{
 "categories": [
  "identity",
  "government",
  "public-sector"
 ],
 "deployment": "saas",
 "evidence": [
  {
   "date": "2026-09-02",
   "fact": "homepage",
   "note": "Digdir's Samarbeidsportalen page presents Maskinporten as the trust anchor for machine-to-machine data exchange, where API providers grant scopes by consumer organisation number.",
   "source": "https://samarbeid.digdir.no/maskinporten/dette-er-maskinporten/96",
   "tier": "declared"
  },
  {
   "date": "2026-09-02",
   "fact": "vendor",
   "note": "The consumer guide identifies Digitaliseringsdirektoratet as the steward of Maskinporten client registration and token issuance.",
   "source": "https://docs.digdir.no/docs/Maskinporten/maskinporten_guide_apikonsument",
   "tier": "declared"
  },
  {
   "date": "2026-09-02",
   "fact": "license",
   "note": "Becoming an API consumer is cost-free. API providers pay an annual base price plus a per-consumer fee, with a yearly cap. Test use is free.",
   "source": "https://samarbeid.digdir.no/maskinporten/kostnadsmodell-maskinporten/64",
   "tier": "declared"
  },
  {
   "date": "2026-09-02",
   "fact": "modalities.api.exists",
   "note": "Digdir documents Maskinporten as a server-to-server OAuth 2.0 authorization server based on RFC 7523 JWT-bearer grants.",
   "source": "https://docs.digdir.no/docs/Maskinporten/maskinporten_auth_server-to-server-oauth2",
   "tier": "declared"
  },
  {
   "date": "2026-09-02",
   "fact": "modalities.api.kinds[0]",
   "note": "The architecture page describes Maskinporten as an OAuth2 API-protection service using JWT-bearer grants, not an OpenID Connect login product.",
   "source": "https://docs.digdir.no/docs/Maskinporten/maskinporten_overordnet",
   "tier": "declared"
  },
  {
   "date": "2026-09-02",
   "fact": "modalities.api.auth[0]",
   "note": "The /token endpoint accepts grant_type urn:ietf:params:oauth:grant-type:jwt-bearer and an assertion JWT. Client authentication is implicit in the signed grant.",
   "source": "https://docs.digdir.no/docs/Maskinporten/maskinporten_protocol_token",
   "tier": "declared"
  },
  {
   "date": "2026-09-02",
   "fact": "modalities.api.auth[1]",
   "note": "Clients must register token_endpoint_auth_method private_key_jwt. Maskinporten accepts only certificates and keys, not client_secret.",
   "source": "https://docs.digdir.no/docs/Maskinporten/maskinporten_guide_apikonsument",
   "tier": "declared"
  },
  {
   "date": "2026-09-02",
   "fact": "modalities.api.coverage",
   "note": "Coverage is token issuance for pre-granted scopes. Implicit, password, and client-credentials grants are not used. That is a complete M2M issuer subset, not a general application API.",
   "source": "https://docs.digdir.no/docs/Maskinporten/maskinporten_guide_apikonsument",
   "tier": "declared"
  },
  {
   "date": "2026-09-02",
   "fact": "modalities.api.docs",
   "note": "Opened as Digdir's current consumer guide covering client registration, JWT grants, /token, and Altinn scope delegation.",
   "source": "https://docs.digdir.no/docs/Maskinporten/maskinporten_guide_apikonsument",
   "tier": "declared"
  },
  {
   "date": "2026-09-02",
   "fact": "modalities.extensibility.scripting[0]",
   "note": "Consumers integrate as OAuth2 clients: generate and sign a JWT grant, exchange it at /token, and present the access token to the target API.",
   "source": "https://docs.digdir.no/docs/Maskinporten/maskinporten_auth_server-to-server-oauth2",
   "tier": "declared"
  },
  {
   "date": "2026-09-02",
   "fact": "modalities.extensibility.scripting[1]",
   "note": "Providers and consumers can administer scopes, access grants, and clients through Digdir's self-service API at api.samarbeid.digdir.no, using an administration client with a virksomhetssertifikat.",
   "source": "https://docs.digdir.no/docs/Maskinporten/maskinporten_sjolvbetjening_api.html",
   "tier": "declared"
  },
  {
   "date": "2026-09-02",
   "fact": "modalities.data_access.export",
   "note": "A successful token response returns a self-contained JWT access_token, expires_in, token_type Bearer, and the issued scope list.",
   "source": "https://docs.digdir.no/docs/Maskinporten/maskinporten_protocol_token",
   "tier": "declared"
  },
  {
   "date": "2026-09-02",
   "fact": "modalities.agent_docs.llms_txt",
   "note": "https://docs.digdir.no/llms.txt returned HTTP 404 on 2026-09-02.",
   "source": "https://docs.digdir.no/llms.txt",
   "tier": "scraped"
  },
  {
   "date": "2026-09-02",
   "fact": "verdict.scores.api",
   "note": "The OAuth2 JWT-bearer surface is documented, maintained, and practical for agents acting as confidential M2M clients, with virksomhetssertifikat, scope grants, and Digdir onboarding as material operational limits.",
   "source": "https://docs.digdir.no/docs/Maskinporten/maskinporten_guide_apikonsument",
   "tier": "declared"
  },
  {
   "date": "2026-09-02",
