forterMobileUID - Mobile SDKs

iOS SDK

forterMobileUID

iOS Unique Identifiers

Why does Forter need a Unique Identifier?

In the SDK

Forter's SDK requires a unique mobile device identifier to connect the activity and behavioral data collected by the SDK to the specific device and user. This identifier should be specific to iOS device.

In the Order API

If/when a customer makes a purchase from the mobile app, the unique Identifier must be included as the forterMobileUID value in the connectionInformation object of the Forter Orders API. Since the Orders API call is made entirely from your system's backend, this ID should be retrievable from the HTTPS request headers and in the same casing as the value generated in the Forter SDK.

In the case of native mobile app orders, make sure that the following fields are populated:

  1. orderType: "MOBILE", "iOS", or "ANDROID" depending on your OS (mobile can be used for either OS)
  2. forterMobileUID: should be populated instead of the forterTokenCookie if your app is fully native, including your checkout page
  3. mobileAppVersion: should reflect the version of the app the user is on

JSON

{
  "orderId": "Example_order_fdse0rr489",
  "orderType": "iOS",
  "timeSentToForter": 1415287568000,
  "checkoutTime": 1415273168,
  "connectionInformation": {
    "customerIP": "107.57.208.5",
    "userAgent": "testStore 18.4.1 rv:184100001 (iPhone; iOS 12.4.1; en_US; iPhone10,3)",
    "forterMobileUID": "6A9798AG16FF41F7B6B9878DD488ADD5_c2Vzc2lvbnRva2VuaGVyZQ==_CF4_ES4",
    "mobileAppVersion": "18.4.1"
  },
  "totalAmount": {
    "amountUSD": "99.95"
  }
}

Getting the right identifier

For SDK version 3.0.0 and above:

Do not store or reuse a previously retrieved token. The token is refreshed throughout the SDK lifecycle, so you must always call ForterSDK.getInstance().getForterToken() at checkout and send the latest value to the server-side Order API.

For SDK versions prior to 3.0.0:

Casing

Ensure that the forterMobileUID is passed to the Order API in exactly the same casing as returned by the SDK. Forter does not enforce uppercase or lowercase, but any mismatch will prevent correct linkage between SDK device data and backend Order API data.

Provide Account Identifiers (Recommended)

If your app also leverages a separate account identifier and/or social network connectors/3rd-party authentication mechanisms, please provide us with the account ids received from those 3rd-party services.

NOTE Account Identifiers should be passed to the accountOwner.accountId field in the Order API and NOT the forterMobileUID field.

For example: If you use a Facebook social connector, you can provide us with the account id by calling:

[[ForterSDK sharedInstance] setAccountIdentifier:@"the FB account id"  
                                              withType:FTRSDKAccountIdTypeFacebook];

To pass any existing account identifiers currently used by your mobile app, use

[[ForterSDK sharedInstance] setAccountIdentifier:@"The user's account ID"  
                                              withType:FTRSDKAccountIdTypeMerchant];

Do not provide personally identifiable information (PII) as an identifier. If you use the user's email address as an ID, encode/hash it before sending.