About yourself
I am the Director of Global Solutions at OneSpan. I joined OneSpan in 2001 and have over 25 years of software and cybersecurity experience. Since joining OneSpan, I have been involved in all aspects of product implementation and market direction within our financial institutions and major accounts. I have a background in security, systems and architectures and development. I lead a strong team of people that are fully versed in many mobile, desktop and server code bases and platforms. Feel free to reach out and ask any questions you may have.



Earned badges

Achievement: Latest Unlocked

Topic Started


Replies Created

Reply to: What does OOB stand for?

1 votes

To further clarify,  OOB (Out-Of-Band) authentication, is the process in which the user retrieves an authentication credential (like a One Time Password [OTP]) from some other electronic channel than the one that the user requested it on.  Electronic channels can be anything on a computer, like a web site, or Windows login, or VPN access.  The term OOB is typically used to refer to when an Email or SMS text is sent to the user and the message contains a One Time Password, which the user then types into the original electronic channel to authenticate themselves.  There are many other solutions that fit into this definition of OOB authentication, including the OneSpan Cronto color cryptogram.  Many of these are much more secure than Email or SMS virtual OTP.  It is important to point out that OOB authentication by itself is not two-factor authentication.  In some cases, OOB authentication can be accepted as one of the second forms of authentication that make up a two-factor authentication solution.  If you are interested to learn more about OOB authentication, please let us know.

Reply to: Verify transaction on Mobile Device - Page Cannot be Found

0 votes

Hi Nabil,

This happens when you refresh on a transaction that has already been processed, or if you refresh on a page after landing on the page the first time. Can you try in a new browser on your mobile device, or better in a private browsing session?


Reply to: Verify transaction on Mobile Device - Page Cannot be Found

0 votes


Looking at your request, I think I see an issue in where you are sending the request.  A change was just pushed out this morning to the environment, all of your requests should be sent to the domain, instead of the  For your request send it to:


Reply to: Verify transaction on Mobile Device - Page Cannot be Found

0 votes

Hi Nabil,

Sorry for the confusion, but we recently made a change (this morning during our recent release), please remove and replace it with

We are updating our documentation and emails to reflect this change.  All of your requests should now go to the endpoint


Reply to: ID Verification - Integration with Mobile Application

0 votes
  1. How we can integrate the IDV within our mobile application ? is it by redirecting to the mobile default browser to open the transaction URL ({transaction_id}?access_token={access_token}) ? is this the only possible way ? knowing that it's not user friendly to switch from our mobile app to the device browser. 

Using the web browser is the recommended approach.  We have seen some customers use the webkit within an app to handle the requests directly, however, this is not officially supported from our product support group.

  1. do you have a native mobile SDK / native plugin (Android and IOS) that we can integrate with our mobile app to open the IDV transaction from within our mobile app and complete the transaction (taking capture of national id doc then a face capture with smile ). Noting that we are using Ionic Framework in our mobile app, so if you have a Cordova Plugin then we can integrate it and call it from our app to open and complete the transaction. Or if you have an Angular Library / Javascript Library to perform the same so we can call it. Please could you feedback if you support one of the aforementioned options ?

We currently do not have a native mobile, js, or 3rd party library SDK for our IDV solution.  It is on our roadmap, but I do not have a date for release yet.

  1. we have tried to open the IDV Transaction URL inside an iframe and we failed due to the security limitation of the 'X-Frame-Options' set to 'sameorigin'. It has been mentioned in latest release August 2021 (Version 2021-R3), is it possible to modify/remove this restriction?

For security reasons, we are not able to modify this in the demo/rapid proof of concept environment.  I will check what is possible in the UAT and PRD environments and get back with you.

  1. we have tried to open the IDV Transaction URL from an in-app browser embedded inside our Ionic mobile app (by using the following cordova plugin but we have faced the following stopper exception "Unsupported Device , No camera found Please enable your camera or use another device" knowing that we have granted access to the camera (this.androidPermissions.PERMISSION.CAMERA) before opening the in-app browser, so we need to know from your side if you are checking on other permissions to be enabled from the browser , do we have to provide specific access/permissions to the browser ? or if you are supporting specific browsers and blocking the URL on some types/models of browsers  ? 

Since this is done within the webkit, it is actually a different type of permission.  You will need to accept the permissions to access the camera through the browser permission set, which is different than the application permission set.  I have upload some sample code that I have previously used to give you some help, please remember this is just sample code, and using a webkit is still not officially support by product support, the only officially support mechanism is directly through a web browser.

  1. Are we obliged to complete the transaction only by opening the URL from a browser ? can't we collect data like document capture and selfie capture from our mobile app and then to call your IDV REST API to complete transaction by providing the images captured from our app ? for sure we will loose some feature related to liveness detection but on the other hand will integrate with you by REST Webservices call only without the need to redirect and complete the flow from the browser.

Currently the images must be captured through the workflow.  As you can see in the sample code there is the possibility of overriding this and allowing the user to upload an image as well, but it is still done through the workflow.  It is our recommendation, for security reasons, that the user be required to take a picture through the workflow only, so that the security checks can be done against the live image as the photo is being taken.

  1. Can we have a separate IDV REST Webservice for OCR and Document Capture Verification only, without the Selfie / Smile Face Capture. So it will be called from our mobile app where we will provide the national id image as input parameter and expecting to receive in response the  validation scoring and fields / values extracted from the capture ? This service is the first part (Document Capture) of the IDV workflow, and we are asking if we can consume it from REST API (if available) without opening a browser and providing the transaction URL. the business advantage is that we can apply OCR Parsing and Document validation through IDV REST API automatically without the need of generating a Transaction URL so no need for human/customer intervention.

In the next release of the Demo and Rapid POC environment, we will be introducing a document capture only workflow.  This will allow for capturing and processing, including data extraction, for the document component only.  It will still work like the other workflows, only it will not ask for facial capture.  It is currently already available in our Professional Services Fast Track packages which are available through the sales group.

  1. We have a concern in the list of supported browsers mentioned in the latest release note Version 2021-R3, for example it's mentioned that on Android mobile device, only Chrome is supported however we was confused because we tested on FireFox installed on Android and the URL worked, while the URL failed on Dolphin browser on Android. Please could we have detailed list of supported browsers ?

We officially only support the Chrome browser.  Other browsers and webkits may work, but they are not officially supported by the product support team.

  1. Can we customize the look & feel of OneSpan IDV Transaction URL ? Changing the theme/css/style of the UI to be compatible with the look & feel of our mobile app ?

Yes we can.  We have the ability use custom font, custom logo image and hero image (welcome image), and to customize the colors of particular workflow objects, and even modify the translation of certain phrases.  In order to do this, please send me a private email and I will send you the instructions to get started, [email protected].


Topics Replies Freshness Views Users
3 2 years 5 months ago 208
Profile picture for user wcl
6 2 years 5 months ago 103
Profile picture for user wcl
0 4 years 1 month ago 182

OOB stands for Out-Of-Band.

1 4 years 1 month ago 897
Profile picture for user wcl

Code Share

This user has not submitted any code shares.

Subscriptions Release Notes

This user is not subscribed to any release notes.