Developers ========== Here you find everything you need to implement the BankID services in a secure and user friendly way. Start from the top and get acqainted with our platform, or if you already know what it's about, dive straight into the section you need.  Start ### Good to know before you get going  [Getting started](https://developers.bankid.com/getting-started/introduction) APIs ### Why wait? Go straight to the core  [API references](https://developers.bankid.com/api-references/auth--sign/overview) Test ### Make sure everything works as expected [Testing](https://developers.bankid.com/test-portal/test-information) Popular topics -------------- [Latest news - Read the lastest updates from us. ](https://developers.bankid.com/news)  [Use cases - Common use cases and the differences between them. ](https://developers.bankid.com/use-cases/mobile-bankid-on-the-same-device)  [QR code - All about the animated QR codes. ](https://developers.bankid.com/how-to-guides/qr-code)  [Autostart - How to start BankID in browsers and native apps. ](https://developers.bankid.com/how-to-guides/autostart)  [Signatures - For auth & sign as well as Verification of digital ID card.](https://developers.bankid.com/how-to-guides/verifying-signatures) [Environments - All info about the test- and production environments. ](https://developers.bankid.com/getting-started/environments)  [Certificates - Certificates are central in our services. This is how to get one.  ](https://developers.bankid.com/getting-started/order-certificate/request-a-certificate)   [Digital ID card - Overview for Verification of a digital ID card. ](https://developers.bankid.com/api-references/digital-id-card/overview) Support ======= If you can't find what you are looking for on this site, please send an email to [teknikinfo@bankid.com](mailto:teknikinfo@bankid.com) In non-technical matters, please contact the party you have your agreement about the BankID service with.  FAQs ------ Can you review my code to see why it doesn't work? We don't have capacity to review and troubleshoot third party code. The general principles of integration and methods to be used are described on this site. If you can't find what you are looking for on this site, please send an email to [teknikinfo@bankid.com](mailto:teknikinfo@bankid.com) for guidance. How can I find out if the BankID service is up and running? You find the service status on the top right side of the bankid.com website. If you click that information field you'll land on a page with more information, such as previous, ongoing and planned downtime. You can also sign up for our [technical newsletter](https://developers.bankid.com/news/technical-newsletter) to get tips and information about the service and changes made. How do I give Apple/Google reviewers access to our app when they don't have BankID? As a developer of a service app, you need to ensure that Apple and Google can test the app in order to approve it for distribution. If most of the functionality is "behind" BankID login, you can ask Apple/Google in your review instructions to retrieve a test BankID from the demo bank (provided you have configured the service app for test BankID), or build in a demo mode that gives Apple/Google opportunity to test the app. How do I install and configure BankID in corporate environments? Here you find more information about the [Enterprise version](https://www.bankid.com/en/foretag/enterprise). How do I integrate BankID into my e-services? To use BankID, you need an agreement with a selling bank. You also need to perform a technical integration. [Read about the process and find selling banks](https://www.bankid.com/en/foretag/anslut-foeretag) How do I order and install the needed certificates? To communicate with our service, you need to add our CA root certificate in your truststore to trust our server certificate. How to do this differs slightly depending on your environment. If this isn't done you typically get various SSL/TLS errors. For authentication to the BankID service, certificate authentication is used and your application need to use a client certificate stored in your keystore. If this isn't done you typically get various SSL/TLS errors. This is issued by the same bank you purchased the service from. You don't need to install additional CA certificates to use the client certificate. [Read more about testing](https://developers.bankid.com/test-portal/test-information) How do I test my BankID implementation? How about automation? Testing can't be automated. Passwords/Security codes have to be manually entered in the BankID clients. We recommend building a so-called test stub that simulates the BankID service web service. It can also be used to perform load tests on your services.  [Read more about testing](https://developers.bankid.com/test-portal/test-information) I have technical questions about BankID. Can you call me? Unfortunately, we don't have phone support. To use BankID in your service, you need an agreement with one of the banks that sells the BankID service. In addition, you need to make the technical integration of BankID in your service. You find all the technical information on this site.  [How to connect your business](https://www.bankid.com/en/foretag/anslut-foeretag) Why doesn't the test environment work? If you try to log in or sign in the test environment, but no sign-in or signing dialog appears in the BankID app, it's probably caused by one of the following: * The BankID app in the phone isn't configured for testing. Note that you must uninstall and reinstall the app to configure it for testing. [Read instructions here](https://developers.bankid.com/test-portal/bankid-for-test). * There's no test BankID on the phone. [Read more about test BankID](https://developers.bankid.com/test-portal/bankid-for-test). * The call from your service is made to the production environment instead of the test environment. If you make a call to the production environment, the login will never appear in an app configured for testing. * You havn't installed the correct certificates to reach the test environment in your truststore and keystore. Note that there are different certificates for the test and production environments. . * A useful tip is to test at [Demo bank](https://demo.bankid.com/). Select “Log in with a Test BankID”. If that works, your client is correctly configured for test and you have a working test BankID. In this case the problem is likely to be found in your implementation.  Do you provide sample code? There are some code snippets available on this site, both on content pages and in the API specifications.  What does error 10026 mean? Error code 10026 on a PC or MAC is probably occuring because you havn't configured the BankID Security Application for test. [Read instructions here](https://developers.bankid.com/test-portal/bankid-for-test).  My animated QR code doesn't work. What could be wrong? The most common mistakes when it comes to the animated QR code are:  * Your animated QR-code and your client are communicating with different environments. Make sure your client is configured for test when testing.  * The QR code is too old. Your service should update the QR code every second. The codes should be generated continuously, not in advance since pre-generation would lower security.  * The ‘QR code error correction level’ is set to 'high', wheras it could be better to set it to 'low'.  [Read instructions here](https://developers.bankid.com/how-to-guides/qr-code) Introduction ============ BankID is an eID. We provide secure digital identification and signature as well as a digital ID card. Before implementing our services, you need to have an agreement with one of the reseller banks. [Read about connecting to BankID](https://www.bankid.com/foretag/anslut-foretag)  For the technical implementation you'll need:   * A **certificate**, which is ordered from the bank you have your BankID agreement with.  * A **backend** part that communicates with the frontend as well as with the BankID service.   * A **frontend** part that can display information for the users.   