{
 "categories": [
  "identity",
  "government",
  "public-sector"
 ],
 "deployment": "saas",
 "evidence": [
  {
   "date": "2026-09-02",
   "fact": "homepage",
   "note": "Digdir presents Ansattporten as an independent login service for acting as an employee or in a representation relationship on behalf of an organisation.",
   "source": "https://docs.digdir.no/docs/ansattporten/ansattporten_om.html",
   "tier": "declared"
  },
  {
   "date": "2026-09-02",
   "fact": "vendor",
   "note": "Digdir Docs identifies Digitaliseringsdirektoratet as the steward. Customers on Digdir common-solution terms can use ordinary point authentication.",
   "source": "https://docs.digdir.no/docs/ansattporten/ansattporten_om.html",
   "tier": "declared"
  },
  {
   "date": "2026-09-02",
   "fact": "license",
   "note": "Ansattporten uses the same cost model as ID-porten. The cost-free 200,000-login annual quota is shared across the two ports.",
   "source": "https://samarbeid.digdir.no/ansattporten/kostnadsmodell-ansattporten/2714",
   "tier": "declared"
  },
  {
   "date": "2026-09-02",
   "fact": "modalities.api.exists",
   "note": "Digdir documents point login as an authorization-code flow: redirect to /authorize, exchange the code at /token, receive an id_token.",
   "source": "https://docs.digdir.no/docs/ansattporten/ansattporten_guide.html",
   "tier": "declared"
  },
  {
   "date": "2026-09-02",
   "fact": "modalities.api.kinds[0]",
   "note": "Ansattporten publishes OpenID Connect Discovery metadata. Production issuer is https://ansattporten.no.",
   "source": "https://docs.digdir.no/docs/ansattporten/ansattporten_wellknown.html",
   "tier": "declared"
  },
  {
   "date": "2026-09-02",
   "fact": "modalities.api.kinds[1]",
   "note": "Digdir states Ansattporten is its own OAuth2 authorization server / OpenID Provider, identified by its issuer value, and is isolated from ID-porten.",
   "source": "https://docs.digdir.no/docs/ansattporten/ansattporten_om.html",
   "tier": "declared"
  },
  {
   "date": "2026-09-02",
   "fact": "modalities.api.auth[0]",
   "note": "Production discovery lists token_endpoint_auth_methods_supported including client_secret_basic and client_secret_post.",
   "source": "https://ansattporten.no/.well-known/openid-configuration",
   "tier": "declared"
  },
  {
   "date": "2026-09-02",
   "fact": "modalities.api.auth[1]",
   "note": "Production discovery lists token_endpoint_auth_methods_supported including private_key_jwt. Digdir's ID-porten guide, which Ansattporten protocol support refers to, recommends private_key_jwt over a static secret.",
   "source": "https://ansattporten.no/.well-known/openid-configuration",
   "tier": "declared"
  },
  {
   "date": "2026-09-02",
   "fact": "modalities.api.coverage",
   "note": "Protocol support is documented as nearly identical to ID-porten, with Ansattporten endpoints, RAR representation, and extra acr_values including entraid. Discovery advertises response_types_supported code only. That is a complete IdP subset, not a general application API.",
   "source": "https://docs.digdir.no/docs/ansattporten/ansattporten_protocol.html",
   "tier": "declared"
  },
  {
   "date": "2026-09-02",
   "fact": "modalities.api.docs",
   "note": "Opened as Digdir's current Ansattporten point-login integration guide, including isolated SSO and front-channel logout.",
   "source": "https://docs.digdir.no/docs/ansattporten/ansattporten_guide.html",
   "tier": "declared"
  },
  {
   "date": "2026-09-02",
   "fact": "modalities.extensibility.scripting[0]",
   "note": "Public services integrate as relying parties against Ansattporten endpoints. Representation login adds authorization_details to /authorize.",
   "source": "https://docs.digdir.no/docs/ansattporten/ansattporten_guide.html",
   "tier": "declared"
  },
  {
   "date": "2026-09-02",
   "fact": "modalities.extensibility.scripting[1]",
   "note": "Clients are administered through the same self-service as ID-porten and must be created with integration_type=ansattporten.",
   "source": "https://docs.digdir.no/docs/ansattporten/ansattporten_admin.html",
   "tier": "declared"
  },
  {
   "date": "2026-09-02",
   "fact": "modalities.data_access.export",
   "note": "A successful token response returns id_token, access_token, optional refresh_token, and representation facts in authorization_details. Access tokens can carry clm for userinfo claim selection.",
   "source": "https://docs.digdir.no/docs/ansattporten/ansattporten_representasjon.html",
   "tier": "declared"
  },
  {
   "date": "2026-09-02",
   "fact": "modalities.agent_docs.llms_txt",
   "note": "https://docs.digdir.no/llms.txt returned HTTP 404 on 2026-09-02.",
   "source": "https://docs.digdir.no/llms.txt",
   "tier": "scraped"
  },
  {
   "date": "2026-09-02",
   "fact": "verdict.scores.api",
   "note": "The OIDC surface is documented, maintained, and practical for agents acting as relying parties, with isolated SSO, representation sources, Entra ID pilot status, and Digdir client registration as material operational limits.",
