The OneSpan Identity Verification integration model is geared towards simplicity and security. System-to-system integration is done via the OneSpan Identity Verification REST API. For more information, see OneSpan Identity Verification REST API.
Authentication
Authentication for access to the OneSpan Identity Verification REST API happens via two-legged OAuth2 with a JSON Web Token (JWT). OneSpan support provides a JWT to OneSpan Identity Verification customers. This token is used to restrict access to resources that are authorized for a given tenant, such as transactions, providers, or data sources. Effectively, the JWT Bearer schema is used as client credentials for API requests.
PUT /api/transaction/ HTTP1.1
Host: onespan.com
Accept: application/json, text/javascript
Authorization: Bearer xxxxxx\!
xxxxx...
{
"tenant_id":"12345678-1234-5678-901234567",
"workflow_id":"12345678-1234-5678-901234567",
"urlSetKey":"default",
"brand_id:"12345678-1234-5678-901234567",
"language":"english",
"users": [...],
"documents": [...]
}JSON Web Tokens
The OneSpan Professional Services Team provides the access token, which will be used by the client when creating transactions.
Scopes: tenant_access
Access token
Header: Algorithm and token type
{
"alg":"A1234"
"typ":"JWT"
}Payload: Data
{
"scope": [
"tenant_access"
],
"exp": 3698071610,
"jti": "12345678-1234-5678-901234567"
"client_id": "onespan"
}Token
<token key>Session token
Header: Algorithm and token type
{
"alg":"A12345"
"typ":"JWT"
}Payload: Data
{
"session": {
"role": "Borrower"
},
"scope": [
"session_creation_authorization_code"
],
"transaction_uuid": "12345678-1234-5678-901234567,
"exp": 1550591677,
"jti": "12345678-1234-5678-901234567",
"client_id": "onespan"
}Token
<token key>