1. Verify
  2. eIDs
  3. Norwegian BankID

Idura is part of Stø (the company behind Norwegian BankID) and helps you add BankID logins to your website or application. You integrate with Idura using one of our SDKs or a standard OpenID Connect library. We handle the BankID API integration for you. When you’re ready to go live, you order client credentials from Stø through the Idura dashboard.

BankID overview

CountryNorway
Operated byStø AS
acr_values

urn:grn:authn:no:bankid or urn:grn:authn:no:bankid:high (Kodebrikke authenticators) · urn:grn:authn:no:bankid:substantial (BankID Biometrics)

Levels of assurance (LoA)Substantial (BankID Biometrics) · High (Kodebrikke authenticators)
User databirthdate · family_name · given_name · name · country
Optional user data

socialno (ssn scope; requires user consent to share their SSN)

Caller authenticationSikker samtale

Token examples

Once a user has successfully authenticated with BankID, Idura Verify issues an ID token in JWT format to your application. The token contains a set of claims about the user and the authentication event itself. The examples below show the structure of the ID tokens issued for Norwegian BankID logins.

Kodebrikke authenticators

Triggered with acr_values=urn:grn:authn:no:bankid:high (or acr_values=urn:grn:authn:no:bankid)

The level of assurance for these authenticators are: High

{
"identityscheme": "nobankid-oidc",
Overall eID used to authenticate
"nameidentifier": "ee9b1bb905a6458e9f3b9d068f1a3765",
Legacy format of 'sub'
"sub": "{ee9b1bb9-05a6-458e-9f3b-9d068f1a3765}",
Persistent pseudonym. Uniquely identifies an eID user (per Idura Verify tenant)
"uniqueuserid": "9578-6000-4-351726",
Identifies the legal person corresponding to the login (just like the socialno does, but is not considered to be sensitive)
"certissuer": "CN=BankID - TestBank1 - Bank CA 3,OU=123456789,O=TestBank1 AS,C=NO;OrginatorId=9980;OriginatorName=BINAS;OriginatorId=9980",
"certsubject": "CN=Larsen\\, Mikkel,O=TestBank1 AS,C=NO,SERIALNUMBER=9578-6000-4-351726",
"birthdate": "1946-03-27",
"socialno": "27034698436",
Social security number
"family_name": "Larsen",
"given_name": "Mikkel",
"name": "Mikkel Larsen",
"country": "NO"
}

The uniqueUserId identifies the legal person corresponding to the login, and is not considered sensitive.

Biometric authenticator (BankID app)

Triggered with acr_values=urn:grn:authn:no:bankid:substantial

The level of assurance for this authenticator is: Substantial

Note that there is no certsubject returned when using Biometrics.

{
"identityscheme": "nobankid-oidc",
Overall eID used to authenticate
"authenticationtype": "urn:grn:authn:no:bankid:substantial",
acr_values used to authenticate
"nameidentifier": "cde37629c67b4318988ca0b378931e7d",
Legacy format of 'sub'
"sub": "{cde37629-c67b-4318-988c-a0b378931e7d}",
Persistent pseudonym. Uniquely identifies an eID user (per Idura Verify tenant)
"uniqueuserid": "9578-6000-4-476957",
Identifies the legal person corresponding to the login (just like the socialno does, but is not considered to be sensitive)
"certissuer": "CN=BankID - TestBank1 - Bank CA 3,OU=123456789,O=TestBank1 AS,C=NO;OrginatorId=9980;OriginatorName=BINAS;OriginatorId=9980",
"birthdate": "1941-08-16",
"dateofbirth": "1941-08-16",
"emailaddress": "mikkel@idura.com",
"email": "mikkel@idura.com",
"mobilephone": "90724328",
"phone_number": "90724328",
"socialno": "16084138758",
Social security number
"family_name": "Larsen",
"surname": "Larsen",
"given_name": "Mikkel",
"givenname": "Mikkel",
"name": "Mikkel Larsen",
"country": "NO"
}

Test users

Creating netcentric test users

Test users are created through the web page at https://ra-preprod.bankidnorge.no/#/search/endUser.