   "fact": "freshness.watch[0].url",
   "note": "Opened and verified as Digdir's current Maskinporten consumer guide for registration, JWT grants, and /token.",
   "source": "https://docs.digdir.no/docs/Maskinporten/maskinporten_guide_apikonsument",
   "tier": "declared"
  },
  {
   "date": "2026-09-02",
   "fact": "freshness.watch[1].url",
   "note": "Opened and verified as the current JWT-grant claim table, including aud, iss, scope, x5c/kid, and consumer_org delegation.",
   "source": "https://docs.digdir.no/docs/Maskinporten/maskinporten_protocol_jwtgrant",
   "tier": "declared"
  },
  {
   "date": "2026-09-02",
   "fact": "freshness.watch[2].url",
   "note": "Opened and verified as the current /token request and access-token claim specification, including client_amr values.",
   "source": "https://docs.digdir.no/docs/Maskinporten/maskinporten_protocol_token",
   "tier": "declared"
  },
  {
   "date": "2026-09-02",
   "fact": "freshness.watch[3].url",
   "note": "Opened production RFC 8414 metadata. issuer is https://maskinporten.no/, grant_types_supported is jwt-bearer only, and token_endpoint_auth_methods_supported is private_key_jwt only.",
   "source": "https://maskinporten.no/.well-known/oauth-authorization-server",
   "tier": "declared"
  }
 ],
 "freshness": {
  "last_verified": "2026-09-02",
  "volatility": "medium",
  "watch": [
   {
    "type": "docs",
    "url": "https://docs.digdir.no/docs/Maskinporten/maskinporten_guide_apikonsument"
   },
   {
    "type": "docs",
    "url": "https://docs.digdir.no/docs/Maskinporten/maskinporten_protocol_jwtgrant"
   },
   {
    "type": "docs",
    "url": "https://docs.digdir.no/docs/Maskinporten/maskinporten_protocol_token"
   },
   {
    "type": "docs",
    "url": "https://maskinporten.no/.well-known/oauth-authorization-server"
   }
  ]
 },
 "homepage": "https://samarbeid.digdir.no/maskinporten/dette-er-maskinporten/96",
 "id": "maskinporten",
 "license": "free",
 "modalities": {
  "agent_docs": {
   "llms_txt": false
  },
  "api": {
   "auth": [
    "jwt-bearer",
    "private-key-jwt"
   ],
   "coverage": "partial",
   "docs": "https://docs.digdir.no/docs/Maskinporten/maskinporten_guide_apikonsument",
   "exists": true,
   "kinds": [
    "oauth2"
   ]
  },
  "cli": {
   "exists": "unknown"
  },
  "computer_use": {
   "issues": [],
   "viability": "unknown"
  },
  "data_access": {
   "export": [
    "access-token"
   ],
   "import": []
  },
  "extensibility": {
   "scripting": [
    "oauth2-client",
    "self-service-api"
   ],
   "webhooks": "unknown"
  },
  "integrations": {
   "make": "unknown",
   "n8n": "unknown",
   "power_automate": "unknown",
   "zapier": "unknown"
  },
  "mcp": {
   "first_party": "unknown",
   "third_party": [],
   "verdict": "unknown"
  },
  "rpa": {
   "drivability": "unknown",
   "notes": "No repeatable UI probe was run. Maskinporten is a machine-to-machine OAuth 2.0 issuer, not an application to drive. The documented path is a pre-registered client posting a JWT-bearer grant to /token. Samarbeidsportalen self-service is a web console for client and scope administration, not the runtime integration surface.\n",
   "ui_stack": [
    "web-dom"
   ],
   "vendor_support": []
  },
  "sdk": {
   "exists": "unknown",
   "languages": [],
   "official": "unknown"
  }
 },
 "name": "Maskinporten",
 "platforms": [
  "web"
 ],
 "related": {
  "alternatives": [
   "id-porten",
   "altinn",
   "helseid"
  ],
  "our_products": []
 },
 "schema_version": 1,
 "score_version": 1,
 "status": "active",
 "vendor": "Digitaliseringsdirektoratet (Digdir)",
 "verdict": {
  "best_path": "api",
  "scores": {
   "api": 7,
   "cli": null,
   "computer_use": null,
   "integrations": null,
   "mcp": null,
   "overall": 7,
   "rpa": null
  },
  "summary": "Maskinporten is automatable today as Digdir's national machine-to-machine OAuth 2.0 authorization server, not as ID-porten, Ansattporten, Altinn, or HelseID. A pre-registered client signs a JWT-bearer grant with a Norwegian virksomhetssertifikat or a pre-registered asymmetric key, posts it to /token as grant_type urn:ietf:params:oauth:grant-type:jwt-bearer, and receives a self-contained JWT access token bound to the consumer organisation number and requested scopes. Client authentication at the token endpoint is private_key_jwt only; client_secret is not accepted. API providers define scopes and grant them to organisation numbers through Samarbeidsportalen or the self-service API. Consumers must sign Digdir bruksvilk\u00e5r and hold a virksomhetssertifikat. API-provider use is invoiced; becoming a consumer is cost-free. This record is the M2M issuer. ID-porten login, Ansattporten representation, Altinn apps, and HelseID are outside the product boundary. Vendor documentation does not settle first-party MCP ownership. No official SDK, general CLI, or computer-use probe was established.\n"
 }
}