Can AI agents automate HelseID?
Norsk Helsenett · saas · identityhealthcarepublic-sector
HelseID is automatable as NHN's healthcare authorization server, not as Helsenorge and not as ID-porten. Personnel-facing clients use OpenID Connect authorization code with PAR, PKCE, and private_key_jwt. System clients use client credentials the same way. HelseID documents DPoP on every token request, including a nonce handshake, and forbids client-secret and mTLS client authentication. Citizens cannot log in here. Suppliers register klientsystemer and klientkonfigurasjoner in HelseID Selvbetjening, then promote from test to production after code review and leverandørvilkår. NHN publishes an official .NET client-credentials library. Other stacks must use approved OIDC libraries, not a hand-rolled protocol. Virksomhetssertifikat is not the documented HelseID client-auth method. First-party MCP ownership is not established. Computer-use viability is unassessed.
Best path today: api · Overall automatability: 7/10
Modalities
| Modality | Status | Detail |
|---|---|---|
| API | yes | openid-connectoauth2private-key-jwtdpop coverage: partial · docs |
| SDK | yes | dotnet official: yes |
| MCP | unknown | verdict: unknown |
| Integrations | unknown | |
| CLI | unknown | |
| Extensibility | yes | self-service-portaloidc-client webhooks: unknown |
| Data access | export: id-token, access-token, refresh-token · import: unknown | |
| RPA / UI automation | unknown | web-dom No repeatable UI probe was run. HelseID is an authorization server, not a journal or citizen portal. The documented path is a confidential client using private_key_jwt and DPoP against helseid-sts.nhn.no.
|
| Computer use | unknown | measured verdicts only — "unknown" means not yet probed by us |
Scores
| api | mcp | integrations | cli | rpa | computer use | overall |
|---|---|---|---|---|---|---|
| 7 | — | — | — | — | — | 7 |
Evidence
| Fact | Tier | Source | Date |
|---|---|---|---|
homepage | declared | source | 2026-08-30 |
vendor | declared | source | 2026-08-30 |
license | declared | source | 2026-08-30 |
modalities.api.exists | declared | source | 2026-08-30 |
modalities.api.kinds[0] | declared | source | 2026-08-30 |
modalities.api.kinds[1] | declared | source | 2026-08-30 |
modalities.api.auth[0] | declared | source | 2026-08-30 |
modalities.api.auth[1] | declared | source | 2026-08-30 |
modalities.api.coverage | declared | source | 2026-08-30 |
modalities.sdk.exists | declared | source | 2026-08-30 |
modalities.sdk.languages[0] | declared | source | 2026-08-30 |
modalities.extensibility.scripting[0] | declared | source | 2026-08-30 |
modalities.extensibility.scripting[1] | declared | source | 2026-08-30 |
modalities.data_access.export[0] | declared | source | 2026-08-30 |
modalities.agent_docs.llms_txt | scraped | source | 2026-08-30 |
verdict.scores.api | declared | source | 2026-08-30 |
freshness.watch[0].url | declared | source | 2026-08-30 |
freshness.watch[1].url | declared | source | 2026-08-30 |
freshness.watch[2].url | declared | source | 2026-08-30 |
freshness.watch[3].url | declared | source | 2026-08-30 |
Related tools
Other products in this database that share a category with HelseID.
Last verified 2026-08-30 · volatility medium · JSON record