About our services -------------------- We provide solutions for fast and secure digital identification and signature, as well as an option for end users to activate a digital ID card. * **Identification**: Equivalent to presenting a physical ID but in a digital context. Often used to identify individuals when they log on to an online service. Can be used in e-services as well as in phone calls. [API overview](https://developers.bankid.com/api-references/auth--sign/overview) * **Signature**: Equivalent to making a physical signature but in a digital context. Often used for signing online payments, contracts or other agreements. Can be used in e-services as well as in phone calls. [API overview](https://developers.bankid.com/api-references/auth--sign/overview) * **Digital ID card**: An ID card in the BankID app that end users can have as a substitute for a physical ID card. You can verify the digital ID card in several ways, one being through the API Verification of digital ID card, read more below. ### Client platforms and system requirements ### Mobile BankID Mobile BankID is available for: * iOS 16 and later * Android 9 or higher ### BankID on file and card BankID on file and card are available for: * Windows 10 and later * Internet Explorer version 11 and later * Microsoft Edge latest version * Mozilla Firefox latest version * Google Chrome latest version * macOS 10.15 and later, on Intel and Apple M1 platforms * Safari latest version * Mozilla Firefox latest version * Google Chrome latest version ### Verification of our digital ID card To verify the digital ID card, use the API 'Verification of digital ID card'. When an end user shows their digital ID card, an animated QR code is shown on the screen. By scanning the QR code using i.e. a scanner connected to our services, the same verification process as an ordinary identification with BankID eID service is executed. Resources and guidance ------------------------ On this site you find instructions for how to implement our services and specific functionality connected to them. There are guides available, a [test portal](https://developers.bankid.com/test-portal/testing) and you'll find some code snippets on content pages as well as in the API references. Environments ============ On this page you find general information about certificates in our services, and information about the production- and test environments. Please note that you need to use different certificates for these two environments. The certificate for the test environment can be downloaded here, but the one for the production environment must be ordered from the bank you have your agreement about our services with.  About certificates -------------------- Our services are certificate based and you need a valid certificate to use them. Certificates are used both to identify your company and for showing which service an end user is identifying themselves with or signing information at.  Your certificate must be installed/configured in your “key store”. It doesn't need to be verified by your application and the issuer of the certificate isn't needed. Our server will present its own server certificate to your application, and verification of your certificate will be performed during a TLS handshake when the channel is established. However, our server certificate needs to be verified by your application. To make the verification possible, the issuer of the server certificate needs to be installed/configured in your “trust store”. Key stores and trust stores are managed differently depending on your environment and are not explained here.  ### **Good to know** * Different certificates are used for production and test.  * The certificates may need to be converted to a different file format to be accepted by your environment. * Your application needs access to your key store and trust store and your application needs to use correct key store and trust store. * Line breaks may need to be removed from the issuer of the server certificate pasted from this site.  Production environment ------------------------ ### Web service URLs * **Auth and sign**: https://appapi2.bankid.com/  * **Verification of digital ID card**: https://idcardapi.bankid.com/  ### Certificate for production The certificate for the production environment is provided by the bank you have a BankID agreement with. [Read more about certificates](https://developers.bankid.com/getting-started/order-certificate/request-a-certificate) You must use the _issuer_ of the certificate as trusted root. If the certificate is used as trusted, your service won't be able to access our server when the certificate is changed. #### Issuer of production certificate The production certificate is issued by the following CA: CN = BankID SSL Root CA v1 OU = Infrastructure CA O = Finansiell ID-Teknik BID AB  -----BEGIN CERTIFICATE----- MIIFvjCCA6agAwIBAgIITyTh/u1bExowDQYJKoZIhvcNAQENBQAwYjEkMCIGA1UE CgwbRmluYW5zaWVsbCBJRC1UZWtuaWsgQklEIEFCMRowGAYDVQQLDBFJbmZyYXN0 