{
 "categories": [
  "identity",
  "government",
  "public-sector"
 ],
 "deployment": "saas",
 "evidence": [
  {
   "date": "2026-08-28",
   "fact": "homepage",
   "note": "Digdir's Samarbeidsportalen page presents ID-porten as the national login trust anchor that lets inhabitants use MinID, BankID, Buypass or Commfides against public digital services.",
   "source": "https://samarbeid.digdir.no/id-porten/dette-er-id-porten/58",
   "tier": "declared"
  },
  {
   "date": "2026-08-28",
   "fact": "vendor",
   "note": "Digdir Docs identifies Digitaliseringsdirektoratet as the steward of ID-porten's OpenID Connect authentication service.",
   "source": "https://docs.digdir.no/docs/idporten/oidc/oidc_guide_idporten",
   "tier": "declared"
  },
  {
   "date": "2026-08-28",
   "fact": "license",
   "note": "The national login service is offered to public relying parties. Optional add-on services such as extended operations support are ordered and paid separately.",
   "source": "https://samarbeid.digdir.no/id-porten/dette-er-id-porten/58",
   "tier": "declared"
  },
  {
   "date": "2026-08-28",
   "fact": "modalities.api.exists",
   "note": "Digdir documents ID-porten as an OpenID Provider that issues ID tokens to public end-user services over the authorization-code flow.",
   "source": "https://docs.digdir.no/docs/idporten/oidc/oidc_guide_idporten",
   "tier": "declared"
  },
  {
   "date": "2026-08-28",
   "fact": "modalities.api.kinds[0]",
   "note": "The English summary states ID-porten implements a subset of OpenID Connect and that most services should use the standardized authorization-code flow.",
   "source": "https://docs.digdir.no/docs/idporten/oidc/oidc_guide_english.html",
   "tier": "declared"
  },
  {
   "date": "2026-08-28",
   "fact": "modalities.api.kinds[1]",
   "note": "Digdir states that OpenID Connect builds on OAuth 2.0 and that the token endpoint issues access_token and refresh_token in addition to id_token.",
   "source": "https://docs.digdir.no/docs/idporten/oidc/oidc_guide_idporten",
   "tier": "declared"
  },
  {
   "date": "2026-08-28",
   "fact": "modalities.api.auth[0]",
   "note": "The English guide documents static client-secret authentication at /token using HTTP Basic (client_secret_basic / client_secret_post).",
   "source": "https://docs.digdir.no/docs/idporten/oidc/oidc_guide_english.html",
   "tier": "declared"
  },
  {
   "date": "2026-08-28",
   "fact": "modalities.api.auth[1]",
   "note": "The English guide documents private_key_jwt client authentication signed with a valid Norwegian business certificate and recommends that method over a static secret.",
   "source": "https://docs.digdir.no/docs/idporten/oidc/oidc_guide_english.html",
   "tier": "declared"
  },
  {
   "date": "2026-08-28",
   "fact": "modalities.api.coverage",
   "note": "ID-porten supports authorization-code flow only (response_type=code). Implicit, password and client-credentials grants are outside this login product. That is a complete IdP subset, not a general application API.",
   "source": "https://docs.digdir.no/docs/idporten/oidc/oidc_guide_english.html",
   "tier": "declared"
  },
  {
   "date": "2026-08-28",
   "fact": "modalities.api.docs",
   "note": "Opened as Digdir's current Norwegian integration guide for ID-porten authentication over OpenID Connect.",
   "source": "https://docs.digdir.no/docs/idporten/oidc/oidc_guide_idporten",
   "tier": "declared"
  },
  {
   "date": "2026-08-28",
   "fact": "modalities.extensibility.scripting[0]",
   "note": "Public services integrate as relying parties: redirect to /authorize, exchange the code at /token, and map the ID token into a local session.",
   "source": "https://docs.digdir.no/docs/idporten/oidc/oidc_guide_idporten",
   "tier": "declared"
  },
  {
   "date": "2026-08-28",
   "fact": "modalities.extensibility.scripting[1]",
   "note": "Clients are pre-registered through Samarbeidsportalen self-service, Digdir's self-service API, or a service-desk request. Integration types include ID-porten login, API client, Ansattporten, Maskinporten and Kontaktregisteret.",
   "source": "https://docs.digdir.no/docs/idporten/oidc/oidc_func_clientreg.html",
   "tier": "declared"
  },
  {
   "date": "2026-08-28",
   "fact": "modalities.data_access.export",
   "note": "A successful token response returns id_token, optional access_token and refresh_token. The profile scope adds userinfo access for pid, locale and, when present, given_name and family_name.",
   "source": "https://docs.digdir.no/docs/idporten/oidc/oidc_guide_idporten",
   "tier": "declared"
  },
  {
   "date": "2026-08-28",
   "fact": "modalities.agent_docs.llms_txt",
   "note": "https://docs.digdir.no/llms.txt returned 404 on 2026-08-28.",
   "source": "https://docs.digdir.no/llms.txt",
   "tier": "scraped"
