---
title: ASWebAuthenticationSession
description: 'How to implement the Card Not Present Verification capture experience on iOS using ASWebAuthenticationSession: authentication controller, session setup, and required permissions.'
canonical: https://developer.unico.io/dual-api/developers/regional-solutions/card-not-present-verification/integration/controlling-the-experience/mobile/ios/aswebauthenticationsession
locale: en
generated_by: markdown-export
---

For iOS usage, using ASWebAuthenticationSession is one of the recommended approaches.

After creating the transaction and obtaining the transaction link, the following implementation is recommended:

- In your regular flow (which includes Card Not Present Verification), you will open the ASWebAuthenticationSession with the link generated via API.
- You can customize this opening in the way that works best for your app.
- You will monitor if the URL has changed (to the `redirectUrl`) and then close the page.

To make the flow work, you need to follow the following steps:

### Step 1: Create the Payment Authentication Controller

The first step is to create the payment authentication controller. To do this, create a class called `IDPayAuthenticationController` (or any name you prefer).

Next, import the `AuthenticationServices` framework at the top of the class.

Declare the class as `NSObject` and implement the `ASWebAuthenticationPresentationContextProviding` protocol.

The result should be:

```swift
import AuthenticationServices

class IDPayAuthenticationController: NSObject, ASWebAuthenticationPresentationContextProviding {
    func presentationAnchor(for session: ASWebAuthenticationSession) -> ASPresentationAnchor {
           if let windowScene = UIApplication.shared.connectedScenes.first as? UIWindowScene {
               if let mainWindow = windowScene.windows.first {
                   return mainWindow
               }
           }
           return ASPresentationAnchor()
       }
}
```

### Step 2: Implement Authentication

Open the file where you will perform the authentication and add the necessary imports (in our example, we are doing this in `ContentView.swift`).

```swift
import SwiftUI
import AuthenticationServices
```

To control the authentication state, we will create a `@State` property.

```swift
@State private var isAuthenticated = false
```

Create an instance of the `IDPayAuthenticationController` class outside the body of the `ContentView` structure.

```swift
let idPayController = IDPayAuthenticationController()
```

To validate the payment, create a function called `authenticatePayment`.

```swift
func authenticatePayment() {
    guard let url = URL(string: "URL_AUTHENTICATION") else { return }

    var session: ASWebAuthenticationSession?
    session = ASWebAuthenticationSession(url: url, callbackURLScheme: "BUNDLE") { callbackURL, error in
        guard callbackURL != nil else {
            if let error = error {
                return print("Error during authentication: \(error.localizedDescription)")
            }
            return
        }

        // Processes the callback URL to check whether authentication succeeded
        session?.cancel()
        isAuthenticated = true
    }

    session?.presentationContextProvider = idPayController
    session?.prefersEphemeralWebBrowserSession = true
    session?.start()
}
```

:::danger
Remember to change the URL `URL_AUTHENTICATION` to the authentication URL received in your transaction and also the `callbackURLScheme` `BUNDLE` to the redirect provided when creating your transaction (we recommend using the Bundle Identifier of your app).
:::

:::note
It is important to set `prefersEphemeralWebBrowserSession` to `true` to ensure a unique authentication per transaction.
:::

:::note
Some permissions are required for it to work properly, such as:
- Camera
- Geolocation
:::

To learn more, we recommend reading the official [ASWebAuthenticationSession documentation](https://developer.apple.com/documentation/authenticationservices/aswebauthenticationsession).