iOS and Android Native Apps and Authentication with CIS2

Hi there, wonder if anyone can help. We are about to start a programme of work which consist of developing a suite of iOS and Android phone native apps which integrate with our EPR solution. Our EPR already supports CIS2, can CIS2 be used on iOS and Android phones for authentication too ? I’ve heard that NHS Mail can be used with CIS2 combined with Microsoft Authenticator to provide MFA.

Has anyone got experience of developing native phone apps which use CIS2 for authentication ? If so, any tips or tricks you could share ? or any barriers/problems/pitfalls too ?

Hi Lee, CIS2 works on mobile devices and your users will be able to use the AAL2 authenticators such as NHSmail or security keys which are cross device compatible. For integration you can either embed a native browser or pop out to the system browser following common OAuth/OIDC patterns with mobile apps.
We have also released a private beta of passkeys which are also cross device and are on our roadmap this year have a replacement mobile app to replace the existing iOS one which will support device bound passkeys

1 Like