cnVjdHVyZSBDQTEeMBwGA1UEAwwVQmFua0lEIFNTTCBSb290IENBIHYxMB4XDTEx MTIwNzEyMzQwN1oXDTM0MTIzMTEyMzQwN1owYjEkMCIGA1UECgwbRmluYW5zaWVs bCBJRC1UZWtuaWsgQklEIEFCMRowGAYDVQQLDBFJbmZyYXN0cnVjdHVyZSBDQTEe MBwGA1UEAwwVQmFua0lEIFNTTCBSb290IENBIHYxMIICIjANBgkqhkiG9w0BAQEF AAOCAg8AMIICCgKCAgEAwVA4snZiSFI3r64LvYu4mOsI42A9aLKEQGq4IZo257iq vPH82SMvgBJgE52kCx7gQMmZ7iSm39CEA19hlILh8JEJNTyJNxMxVDN6cfJP1jMH JeTES1TmVbWUqGyLpyT8LCJhC9Vq4W3t/O1svGJNOUQIQL4eAHSvWTVoalxzomJh On97ENjXAt4BLb6sHfVBvmB5ReK0UfwpNACFM1RN8btEaDdWC4PfA72yzV3wK/cY 5h2k1RM1s19PjoxnpJqrmn4qZmP4tN/nk2d7c4FErJAP0pnNsll1+JfkdMfiPD35 +qcclpspzP2LpauQVyPbO21Nh+EPtr7+Iic2tkgz0g1kK0IL/foFrJ0Ievyr3Drm 2uRnA0esZ45GOmZhE22mycEX9l7w9jrdsKtqs7N/T46hil4xBiGblXkqKNG6TvAR k6XqOp3RtUvGGaKZnGllsgTvP38/nrSMlszNojrlbDnm16GGoRTQnwr8l+Yvbz/e v/e6wVFDjb52ZB0Z/KTfjXOl5cAJ7OCbODMWf8Na56OTlIkrk5NyU/uGzJFUQSvG dLHUipJ/sTZCbqNSZUwboI0oQNO/Ygez2J6zgWXGpDWiN4LGLDmBhB3T8CMQu9J/ BcFvgjnUyhyim35kDpjVPC8nrSir5OkaYgGdYWdDuv1456lFNPNNQcdZdt5fcmMC AwEAAaN4MHYwHQYDVR0OBBYEFPgqsux5RtcrIhAVeuLBSgBuRDFVMA8GA1UdEwEB /wQFMAMBAf8wHwYDVR0jBBgwFoAU+Cqy7HlG1ysiEBV64sFKAG5EMVUwEwYDVR0g BAwwCjAIBgYqhXBOAQQwDgYDVR0PAQH/BAQDAgEGMA0GCSqGSIb3DQEBDQUAA4IC AQAJOjUOS2GJPNrrrqf539aN1/EbUj5ZVRjG4wzVtX5yVqPGcRZjUQlNTcfOpwPo czKBnNX2OMF+Qm94bb+xXc/08AERqJJ3FPKu8oDNeK+Rv1X4nh95J4RHZcvl4AGh ECmGMyhyCea0qZBFBsBqQR7oC9afYOxsSovaPqX31QMLULWUYoBKWWHLVVIoHjAm GtAzMkLwe0/lrVyApr9iyXWhVr+qYGmFGw1+rwmvDmmSLWNWawYgH4NYxTf8z5hB iDOdAgilvyiAF8Yl0kCKUB2fAPhRNYlEcN+UP/KL24h/pB+hZ9mvR0tM6nW3HVZa DrvRz4VihZ8vRi3fYnOAkNE6kZdrrdO7LdBc9yYkfQdTcy0N+Aw7q4TkQ8npomrV mTKaPhtGhA7VICyRNBVcvyoxr+CY7aRQyHn/C7n/jRsQYxs7uc+msq6jRS4HPK8o lnF9usWZX6KY+8mweJiTE4uN4ZUUBUtt8WcXXDiK/bxEG2amjPcZ/b4LXwGCJb+a NWP4+iY6kBKrMANs01pLvtVjUS9RtRrY3cNEOhmKhO0qJSDXhsTcVtpbDr37UTSq QVw83dReiARPwGdURmmkaheH6z4k6qEUSXuFch0w53UAc+1aBXR1bgyFqMdy7Yxi b2AYu7wnrHioDWqP6DTkUSUeMB/zqWPM/qx6QNNOcaOcjA== -----END CERTIFICATE----- Test environment ------------------ We provide a test environment for you to use when developing and testing your service. To use the test environment, you need to:  1. Have a certificate for the test environment.  2. Use the BankID JSON web service API URL.  3. Trust the issuer of the certificate.  4. Have a BankID app configured for test.  5. Have a test BankID. ### Web service URLs * **eID service**: https://appapi2.test.bankid.com/ * **Digital ID card**: https://idcardapi.test.bankid.com/ ### Certificate for test You can download the certificate for test on the [testing page](https://developers.bankid.com/test-portal/test-information). #### Issuer of test certificate The test certificate is issued by the following CA:  CN = Test BankID SSL Root CA v1 Test OU = Infrastructure CA O = Finansiell ID-Teknik BID AB  -----BEGIN CERTIFICATE----- MIIF0DCCA7igAwIBAgIIIhYaxu4khgAwDQYJKoZIhvcNAQENBQAwbDEkMCIGA1UE CgwbRmluYW5zaWVsbCBJRC1UZWtuaWsgQklEIEFCMRowGAYDVQQLDBFJbmZyYXN0 cnVjdHVyZSBDQTEoMCYGA1UEAwwfVGVzdCBCYW5rSUQgU1NMIFJvb3QgQ0EgdjEg VGVzdDAeFw0xNDExMjExMjM5MzFaFw0zNDEyMzExMjM5MzFaMGwxJDAiBgNVBAoM G0ZpbmFuc2llbGwgSUQtVGVrbmlrIEJJRCBBQjEaMBgGA1UECwwRSW5mcmFzdHJ1 Y3R1cmUgQ0ExKDAmBgNVBAMMH1Rlc3QgQmFua0lEIFNTTCBSb290IENBIHYxIFRl c3QwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQCAKWsJc/kV/0434d+S qn19mIr85RZ/PgRFaUplSrnhuzAmaXihPLCEsd3Mh/YErygcxhQ/MAzi5OZ/anfu WSCwceRlQINtvlRPdMoeZtu29FsntK1Z5r2SYNdFwbRFb8WN9FsU0KvC5zVnuDMg s5dUZwTmdzX5ZdLP7pdgB3zhTnra5ORtkiWiUxJVev9keRgAo00ZHIRJ+xTfiSPd Jc314maigVRQZdGKSyQcQMTWi1YLwd2zwOacNxleYf8xqKgkZsmkrc4Dp2mR5Pkr nnKB6A7sAOSNatua7M86EgcGi9AaEyaRMkYJImbBfzaNlaBPyMSvwmBZzp2xKc9O D3U06ogV6CJjJL7hSuVc5x/2H04d+2I+DKwep6YBoVL9L81gRYRycqg+w+cTZ1TF /s6NC5YRKSeOCrLw3ombhjyyuPl8T/h9cpXt6m3y2xIVLYVzeDhaql3hdi6IpRh6 rwkMhJ/XmOpbDinXb1fWdFOyQwqsXQWOEwKBYIkM6cPnuid7qwaxfP22hDgAolGM LY7TPKUPRwV+a5Y3VPl7h0YSK7lDyckTJdtBqI6d4PWQLnHakUgRQy69nZhGRtUt PMSJ7I4Qtt3B6AwDq+SJTggwtJQHeid0jPki6pouenhPQ6dZT532x16XD+WIcD2f //XzzOueS29KB7lt/wH5K6EuxwIDAQABo3YwdDAdBgNVHQ4EFgQUDY6XJ/FIRFX3 dB4Wep3RVM84RXowDwYDVR0TAQH/BAUwAwEB/zAfBgNVHSMEGDAWgBQNjpcn8UhE Vfd0HhZ6ndFUzzhFejARBgNVHSAECjAIMAYGBCoDBAUwDgYDVR0PAQH/BAQDAgEG MA0GCSqGSIb3DQEBDQUAA4ICAQA5s59/Olio4svHXiKu7sPQRvrf4GfGB7hUjBGk YW2YOHTYnHavSqlBASHc8gGGwuc7v7+H+vmOfSLZfGDqxnBqeJx1H5E0YqEXtNqW G1JusIFa9xWypcONjg9v7IMnxxQzLYws4YwgPychpMzWY6B5hZsjUyKgB+1igxnf uaBueLPw3ZaJhcCL8gz6SdCKmQpX4VaAadS0vdMrBOmd826H+aDGZek1vMjuH11F fJoXY2jyDnlol7Z4BfHc011toWNMxojI7w+U4KKCbSxpWFVYITZ8WlYHcj+b2A1+ dFQZFzQN+Y1Wx3VIUqSks6P7F5aF/l4RBngy08zkP7iLA/C7rm61xWxTmpj3p6SG fUBsrsBvBgfJQHD/Mx8U3iQCa0Vj1XPogE/PXQQq2vyWiAP662hD6og1/om3l1PJ TBUyYXxqJO75ux8IWblUwAjsmTlF/Pcj8QbcMPXLMTgNQAgarV6guchjivYqb6Zr hq+Nh3JrF0HYQuMgExQ6VX8T56saOEtmlp6LSQi4HvKatCNfWUJGoYeT5SrcJ6sn By7XLMhQUCOXcBwKbNvX6aP79VA3yeJHZO7XParX7V9BB+jtf4tz/usmAT/+qXtH CCv9Xf4lv8jgdOnFfXbXuT8I4gz8uq8ElBlpbJntO6p/NY5a08E6C7FWVR+WJ5vZ OP2HsA== -----END CERTIFICATE----- ### Network information The BankID app for Android, iOS, macOS and Windows for test all connect to the BankID server on the IP adresses:  * 185.198.6.16 using port 443 and  * 185.198.6.14 using port 80 The BankID app for macOS and Windows also connects on IP adress 141.226.253.92 using port 80.  ### Test BankID and test configuration * [Issue a test BankID](https://developers.bankid.com/test-portal/testing) * [How to do the configuration for test](https://developers.bankid.com/test-portal/bankid-for-test) Request a certificate ===================== The steps for ordering your certificate are:  1. Create the request with BankID Keygen.  2. Send the request.  3. Receive the issued certificate.  4. Create the PKCS#12 / PFX file.  You'll find more detailed information below.  BankID Keygen --------------- To run the BankID Keygen software you need to start a command prompt or terminal application for your operating system (Windows or Linux). You don’t need to install anything to run this application. The new version from January 2025 should help mitigate issues with anti-virus program warnings. ### Windows [Download Keygen for Windows](https://cdn.bankid.com/tools/keygen/keygen-windows-2.3.6.exe) **Details:** File Name: keygen-windows\_2\_3\_6.exe File Size: 5.7 MB Date Published: 20/10/2025 SHA256SUM: fd3dcf546e87a741662d8936c0886acb9147b611310d7d16c1535e660407b881 ### Linux [Download Keygen for Linux](https://cdn.bankid.com/tools/keygen/keygen-linux-amd64-2.3.6) **Details:** File Name: keygen-linux-amd64\_2\_3\_6 File Size: 5.6 MB Date Published: 20/10/2025 SHA256SUM: 30f691a204f8e0c2cc3ea1f70f747d9eaa74d4b51b9a969e254e0736bf4b86a3 Create request ---------------- Follow the instructions below, for the system you use.  ### Windows From the command prompt, navigate to where you saved the BankID Keygen (keygen-windows.exe) and start the program.  keygen-windows.exe ### Linux Start a terminal and navigate to where you saved BankID Keygen. Depending on your local environment and permissions you might have to change permissions to run the application. To change permission, use the command chmod.  chmod +x keygen-linux Then start the Keygen program.  ./keygen-linux Enter information ------------------- When you start the Keygen program you will se the Keygen welcome screen:  To generate a CSR, select '1' on the welcome screen and press 'Enter'. The following information is required in the CSR process: **Official name of your organisation** This should be your organisation’s registered company name (max 64 characters). **Corporate identity number of your organisation** Enter your company’s corporate registration number according to Bolagsverket or equivalent without hyphens or spaces (10 digits). **Password to protect your private key** This is your password to protect your private key that will be generated. It must be at least 12 characters long and contain four letters and one digit. You will have to use this password later in the process when creating your PKCS#12. _It's very important that you remember this password as it can't be restored!_ **Display name** This will be shown to the user when they identify themselves or sign to your services. Enter the name to be displayed (max 40 characters) according to the instructions from your bank. The display name is usually the organization's registered company name or the name commonly used for the organization /e-service, e.g. a registered trademark. Before the certificate request is created you will have the option of verifying the information. If all looks good, press Y and enter to create the certificate request. **Private key file** The application will suggest a filename for Private Key file. If you accept it the file will be saved in the working directory. If you want to save it in another place you can manually type the path and file name. Make sure the file extension is still .key. **Certificate request file** The