Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Result codes and resolutions

Prev Next

The App SDK returns the following result codes from many of its API calls. The result code is inside the Outcome property of the Result object and the AdaptiveResult object. For a list of API methods that could return a specific Outcome value, refer to the Client API documentation for the global Outcome.

ALREADY_INITIALIZED

Indicates that this is not the first time the init() operation is called. This code can only be returned when the SDK is used in a Cordova application.

Resolution: You can ignore this result code

APP_NOT_FOUND

This result code can occur if:

  • A web application's origin does not match with the FIDO2/WebAuthn RP ID configured in the Authentication Server.

  • A UAF Cordova application's facet ID could not be found in the file facets.uaf, which is hosted on your Server.

  • A FIDO2 Cordova application wasn't added to the Authentication Server or the application's package name and SHA256 fingerprints of the application's signing certificate are missing from the file assetlinks.json.

  • In the case of UAF, this corresponds to UNTRUSTED_FACET_ID error. In the case of FIDO2 (WebAuthn) corresponds to SecurityError.

Resolution: Inform the user that the operation was unsuccessful. If the user is trying to authenticate, offer them an alternate form of authentication.

AUTHENTICATOR_ACCESS_DENIED

The authenticator denied the request. Check the logs and configuration. This code can be returned only when the SDK is used in a Cordova application.

Resolution: Ask the user to register again.

CANCELED

The operation was canceled by the user. In case of UAF, this corresponds to USER_CANCELLED error.

Resolution: The user can restart the operation.

CONNECTION_ERROR

The App SDK cannot connect to a Server due to a network issue. This can happen if there is no Internet connection or the Server URL is incorrect.

Resolution: Inform the user that the Internet connection is not working.

CONSTRAINT_ERROR

The user tried to register a FIDO2 authenticator that does not support the FIDO policy settings, specifically the authenticator attributes Require Resident Key and User Verification. This code can be returned when FIDO2 (WebAuthn) is used.

Resolution: Inform the user that the registration operation was unsuccessful.

FAILURE

The operation failed for a non-specific reason. Examine the client and Server logs to determine potential causes. In the case of UAF, this corresponds to an UNKNOWN error.

Resolution: Inform the user that the operation was unsuccessful. If the user is trying to authenticate, offer them an alternate form of authentication.

FALLBACK

If an authenticator supports fallback, it displays a button for fallback labelled Use Alternate Authentication. If the user taps this button, this result code is returned. FALLBACK only applies to UAF authenticators. This code can only be returned when the SDK is used in a Cordova application.

Resolution: The user can use the alternate authentication mechanism.

INVALID_QR

The QR image data is missing from the server response, or the data is present but the App SDK is not able to decode and convert it into a bitmap. This can happen if the OOB configuration on the Server is incorrect. See Out-of-band section Step 1. Configure the Auth Server.

Resolution: Inform the user that the QR code is invalid.

INVALID_SESSION

There is a problem with the user session, most likely the session has expired.

Resolution: Ask the user to sign in again.

INVALID_STATE

The user tried to register an authenticator that has already been registered. This code can be returned when FIDO2 (WebAuthn) is used.

Resolution: Inform the user that the registration operation was unsuccessful.

INVALID_TRANSACTION_CONTENT

The Authenticator Specific Module (ASM) reported that the transaction content cannot be rendered. For example, the format doesn't fit the authenticator's need. Currently not used.

KEY_DISAPPEARED_PERMANENTLY

When biometric templates for certain biometric authenticators are added or removed, existing FIDO registrations for those biometric authenticators can be invalidated. This result code can occur during authentication or transaction confirmation. This code can only be returned when the SDK is used in a Cordova application.

Resolution: Ask the user to register again.

NO_MATCH

This result code can occur during registration, authentication, or transaction confirmation. During registration, it occurs when the user's device has no available authenticators to register that match the FIDO policy. During authentication or transaction confirmation, it occurs when the user has no registered authenticators to authenticate that match the FIDO policy.

