HID
Documentation | Temenos Digital Components 12.0

Documentation Home

Choose a documentation area to get started.

HID Components Overview

A unified guide to the HID Temenos Digital web and mobile components, their primary responsibilities, and the onboarding and login journeys available for each authentication choice.

Scope. This guide consolidates the supplied authentication, user-management, transaction-signing, mobile-component, and Infinity workflow documentation. It focuses on the component capabilities and user journeys relevant to web and mobile banking implementations.

Guide Overview

The component set supports user authentication, onboarding, device lifecycle management, and transaction authorization across web and mobile channels. The exact screens and factors shown are controlled by the selected component properties and configured authenticators.

Web channel

Authentication

Login, multi-factor authentication, user management, and transaction signing.

Mobile channel

HID Approve SDK

Onboarding, PIN and biometric sign-in, Secure Code, QR journeys, and device lifecycle.

Shared services

HID Authentication Service

Activation, credential validation, OTP, device registration, and authenticator policies.

Component Catalogue

Choose a channel to review the included components. Open a component to view its role, supported actions, and relevant configuration choices.

Onboarding and Login Flow Selector

Select an authenticator choice to view the corresponding onboarding and login flows that may be configured. These flows provide a decision view; the exact availability depends on the selected component properties and deployed HID authenticators.

Login formation: SECURE_CODEAPPROVE
Use Secure Code as the first factor and HID Approve as the configured MFA step.

Onboarding

  1. Validate activation details and begin Secure Code device enrollment.
  2. Register the device through QR or manual activation.
  3. Complete HID Approve device registration as the configured MFA step.
  4. Finish onboarding after the required device and factor setup succeeds.

Login

  • User generates or enters Secure Code as the first authentication factor.
  • The service validates Secure Code.
  • HID Approve is invoked as the configured MFA step.

Onboarding

  1. Validate activation code and create a policy-compliant Static Password.
  2. Register the Secure Code device through QR or manual activation.
  3. Validate the new Secure Code and complete enrollment.

Login

  • User enters username and Static Password.
  • The service validates the first factor.
  • User generates and enters Secure Code for MFA validation.

Onboarding

  1. Validate activation details and create a policy-compliant Static Password.
  2. Register the HID Approve device through QR or manual activation.
  3. Complete the Approve registration and finish enrollment.

Login

  • User enters username and Static Password.
  • The service validates the first factor.
  • User approves the HID Approve push request as the MFA step.

Onboarding

  1. Validate activation details and create a Static Password.
  2. Verify the registered mobile number.
  3. Send and validate the SMS OTP to complete enrollment.

Login

  • User enters username and Static Password.
  • The service sends an OTP to the registered mobile number.
  • User enters the SMS OTP to complete MFA validation.

Onboarding

  1. Validate activation details and create a Static Password.
  2. Verify the registered email address.
  3. Send and validate the Email OTP to complete enrollment.

Login

  • User enters username and Static Password.
  • The service sends an OTP to the registered email address.
  • User enters the Email OTP to complete MFA validation.

Onboarding

Onboarding formation: SECURE_CODE + APPROVE

  1. Validate activation details and provision the Secure Code device.
  2. Complete HID Approve device registration as the MFA step.
  3. Complete the onboarding success journey.

Login

Login formation: USER_ID_LESS + NO_MFA

  • User completes the user-ID-less first-factor experience.
  • No additional MFA screen is configured for this login formation.

Onboarding

  1. Validate user activation details.
  2. Display the available FIDO authenticator or passkey registration option.
  3. User follows the browser or platform instructions to register the authenticator.
  4. Validate the registration result and complete onboarding.

Login

Login formation: FIDO + NO_MFA

  • User selects FIDO as the first factor.
  • The browser or platform prompts for the registered authenticator or passkey.
  • No additional MFA is configured after successful FIDO validation.
Web Onboarding Users

Provides a web onboarding workflow for account activation and authentication-factor registration. The selected properties control the first factor and MFA path.

AreaSupported choices
First factorStatic Password, Secure Code, FIDO, OOB SMS OTP, or OOB Email OTP.
Second factorStatic Password, Secure Code, OOB SMS OTP, OOB Email OTP, hardware-token OTP, HID Approve, or no MFA.
Key outcomesActivation validation, credential creation, device enrollment, passkey registration, and device friendly-name update.
User Authentication

Provides the web user-login experience. The first factor and MFA screens are determined by component properties. Version 12.0.0.

AreaSupported choices
First factorStatic Password, Secure Code, FIDO, or User ID Less.
MFASecure Code, OOB SMS OTP, OOB Email OTP, HID Approve push, hardware-token OTP, or no MFA.
Key functionslogoutOnClick, getRmsSessionid, success and failure callbacks, loading and context-change events.
User Management

Manages registered devices, new-device and FIDO registration, password changes, and email or mobile-number updates. The web component can invoke a configured MFA step before sensitive changes.

