Configuration
Besides the standard OAuth2 parameters, the authorization endpoint accepts several eID Hub-specific parameters.
Providers
The provider parameter selects which eID provider to use for the authentication.
| eID provider | Parameter |
|---|---|
| BankID (Sweden) | bankid_se |
| BankID (Norway) | bankid_no |
| FTN | ftn |
| Freja | freja |
| iDIN | idin |
| itsme | itsme |
| MitID | mitid |
| Onfido | onfido |
| Smart-ID | smart_id |
| SMS OTP | sms_otp |
Scope
The authorization endpoint accepts the standard scope query parameter to request specific scope values.
The following scope values are supported:
openid(mandatory to enable the OpenID Connect flow)profileemailaddressphonessn
Localization
You can select a locale through the ui_locales query parameter on the authorization endpoint.
Only 2-letter language tags are accepted (no region subtag). For example: nb, da, en.
The supported languages depend on the selected eID provider. Not all providers support the choice of a locale. See Provider-specific settings for details.
Prompt
The login session is stored in a cookie which makes it possible to remember the session in the user's browser for a short time (under 5 minutes). If you don't want the session to be re-used, add prompt=login. If you want to make sure the session is re-used, prompt=none can be added, however sessions are also remembered automatically when a corresponding cookie exists.
Reference text
The query parameter reference_text can be set to specify the text shown to the end-user. If it's not specified, a default value is used.
| eID provider | RegEx | Default |
|---|---|---|
| BankID (Sweden) | ^.{1,1000}$ | "" |
| MitID | ^.{1,130}$ | "-" |
| iDIN | ^[-0-9a-zA-ZéëïóöüÉËÏÓÖÜ€ ()+,.@&=%"'/:;?$]{0,35}$ | "Identificatie" |
| Smart-ID | ^.{0,60}$ | "" |
| SMS OTP | ^.{0,70}$ | "Your one-time code is" |
Level of Assurance
The query parameter loa can be set to specify the level of assurance for providers that support multiple ones. An unsupported value results in the default.
| eID provider | Supported values | Default |
|---|---|---|
| MitID | low, substantial, high | substantial |
| BankID (Norway) | substantial, high | high |
Personal number
The personal number can be preset via personal_number for providers where it is not considered sensitive.
| eID provider | Format |
|---|---|
| BankID (Sweden) | 12-digit |
Employee login
Employee login can be enabled for providers that support it via the boolean parameter employee_login=true. Currently only supported for MitID.
Phone number
The phone number (MSISDN) can be preset via the msisdn parameter. Must be in international format, e.g. +441234567890. Currently only supported for SMS OTP.
MitID action
The type of action for MitID transactions can be set by adding the mitid_action parameter. Supported values are log_on (default), approve, confirm, accept and sign.