If you intend to use push notifications for FIDO OOB authentication, you must configure your app to work with the appropriate push notification platform. Configure Android apps to work with Firebase Cloud Messaging (FCM) and/or Huawei Mobile Services (HMS). The latest Huawei devices use HMS because they do not support Google Play Services. Configure iOS apps to work with Apple Push Notification service (APNs).
Android Firebase Cloud Messaging
These instructions assume that you configured your Android app for Firebase as outlined in Adding Firebase Configuration in the Developer Guide for Android. Copy the sender id and generate a new private key JSON file from the Firebase console. Add this information to your app’s properties using the Admin Console.
1. Get the Sender ID and Generate a New Private Key
Use the Firebase console to get your project's sender ID and generate a new private key for your app.
Login to the Firebase console (https://console.firebase.google.com) and open your project.
Click the settings icon and select Project settings from the menu.
.png?sv=2026-02-06&spr=https&st=2026-09-30T02%3A18%3A45Z&se=2026-09-30T02%3A32%3A45Z&sr=c&sp=r&sig=LTMIaISyyNUWXXbDWraoTa%2FCJ2iCgnWc19Zk02yeIuk%3D)
When the Settings panel appears, click the Cloud Messaging tab. Copy the sender ID from this window.
.png?sv=2026-02-06&spr=https&st=2026-09-30T02%3A18%3A45Z&se=2026-09-30T02%3A32%3A45Z&sr=c&sp=r&sig=LTMIaISyyNUWXXbDWraoTa%2FCJ2iCgnWc19Zk02yeIuk%3D)
In the Settings panel, click the Service accounts tab. At the bottom of the Firebase Admin SDK panel is the Generate new private key button. Click that button.
.png?sv=2026-02-06&spr=https&st=2026-09-30T02%3A18%3A45Z&se=2026-09-30T02%3A32%3A45Z&sr=c&sp=r&sig=LTMIaISyyNUWXXbDWraoTa%2FCJ2iCgnWc19Zk02yeIuk%3D)
The Generate new private key dialog appears. Click Generate key. Firebase downloads a JSON file containing your private key. Note the file's location.
2. Configure Your App to Receive Push Notification
Login to Digipass S3 Admin Console and, if needed, switch to the correct tenant. Navigate to Configuration > Apps.
Click on your app in the Apps list. The App page appears. Select the Push Notification and Google Push Service (FCM) checkboxes.
If you are not using the Secrets plugin, the page looks like this:

Enter the FCM Sender ID. If you are not using the Secrets plugin, Click Choose File. Navigate to the location of the JSON file containing your private key and upload that file. Click Save.
If you are using the Secrets plugin, select Handle for HTTP Key. Enter your handle for the external secrets manager. Click Save.
By default, Firebase push messages are sent with HIGH priority. To downgrade the priority to NORMAL, use the Digipass S3 Command Line Interface (CLI) to modify the Android App FCM property oob.fcm.push.priority. The following example CLI command sets the oob.fcm.push.priority for OneSpan's Passport app:
./nnl-mgmt.sh properties set -name android:com.noknok.android.passport2##oob.fcm.push.priority -value NORMALiOS
Apple provides development servers as well as production servers for APNs. During development, choose a development server so you can use a debugger. Production servers are more reliable but they do not allow debuggers.
Configure your app to use APNs by uploading either a token signing key or an APNs certificate. Digipass S3 strongly recommends using a token signing key, because Apple is phasing out support for the binary protocol used with an APNs certificate. For more information about APNs, see Local and Remote Notification Programming Guide: Communicating with APNs.
Your app needs different APNs certificates or token signing keys to run on a development server vs. production server.
1. Allow Outgoing Connections from Your Server
To use Apple Push Notification Service (APNs), you must allow outgoing connections from your Server on port 2195. During development, your Server must be able to make connections to gateway.sandbox.push.apple.com:2195. For production usage, your Server must be able to make connections to gateway.push.apple.com:2195.
For more information on using APNs, see the Apple Developer documentation at Registering Your App with APNs.
2. Obtain APNs Credentials
To use a token signing key:
You need 3 things: the token signing key, the Key ID, and your Team ID.
Create a token signing key, a text file with a .p8 extension. See Establishing a token-based connection to APNs | Apple Developer Documentation. The Key ID, a 10 character string, is created at the same time.
Find the Team ID of your Apple Developer Account. This can be found at https://developer.apple.com/account/<your membership number>/membership/.
To use an APNs certificate:
See the Apple Developer documentation for instructions to obtain an APNs certificate and password.
3. Configure Your App to Use APNs with a Token Signing Key
Login to Digipass S3 Admin Console. If needed, switch to the correct tenant. Navigate to Configuration > Apps.
Click on your app's name in the Apps list. The App page appears.
Select the Push Notification checkbox. If your app only supports push notifications, then deselect the QR Code checkbox. If you are not using the Secrets plugin, you see this:

Click Choose File to upload the token signing key. Enter the Team ID and Key ID.
If you are using the Secrets plugin, the bottom half of the App page looks like this:
.png?sv=2026-02-06&spr=https&st=2026-09-30T02%3A18%3A45Z&se=2026-09-30T02%3A32%3A45Z&sr=c&sp=r&sig=LTMIaISyyNUWXXbDWraoTa%2FCJ2iCgnWc19Zk02yeIuk%3D)
Enter your handle to the Token Signing Key in the external secrets manager. Enter the Team ID and Key ID.
Click the Use APNs Production Server checkbox if you are using an APNs production server.
Alternate 3. Configure Your App to Use APNs with an APNs Certificate
Login to Digipass S3 Admin Console. If needed, switch to the correct tenant. Navigate to Configuration > Apps.
Click on your app's name in the Apps list. The App page appears.
Select the Push Notification checkbox and click Use APNs Certificate. If your app only supports push notifications, then deselect the QR Code checkbox. If you are not using the Secrets plugin, your App page looks like this:
.png?sv=2026-02-06&spr=https&st=2026-09-30T02%3A18%3A45Z&se=2026-09-30T02%3A32%3A45Z&sr=c&sp=r&sig=LTMIaISyyNUWXXbDWraoTa%2FCJ2iCgnWc19Zk02yeIuk%3D)
Click Choose File. Navigate to your APNs Certificate and upload. Enter the APNs Certificate's password in plain text.
The screenshot below shows what the App page looks like if you use the Secrets plugin.
.png?sv=2026-02-06&spr=https&st=2026-09-30T02%3A18%3A45Z&se=2026-09-30T02%3A32%3A45Z&sr=c&sp=r&sig=LTMIaISyyNUWXXbDWraoTa%2FCJ2iCgnWc19Zk02yeIuk%3D)
Click Configure with handle and enter your handle to the password in the external secrets manager.
Select the Use APNs Production Server checkbox if you are using an APNs production server.