{
 "categories": [
  "identity",
  "public-sector"
 ],
 "deployment": "saas",
 "evidence": [
  {
   "date": "2026-09-26",
   "fact": "homepage",
   "note": "Signicat presents authentication products, including the eID and Wallet Hub, and invites developers to start a free API test account.",
   "source": "https://www.signicat.com/products/authentication",
   "tier": "declared"
  },
  {
   "date": "2026-09-26",
   "fact": "license",
   "note": "The eID hub quick start says to sign up to the Signicat Dashboard for free and recommends a sandbox account before production. Production eID activation may require additional procedures.",
   "source": "https://developer.signicat.com/docs/eid-hub/quick-start.md",
   "tier": "declared"
  },
  {
   "date": "2026-09-26",
   "fact": "modalities.api.exists",
   "note": "The eID and Wallet Hub documents one integration point over OpenID Connect, SAML 2.0, or the Authentication REST API.",
   "source": "https://developer.signicat.com/docs/eid-hub/",
   "tier": "declared"
  },
  {
   "date": "2026-09-26",
   "fact": "modalities.api.kinds",
   "note": "The hub overview names OpenID Connect, SAML 2.0, and the Authentication REST API as the three protocols.",
   "source": "https://developer.signicat.com/docs/eid-hub/",
   "tier": "declared"
  },
  {
   "date": "2026-09-26",
   "fact": "modalities.api.auth[0]",
   "note": "client_secret_post sends grant_type client_credentials, scope signicat-api, client_id, and client_secret in the form body to https://api.signicat.com/auth/open/connect/token.",
   "source": "https://developer.signicat.com/docs/dashboard/connect-to-signicat-apis/quick-start-guide.md",
   "tier": "declared"
  },
  {
   "date": "2026-09-26",
   "fact": "modalities.api.auth[1]",
   "note": "client_secret_basic sends the same token URL an Authorization Basic header of the Base64-encoded client_id and client_secret.",
   "source": "https://developer.signicat.com/docs/dashboard/connect-to-signicat-apis/quick-start-guide.md",
   "tier": "declared"
  },
  {
   "date": "2026-09-26",
   "fact": "modalities.api.auth[2]",
   "note": "API calls after the token response send Authorization Bearer. The example token response sets expires_in to 600 seconds.",
   "source": "https://developer.signicat.com/docs/dashboard/connect-to-signicat-apis/quick-start-guide.md",
   "tier": "declared"
  },
  {
   "date": "2026-09-26",
   "fact": "modalities.api.coverage",
   "note": "The Authentication REST API documents redirect, embedded, and headless flows. Headless is listed only for specific eIDs, including Norwegian BankID and Swedish BankID. The end user still completes the eID step in redirect and embedded flows.",
   "source": "https://developer.signicat.com/docs/eid-hub/authentication-api.md",
   "tier": "declared"
  },
  {
   "date": "2026-09-26",
   "fact": "modalities.api.docs",
   "note": "The Authentication REST API reference states base URL https://api.signicat.com/auth/rest/, OAuth 2.0, JSON bodies, and session create, status, and cancel.",
   "source": "https://developer.signicat.com/apis/eid-hub/",
   "tier": "declared"
  },
  {
   "date": "2026-09-26",
   "fact": "modalities.mcp.first_party",
   "note": "The opened hub documentation does not declare a Signicat product MCP server. The page HTML includes a Kapa documentation assistant at https://signicat-documentation.mcp.kapa.ai. That widget is not assessed as the hub API.",
   "source": "https://developer.signicat.com/docs/eid-hub/",
   "tier": "declared"
  },
  {
   "date": "2026-09-26",
   "fact": "modalities.mcp.verdict",
   "note": "A bounded official-registry search for signicat on 2026-09-26 returned an empty server list. An empty search does not establish that no vendor server exists.",