application will suggest a filename for CSR file. If you accept it, the file will be saved in the working directory. If you want to save it in another place you can manually type the path and file name. Make sure it's still .p10. This is the file you need to send to the bank in order to get your certificate. The CSR-generation is finished and you can ensure your request is created and saved on the disc:  Send request -------------- You should now send your certificate request (example: CSR\_Ericsson\_20200323.p10). * If you have an agreement for the BankID service with a bank you are to send your file to them according to their instructions. You should receive the recipient and delivery information from the bank. * Public organisations connecting through "Auktorisationssystem för elektronisk identifiering" should send their file to [auktorisationssystem@bankid.com](mailto:auktorisationssystem@bankid.com). #### Please note * It’s only the **P10 file** you should send. Never the private key file. Receive the issued certificate -------------------------------- Your request is usually handled within three workdays. Once you've received the certificate it's time to [create the PKCS#12 / PFX file](https://developers.bankid.com/getting-started/order-certificate/create-file). Create the PKCS#12 / PFX file ============================= Once you've received the issued certificate from the bank it's time to create a bundle containing the private key and the certificate. This will be used from your application in communication with the our service. The bundle is often referred to as a PKCS#12, P12 or PFX file.  ### Windows From a command prompt, navigate to where you saved BankID Keygen (keygen.exe) and then run the command keygen.exe. ### Linux Depending on your local environment and permissions, you might have to change permissions to run the application. To change permission, write 'chmod-x keygen'. Start a terminal and navigate to where you saved BankID Keygen and then type './keygen'. This will start the welcome screen of BankID Keygen: 1. On the welcome screen, select 3 'Generate PKCS#12 / PFX'_._ 2. BankID Keygen will now show a numbered list of all the files with a .key extension found in the working directory. Select the number in the list corresponding to the private key you want to use and press 'Enter'. You should select the key corresponding to the CSR you previously sent to the bank. If there’s only one key in the directory the number will be 1. 3. You will now be asked to enter the password for the private key. This is the password you set when you created the CSR. Type the password and press 'Enter'. 4. Next, you will be asked for the certificate you've received from the bank. If you've saved the file in the working directory, where keygen is saved, it will be shown in a numbered list. If you've saved it somewhere else you need to manually enter the path to the file. 5. The PKCS#12 output file is the final step where you enter the path to where you want to save the PKCS#12 file. Press 'Enter' to save it in the working directory with a default file name, or manually enter a new file name and path to save the file. BankID on the same device ========================= This page describes a common use case; when the user wants to identify themselves or sign something in your service, using a Mobile BankID on the same device as they visit the service on. Mobile BankID on the same device ---------------------------------- A. The user selects _identify with BankID_ in your app. 1. Your frontend calls your backend to indicate that the user wants to authenticate. 2. Your backend then calls BankID service to create an order. 3. BankID service returns an orderRef and autoStartToken. 4. Your backend passes the autoStartToken to your client. 5. Your frontend starts the BankID app using the autoStartToken. B. The BankID app starts on the user’s device. The user authenticates in the BankID app. C. The BankID app closes and the user is returned to your frontend. D. In the background, your backend uses the Collect method in the BankID service to check order status. Collect should be called every 2 seconds. 1. Once the order is completed, your backend gets the personalNumber used as well as other user specific information. 2. Check that the ipAddress you get back from the /collect matches the IP adress you observe. This is important to ensure session fixation. 