

The Server uses the allowed UAF authenticators specified by the FIDO registration policy passed to START_OOB_REG and device information to create a list of permitted authenticators that the user could register.

For FIDO2 authenticators, the Server compares the authenticator's characteristics to the desired FIDO2 authenticator characteristics specified by the registration policy. The client uses these as hints to prompt the end user for the authenticator. The Server enforces user verification and attestation preference during FINISH_OOB_REG based on the policy configuration. If you have not configured the registration policy for FIDO2 authenticators, then INIT_OOB_REG fails with a 4403 when a web app tries to register a FIDO2 authenticator.

Request

Attribute

Description

operation

Required. The string INIT_OOB_REG.

callerOrigin

Required if a web app is sending the request and that app has a different origin than the Digipass S3 API Server. A web origin is defined by the scheme (protocol), host (domain), and port of the URL used to access it.

The API Server checks if this origin is listed in its origin allow list, if not, the request is rejected. See My Web Apps Have a Different Origin.

message

Required. Generated by the App SDK on the client. This is an opaque value. The client app is responsible for sending message. This is a base64-URL encoded string.

optionsData

Optional. An object used to pass additional attributes to REST API operations. See OptionsData for a complete description.

sessionData

Optional. An object containing the user's session information. See SessionData.

This is for the user who is logged in on the second device. This person must be the same user logged in on the primary device. Omit if the user is not logged in on the second device.

Response

The following attributes are always present in the JSON payload of the response.

Attribute

Description

id

The unique id that correlates START_OOB_REG, INIT_OOB_REG, and FINISH_OOB_REG operations for the same user. String.

If id was sent in the request, the same id is returned. If not, a server-generated ID is returned. If id was provided in the REST payload but the server was unable to parse the payload, the value is unknown.

statusCode

Server-specific status code that reports the success or failure of the requested operation. Integer.

See Response Status Codes below for the status and error codes.

The following attributes are present in the response upon a successful operation (Server status code 4000).

Attribute

Description

additionalInfo

An object containing information about the client app and device from the second device. Contains the 5 attributes listed in the rows below.

In order for the API Server to return this information:

  1. The client app must have sent device, protocol, and extension information in the INIT_OOB_REG request's message attribute

  2. Update the response filter configuration so the API Server returns the elapsed time, payload extensions, OOB reference ID, and protocol.

    By default, device information is automatically returned. Refer to Response Filter Configuration.

additionalInfo.device

A DeviceDetail object containing information about the second device such as the device’s unique ID, model, and manufacturer.

additionalInfo.elapsedTime

The amount of time to process the request.

additionalInfo.extensions

Information about a device’s location and jailbreak status. List<Extension>.

additionalInfo.oobRefId

ID provided by the RP app to retrieve contextual information from the RP server that can be displayed to the app user. Only returned if oobRefId was included inside oobData in the scanned QR code.

additionalInfo.protocol

The protocol used by the Authentication Server based on information from the request. String. One of UAF or Web.

lifetimeMillis

Lifetime of message in milliseconds. Long.

Your client or web app can use this to tell a user how much time they have to complete the operation or warn the user that the Server does not accept a response once lifetimeMillis has expired.

message

An opaque value that contains the challenge exchanged between the Server and the App SDK. A base64-URL encoded string.

message must be sent to the App SDK.

Response status codes

The following are the descriptions of the Auth Server status codes returned by INIT_OOB_REG. Under certain circumstances, the API Server returns an unsuccessful HTTP status code. Examples include an invalid request or invalid session. You can find descriptions of these in API Server Status Codes.

Server Status Code

Description

Examples

4000

OK. Operation completed

Request created successfully.

4403

PolicyVerificationException

Requested policy is not available on Server.

4404

Internal Server Error

Internal server error.

Failed to read from the database.

Failed to connect to the database.

Failed to read required properties.

4406

Payload

Exception

An error occurred with one or more attributes. For example, message has an invalid type.

4408

UnsupportedClient

MessageException

message cannot be handled.