CapabilityWhat the component supports
Device lifecycleRegister, rename, suspend, reactivate, unassign, and remove devices.
Credentials and profileChange password and retrieve or update email and mobile-number attributes.
Step-up choicesHID Approve, Secure Code, OOB SMS OTP, OOB Email OTP, hardware OTP, or no MFA, as configured.
Transaction Signing

Provides transaction authorization for web and mobile channels. The component is a non-UI transaction-details integration with an MFA experience determined by the selected signing factor.

Signing factorJourney
HID ApproveSingle-device or multi-device push approval, with device selection when needed.
Secure CodeQR or manual transaction-data entry in the mobile app generates an OCRA Secure Code for validation.
OTP SMSFetches registered communication details, sends OTP, validates the entered OTP, and returns the result to the transaction process.
Onboarding and Login

The principal mobile component for onboarding, sign-in, Secure Code generation, profile renewal, container deletion, and password-expiry handling. It supports activation-code and QR-code onboarding modes.

AreaMobile behavior
OnboardingActivation Code, QR Scan, and manual onboarding. Successful enrollment leads to PIN setup and optional biometric enablement.
LoginSingle-user or multiple-user pre-login experience, protected by biometric authentication or PIN.
Supported operating systemsAndroid 8 and later; iOS 10 and later, as stated in the supplied material.
Mobile Transaction Signing

Supports Scan to Pay, Secure Code generation, push approval, and transaction-signing journeys initiated by the connected digital-banking application.

  • Use Scan to Pay to scan a QR code or enter transaction data manually.
  • Use PIN or enrolled biometrics before generating or signing with a Secure Code.
  • Return signed results to the HID Authentication Service for validation.
Approve Notification

Handles registered-device push notifications and the related mobile approval or decline journey. The mobile app receives the prompt, retrieves the transaction context, performs the selected local authentication, and sends the signed response for validation.

Mobile User Management

Supports profile and device actions for the active mobile user, including container renewal or deletion, PIN changes, biometric preference changes, and device-specific status information.

Detailed Component Reference

Each component below follows the same detailed structure used for the onboarding documentation: overview, key capabilities, and applicable flow guidance.

Web Components

Web Onboarding UsersDetailed reference

Component Overview

AttributeValue
Component packagecom.hid.olb.onboarding
PlatformWeb
User interfaceFirst-factor and MFA screens are added according to the selected component properties.
FunctionalityUser onboarding and authentication-factor registration.
VersionVersion 12.0.0

Key Capabilities

  • Activation-code validation and guided user account setup.
  • Static-password creation with password-policy validation.
  • Secure Code device enrollment by QR code or manual activation, including friendly device naming.
  • OOB SMS or Email OTP enrollment.
  • FIDO2 authenticator or passkey registration through the web authentication platform.

Onboarding Workflow

  1. User enters their username and activation code.
  2. The component validates the activation details and displays the selected first-factor journey.
  3. For Static Password, the user creates and confirms a policy-compliant password.
  4. For Secure Code or HID Approve, the component displays QR or manual-registration information, validates device enrollment, and captures a friendly device name.
  5. For OOB, the component sends and validates the OTP before progressing to the next configured factor.
  6. For FIDO, the user registers a supported authenticator or passkey and is directed to the successful onboarding result.

Static Password: validate activation details, create and confirm a policy-compliant password, then continue to the configured MFA factor. Secure Code: validate activation details, register the device by QR code or manual activation, then update the device friendly name after successful registration.

User AuthenticationDetailed reference

Component Overview

AttributeValue
Component packagecom.hid.olb.loginComponent
PlatformWeb
User interfaceFirst-factor and MFA screens are added according to the selected component properties.
FunctionalityUser login and authentication-factor validation.
VersionVersion 12.0.0

Key Capabilities

  • Supports Static Password, Secure Code, FIDO, and User ID Less as the first factor.
  • Supports Secure Code, OOB SMS OTP, OOB Email OTP, HID Approve Push, hardware-token OTP, and no MFA as configured.
  • Provides success, failure, loading, context-change, and contact-support callbacks.

Login Flow

  1. User enters the selected first factor.
  2. The component validates the first factor with the HID Authentication Service.
  3. If MFA is configured, the component displays the required factor screen.
  4. After successful validation, the host application processes the success callback.
User ManagementDetailed reference

Component Overview

AttributeValue
Component packagescom.hid.olb.userManagement and com.hid.rms.olb.nonFinancialComponent
PlatformWeb
FunctionalityDevice management, new-device and FIDO registration, password changes, email updates, and mobile-number updates.
VersionVersion 12.0.0

Key Capabilities

  • Register, rename, suspend, reactivate, unassign, and remove registered devices.
  • Change a password and retrieve the policy instructions for the new password.
  • Retrieve and update email and mobile-number attributes.
  • Invoke an approved MFA factor before sensitive changes.