   "source": "https://registry.modelcontextprotocol.io/v0.1/servers?search=signicat&version=latest",
   "tier": "scraped"
  },
  {
   "date": "2026-09-26",
   "fact": "modalities.extensibility.webhooks",
   "note": "Signicat Events can deliver subscriptions as webhooks. With a secret, requests include an X-Signicat-Signature HMAC-SHA256 of the raw body. The Authentication REST API page points at this Events service.",
   "source": "https://developer.signicat.com/docs/dashboard/settings/events.md",
   "tier": "declared"
  },
  {
   "date": "2026-09-26",
   "fact": "modalities.data_access.export[0]",
   "note": "The Authentication REST API says request and response bodies are JSON. A successful session status response carries the authenticated subject.",
   "source": "https://developer.signicat.com/apis/eid-hub/",
   "tier": "declared"
  },
  {
   "date": "2026-09-26",
   "fact": "modalities.data_access.import[0]",
   "note": "Creating a session sends a JSON body. The quick start describes the REST API as JSON calls, including the session flow.",
   "source": "https://developer.signicat.com/docs/eid-hub/quick-start.md",
   "tier": "declared"
  },
  {
   "date": "2026-09-26",
   "fact": "modalities.agent_docs.llms_txt",
   "note": "https://developer.signicat.com/llms.txt is a first-party index of Signicat documentation sections, including the eID and Wallet Hub and the API index.",
   "source": "https://developer.signicat.com/llms.txt",
   "tier": "declared"
  },
  {
   "date": "2026-09-26",
   "fact": "verdict.scores.api",
   "note": "OIDC and the Authentication REST API are documented, with client-credentials tokens, a published token URL, and JSON session calls. Headless coverage is method-specific, tokens expire in 600 seconds, and production eID setup can require extra steps, so the path scores 7.",
   "source": "https://developer.signicat.com/docs/dashboard/connect-to-signicat-apis/quick-start-guide.md",
   "tier": "declared"
  },
  {
   "date": "2026-09-26",
   "fact": "freshness.watch[0].url",
   "note": "Opened the eID and Wallet Hub overview, including OIDC, SAML 2.0, and the Authentication REST API.",
   "source": "https://developer.signicat.com/docs/eid-hub/",
   "tier": "declared"
  },
  {
   "date": "2026-09-26",
   "fact": "freshness.watch[1].url",
   "note": "Opened the Authentication REST API reference, including the base URL, OAuth 2.0, and the session endpoints.",
   "source": "https://developer.signicat.com/apis/eid-hub/",
   "tier": "declared"
  },
  {
   "date": "2026-09-26",
   "fact": "freshness.watch[2].url",
   "note": "Opened the connect-to-APIs quick start, including client_secret_post, client_secret_basic, the token URL, and Bearer calls.",
   "source": "https://developer.signicat.com/docs/dashboard/connect-to-signicat-apis/quick-start-guide.md",
   "tier": "declared"
  },
  {
   "date": "2026-09-26",
   "fact": "freshness.watch[3].url",
   "note": "Opened the Events guide, including webhook delivery and the HMAC signature header.",
   "source": "https://developer.signicat.com/docs/dashboard/settings/events.md",
   "tier": "declared"
  },
  {
   "date": "2026-09-26",
   "fact": "freshness.watch[4].url",
   "note": "Opened the developer llms.txt index.",
   "source": "https://developer.signicat.com/llms.txt",
   "tier": "declared"
  }
 ],
 "freshness": {
  "last_verified": "2026-09-26",
  "volatility": "medium",
  "watch": [
   {
    "type": "docs",
    "url": "https://developer.signicat.com/docs/eid-hub/"
   },
   {
    "type": "docs",
    "url": "https://developer.signicat.com/apis/eid-hub/"
   },
   {
    "type": "docs",
    "url": "https://developer.signicat.com/docs/dashboard/connect-to-signicat-apis/quick-start-guide.md"
