Skip to main content

Authorization code flow

The eID Hub supports the Authorization Code Flow.

  • An authorization URL is constructed with the appropriate query parameters, and the user is redirected there. The response_type parameter should be set to code.

  • If the authentication fails, the user is redirected to the client's redirect-URI with an error code in the error query parameter and an error description in the error_description query parameter.

  • If the authentication is successful, the user is redirected to the client's redirect-URI with a temporary authorization code in the code query parameter.

  • The code is exchanged with an access-token and an id-token through a back-channel call to the token endpoint.

  • The client validates the id-token.

Example request​

An authentication request can look like this:

https://testbed-eid-oidc.scrive.com/oauth2/auth?
response_type=code
&scope=openid+profile
&client_id={your-client-id}
&redirect_uri={your-registered-redirect-uri}
&state={state-parameter-generated-on-your-side}
&prompt=login
&provider=bankid_se
&ui_locales=en
&reference_text=Identify+to+login+to+My+Company

See the Configuration page for a detailed description of all supported parameters.