Unacceptable Client Capabilities - invalid protocol version.

4409

ClientMessageException

message is invalid JSON.
The message from the App SDK is malformed (unable to decode base64URL).

4450

UserCancelledException

The user canceled the registration operation.

Samples

Sample request URL

https://www.example.com:8443/nnlgateway/nnl/<tenant_id>/reg

Sample request

{
    "operation":"INIT_OOB_REG",
    "message":"<base64url-encoded-data>"
}

Sample response

A developer updated the response filter configuration so the API Server returns the protocol and OOB Reference ID in additionalInfo.

{
    "id": "INIT_OOB_REG_1439247650812",
    "statusCode": 4000,
    "message": "<base64url-encoded-data>",
    "additionalInfo": {
        "protocol":"uaf_1.0",
        "oobRefId":"12345",
        "device": {
            "id": "123456789abcdef1234567890",
            "type": "android",
            "info": "OneSpan's device"
        }
    },
    "lifetimeMillis": 300000
}

FINISH_OOB_REG

Processes the registration response provided by the caller and completes the OOB registration process.

Request

Attribute

Description

operation

Required. The string FINISH_OOB_REG.

callerOrigin

Required if a web app is sending the request and that app has a different origin than the Digipass S3 API Server. A web origin is defined by the scheme (protocol), host (domain), and port of the URL used to access it.

The API Server checks if this origin is listed in its origin allow list, if not, the request is rejected. See My Web Apps Have a Different Origin.

channelBinding

Optional. Channel binding data available from the TLS endpoint. ChannelBinding object.

message

Required. Generated by the App SDK on the client. This is an opaque value. The client app is responsible for sending message. This is a base64-URL encoded string.

optionsData

Optional. An object used to pass additional attributes to REST API operations. See OptionsData for a complete description.

sessionData

Optional. An object containing the user's session information. See SessionData.

This is for the user who is logged in on the second device. This person must be the same user logged in on the primary device. Omit if the user is not logged in on the second device.

Response

The following attributes are always present in the JSON payload of the response.

Attribute

Description

id

The unique id that correlates START_OOB_REG, INIT_OOB_REG, and FINISH_OOB_REG operations for the same user. String.

If id was sent in the request, the same id is returned. If not, a server-generated ID is returned. If id was provided in the REST payload but the server was unable to parse the payload, the value is unknown.

statusCode

Server-specific status code that reports the success or failure of the requested operation. Integer.

See Response Status Codes below for the status and error codes.

The following attributes are present in the response upon a successful operation (Server status code 4000).

Attribute

Description

additionalInfo

An object containing information about the client app and device from the second device. Contains the attributes listed in the rows below.

In order for the API Server to return this information,

  1. The client app must have sent this information in the FINISH_OOB_REG request’s message attribute.

  2. Update the response filter configuration so the API Server returns additional authenticator details, elapsed time, extension information, OOB reference ID, policy name, protocol, and post operation rule results.
    By default, the API Server automatically returns device information, authenticator handles, and authenticator attachment hints. Refer to Response Filter Configuration.

additionalInfo.authenticatorsResult

The authenticator that the user registered. Also, the status reflects the action for the App SDK. List<AuthenticatorResult>.

additionalInfo.device

A DeviceDetail object containing information about the second device, such as the device’s unique ID, model, and manufacturer.

additionalInfo.elapsedTime

The number of milliseconds to process the request.

additionalInfo.extensions

Information about a device’s location and jailbreak status. Message payload extensions received by the Server in FINISH_OOB_REG and INIT_OOB_REG requests. List<Extension>.

additionalInfo.headerExtensions

Protocol-specific header extensions. List<HeaderExtension>

additionalInfo.oobRefId

ID provided by the RP app to retrieve contextual information from the RP server that can be displayed to the app user. Only returned if oobRefId was included inside oobData in the scanned QR code.

additionalInfo.policyName

FIDO registration policy used for the operation. String.

additionalInfo.protocol

The protocol used by the Authentication Server based on information from the request. String. One of UAF or Web.

additionalInfo.rulesResult

RulesResult populated as a result of policy rules processing giving out the matched rules details. RulesResult.

message

An opaque value that contains the challenge exchanged between the Server and the App SDK. A base64-URL encoded string.

message must be sent to the App SDK.