Protected Action Flow

  1. User selects a device or profile-management action.
  2. The component shows the required action screen and requests the configured MFA factor.
  3. The identity service validates the selected factor.
  4. The component returns the action result to the host application and refreshes the displayed state.

Sensitive User Management actions require the configured MFA factor. The reference supports HID Approve, Secure Code, OOB SMS or Email OTP, or Static Password as configured.

Transaction SigningDetailed reference

Component Overview

AttributeValue
Component packagecom.hid.olb.TransactionSigningFlow
PlatformsOmnichannel - Web and Mobile
FunctionalityTransaction-details and MFA orchestration for transaction authorization.
VersionVersion 12.0.0

Supported Signing Methods

  • HID Approve: single-device and multi-device push approval.
  • Secure Code: QR scan or manual transaction-data entry followed by OCRA Secure Code validation.
  • OTP SMS: OTP delivery to the registered number and validation before transaction completion.

Transaction Flow

  1. User enters transaction details and selects the configured signing method.
  2. The component displays the corresponding MFA experience.
  3. The user approves, supplies Secure Code, or enters OTP.
  4. The authentication result is returned to the transaction process for completion or rejection.

Mobile Components

Onboarding and LoginDetailed reference

Component Overview

AttributeValue
Component packagecom.hid.mb.MobileApproveSDK
PlatformMobile
User interfaceOnboarding screens are added according to the selected onboarding mode: Activation Code or QR Scan.
FunctionalityUser onboarding, login, Secure Code generation, profile renewal, container deletion, and password-expiry handling.
VersionVersion 12.0.0

Key Capabilities

  • Supports activation-code, QR-scan, and manual onboarding.
  • Creates a local service PIN and offers optional Face ID, Touch ID, or fingerprint authentication when supported by the device.
  • Supports single-user and multiple-user pre-login experiences.
  • Generates Secure Code for a connected web-channel login and supports Scan to Login journeys.
  • Handles profile renewal, device container deletion, PIN expiry, and key-expiry notices.

Onboarding Flow

  1. User selects Enroll or Activate from the pre-login screen.
  2. User chooses Activation Code or QR Scan. QR Scan can continue with camera permission, a web QR code, or manual username, invite-code, and service-URL entry.
  3. The component validates the supplied activation or registration details.
  4. User creates and confirms a PIN.
  5. User can enable biometrics. The component shows the activation-success outcome after enrollment completes.

Login and Secure Code Flow

  1. The active username is shown on the pre-login screen; multiple registered users can select the appropriate profile.
  2. User verifies with biometrics or PIN.
  3. For web Secure Code login, the user selects Secure Code, completes local authentication, and the component displays the generated code.
  4. The generated code is entered in the web application for identity-service validation.

The reference supports Activation Code, QR Scan, and manual QR onboarding. After PIN setup, the user can opt into Face ID, Touch ID, or fingerprint authentication when the device supports it.

Mobile Transaction Signing and Approve NotificationDetailed reference

Component Overview

These mobile functions support Secure Code, Scan to Pay, and HID Approve push-notification journeys initiated by the digital-banking application.

Key Capabilities

  • Scan a transaction QR code or manually enter transaction data to generate a signing Secure Code.
  • Use biometric authentication or PIN before generating or signing an authorization response.
  • Receive HID Approve push notifications, review the request, approve or decline, and send the signed response for validation.

Flow

  1. The web or mobile application initiates the signing or approval request.
  2. The mobile component displays a PIN or biometric prompt when required.
  3. The user completes approval, decline, Secure Code generation, or transaction signing.
  4. The signed result is sent to the HID Authentication Service for validation.
Mobile User ManagementDetailed reference

Component Overview

Provides the mobile profile and device-management actions available to the active registered user.

Key Capabilities

  • Renew the profile container before expiry and delete a container when required.
  • Change the service PIN and update biometric authentication preferences.
  • Retrieve the active username and device-specific information for the current session.
  • Support the host application's navigation and UI changes during Secure Code and Scan to Login flows.

Operational Considerations

Recovery and lifecycle. Treat device removal, device suspension, and profile or PIN recovery as protected actions. The workflow material describes authenticating the user before sensitive changes and using service-desk recovery when authentication policies are blocked or a credential cannot be recovered.
  • Warn users before removing their only registered device because this can prevent future access.
  • Apply the configured thresholds for invalid Secure Codes, push challenges, and repeated OTP requests; show the configured recovery route when a threshold is reached.
  • For a lost device, locked HID Approve PIN, or additional-device registration, use the applicable activation or QR-based registration process.
  • Keep the web and mobile application implementations aligned on the selected authenticator, device type, and service configuration.

Content is based on the supplied HID Temenos Digital Component 12.0 documentation and HID Infinity component workflow material.