  },
  {
   "date": "2026-08-28",
   "fact": "verdict.scores.api",
   "note": "The OIDC surface is documented, maintained and practical for agents acting as relying parties, with public-sector client registration, authorization-code-only login and eID MFA as material operational limits.",
   "source": "https://docs.digdir.no/docs/idporten/oidc/oidc_guide_english.html",
   "tier": "declared"
  },
  {
   "date": "2026-08-28",
   "fact": "freshness.watch[0].url",
   "note": "Opened and verified as Digdir's current Norwegian ID-porten authorization-code integration guide.",
   "source": "https://docs.digdir.no/docs/idporten/oidc/oidc_guide_idporten",
   "tier": "declared"
  },
  {
   "date": "2026-08-28",
   "fact": "freshness.watch[1].url",
   "note": "Opened and verified as the current English summary covering authorization-code-only flow, client-secret and private_key_jwt authentication, and session lifetimes.",
   "source": "https://docs.digdir.no/docs/idporten/oidc/oidc_guide_english.html",
   "tier": "declared"
  },
  {
   "date": "2026-08-28",
   "fact": "freshness.watch[2].url",
   "note": "Opened and verified as the current client-registration page listing integration types, token_endpoint_auth_method values and supported grants.",
   "source": "https://docs.digdir.no/docs/idporten/oidc/oidc_func_clientreg.html",
   "tier": "declared"
  }
 ],
 "freshness": {
  "last_verified": "2026-08-28",
  "volatility": "medium",
  "watch": [
   {
    "type": "docs",
    "url": "https://docs.digdir.no/docs/idporten/oidc/oidc_guide_idporten"
   },
   {
    "type": "docs",
    "url": "https://docs.digdir.no/docs/idporten/oidc/oidc_guide_english.html"
   },
   {
    "type": "docs",
    "url": "https://docs.digdir.no/docs/idporten/oidc/oidc_func_clientreg.html"
   }
  ]
 },
 "homepage": "https://samarbeid.digdir.no/id-porten/dette-er-id-porten/58",
 "id": "id-porten",
 "license": "free",
 "modalities": {
  "agent_docs": {
   "llms_txt": false
  },
  "api": {
   "auth": [
    "client-secret-basic",
    "private-key-jwt"
   ],
   "coverage": "partial",
   "docs": "https://docs.digdir.no/docs/idporten/oidc/oidc_guide_idporten",
   "exists": true,
   "kinds": [
    "openid-connect",
    "oauth2"
   ]
  },
  "cli": {
   "exists": "unknown"
  },
  "computer_use": {
   "issues": [],
   "viability": "unknown"
  },
  "data_access": {
   "export": [
    "id-token",
    "access-token",
    "userinfo"
   ],
   "import": []
  },
  "extensibility": {
   "scripting": [
    "oidc-relying-party",
    "self-service-client-registration"
   ],
   "webhooks": "unknown"
  },
  "integrations": {
   "make": "unknown",
   "n8n": "unknown",
   "power_automate": "unknown",
   "zapier": "unknown"
  },
  "mcp": {
   "first_party": "unknown",
   "third_party": [],
   "verdict": "unknown"
  },
  "rpa": {
   "drivability": "unknown",
   "notes": "No repeatable UI probe was run. ID-porten is an OpenID Provider, not an application to drive. End-user login uses MinID, BankID, Buypass or Commfides. The documented path is a pre-registered relying party calling /authorize and /token.\n",
   "ui_stack": [
    "web-dom"
   ],
   "vendor_support": []
  },
  "sdk": {
   "exists": "unknown",
   "languages": [],
   "official": "unknown"
  }
 },
 "name": "ID-porten",
 "platforms": [
  "web"
 ],
 "related": {
  "alternatives": [
   "altinn"
  ],
  "our_products": []
 },
 "schema_version": 1,
 "score_version": 1,
 "status": "active",
 "vendor": "Digitaliseringsdirektoratet (Digdir)",
 "verdict": {
  "best_path": "api",
  "scores": {
   "api": 7,
   "cli": null,
   "computer_use": null,
   "integrations": null,
   "mcp": null,
   "overall": 7,
   "rpa": null
  },
  "summary": "ID-porten is automatable today as a national OpenID Connect authentication service, not as a line-of-business application. Digdir documents the authorization-code flow as the preferred integration: a pre-registered relying party redirects the end user to /authorize, exchanges the code at /token, and receives an ID token plus optional access and refresh tokens. Client authentication at the token endpoint is client_secret_basic, client_secret_post, or the recommended private_key_jwt signed with a Norwegian virksomhetssertifikat. Only response_type=code is supported. Clients must implement single logout and front-channel logout. The ID token carries a pairwise sub and a proprietary pid national-identifier claim. Client registration is available through Samarbeidsportalen self-service, a self-service API, or a service-desk request. This record is the identity provider; Altinn, Maskinporten, Ansattporten, Feide and BankID as a standalone eID are outside the product boundary. Vendor documentation does not settle first-party MCP ownership. No official SDK, general CLI or computer-use probe was established.\n"
 }
}