Response status codes

The following are the descriptions of the Auth Server status codes returned by FINISH_OOB_REG. Under certain circumstances, the API Server returns an unsuccessful HTTP status code. Examples include an invalid request or invalid session. You can find descriptions of these in API Server Status Codes.

Server Status Code

Description

Examples

4000

OK. Operation completed

Registration completed successfully.

4002

OK. Optional security checks failed

Failed to validate ChannelBinding.

4401

Challenge Expired

Exception

The request challenge has expired.

4402

Security Exception

Failed to validate the attestation.

Failed to validate Server challenge.

Failed to validate the Server data.

Failed to locate authenticator metadata.

Challenge replay detected.

Failed to validate extension data.

4403

Policy Exception

Failed to match policy.

Policy not supported.

Failed to register as configured max limit of registrations reached for the user.

4404

Internal Server Error

Internal server error.

Failed to write to the database.

Failed to read from the database.

Failed to connect to the database.

Failed to read properties.

4406

Payload

Exception

An error occurred with one or more attributes. For example, message has an invalid type.

4408

Unsupported

ClientMessageException

Attribute message cannot be handled.

Unacceptable Client Capabilities - invalid protocol version.

4409

ClientMessageException

Attribute message has invalid JSON. The message attribute from the App SDK is malformed (unable to decode base64URL).

4450

UserCancelledException

The user canceled registration.

Samples

Sample request URL

https://www.example.com:8443/nnlgateway/nnl/<tenant_id>/reg

Sample request

{
    "operation": "FINISH_OOB_REG",
    "message": "<base64url-encoded-data>"
}

Sample response

A developer updated the response filter configuration so the API Server returns the protocol, the elapsed time to process the request, additional authenticator details, FIDO policy used, post operation rule results, client app information, and payload extensions in additionalInfo.