   },
   {
    "type": "docs",
    "url": "https://developer.signicat.com/docs/dashboard/settings/events.md"
   },
   {
    "type": "docs",
    "url": "https://developer.signicat.com/llms.txt"
   }
  ]
 },
 "homepage": "https://www.signicat.com/products/authentication",
 "id": "signicat",
 "license": "freemium",
 "modalities": {
  "agent_docs": {
   "llms_txt": true
  },
  "api": {
   "auth": [
    "client-secret-post",
    "client-secret-basic",
    "bearer"
   ],
   "coverage": "partial",
   "docs": "https://developer.signicat.com/apis/eid-hub/",
   "exists": true,
   "kinds": [
    "rest",
    "openid-connect",
    "oauth2",
    "saml"
   ]
  },
  "cli": {
   "exists": "unknown"
  },
  "computer_use": {
   "issues": [],
   "viability": "unknown"
  },
  "data_access": {
   "export": [
    "json"
   ],
   "import": [
    "json"
   ]
  },
  "extensibility": {
   "scripting": [],
   "webhooks": true
  },
  "integrations": {
   "make": "unknown",
   "n8n": "unknown",
   "power_automate": "unknown",
   "zapier": "unknown"
  },
  "mcp": {
   "first_party": "unknown",
   "third_party": [],
   "verdict": "unknown"
  },
  "rpa": {
   "drivability": "unknown",
   "notes": "No repeatable UI probe was run. Signicat documents OIDC, SAML 2.0, and the Authentication REST API for the eID and Wallet Hub. The end user still completes the selected eID flow.\n",
   "ui_stack": [
    "web-dom"
   ],
   "vendor_support": []
  },
  "sdk": {
   "exists": "unknown",
   "languages": [],
   "official": "unknown"
  }
 },
 "name": "Signicat",
 "platforms": [
  "web"
 ],
 "related": {
  "alternatives": [
   "bankid",
   "mitid",
   "freja-eid",
   "suomi-fi-identification"
  ],
  "our_products": []
 },
 "schema_version": 1,
 "score_version": 1,
 "status": "active",
 "vendor": "Signicat",
 "verdict": {
  "best_path": "api",
  "scores": {
   "api": 7,
   "cli": null,
   "computer_use": null,
   "integrations": null,
   "mcp": null,
   "overall": 7,
   "rpa": null
  },
  "summary": "Signicat is automatable today through the eID and Wallet Hub APIs. This record is that hub, the broker in front of national eIDs and the EU Digital Identity Wallet. It is not BankID, MitID, Freja eID, or Suomi.fi. The hub documents three protocols: OpenID Connect, SAML 2.0, and the Authentication REST API. Signicat recommends OIDC. The authorize endpoint is https://<customer-domain>/auth/open/connect/authorize. Machine access to Signicat APIs uses OAuth 2.0 client credentials. The token URL is https://api.signicat.com/auth/open/connect/token, scope signicat-api, with either client_secret_post or client_secret_basic. The example token lifetime is 600 seconds. Later calls send Authorization Bearer. The Authentication REST API base is https://api.signicat.com/auth/rest/. It creates a session, reads session status, and cancels a session, and the bodies are JSON. The API client needs the Authentication REST API permission. Redirect, embedded, and headless flows are documented. Headless is limited to specific eIDs, including Norwegian BankID and Swedish BankID. A free Dashboard signup creates a sandbox. Production eID activation can require extra steps. Signicat Events can deliver webhooks, with an HMAC-SHA256 signature in X-Signicat-Signature when a secret is set. A bounded official-registry search for signicat on 2026-09-26 returned no servers. The eID hub docs page also embeds a Kapa documentation assistant. That widget was not assessed as a product server, and first-party MCP ownership stays unknown. Connector catalogs, a product SDK, and a CLI were not established. Computer-use viability is unassessed. The API scores 7 and is the best path.\n"
 }
}