oidf-structure August 2026
Lindström Informational [Page]
Published:
Author:
M. Lindström
The Swedish Agency for Digital Government (Digg)

Sweden Connect – OpenID Federation Structure

Abstract

The Sweden Connect identity federation for OpenID Connect is built upon OpenID Federation [OpenID.Federation] and profiled by the "Swedish OpenID Federation Deployment and Interoperability Profile" [OIDC.Sweden.Federation]. This document specifies the Sweden Connect OpenID Federation structure and provides registration information for connecting parties.

Table of Contents

1. Introduction

Sweden Connect is an identity federation operated by the Swedish Agency for Digital Government (Digg). It connects organizations that offer electronic identification services with organizations that need to authenticate the users of their services, so that a Relying Party can obtain authentication of a user from an OpenID Provider that Digg has approved, without having to establish a separate relationship with each individual provider.

The federation is built upon OpenID Federation 1.0 [OpenID.Federation], and profiled by the "Swedish OpenID Federation Deployment and Interoperability Profile" [OIDC.Sweden.Federation]. OpenID Federation gives the federation a common root of trust, the Trust Anchor, whose federation key every participant configures. Starting from that root, trust in an individual Entity is established by collecting and validating a chain of signed Entity Statements, and the metadata that a participant needs in order to interact with that Entity is carried in the same chain. Approvals that an Entity holds, such as the levels of assurance an OpenID Provider may issue tokens under, are expressed as Trust Marks. Registration and metadata discovery are in this way automated, so that participants do not need to exchange configuration out of band.

Registering an Entity in the Production or QA environments requires that the organization has a contract or an agreement with Digg. The Sandbox environment carries no such requirement, and is open to any organization that wants to test or develop against the federation. See Sweden Connect Federation Environments for the environments themselves, and Sweden Connect Contract Trust Marks for how a signed contract is reflected within the federation.

This document describes how the Sweden Connect OpenID Connect federation is put together, and provides the information a party needs in order to connect to it. It does not itself define protocol requirements; those are found in the profiles it references. The intended audience is organizations that are joining, or have joined, the Sweden Connect OpenID Connect federation, together with the developers and operators of their Relying Parties and OpenID Providers.

The reader will find the Entities that act as federation services within the federation, and the role each of them has, in Federation Structure. How a Relying Party or an OpenID Provider is registered is described in Joining the Federation, and the Trust Mark types defined for the federation are documented in Trust Marks. Finally, Sweden Connect Federation Environments gives the Entity Identifiers, endpoints, and Trust Anchor keys for each of the environments.

1.1. Terminology

This document uses the terms "OpenID Provider (OP)" and "Relying Party (RP)" as defined by OpenID Connect Core 1.0 [OpenID.Core], and the terms "Entity", "Entity Configuration, "Subordinate Statement", "Intermediate Entity", "Subordinate Entity", "Superior Entity", "Trust Anchor", "Trust Mark", and "Trust Mark Issuer" defined in OpenID Federation 1.0 [OpenID.Federation].

2. Federation Structure

The Sweden Connect OpenID Federation structure can be visualized as shown below:

Figure 1: OpenID Federation structure for Sweden Connect.

Sweden Connect Trust Anchor

The Trust Anchor is the root of the federation, and defines policies and constraints that apply to the entire federation. Participants within the federation configure trust to the federation by trusting the Trust Anchor federation key, see Sweden Connect Federation Environments below.
Resolver

The Trust Anchor exposes a "resolver endpoint" according to Section 8.3 of [OpenID.Federation].
Trust Mark Issuers

There are two Trust Marks Issuers within the Sweden Connect federation; one issuer for issuing Trust Marks that assert OpenID Providers have been approved for issuing tokens under specific "Level of Assurance" URIs, and one issuer that issues Trust Marks indicating that an RP or OP has signed a particular Sweden Connect contract. See Section 4, Trust Marks, below.
Sweden Connect RP Registration Intermediate

An Intermediate Entity that is responsible of registering OpenID Connect Relying Parties to the federation. This entity issues Subordinate Statements for all RPs joining the federation, and also supports hosting of RP Entity Configurations for those RPs that lacks sufficient OpenID Federation-support.
Sweden Connect OP Registration Intermediate

An Intermediate Entity that is responsible of registering OpenID Connect Providers to the federation.

3. Joining the Federation

An organization that has signed any of the contracts that give access to Sweden Connect can join the federation. For joining the Sandbox federation, no contract is required, see Section 3.1, Joining the Sandbox Federation, below.

A Relying Party can join in one of two ways:

An OpenID Provider can only join the federation by providing its Entity Identifier, from which its published Entity Configuration can be retrieved.

Note: The Sweden Connect Registration Intermediates will check the parties that join the federation. This includes manual checks of display names and similar claims, and automated checks that verify compliance with the underlying standards.

3.1. Joining the Sandbox Federation

Until the self-service portal has been launched, joining the Sandbox federation is done manually, by sending an email to operations@swedenconnect.se and requesting access to the Sandbox federation.

