Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Configure the Server for your apps

Prev Next

iOS app

You must register an App ID on the Apple Developer website for each iOS app that uses App Attest. You need the Team ID of your Apple Developer Account to configure your iOS App. This can be found at

          https://developer.apple.com/account/<your membership number>/membership/

Use the Admin Console to update your iOS App.

  1. Login to the Admin Console and, if needed, switch to the desired tenant. Navigate to Configuration > Apps.

  2. The Apps page appears. Find your app in the list and either click its name or the (edit) icon at the end of its row.

  3. The App page appears. Enter your Team ID and Save.

Android app

Configuring the server for your Android app depends on where decryption and verification of the app's integrity token takes place. These operations are either done locally on the Auth Server or remotely on Google Play's server.

  • If you elect to do these operations locally, you must assign values to the decryption and verification key properties.

  • If you choose to do these operations remotely, you must assign a file containing your service account key to the service account key file property.

Refer to Setup | Google Play | Android Developers to get these values.

The decryption key, verification key, and service account key are sensitive credentials that either need to be encrypted or stored in an external secrets manager. If you've created a Secrets plugin, the Apps page in the Admin Console prompts you for the handles for these credentials.

Use the Admin Console to configure your Android App.

1. Login to the Admin Console and, if needed, switch to the desired tenant. Navigate to Configuration > Apps.

2. The Apps page appears. Find your app in the list and either click its name or the (edit) icon at the end of its row.

3. The App page appears. Select the Play Integrity Configurations checkbox.

4. Enter the Google Cloud project number. You can find this in the Google Play Console dashboard after you have started the Google Play Integrity integration for your app.

5. Find and enter the SHA256 digest for your app's APK signing certificate. To retrieve the SHA256 digest, use the following command:

./keytool -exportcert -alias <alias-of-entry> \
-keystore <path-to-apk-signing-keystore> &>2 /dev/null | \
openssl sha256 -binary | openssl base64 | sed 's/=//g'

6. Choose where the integrity token is decrypted and verified, foloow the instructions below to either verify the token locally or verify the token remotely.

Verify the token locally

If you want the Digipass S3 Auth Server to decrypt and verify the integrity token locally, select Locally and find the Play Integrity Decryption Key and the Play Integrity Verification Key in the Google Play Console dashboard by following these instructions:

  1. Select your app. Then choose App Integrity from the left navigation bar.

  2. On the right side of the Play Integrity API pane, click Settings.

  3. On the right side of the Classic requests screen, choose Download keys.

  4. Follow the instructions on the Download API keys screen to generate a PEM file, upload the PEM file, download the encrypted file, and decrypt the file. This results in the decryption and verification keys.

  5. Back in the Digipass S3 Admin Console, navigate to Configuration > Apps and enter the decryption and verification keys in one of the following 2 ways:

    If you are not using the Secrets plugin to store the decryption and verification keys, enter the keys directly into the Admin Console. The Server automatically encrypts them.

    If you are using the Secrets plugin to store other credentials but you choose not to store the decryption and verification keys using the Secrets plugin, make sure that Configure with key is selected before entering both the decryption and the verification key.

If you are using the Secrets plugin to store the decryption and verification keys, select Configure with handle for key in the vault and enter handles to the decryption and verification keys.

Verify the token remotely

If the Google Play Server will decrypt and verify the integrity token, then select Remotely.

Specify the Service Account Key in the Admin Console in one of the following 2 ways:

If you are not using the Secrets plugin to store the Service Account key, then select Upload File and click Choose File to upload the file containing the Service Account Key.

If you are using the Secrets plugin to store the Service Account Key, select Handle for service account key in the vault and enter a handle to the service account key in the external vault.