In the case of UAF, this corresponds to NO_SUITABLE_AUTHENTICATOR error.

This code can be returned when FIDO2 (WebAuthn) is used.

Resolution: For authentication or transaction confirmation, offer the user an alternate form of authentication. For registration, inform the user that all suitable FIDO credentials have been registered.

NOT_INSTALLED

In the case of web applications, this result code can occur if FIDO is not supported by the platform. In the case of Cordova applications, this result code can occur if it is trying to use an external FIDO Client, but that client is not installed.

Resolution: Inform the user that the operation was unsuccessful. If the user is trying to authenticate, offer them an alternate form of authentication.

NOT_COMPATIBLE

The installed version of FIDO client is not compatible. In the case of UAF this corresponds to UNSUPPORTED_VERSION error.

Resolution: Inform the user that the operation was unsuccessful. If the user is trying to authenticate, offer them an alternate form of authentication.

PROTOCOL_ERROR

A violation of the UAF Protocol occurred. Examine logs and look for coding errors. In case of UAF, this corresponds to PROTOCOL_ERROR error. This code can also be returned when FIDO2 (WebAuthn) is used.

Resolution: Inform the user that the operation was unsuccessful. If the user is trying to authenticate, offer them an alternate form of authentication.

SERVER_ERROR

This is a generic result code sent by the Server. Check the logs on the Server.

Resolution: Inform the user that the operation was unsuccessful. If the user is trying to authenticate, offer them an alternate form of authentication.

SERVER_REG_NOT_FOUND

The Server found the user but was unable to find a registered authenticator for that user. Corresponds to UAF_REG_NOTFOUND_STATUS_CODE.

Resolution: Your app can treat this the same as Outcome.NO_MATCH.

SERVER_UVI_NOT_MATCH

This can only occur on old devices. The UVI provided during authentication doesn't match the UVI provided during registration. Corresponds to UAF_UVI_NOT_MATCH_STATUS_CODE.

Resolution: Inform the user that the operation was unsuccessful. If the user is trying to authenticate, offer them an alternate form of authentication.

SERVER_USER_NOT_FOUND

The Server can't find the user. Corresponds to UAF_NO_REGISTRATIONS_STATUS_CODE.

Resolution: Inform the user that the operation was unsuccessful. If the user is trying to authenticate, offer them an alternate form of authentication.

SERVER_VERIFICATION_ERROR

This result code can occur during registration, authentication, or transaction confirmation. This result code is based on the Policy Verification Failed (code 4403) error returned from the Server. Normally this error should not occur because the App SDK filters out authenticators that do not match the FIDO policy.

Resolution: Your app can treat this the same as Outcome.NO_MATCH.

SUCCESS

The operation completed successfully. No resolution necessary.

SYSTEM_CANCELED

The system cancelled the operation. This typically occurs when the application is moved to the background. For example, the user taps the home button or brings another application to the foreground. This code can be returned when FIDO2 (WebAuthn) is used.

Resolution: The user can restart the operation.

TRANSACTION_ERROR

The transaction text could not be processed. For example, certain HTML tags are not allowed. This is currently not used.

USER_LOCKOUT

The user exceeded the maximum allowed attempts to enter their credentials.

Resolution: Inform the user that registration is locked because of too many failed attempts. If the registration is deleted, the user will need to register again.

USER_NOT_ENROLLED

The user's biometrics have not been enrolled on the device. This is returned during registration if there is no enrollment in the system. This code can only be returned when the SDK is used in a Cordova application.

Resolution: Inform the user that there's no enrollment on the device. Ask them to enroll and try registering again.

USER_NOT_RESPONSIVE

The operation timed out.

Resolution: The user should try the operation again.

WAIT_USER_ACTION

Waiting on user action to proceed. In the case of UAF, this corresponds to WAIT_USER_ACTION error. This is currently not used.