Can AI agents automate HelseID?

Norsk Helsenett · saas · identityhealthcarepublic-sector

HelseID is automatable as NHN's healthcare authorization server, not as Helsenorge and not as ID-porten. Personnel-facing clients use OpenID Connect authorization code with PAR, PKCE, and private_key_jwt. System clients use client credentials the same way. HelseID documents DPoP on every token request, including a nonce handshake, and forbids client-secret and mTLS client authentication. Citizens cannot log in here. Suppliers register klientsystemer and klientkonfigurasjoner in HelseID Selvbetjening, then promote from test to production after code review and leverandørvilkår. NHN publishes an official .NET client-credentials library. Other stacks must use approved OIDC libraries, not a hand-rolled protocol. Virksomhetssertifikat is not the documented HelseID client-auth method. First-party MCP ownership is not established. Computer-use viability is unassessed.

Best path today: api · Overall automatability: 7/10

Modalities

ModalityStatusDetail
APIyesopenid-connectoauth2private-key-jwtdpop
coverage: partial · docs
SDKyesdotnet
official: yes
MCPunknown
verdict: unknown
Integrationsunknown
CLIunknown
Extensibilityyesself-service-portaloidc-client
webhooks: unknown
Data access
export: id-token, access-token, refresh-token · import: unknown
RPA / UI automationunknownweb-dom
No repeatable UI probe was run. HelseID is an authorization server, not a journal or citizen portal. The documented path is a confidential client using private_key_jwt and DPoP against helseid-sts.nhn.no.
Computer useunknown
measured verdicts only — "unknown" means not yet probed by us

Scores

apimcpintegrationsclirpacomputer useoverall
77

Evidence

FactTierSourceDate
homepagedeclaredsource2026-08-30
vendordeclaredsource2026-08-30
licensedeclaredsource2026-08-30
modalities.api.existsdeclaredsource2026-08-30
modalities.api.kinds[0]declaredsource2026-08-30
modalities.api.kinds[1]declaredsource2026-08-30
modalities.api.auth[0]declaredsource2026-08-30
modalities.api.auth[1]declaredsource2026-08-30
modalities.api.coveragedeclaredsource2026-08-30
modalities.sdk.existsdeclaredsource2026-08-30
modalities.sdk.languages[0]declaredsource2026-08-30
modalities.extensibility.scripting[0]declaredsource2026-08-30
modalities.extensibility.scripting[1]declaredsource2026-08-30
modalities.data_access.export[0]declaredsource2026-08-30
modalities.agent_docs.llms_txtscrapedsource2026-08-30
verdict.scores.apideclaredsource2026-08-30
freshness.watch[0].urldeclaredsource2026-08-30
freshness.watch[1].urldeclaredsource2026-08-30
freshness.watch[2].urldeclaredsource2026-08-30
freshness.watch[3].urldeclaredsource2026-08-30

Related tools

Other products in this database that share a category with HelseID.

Last verified 2026-08-30 · volatility medium · JSON record