{
  "statusCode":4000,
  "id":"rDRwiwww-m2CS3IWBbPuZw",
  "message":
"eyJzZXJ2ZXIiOnsiYXV0aGVudGljYXRvcnNSZXN1bHQiOlt7ImFhaWQiOiJBQkNEI0FCQ0QiLCJrZXlJRCI6ImZaeVNBMDNoN3h1c1gxRFpLdS11MzJ1RV9sX25RSG1tTGtSVHFDTlZ1YkEiLCJzdGF0dXMiOjQwMDB9XSwiYXBwSUQiOiJodHRwczovLzEyNy4wLjAuMTo4NDQzL1NhbXBsZUFwcCJ9LCJ1c2VyTmFtZSI6Im8yIiwidmVyc2lvbiI6IjEuMCIsIm9wZXJhdGlvbiI6IkZJTklTSF9PT0JfUkVHIiwicHJvdG9jb2wiOiJ1YWZfMS4wIn0",
  "additionalInfo":{
    "device":{
      "id":"123456789abcdef1234567890",
      "type":"android",
      "info":"NokNok Emulator",
      "model":"NokNok-AE 8.0",
      "os":"NokNokOS 8.0",
      "manufacturer":"NokNok",
      "supportsPlatformAuthenticator":true
    },
    "protocol":"uaf_1.0",
    "elapsedTime":25,
    "authenticatorsResult":[
      {
        "handle":
"WyJ1YWZfMS4wIiwiQUJDRCNBQkNEIiwiZlp5U0EwM2g3eHVzWDFEWkt1LXUzMnVFX2xfblFIbW1Ma1JUcUNOVnViQSJd",
        "uvi":"VPAT7rKZAfKqGzGgnX1_qLzZZ9lF9FPPpO64SfufBEg",
        "uviStatus":4,
        "status":4000,
        "aaid":"ABCD#ABCD",
        "authenticatorVersion":1,
        "attestationType":15879,
        "attestationTypeName":"basic_full",
        "attachmentHints":[
          "internal"
        ]
      }
    ],
    "oobRefId":"12345",
    "policyName":"default",
    "rulesResult":{
      "action":"ALLOW",
      "matchedRules":[
        {
          "name":"LocationVelocity",
          "riskScore":0,
          "template":"DummyRule",
          "group":"dummy group"
        }
      ]
    },
    "app":{
      "id":"android:apk-key-hash:rDQ4Tn60fAvxP8thtp6sOh5ococ",
      "name":"android:com.noknok.test.client",
      "qrSupported":false
    },
    "extensions":[
      {
        "id":"noknok.ipaddress",
        "data":"192.168.0.102",
        "operation":"FINISH_OOB_REG"
      },
      {
        "id":"noknok.ipaddress",
        "data":"192.168.0.102",
        "operation":"INIT_OOB_REG"
      },
      {
        "id":"noknok.wifi.ssid",
        "data":"Oviya",
        "operation":"FINISH_OOB_REG"
      },
      {
        "id":"noknok.wifi.ssid",
        "data":"Oviya",
        "operation":"INIT_OOB_REG"
      },
      {
        "id":"noknok.uaf.location",
        "data":"{\"accuracy\":99.2,\"countryCode\":\"US\",\"latitude\":32.52,\"longitude\":-124.482,\"status\":0}",
        "operation":"FINISH_OOB_REG"
      },
      {
        "id":"noknok.uaf.location",
        "data":"{\"accuracy\":99.2,\"countryCode\":\"US\",\"latitude\":32.52,\"longitude\":-124.482,\"status\":0}",
        "operation":"INIT_OOB_REG"
      },
      {
        "id":"noknok.uaf.jailbreak",
        "data":"{\n  \"status\" : \"0\",\n  \"isJailbroken\" : \"false\"\n}",
        "operation":"FINISH_OOB_REG"
      },
      {
        "id":"noknok.uaf.jailbreak",
        "data":"{\n  \"status\" : \"0\",\n  \"isJailbroken\" : \"false\"\n}",
        "operation":"INIT_OOB_REG"
      }
    ]
  }
}

STATUS_OOB_REG

Checks the OOB registration status on the device. This occurs on the device that starts the OOB registration operation.

The Server polls for the status of the registration operation identified by oobStatusHandle. Check if oobStatusHandle has expired since it has a lifetime.

Request

Attribute

Description

operation

Required. The string STATUS_OOB_REG.

callerOrigin

Required if a web app is sending the request and that app has a different origin than the Digipass S3 API Server. A web origin is defined by the scheme (protocol), host (domain), and port of the URL used to access it.

The API Server checks if this origin is listed in its origin allow list, if not, the request is rejected. See My Web Apps Have a Different Origin.

oobStatusHandle

Required. Identifies a specific OOB registration operation.

An alphanumeric string, maximum 4000 characters.

Use the oobStatusHandle returned in the response from a START_OOB_REG operation.

optionsData

Optional. An object used to pass additional attributes to REST API operations. See OptionsData for a complete description.

sessionData

Required. An object containing the user's session information. See SessionData.

Response

The following attributes are always present in the JSON payload of the response.

Attribute

Description

id

The unique id that correlates INIT_OOB_REG and FINISH_OOB_REG operations for the same user. Base64-URL encoded string.

If id was sent in the request, the same id is returned. If not, a server-generated ID is returned. If id was provided in the REST payload but the server was unable to parse the payload, the value is unknown.

statusCode

Server-specific status code that reports the success or failure of this operation. Integer.

See Response Status Codes below for the status and error codes.

The following attributes are present in the response upon a successful operation (Server status 4000).

Attribute

Description

additionalInfo

An object containing information about the client app and device from the second device. Contains the attributes listed in the rows below.

