Can AI agents automate Signicat?

Signicat · saas · identitypublic-sector

Signicat is automatable today through the eID and Wallet Hub APIs. This record is that hub, the broker in front of national eIDs and the EU Digital Identity Wallet. It is not BankID, MitID, Freja eID, or Suomi.fi. The hub documents three protocols: OpenID Connect, SAML 2.0, and the Authentication REST API. Signicat recommends OIDC. The authorize endpoint is https://<customer-domain>/auth/open/connect/authorize. Machine access to Signicat APIs uses OAuth 2.0 client credentials. The token URL is https://api.signicat.com/auth/open/connect/token, scope signicat-api, with either client_secret_post or client_secret_basic. The example token lifetime is 600 seconds. Later calls send Authorization Bearer. The Authentication REST API base is https://api.signicat.com/auth/rest/. It creates a session, reads session status, and cancels a session, and the bodies are JSON. The API client needs the Authentication REST API permission. Redirect, embedded, and headless flows are documented. Headless is limited to specific eIDs, including Norwegian BankID and Swedish BankID. A free Dashboard signup creates a sandbox. Production eID activation can require extra steps. Signicat Events can deliver webhooks, with an HMAC-SHA256 signature in X-Signicat-Signature when a secret is set. A bounded official-registry search for signicat on 2026-09-26 returned no servers. The eID hub docs page also embeds a Kapa documentation assistant. That widget was not assessed as a product server, and first-party MCP ownership stays unknown. Connector catalogs, a product SDK, and a CLI were not established. Computer-use viability is unassessed. The API scores 7 and is the best path.

Best path today: api · Overall automatability: 7/10

Modalities

ModalityStatusDetail
APIyesrestopenid-connectoauth2samlclient-secret-postclient-secret-basicbearer
coverage: partial · docs
SDKunknown
official: unknown
MCPunknown
verdict: unknown
Integrationsunknown
CLIunknown
Extensibilityyes
webhooks: True
Data access
export: json · import: json
RPA / UI automationunknownweb-dom
No repeatable UI probe was run. Signicat documents OIDC, SAML 2.0, and the Authentication REST API for the eID and Wallet Hub. The end user still completes the selected eID flow.
Computer useunknown
measured verdicts only — "unknown" means not yet probed by us

Scores

apimcpintegrationsclirpacomputer useoverall
7—————7

Evidence

FactTierSourceDate
homepagedeclaredsource2026-09-26
licensedeclaredsource2026-09-26
modalities.api.existsdeclaredsource2026-09-26
modalities.api.kindsdeclaredsource2026-09-26
modalities.api.auth[0]declaredsource2026-09-26
modalities.api.auth[1]declaredsource2026-09-26
modalities.api.auth[2]declaredsource2026-09-26
modalities.api.coveragedeclaredsource2026-09-26
modalities.api.docsdeclaredsource2026-09-26
modalities.mcp.first_partydeclaredsource2026-09-26
modalities.mcp.verdictscrapedsource2026-09-26
modalities.extensibility.webhooksdeclaredsource2026-09-26
modalities.data_access.export[0]declaredsource2026-09-26
modalities.data_access.import[0]declaredsource2026-09-26
modalities.agent_docs.llms_txtdeclaredsource2026-09-26
verdict.scores.apideclaredsource2026-09-26
freshness.watch[0].urldeclaredsource2026-09-26
freshness.watch[1].urldeclaredsource2026-09-26
freshness.watch[2].urldeclaredsource2026-09-26
freshness.watch[3].urldeclaredsource2026-09-26
freshness.watch[4].urldeclaredsource2026-09-26

Related tools

Other products in this database that share a category with Signicat.

Last verified 2026-09-26 · volatility medium · JSON record