3. The user is authenticated in your app. Mobile BankID on another device =============================== This page describes a common use case; when the user wants to identify themselves or sign something in your service, using a Mobile BankID on another device.  A. The user selects _identify with BankID_ on i.e. your website.  1. Your frontend calls your backend to indicate that the user wants to authenticate. 2. Your backend calls BankID service to create an order. 3. BankID service returns an orderRef, qrStartToken and qrStartSecret. 4. Your backend uses the qrStartToken and qrStartSecret as input when generating the QR data.  5. Your frontend gets the QR data from your backend.  6. Your frontend generates and displays the animated QR code to the user. B. The user opens their BankID app, scans the animated QR code and completes the authentication in the BankID app. C. In the background, your backend uses the Collect method in our service to check the order status. Collect should be called every 2 seconds.  1. Once the order is completed your backend revecives the personalNumber used as well as other user specific information. D. The user is authenticated in your app. Verification of digital ID card =============================== This page describes a common use case; when you wish to verify a digital ID card from BankID using our API Verification of digital ID card.  A. The user presents the opened digital ID card (with an animated QR code).  B. The person verifying the ID card scans the presented animated QR code using i.e. a scanner.  C. Your backend request 'Verification of digital ID card from BankID' using BankID Web Service API:s /rp/v1/verify endpoint. D. BankID service verifies the authenticity of the animated QR code and the digital ID card. E. Your backend receives a signed proof-of-identification from the Web Service API. Animated QR codes are meant to be consumed within a short period of time and thus expire after a certain amount of time. If an expired QR code is used, an error is returned, see [Errors page](https://developers.bankid.com/api-references/errors). Read more about the signed proof-of-identification. Fallback ======== There are instances where it can be hard to detect if your app is running on the same device as the BankID app or not. Therefore, it is recommended to have a fallback in the interface when: * BankID is used on the same device, it is recommended to present an animated QR code and the option to “Open BankID on another device.  * Your application and BankID are on different devices and the animated QR code is shown, giving the user an option to “Open on this device” is recommended. Autostart ========= Here you find instructions for how to start the BankID app when it's stored on the same device used to visit your app or webpage. The app is started by using autostart. This is done by using web urls and depending what platform your client is running on, the methods vary slightly. Below we describe the different ways to start the BankID app. For an overview of the most common use cases, see [use cases](https://developers.bankid.com/use-cases/mobile-bankid-on-the-same-device). Parameters ------------ | Parameter | Description | | --- | --- | | autostarttoken | Required Holds the autoStartToken returned from the web service call. | | redirect | OptionalDeprecated. This is replaced by sending the redirect in the backend call when you create the order istead. See API references page for how to send 'returnUrl'.The BankID app uses the parameter redirect to launch your web app after completing (including cancelled) auth or sign.The redirect URL:Must be UTF-8 and URL encoded.Must start with https://Should take the user back to the same webpage.May include parameters to be passed to the browser.Can be set to null.If the redirect URL is set to null, the BankID app will close without launching any URL and the app behind it will be in focus. This is likely to be the calling app.Note:The redirect URL will always be opened in the user's default browser, even if a different browser opened the BankID app.Note iOS:On iOS, Redirect=null means that your web or app won't be launched once the order is completed. | | rpref | OptionalThis is a relying party reference. It isn't supported on mobile devices.It can be any reference you want to