In order for the API Server to return this information,

  1. The client app must have sent this information in the INIT_OOB_REG request’s message attribute

  2. Update the response filter configuration so the API Server returns the additional authenticator details, elapsed time, header extensions, payload extensions, OOB reference ID, policy name, and protocol.

    By default, the API Server automatically returns device information, authenticator handles, and authenticator attachment hints. Refer to Response Filter Configuration.

additionalInfo.authenticatorsResult

Authenticators that succeeded or failed to complete the OOB registration. List<AuthenticatorResult>.

The status reflects the action for App SDK.

additionalInfo.device

A DeviceDetail object containing information about the client.

additionalInfo.elapsedTime

The amount of time, in milliseconds, to process the request.

additionalInfo.extensions

Message payload extensions received by the Server in FINISH_OOB_REG and INIT_OOB_REG requests. List<Extension>.

additionalInfo.headerExtensions

Protocol-specific header extensions. List<HeaderExtension> .

additionalInfo.oobRefId

ID provided by the RP app to retrieve contextual information from the RP server that can be displayed to the app user. Only returned if oobRefId was included inside oobData in the scanned QR code. String.

oobRefId is present in the STATUS_OOB_REG operation following the FINISH_OOB_REG operation.

additionalInfo.policyName

FIDO registration policy used for the operation. String.

additionalInfo.protocol

The protocol used by the Server based on information from the request. String. One of UAF or Web.

push

If the client app is able to enroll for push notification with Apple Push Notification Service (APNS) or Firebase Cloud Messaging (FCM), then this object is returned.

Contains the 4 attributes listed below.

push.createdTimeStamp

Creation date and time of push handle in UTC format. String

push.handleLifetimeDays

Remaining lifetime of push handle in days. Long.

push.pushHandle

Identifies the device that receives a push notification and then initiates an OOB registration. A Base64-encoded string, maximum 4000 characters.

push.status

Result of the push notification. Integer.

Also indicates status when the Server is unable to generate a new pushHandle because the maximum number of push notifications has been reached. This could be due to delivery or processing failures.

remainingTimeMillis

Lifetime of oobStatusHandle in milliseconds. If the lifetime has expired, the value is negative.

Response status codes

The following are the descriptions of the Auth Server status codes returned by STATUS_OOB_REG. Under certain circumstances, the API Server returns an unsuccessful HTTP status code. Examples include an invalid request or invalid session. You can find descriptions of these in API Server Status Codes.

Server Status Code

Description

Examples

4000

OK. Operation completed

Registration has been completed successfully.

4004

OK. Operation in progress

The OOB Reg operation has started and is still in progress.

4005

OK. Operation Pending

The OOB Reg operation is pending. Also implies there is more info available when the statusCode is: 4004.

4401

Challenge Expired

Exception

The request challenge has expired.

4402

Security exception

Failed to decrypt data.

Failed to validate extension data.

Failed to decode CodeP.

Poll input validation has failed against data.

CodeP has an invalid length.

4404

Internal Server Error

Internal server error.

Failed to read from the database.

Failed to connect to the database.

Failed to read required properties.

4406

Payload

Exception

An error occurred with one or more attributes. For example:

  • Parameter oobStatusHandle is empty.

  • Parameter message has an invalid type.

4450

UserCancelledException

Operation is canceled.

Samples

Sample request URL

https://www.example.com:8443/nnlgateway/nnl/<tenant_id>/reg

Sample request

{
    "operation": "STATUS_OOB_REG",
    "sessionData":{
        "sessionKey":"<session JWT>"
    },
    "oobStatusHandle": "AgAgUIh9AFHjsDU_mPp_DUsghnYn7kg3sl3z-keVqCtM09IDAAgAAAFPGdfXiwQAAQEBACCAcQ81Htjr69mhHEuluuT9Y9orXRfyRqZ_plbHpTNwRQ"
}

Sample response

A developer updated the response filter configuration so the API Server returns the FIDO policy used, the elapsed time for processing the request, protocol, and additional authenticator details in additionalInfo.