  1. Go to the “TEST NUMBER GENERATOR” to generate a random, valid SSN. If you want to test BankID Biometric, please make sure that the “Synthetic” checkbox is unchecked before generating a new number. BankID Biometric app does not currently support synthetic SSN numbers, so you won’t be able to use them for testing.
  2. It now says “Could not find any bankIDs for …”.
  3. Fill out the first name, last name, and BankID friendly name.
  4. Ensure that BankID app is enabled in the “HA services” section, if you want to use BankID Biometric.
  5. Click “Order” to initiate the process.
  6. Click the pencil icon and add a phone number and an email that you want to associate with the test user. You can use any values that match the correct email and phone number formats (note that the number of digits will differ per country). Random values are acceptable as you’ll be able to access the one-time codes via URLs, as shown in steps 5 and 11 of the Testing BankID Biometric section.
  7. Once the process is complete, you will have a test user. User name is the generated SSN, one time password (OTP) is always “otp”, and password is always “qwer1234”.

It can take up to 1 hour before a newly created test user is activated.

You can test it out at our authentication demo site, which is a small sample hosted by Idura.

Renewing netcentric test users

If you run into issues with test users created earlier (e.g. errors when entering the one time password), your test user certificate might have expired.

BankID test user error

This can be fixed by ordering a new netcentric BankID:

Order new BankID

Testing BankID Biometric

Start by creating a netcentric test user as described above.

You will then need to install the test version of the BankID App. Contact our support team to get access to the iOS (distributed via TestFlight) or Android version of the test app. In your request, please provide the email address linked to your Apple ID (for iOS) or your Google account for the Play Store (for Android) used for testing. Our team will get back to you with confirmation and download links for the test app.

The app must be activated before first use:

  1. Press the Get started button
  2. Enter the birth number (SSN) for the test user you created and press the Next button
  3. Enter the phone number you associated to the test user and press the Next button
  4. Open the following page and enter the birth number for the test number in the NNIN field to get your your SMS one-time code: https://toba-preprod.bankidapis.no/test/events Note: The page might need to be refreshed several times, and if multiple activations are done in a short period, old SMS codes may be shown. Only the newest activation code will at any point be valid
  5. Type the one-time code that is shown on the website into the app and press the Next button
  6. Check the Accept terms box and press the Approve button
  7. On the Choose activation method screen, press Other alternatives, then press Activation codes
  8. Press the Send code words button in the “Is this your email?” screen
  9. Open the following page and enter the birth number for the test number in the NNIN field to get your your email code words: https://toba-preprod.bankidapis.no/test/events
  10. Type the code words that are shown on the website into the app and press the Next button
  11. Press the Next button in the “Log in using BankID to complete the activation” screen
  12. Wait until BankID client has loaded in the browser. Pick BankID app in the method list if it is not already preselected.
  13. Type “qwer1234” as personal password and click the Next button
  14. A progress bar will appear and when finished you will be activated
  15. Enable biometrics (which will take you through a flow where you must agree to the terms and conditions)
  16. Run your first biometrics-based login to sign the biometrics terms

Available data / scopes

Basic user information, full name, and date of birth are always made available. Additionally, you can request the user’s social security number (SSN) by including the ssn scope in your authorize request. (Note that your application must be configured to use dynamic scope strategy.) Norwegian law governs access to SSN. You request access as part of ordering Norwegian BankID in the dashboard.

Data typeReleasedVerifiedscopelogin_hint
Full nameAlwaysYes
Date of birthAlwaysYes
SSN (“fødselsnummer” in Norwegian)User consentYesssnscope:ssn

Example (partial) authorize request with scopes

https://YOUR_SUBDOMAIN.idura.broker/oauth2/authorize?scope=openid ssn&...

Alternatively, you can send the scope in the login_hint

https://YOUR_SUBDOMAIN.idura.broker/oauth2/authorize?...&login_hint=scope:ssn&...

which can be useful if you are working with technology that does not let you control the scope value.

