Strong Customer Authentication
The strong anthentification is needed for some sensitive actions.
Sensitive actions
The following actions might be securized with a previous SCA:
- KYC initialisation
- User information update
- Beneficiaries creation and update
- PayOut operations
Strong Authentication Enrollment
Xpollens offers two kind of usage that require the use of a mobile phone by the customer:
- KYC process during the user’s onboarding (please refer to Know your customer)
- Strong authentication process (please refer to Strong customer authentication)
Authentication is required for your end-customers if you are on the Retail B2C market ; it is also required for all key individuals of your professional customers, if you are on the Corporates B2B market.
Strong Customer Authentication will occur in two situations :
- Online card payment
- Sensitive Operations (amongst which, some require secure display)
This document aims at presenting the key elements to use these features.
The first step consists of integrating our SDK in your mobile application.
SDK’s documentation is available at : 🔗https://doc.antelop-solutions.com/latest/wallet/sdk/index.html
To access this online documentation, you shall use the ID / pwd provided by Xpollens, during your Onboarding process.
sequenceDiagram autoNumber Participant User Participant Partner Participant XPO User ->> Partner : Account creation requested<br/>appUserId<br/>civility<br/>lastName<br/>... Partner ->> XPO : POST /v2.0/users XPO -->> Partner: HTTP/201 XPO --) Partner : Callback 34<br/>userRecordStatus :Initialized Partner ->> XPO : POST kyc/demand XPO --) Partner : Callback 4 XPO --) Partner : Callback 35<br/>Strong authentication enrollment
Check mobile eligibility
sequenceDiagram autoNumber Participant Partner Mobile App Participant Wallet Provider SDK Participant Wallet Provider Partner Mobile App ->> Wallet Provider SDK: Check device eligibility Wallet Provider SDK ->> Wallet Provider : Check device eligibility Wallet Provider -->> Wallet Provider SDK: OK Wallet Provider SDK -->> Partner Mobile App: OK
Wallet initialization
sequenceDiagram
autoNumber
Participant Partner
Participant Wallet Provider SDK
Participant Wallet Provider
Participant XPO
Partner ->> XPO: POST user
XPO ->> Partner : HTTP/201
XPO --) Partner : Callback 34<br/>{appUserId}
Partner ->> XPO: POST kyc/demand
XPO --) Partner : Callback 4<br/>{appUserId}
XPO -->> Wallet Provider: Post wallet
Wallet Provider -->> XPO: AntelopWalletId, ActivationCode
XPO --) Partner : Callback 35<br/>{AppUserId, ActivateCode, ExtraData.WebViewUrl}
Partner -->> Wallet Provider SDK : Initialize Wallet
Wallet Provider SDK -->> Wallet Provider: Initialize Wallet
To access this online documentation, you shall use the ID / pwd provided by Xpollens, during your Onboarding process.
Wallet initialization
The Customer Authentication is based on Authentication Patterns, which define the possible combinations of authentication methods toauthenticate for a given operation.The authentication pattern used by Xpollens when creating the wallet is « BIOORPIN ».
For more details, please refer to : 🔗sca intro
APIs, callbacks & technical items
Callback #34
Callback #35
Updated 10 months ago