use. The value will be included in the resulting signature. A typical use case is to protect a file when it's transported from a client to a server. The value must be base64 encoded, URL encoded, and 8 – 255 bytes (after encoding). | Native app on mobile device ----------------------------- ### iOS If your client is an iOS app you should start the BankID app by using a univeral link. let url = URL(string: "https://app.bankid.com/?autostarttoken=[TOKEN]") UIApplication.shared.open(url!, options: [.universalLinksOnly:true]) { (success) in // handle success/failure } If the BankID app isn’t present on the user's device, the answer ‘false’ is returned. In that case you need to inform the user that they need to install the BankID app and get a BankID. Your app must register a universal link or a custom URL scheme to make it possible for the BankID app to re-launch your app. The Apple App Store review process requires login information to a demo account for the app to be approved. This can be a demo account that doesn’t require a BankID to login, or a way to configure the app to use the BankID test environment. ### Android If your client is an Android app you should start the BankID app by using a url.  class MyActivity : AppCompatActivity() { // The calling app should not rely on the value of the result, or on // the result to be returned at any particular time. private val launcher = registerForActivityResult(ActivityResultContracts.StartActivityForResult()) { } ... val intent = Intent().apply { action = Intent.ACTION_VIEW data = Uri.parse("https://app.bankid.com/?autostarttoken=[TOKEN]&redirect=null") } launcher.launch(intent) If the BankID app isn’t present on the user's device, an android.content.ActivityNotFoundException is thrown. In that case you need to inform the user that they need to install the BankID app and get a BankID.  A valid result isn't guaranteed to be returned from the BankID app to your own app's activity. Your app should rely on the collect call to get the result of the auth or sign order. Launching from a browser -------------------------- If your frontend is a web page you should start the BankID app using a web link url. You need to check if the user's browser is running on a mobile or a desktop device.  ### Mobile device To open the Mobile BankID app from a browser on a mobile device, you should use unversal links for iOS and app links for Android. They are opened with the following syntax: const link = document.createElement("a") link.href="https://app.bankid.com/?autostarttoken=[TOKEN]" link.referrerPolicy="origin" link.click() ### Desktop The URL works on PCs with all commonly used browsers. Variations exist on different platforms. The syntax is:   bankid:///?autostarttoken=[TOKEN] QR code ------- Animated QR codes are used with BankID when the user visits your service on one device, i.e. a computer, but use BankID on another device, i.e. their mobile. The flow is:   1. Your service generates a QR code. 2. Your service presents the QR code to the user.   3. The user scans the QR code using their BankID app.   If successful, the BankID app will proceed with the order.  [View an overview](https://developers.bankid.com/use-cases/mobile-bankid-on-another-device) Animation and timings ----------------------- To increase security, animated QR codes are used. This means that your service updates the QR code continuously, thereby making remote fraud more difficult.   * Your service should update the QR code every second.   * The codes should be generated continuously, not in advance since pre-generation would lower security.   * The order to our server is valid for 30 seconds, meaning the user must scan the QR code within this time limit. To give a longer display time you can create new orders, for example for five minutes. * If the user approaches a time-out, you should provide the user with an option to extend the session. If the time is extended, a new order must be created.  Accessibility --------------- Since July 2025, stronger requirements regarding accessibility must be fulfilled to meet legal demands. Amongst other things, these will affect the two-device flow for BankID where the animated QR code is used. Read about the [legal requirements](https://www.w3.org/WAI/WCAG21/Understanding/timing-adjustable.html), and please consider the tips below.  * The QR code should be a