Stø requires that end-users explicitly consent to sharing their SSN with your application.

Enabling SSN access for your application

To enable SSN access, both a dashboard configuration and a consent collection mechanism in your application UI are required.

1. Configure the dashboard

In the Idura Dashboard, navigate to the Norwegian BankID provider page. In the SSN consent section, select Already granted.

SSN consent configuration

2. Collect consent from your end-users in your website or application

By selecting Already granted, you take responsibility for obtaining the user’s consent to release their SSN before they start the BankID login flow.

In practice, this means adding a step to your application where the user agrees to share their SSN — for example, an explicit consent checkbox, or a notice on the login screen that references your terms of service and privacy policy. The exact implementation is up to you and your legal team.

Idura stores SSN consent for 1 year per tenant. After that period, the user must provide explicit SSN consent again.

Idura does not store the SSN itself, just the fact that the user has granted your tenant access to it.

You can add a "forget-me" link on your website if you want to let users revoke the consent again. Use a normal authorize request as target, but add a prompt=consent_revoke query parameter to the request. Idura will then run a login flow (to be able to recognize the end user), and delete the granted consent.

You can learn more about authorize requests in our authorize URL builder.

Configuration

You can tweak core operational parameters and configure access to the optional user data on the Norwegian BankID eID provider page of the Idura Dashboard.

BankID Biometrics assurance level

BankID Biometrics assurance level is “Substantial”.

Learn more about assurance levels.

If you can only use assurance level “High” in your login flow, you must explicitly specify the login_hint=BID in your authorize requests to Idura Verify. Please note that using login_hint=BID will disable biometrics in the BankID app.

Modifying user flows

By default, the user flow is controlled by the user-defined settings of the BankID app: no additional configurations required. If necessary, you can adjust the user flow by adding a login_hint to the authorize URL.

The table below provides a list of options for using login_hint with Norwegian BankID, and the resulting user flows. Check our guide on prefilled fields to learn more.

Parameter name Description
login_hint=BID

The user will be redirected to the BankID app, with biometrics disabled. The user will be queried for userID(i.e. national identity number) in the first dialogue.

login_hint=BID:[SSN], where [SSN] has the format DDMMYYXXXXX

The user will be redirected to the BankID app (with biometrics disabled) along with a pre-selected userID. The userID dialogue is omitted in this case.

login_hint=BIS

The user will be redirected to the BankID app. The user will be queried for userID in the first dialogue. This option does not disable biometrics.

login_hint=BIS:[SSN], where [SSN] has the format DDMMYYXXXXX

The user will be redirected to the BankID app with a pre-selected userID. This option does not disable biometrics.

no login_hint provided

The default settings of the BankID app on the user’s device will determine the flow (whether biometrics are enabled or disabled).

Caller Authentication

Sikker samtale (“secure conversation”) lets an agent verify a caller’s identity with BankID during a phone call.

For details and integration instructions, see Caller Authentication with CIBA.

Ordering Norwegian BankID

To start accepting real users with Norwegian BankID, you must order your client credentials from Stø. The credentials consist of a client id and a client secret. You order them through the Idura dashboard.

Prerequisites for ordering

To order BankID client credentials for your company, you must meet these basic requirements:

  • Your company must be a Norwegian company. Foreign companies can order through a Norwegian subsidiary.
  • The person(s) signing the agreement must be listed in the business registry and have the authorization to sign for the company.
  • You must have set up your production environment with a production domain. See the Get ready for production guide.

The BankID OIDC Biometrics option is always included in the basis agreement.

To order:

  1. In the Idura dashboard, switch to the production environment.
  2. Open the Norwegian BankID provider page.
  3. Fill out the order form. The form guides you through the required information.

After you submit, Idura reviews your order. Your signatories then receive the agreement for signing. Once everyone has signed, Stø issues your credentials. Expect around 10-13 working days from submission until you receive your credentials. The dashboard shows the status of your order.