The App SDK returns the following result codes from many of its API calls. The result code is inside the Outcome property of the Result object and the AdaptiveResult object. For a list of API methods that could return a specific Outcome value, refer to the Client API documentation for the global Outcome.
ALREADY_INITIALIZED
Indicates that this is not the first time the init() operation is called. This code can only be returned when the SDK is used in a Cordova application.
Resolution: You can ignore this result code
APP_NOT_FOUND
This result code can occur if:
A web application's origin does not match with the FIDO2/WebAuthn RP ID configured in the Authentication Server.
A UAF Cordova application's facet ID could not be found in the file facets.uaf, which is hosted on your Server.
A FIDO2 Cordova application wasn't added to the Authentication Server or the application's package name and SHA256 fingerprints of the application's signing certificate are missing from the file assetlinks.json.
In the case of UAF, this corresponds to UNTRUSTED_FACET_ID error. In the case of FIDO2 (WebAuthn) corresponds to SecurityError.
Resolution: Inform the user that the operation was unsuccessful. If the user is trying to authenticate, offer them an alternate form of authentication.
AUTHENTICATOR_ACCESS_DENIED
The authenticator denied the request. Check the logs and configuration. This code can be returned only when the SDK is used in a Cordova application.
Resolution: Ask the user to register again.
CANCELED
The operation was canceled by the user. In case of UAF, this corresponds to USER_CANCELLED error.
Resolution: The user can restart the operation.
CONNECTION_ERROR
The App SDK cannot connect to a Server due to a network issue. This can happen if there is no Internet connection or the Server URL is incorrect.
Resolution: Inform the user that the Internet connection is not working.
CONSTRAINT_ERROR
The user tried to register a FIDO2 authenticator that does not support the FIDO policy settings, specifically the authenticator attributes Require Resident Key and User Verification. This code can be returned when FIDO2 (WebAuthn) is used.
Resolution: Inform the user that the registration operation was unsuccessful.
FAILURE
The operation failed for a non-specific reason. Examine the client and Server logs to determine potential causes. In the case of UAF, this corresponds to an UNKNOWN error.
Resolution: Inform the user that the operation was unsuccessful. If the user is trying to authenticate, offer them an alternate form of authentication.
FALLBACK
If an authenticator supports fallback, it displays a button for fallback labelled Use Alternate Authentication. If the user taps this button, this result code is returned. FALLBACK only applies to UAF authenticators. This code can only be returned when the SDK is used in a Cordova application.
Resolution: The user can use the alternate authentication mechanism.
INVALID_QR
The QR image data is missing from the server response, or the data is present but the App SDK is not able to decode and convert it into a bitmap. This can happen if the OOB configuration on the Server is incorrect. See Out-of-band section Step 1. Configure the Auth Server.
Resolution: Inform the user that the QR code is invalid.
INVALID_SESSION
There is a problem with the user session, most likely the session has expired.
Resolution: Ask the user to sign in again.
INVALID_STATE
The user tried to register an authenticator that has already been registered. This code can be returned when FIDO2 (WebAuthn) is used.
Resolution: Inform the user that the registration operation was unsuccessful.
INVALID_TRANSACTION_CONTENT
The Authenticator Specific Module (ASM) reported that the transaction content cannot be rendered. For example, the format doesn't fit the authenticator's need. Currently not used.
KEY_DISAPPEARED_PERMANENTLY
When biometric templates for certain biometric authenticators are added or removed, existing FIDO registrations for those biometric authenticators can be invalidated. This result code can occur during authentication or transaction confirmation. This code can only be returned when the SDK is used in a Cordova application.
Resolution: Ask the user to register again.
NO_MATCH
This result code can occur during registration, authentication, or transaction confirmation. During registration, it occurs when the user's device has no available authenticators to register that match the FIDO policy. During authentication or transaction confirmation, it occurs when the user has no registered authenticators to authenticate that match the FIDO policy.
In the case of UAF, this corresponds to NO_SUITABLE_AUTHENTICATOR error.
This code can be returned when FIDO2 (WebAuthn) is used.
Resolution: For authentication or transaction confirmation, offer the user an alternate form of authentication. For registration, inform the user that all suitable FIDO credentials have been registered.
NOT_INSTALLED
In the case of web applications, this result code can occur if FIDO is not supported by the platform. In the case of Cordova applications, this result code can occur if it is trying to use an external FIDO Client, but that client is not installed.
Resolution: Inform the user that the operation was unsuccessful. If the user is trying to authenticate, offer them an alternate form of authentication.
NOT_COMPATIBLE
The installed version of FIDO client is not compatible. In the case of UAF this corresponds to UNSUPPORTED_VERSION error.
Resolution: Inform the user that the operation was unsuccessful. If the user is trying to authenticate, offer them an alternate form of authentication.
PROTOCOL_ERROR
A violation of the UAF Protocol occurred. Examine logs and look for coding errors. In case of UAF, this corresponds to PROTOCOL_ERROR error. This code can also be returned when FIDO2 (WebAuthn) is used.
Resolution: Inform the user that the operation was unsuccessful. If the user is trying to authenticate, offer them an alternate form of authentication.
SERVER_ERROR
This is a generic result code sent by the Server. Check the logs on the Server.
Resolution: Inform the user that the operation was unsuccessful. If the user is trying to authenticate, offer them an alternate form of authentication.
SERVER_REG_NOT_FOUND
The Server found the user but was unable to find a registered authenticator for that user. Corresponds to UAF_REG_NOTFOUND_STATUS_CODE.
Resolution: Your app can treat this the same as Outcome.NO_MATCH.
SERVER_UVI_NOT_MATCH
This can only occur on old devices. The UVI provided during authentication doesn't match the UVI provided during registration. Corresponds to UAF_UVI_NOT_MATCH_STATUS_CODE.
Resolution: Inform the user that the operation was unsuccessful. If the user is trying to authenticate, offer them an alternate form of authentication.
SERVER_USER_NOT_FOUND
The Server can't find the user. Corresponds to UAF_NO_REGISTRATIONS_STATUS_CODE.
Resolution: Inform the user that the operation was unsuccessful. If the user is trying to authenticate, offer them an alternate form of authentication.
SERVER_VERIFICATION_ERROR
This result code can occur during registration, authentication, or transaction confirmation. This result code is based on the Policy Verification Failed (code 4403) error returned from the Server. Normally this error should not occur because the App SDK filters out authenticators that do not match the FIDO policy.
Resolution: Your app can treat this the same as Outcome.NO_MATCH.
SUCCESS
The operation completed successfully. No resolution necessary.
SYSTEM_CANCELED
The system cancelled the operation. This typically occurs when the application is moved to the background. For example, the user taps the home button or brings another application to the foreground. This code can be returned when FIDO2 (WebAuthn) is used.
Resolution: The user can restart the operation.
TRANSACTION_ERROR
The transaction text could not be processed. For example, certain HTML tags are not allowed. This is currently not used.
USER_LOCKOUT
The user exceeded the maximum allowed attempts to enter their credentials.
Resolution: Inform the user that registration is locked because of too many failed attempts. If the registration is deleted, the user will need to register again.
USER_NOT_ENROLLED
The user's biometrics have not been enrolled on the device. This is returned during registration if there is no enrollment in the system. This code can only be returned when the SDK is used in a Cordova application.
Resolution: Inform the user that there's no enrollment on the device. Ask them to enroll and try registering again.
USER_NOT_RESPONSIVE
The operation timed out.
Resolution: The user should try the operation again.
WAIT_USER_ACTION
Waiting on user action to proceed. In the case of UAF, this corresponds to WAIT_USER_ACTION error. This is currently not used.