Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Step 4. Configure the servers for push notifications

Prev Next

4.a. Verify that the push notification activator is activated

The Digipass S3 API Server's Push Notification Activator must be activated to perform out-of-band authentication and out-of-band transaction confirmation using push notifications. It triggers push notification in the following cases:

  • You assigned a push handle in sessionData. The push notification is sent to the device identified by the push handle. See Sending Custom Push Notifications in the Developer Guide for Web, Android or iOS.

  • There is no push handle in the authentication request. However, in the Session plugin's Main object, push_without_handle is set to true and the username is included in sessionData. In this case, the push notification is sent to the user's recently used device. To configure support for this feature, see 4.b. Optional: Support Push Notifications without a Push Handle immediately below.

Use the instructions below to verify that this plugin is active and activate it if it is deactivated.

  1. Login to the Admin Console and, if needed, switch to the desired tenant. Navigate to Configuration > API Server > Authentication API > Session Plugins.

  2. Look for the label Push Notification Activator. If the Status column shows INACTIVE, click the Activate icon in the Actions column.

4.b. Optional: Support push notifications without a push handle

Typically, sending a push notification requires that the web app use a push handle. You can configure the API Server to send the push notification to the user's most-recently-used device if there is no push handle. This has the following requirements for the client app:

  • A valid session is passed to authenticate()

  • The username is provided in sessionData

You can configure the API Server to include the username in sessionData and send a push without a handle using the Admin Console.

  1. In the Admin Console, login and, if needed, switch to the desired tenant. Navigate to Configuration > API Server > Session Plugins.

  1. Click the value for Authentication with user name. In the drop down, select Enabled.

  2. Click the value for Allow push notifications without push handle. In the drop down, select Enabled.

4.c. Optional: configure static authentication text

You can specify the static text to display to the user when authenticating with a push notification. By default, the client app displays the string "Sign-in" to the end user. You can change this string using either the Admin Console or nnl-mgmt.sh.

Using the Admin Console

  1. In the Admin Console, login and, if needed, switch to the desired tenant. Navigate to Configuration > Authentication Methods > Out-of-band.

  2. Update Push Notification Authentication Text by clicking the blue, underlined text on the same line.

  3. Verify that the value for Push Notification Authentication Text Mode is Static. If you need to change its value, use the instructions in the next section.

Using nnl-mgmt.sh

The static authentication text is stored in a tenant property called oob.auth.notification.text. Use nnl-mgmt.sh's set properties command to update the value. The example below updates the value for the authentication text in the Marketing tenant.

./nnl-mgmt.sh properties set -name oob.auth.notification.text -value "Please sign-in using a verification method on your device"-tenant Marketing

4.d. Optional: configure dynamic authentication text

You can create custom authentication text that includes the user name and other information specific to the user. Setting the push notification authentication text mode to dynamic directs the Auth Server to use custom text from the client app to prompt the user to sign in. To send custom text from your client app, refer to Sending Custom Push Notifications in the iOS, Android, and Web Developer Guides.

Using the Admin Console

  1. In the Admin Console, login and, if needed, switch to the desired tenant. Navigate to Configuration > Authentication Methods > Out-of-band.

  2. Update Push Notification Authentication Text Mode by clicking the blue, underlined text on the same line. Select Dynamic from the dropdown menu.

Using nnl-mgmt.sh

The push notification authentication text mode is stored in a tenant property called oob.auth.notification.text.mode. Use nnl-mgmt.sh's set properties command to update the value. The example below updates the value for the authentication text in the Marketing tenant.

./nnl-mgmt.sh properties set -name oob.auth.notification.text.mode -value dynamic -tenant Marketing