Authorization code flow
The eID Hub supports the Authorization Code Flow.
-
An authorization URL is constructed with the appropriate query parameters, and the user is redirected there. The
response_typeparameter should be set tocode. -
If the authentication fails, the user is redirected to the client's redirect-URI with an error code in the
errorquery parameter and an error description in theerror_descriptionquery parameter. -
If the authentication is successful, the user is redirected to the client's redirect-URI with a temporary authorization code in the
codequery parameter. -
The code is exchanged with an access-token and an id-token through a back-channel call to the token endpoint.
-
The client validates the id-token.
Example request
An authentication request can look like this:
https://testbed-eid-oidc.scrive.com/oauth2/auth?
response_type=code
&scope=openid+profile
&client_id={your-client-id}
&redirect_uri={your-registered-redirect-uri}
&state={state-parameter-generated-on-your-side}
&prompt=login
&provider=bankid_se
&ui_locales=en
&reference_text=Identify+to+login+to+My+Company
See the Configuration page for a detailed description of all supported parameters.