{
  "statusCode":4000,
  "additionalInfo":{
    "device":{
      "info":"OneSpan's device",
      "id":"dID_82b5799d-869a-4a9b-95c6-fdd36a6b61a1_1",
      "type":"android"
    },
    "policyName":"reg_policy",
    "elapsedTime":25,
    "authenticatorsResult":[
      {
        "aaid":"ABCD#ABCD",
        "uvi":"ZsGHbiYd6OgLVYW49G-qQHrwrgw83Wve5Ge5iQVYv8",
        "uviStatus":4,
        "authenticatorVersion":1,
        "attestationType":15879,
        "authenticatorExtensions":[
          {
            "id":"tag1",
            "data":"extensionData1",
            "fail_if_unknown":false
          },
          {
            "id":"tag2",
            "data":"extensionData2",
            "fail_if_unknown":false
          },
          {
            "id":"criticalTag1",
            "data":"criticalExtensionData1",
            "fail_if_unknown":true
          },
          {
            "id":"criticalTag2",
            "data":"criticalExtensionData2",
            "fail_if_unknown":true
          }
        ],
        "status":4000,
        "handle":
"WyJ1YWZfMS4wIiwiQUJDRCNBQkNEIiwiQnVKk5BQlVoVHZUeW1WY3FYMk9fRmhpRFY0aHA1OThxLTI0eWEzVlmUSJd"
      }
    ],
    "protocol":"uaf_1.0"
  },
  "push":{
    "pushHandle":
"m3-ZrKasG_GhxK4IdEIyOIUysfOFcBhMkvm5BOyRZMWCMGozvHP3Fur9edF1mFLwI1iZpc0LuwCiY1ZLGqyWJea7zOp7kGJdHFSuLzd5vCOD7wLmPp2s5ciEtXRPUEaI4z5eZYlqGXKPPtW4s7H_Q5zBOaUiqNVueRoHx_ZBVEy-8A4",
    "handleLifetimeDays":30,
    "createdTimeStamp":"2020-09-08T06:18:08.904Z",
    "status":4000
  },
  "id":"dEgViadKjxcleujKbpfi6g"
}

CANCEL_OOB_REG

Cancels the OOB operation from the second device (authenticating device) on the Server.

Request

Attribute

Description

operation

Required. The string CANCEL_OOB_REG.

callerOrigin

Required if a web app is sending the request and that app has a different origin than the Digipass S3 API Server. A web origin is defined by the scheme (protocol), host (domain), and port of the URL used to access it.

The API Server checks if this origin is listed in its origin allow list, if not, the request is rejected. See My Web Apps Have a Different Origin.

nnlData

Required. Required to cancel the operation from the second device used to perform the OOB registration. You can get nnlData from the response message of INIT_OOB_REG. String.

optionsData

Optional. An object used to pass additional attributes to REST API operations. See OptionsData for a complete description.

sessionData

Optional. An object containing the user's session information. See SessionData.

This is for the person logged in on the second device. Must be the same as the sessionData passed into INIT_OOB_REG. Omit if the user is not logged in on the second device.

Response

The following attributes are always present in the JSON payload of the response.

Attribute

Description

id

The unique id that correlates INIT_OOB_REG and FINISH_OOB_REG operations for the same user. String.

statusCode

Server-specific status code that reports the success or failure of this operation. Integer.

See Response Status Codes below for the status and error codes.

The following attributes are present in the response upon a successful operation (Server status code 4000).

Attribute

Description

additionalInfo

An object containing information returned by the Authentication Server. Contains the 2 attributes listed below.

In order for the API Server to return this information:

  1. Send oobRefID in START_OOB_REG's request

  2. Update the response filter configuration so the API Server returns elapsed time and OOB reference ID. Refer to Response Filter Configuration.

additionalInfo.elapsedTime

The amount of time, in milliseconds, to process the request.

additionalInfo.oobRefId

ID provided by the RP app to retrieve contextual information from the RP server. Alphanumeric string.

