If your web app that initiates the OOB authentication has a different origin than the Digipass S3 API Server, then you need to add the origin of your web app to a list of trusted origins. A web origin is defined by the scheme (protocol), host (domain), and port of the URL used to access it. Two objects have the same origin only when the scheme, host, and port all match.
The trusted origins list is contained in the field origin_allowlist which you can modify using the Admin Console.
In the Admin Console, login and, if needed, switch to the desired tenant. Navigate to Configuration > API Server > Main.
Click Add an origin. A textbox appears under the last list item. Enter your client web app's URL.
.png?sv=2026-02-06&spr=https&st=2026-09-30T02%3A18%3A23Z&se=2026-09-30T02%3A29%3A23Z&sr=c&sp=r&sig=s5s9da9wFTBLXQ0CoN5gWqQi1EjOBqKR50TlsEBQS8M%3D)