   "source": "https://docs.digdir.no/docs/ansattporten/ansattporten_guide.html",
   "tier": "declared"
  },
  {
   "date": "2026-09-02",
   "fact": "freshness.watch[0].url",
   "note": "Opened and verified as Digdir's current product description, including the separate-OP rule, shared codebase with ID-porten, and 2025 ordinary-operations status.",
   "source": "https://docs.digdir.no/docs/ansattporten/ansattporten_om.html",
   "tier": "declared"
  },
  {
   "date": "2026-09-02",
   "fact": "freshness.watch[1].url",
   "note": "Opened and verified as the current point-login guide, including isolated SSO and front_channel_logout.",
   "source": "https://docs.digdir.no/docs/ansattporten/ansattporten_guide.html",
   "tier": "declared"
  },
  {
   "date": "2026-09-02",
   "fact": "freshness.watch[2].url",
   "note": "Opened and verified as the current protocol notes covering RAR, distinct endpoints, userinfo clm, and acr_values high, substantial, and entraid.",
   "source": "https://docs.digdir.no/docs/ansattporten/ansattporten_protocol.html",
   "tier": "declared"
  },
  {
   "date": "2026-09-02",
   "fact": "freshness.watch[3].url",
   "note": "Opened production discovery. issuer is https://ansattporten.no, grant_types_supported are authorization_code and refresh_token, and authorization_details_types_supported include ansattporten:altinn:resource and ansattporten:orgno.",
   "source": "https://ansattporten.no/.well-known/openid-configuration",
   "tier": "declared"
  }
 ],
 "freshness": {
  "last_verified": "2026-09-02",
  "volatility": "medium",
  "watch": [
   {
    "type": "docs",
    "url": "https://docs.digdir.no/docs/ansattporten/ansattporten_om.html"
   },
   {
    "type": "docs",
    "url": "https://docs.digdir.no/docs/ansattporten/ansattporten_guide.html"
   },
   {
    "type": "docs",
    "url": "https://docs.digdir.no/docs/ansattporten/ansattporten_protocol.html"
   },
   {
    "type": "docs",
    "url": "https://ansattporten.no/.well-known/openid-configuration"
   }
  ]
 },
 "homepage": "https://docs.digdir.no/docs/ansattporten/ansattporten_om.html",
 "id": "ansattporten",
 "license": "free",
 "modalities": {
  "agent_docs": {
   "llms_txt": false
  },
  "api": {
   "auth": [
    "client-secret-basic",
    "private-key-jwt"
   ],
   "coverage": "partial",
   "docs": "https://docs.digdir.no/docs/ansattporten/ansattporten_guide.html",
   "exists": true,
   "kinds": [
    "openid-connect",
    "oauth2"
   ]
  },
  "cli": {
   "exists": "unknown"
  },
  "computer_use": {
   "issues": [],
   "viability": "unknown"
  },
  "data_access": {
   "export": [
    "id-token",
    "access-token",
    "userinfo"
   ],
   "import": []
  },
  "extensibility": {
   "scripting": [
    "oidc-relying-party",
    "self-service-client-registration"
   ],
   "webhooks": "unknown"
  },
  "integrations": {
   "make": "unknown",
   "n8n": "unknown",
   "power_automate": "unknown",
   "zapier": "unknown"
  },
  "mcp": {
   "first_party": "unknown",
   "third_party": [],
   "verdict": "unknown"
  },
  "rpa": {
   "drivability": "unknown",
   "notes": "No repeatable UI probe was run. Ansattporten is a separate OpenID Provider for employee and representation login, not an application to drive. End-user login uses MinID, BankID, Buypass, Commfides, or the Entra ID pilot. The documented path is a pre-registered relying party calling Ansattporten /authorize and /token.\n",
   "ui_stack": [
    "web-dom"
   ],
   "vendor_support": []
  },
  "sdk": {
   "exists": "unknown",
   "languages": [],
   "official": "unknown"
  }
 },
 "name": "Ansattporten",
 "platforms": [
  "web"
 ],
 "related": {
  "alternatives": [
   "id-porten",
   "helseid",
   "feide"
  ],
  "our_products": []
 },
 "schema_version": 1,
 "score_version": 1,
 "status": "active",
 "vendor": "Digitaliseringsdirektoratet (Digdir)",
 "verdict": {
  "best_path": "api",
  "scores": {
   "api": 7,
   "cli": null,
   "computer_use": null,
   "integrations": null,
   "mcp": null,
   "overall": 7,
   "rpa": null
  },
  "summary": "Ansattporten is automatable today as Digdir's national employee and representation OpenID Provider, not as ID-porten, Maskinporten, Feide, or HelseID. Digdir documents the same authorization-code flow as ID-porten, against Ansattporten endpoints and a client registered with integration_type ansattporten. Production issuer is https://ansattporten.no. Token-endpoint authentication includes client_secret_basic and the recommended private_key_jwt. Only response_type=code is advertised. There is no SSO to ID-porten and no cross-service SSO inside Ansattporten; clients must handle front-channel logout. Representation uses Rich Authorization Requests, with Altinn Autorisasjon for pid login and Virksomhetsbroen for job-account login. Entra ID and Virksomhetsbroen remain documented as a pilot. Ordinary point login is available to customers on Digdir common-service terms; the 200,000-login quota is shared with ID-porten. Vendor documentation does not settle first-party MCP ownership. No official SDK, general CLI, or computer-use probe was established.\n"
 }
}