The API Server only returns this attribute if you sent oobRefID in START_OOB_REG's request.

Response status codes

The following are the descriptions of the Auth Server status codes returned by CANCEL_OOB_REG. Under certain circumstances, the API Server returns an unsuccessful HTTP status code. Examples include an invalid request or invalid session. You can find descriptions of these in API Server Status Codes.

Server Status Code

Description

Examples

4000

OK. Operation completed

Authentication Request created successfully.

4401

Challenge Expired

Exception

The request challenge has expired.

4402

Security Exception

Cancel input validation has failed against DB.

Username mismatch.

NNLData validation failed.

4404

Internal Server Error

Internal server error.

Failed to read from the database.

Failed to connect to the database.

Failed to read required properties.

4406

Payload

Exception

Parameter nnlData is empty.

4453

Operation already completed

Unable to cancel because registration has completed.

Samples

Sample request URL

https://www.example.com:8443/nnlgateway/nnl/<tenant_id>/reg

Sample request

{
    "operation":"CANCEL_OOB_REG",
    "nnlData":"giltFqT8g5CblHqnzXLrrYoxG6nmseHYWGSdWUxBW6hHVJ9RHj9WgmYxbLE8C98YSizqHqUlqzkeVZ7F_5GzigU8X67qyg"
}

Sample Response

{
    "id":"CANCEL_OOB_REG_1439247762691",
    "statusCode":4000
}

CANCEL_STATUS_OOB_REG

Checks the OOB cancel registration status on the second device.

Request

Attribute

Description

Operation

Required. The string CANCEL_STATUS_OOB_REG.

callerOrigin

Required if a web app is sending the request and that app has a different origin than the Digipass S3 API Server. A web origin is defined by the scheme (protocol), host (domain), and port of the URL used to access it.

The API Server checks if this origin is listed in its origin allow list, if not, the request is rejected. See My Web Apps Have a Different Origin.

oobStatusHandle

Required. Identifies the specific OOB registration operation that you want to cancel on the initiating device.

An alphanumeric string, maximum 4000 characters.

Use the oobStatusHandle returned in the response from a START_OOB_REG operation.

optionsData

Optional. An object used to pass additional attributes to REST API operations. See OptionsData for a complete description.

sessionData

Required. An object containing the user's session information. See SessionData.

Response

The following attributes are always present in the JSON payload of the response.

Attribute

Description

id

The unique id that correlates INIT_OOB_REG and FINISH_OOB_REG operations for the same user. Base64-URL encoded string.

statusCode

Server-specific status code that reports the success or failure of this operation. Integer.

See Response Status Codes below for the status and error codes.

Response status codes

The following are the descriptions of the Auth Server status codes returned by CANCEL_STATUS_OOB_REG. Under certain circumstances, the API Server returns an unsuccessful HTTP status code. Examples include an invalid request or invalid session. You can find descriptions of these in API Server Status Codes.

Server Status Code

Description

Examples

4000

OK. Operation completed

Registration request canceled successfully.

4402

Security Exception

Failed to validate extension data.

4404

Internal Server Error

Internal server error.

Failed to read required properties.

4406

Payload Exception

An error occurred with one or more attributes. For example, attribute oobStatusHandle is empty.

4453

OperationAlreadyCompleted

Unable to cancel even if the operation is completed.

Samples

Sample Request URL

https://www.example.com:8443/nnlgateway/nnl/<tenant_id>/reg

Sample request

{
    "operation":"CANCEL_STATUS_OOB_REG",
    "sessionData":{
        "sessionKey":"<session JWT>"
    },
    "oobStatusHandle":"AgAgCcIuezLxWhezpTS7Le3-lGQsTmO7TqJ7IYspDote_gsDAAgAAAFPcv9jhwQAAQEBACCCp9fGEPR4GC-S57z1UCTtCXbPYBlhu5acflIHXMyUvA"
}

Sample response

{
    "id":"dEgViadKjxcleujKbpfi6g",
    "statusCode":"4000"
}