4. Trust Marks

This section specifies the Trust Marks that are defined within the Sweden Connect federation.

4.1. Level of Assurance Trust Marks

Level of Assurance Trust Marks are assigned to OpenID Providers according to the Level of Assurance for which they have been approved by the Swedish Agency for Digital Government (Digg). Approval is primarily granted under Digg's Assurance Framework, see Tillitsramverk för Svensk e-legitimation.

When validating an ID Token issued by an OpenID Provider, a Relying Party may check that the OP has been assigned a Trust Mark that corresponds to the ACR-value of the ID Token.

Table 1: Trust Mark types for Level of Assurance values.
Trust Mark Type Description
https://id.swedenconnect.se/loa/loa2 A holder of this Trust Mark has been approved by the Swedish Agency for Digital Government (Digg) for Level of Assurance 2 (LoA 2).
https://id.swedenconnect.se/loa/loa3 A holder of this Trust Mark has been approved by the Swedish Agency for Digital Government (Digg) for Level of Assurance 3 (LoA 3).
https://id.swedenconnect.se/loa/loa4 A holder of this Trust Mark has been approved by the Swedish Agency for Digital Government (Digg) for Level of Assurance 4 (LoA 4).
https://id.swedenconnect.se/loa/eidas A holder of this Trust Mark has been approved to act as an official eIDAS Connector towards countries participating in the eIDAS 1 federation. This means that the holder may issue ID Tokens containing any of the eIDAS Authentication Context URIs specified in Section 3.1.1 of [SC.Registry].
https://id.swedenconnect.se/loa/nonresident A holder of this Trust Mark has been approved to issue ID Tokens containing the special-purpose Authentication Context URIs for Swedish non-residents specified in Section 3.1.1.1 of [SC.Registry]. This Trust Mark is always combined with a Trust Mark stating the Level of Assurance approved for the holder, see above.

Note: ACR-values used in OpenID Connect requests and responses are defined in Section 3.1.1 of [SC.Registry]. For historical reasons, these values do not correspond to the defined Trust Mark types.

4.2. Sweden Connect Contract Trust Marks

Contract Trust Marks are used to indicate which Sweden Connect contracts a Relying Party has signed, and under which contract or contracts an OpenID Provider delivers its services.

An OpenID Provider may check that a Relying Party holds a specific Contract Trust Mark before accepting a request from the Relying Party.

Table 2: Trust Mark types for contracts and agreements.
Trust Mark Type Description
https://id.swedenconnect.se/contract/sc/eid-authorization-system A Trust Mark type assigned to all Relying Parties that have signed the Auktorisationssystem för elektronisk identifiering contract, and the OpenID Providers that deliver authentication services according to this contract.
https://id.swedenconnect.se/contract/sc/prepaid-auth-2021 A Trust Mark type assigned to all Relying Parties that have signed the Förlitandeavtal - Förbetald e-legitimering contract, and the OpenID Providers that deliver authentication services according to this contract.

5. Sweden Connect Federation Environments

This section provides information about the different Sweden Connect environments.

5.1. Production

5.1.1. Trust Anchor

Entity Identifier

https://fed.swedenconnect.se/trustanchor
Resolve Endpoint

https://fed.swedenconnect.se/trustanchor/resolve

Trust Anchor Federation Key:

5.1.2. Trust Mark Issuers

5.1.2.1. Level of Assurance Trust Mark Issuer
Entity Identifier

https://fed.swedenconnect.se/tmi-loa
Trust Mark Endpoint (for issuance)

https://fed.swedenconnect.se/tmi-loa/trust_mark
Trust Mark Status Endpoint (for status check)

https://fed.swedenconnect.se/tmi-loa/trust_mark_status
5.1.2.2. Sweden Connect Contracts Trust Mark Issuer
Entity Identifier

https://fed.swedenconnect.se/tmi-contracts
Trust Mark Endpoint (for issuance)

https://fed.swedenconnect.se/tmi-contracts/trust_mark
Trust Mark Status Endpoint (for status check)

https://fed.swedenconnect.se/tmi-contracts/trust_mark_status

5.1.3. Registration Intermediate Entities

5.1.3.1. RP Registration Intermediate
Entity Identifier

https://fed.swedenconnect.se/im-reg-sc
Federation List Endpoint

https://fed.swedenconnect.se/im-reg-sc/subordinate_listing
5.1.3.2. OP Registration Intermediate
Entity Identifier

https://fed.swedenconnect.se/im-reg-sc-op
Federation List Endpoint

https://fed.swedenconnect.se/im-reg-sc-op/subordinate_listing

5.2. QA

5.2.1. Trust Anchor

Entity Identifier

https://qa.fed.swedenconnect.se/trustanchor
Resolve Endpoint

https://qa.fed.swedenconnect.se/trustanchor/resolve

Trust Anchor Federation Key:

As PEM-encoded key file:

-----BEGIN PUBLIC KEY-----
MIGbMBAGByqGSM49AgEGBSuBBAAjA4GGAAQA0aliFcJ5cpnNjTz87tX6jLdoKTFr
bjLiiwGNBCJrDJWUpPcZtQ36yIXBUqu9p3oe7Og1LZD1kIjIht+myoIlLScA90D5
1nGPdiEsLJlXGgXNsEbhLCOFOul29PcCLp0Vw/t2EpvSVfBXIsa1GigOSKt68iF7
7Ep5V/gWjmlyvYs+2uQ=
-----END PUBLIC KEY-----

As JWK:

{
  "crv": "P-521",
  "kty": "EC",
  "x": "ANGpYhXCeXKZzY08_O7V-oy3aCkxa24y4osBjQQiawyVlKT3GbUN-siFwVKrvad6HuzoNS2Q9ZCIyIbfpsqCJS0n",
  "y": "APdA-dZxj3YhLCyZVxoFzbBG4SwjhTrpdvT3Ai6dFcP7dhKb0lXwVyLGtRooDkirevIhe-xKeVf4Fo5pcr2LPtrk",
  "kid": "TfbPleG2EedBwk48xweaD4PMJUtJfkTUlpJBX1EWmJM=",
  "alg": "ES512",
  "use": "sig"
}

As PEM-encoded X.509 certificate:

-----BEGIN CERTIFICATE-----
MIICCDCCAWmgAwIBAgIUc82lOuDXQzjP469OkjwBntUig6wwCgYIKoZIzj0EAwIw
QDELMAkGA1UEBhMCU0UxFzAVBgNVBAoMDlN3ZWRlbiBDb25uZWN0MRgwFgYDVQQD
DA9RQSBUcnVzdCBBbmNob3IwHhcNMjYwNjE3MTAzMTA5WhcNNDYwNjE3MTAzMTA5
WjBAMQswCQYDVQQGEwJTRTEXMBUGA1UECgwOU3dlZGVuIENvbm5lY3QxGDAWBgNV
BAMMD1FBIFRydXN0IEFuY2hvcjCBmzAQBgcqhkjOPQIBBgUrgQQAIwOBhgAEANGp
YhXCeXKZzY08/O7V+oy3aCkxa24y4osBjQQiawyVlKT3GbUN+siFwVKrvad6Huzo
NS2Q9ZCIyIbfpsqCJS0nAPdA+dZxj3YhLCyZVxoFzbBG4SwjhTrpdvT3Ai6dFcP7
dhKb0lXwVyLGtRooDkirevIhe+xKeVf4Fo5pcr2LPtrkMAoGCCqGSM49BAMCA4GM
ADCBiAJCAXzzLJpLhiwd13cITm3UEmbDS74zI9p55q0reME8VY/nit4f2U4EbwyT
8Md1OVWorflf7ajh6mCnlSSbn6+j840eAkIBqXnuoH3vrZuUycO/clrYb0UNPByY
ogmRYB1V92oqa8iVh1lo9Kum917vyqqtCalNP7X4dHOdhsOQlfU7wGXEiQw=
-----END CERTIFICATE-----

5.2.2. Trust Mark Issuers

5.2.2.1. Level of Assurance Trust Mark Issuer
Entity Identifier

https://qa.fed.swedenconnect.se/tmi-loa
Trust Mark Endpoint (for issuance)

https://qa.fed.swedenconnect.se/tmi-loa/trust_mark
Trust Mark Status Endpoint (for status check)

https://qa.fed.swedenconnect.se/tmi-loa/trust_mark_status
5.2.2.2. Sweden Connect Contracts Trust Mark Issuer
Entity Identifier

https://qa.fed.swedenconnect.se/tmi-contracts
Trust Mark Endpoint (for issuance)

https://qa.fed.swedenconnect.se/tmi-contracts/trust_mark
Trust Mark Status Endpoint (for status check)

https://qa.fed.swedenconnect.se/tmi-contracts/trust_mark_status

5.2.3. Registration Intermediate Entities

5.2.3.1. RP Registration Intermediate
Entity Identifier

https://qa.fed.swedenconnect.se/im-reg-sc
Federation List Endpoint

https://qa.fed.swedenconnect.se/im-reg-sc/subordinate_listing
5.2.3.2. OP Registration Intermediate
Entity Identifier

https://qa.fed.swedenconnect.se/im-reg-sc-op
Federation List Endpoint

https://qa.fed.swedenconnect.se/im-reg-sc-op/subordinate_listing

5.3. Sandbox

5.3.1. Trust Anchor

Entity Identifier

https://fed.sandbox.swedenconnect.se/trustanchor
Resolve Endpoint

https://fed.sandbox.swedenconnect.se/trustanchor/resolve

Trust Anchor Federation Key:

As PEM-encoded key file:

-----BEGIN PUBLIC KEY-----
MIGbMBAGByqGSM49AgEGBSuBBAAjA4GGAAQAythak2N9X+iWmumBTIpVyfxnFk5T
LFMyBe6SrKj6ZXaY3KSZpN25nsneEtGZsJACmo8cC7iCHvkJY8dJge44yQUBCk97
K3liYsy1/BYYQ4YZIqGo9ZAEhb4Fshb0qMnjgqzXjjF0BFIfwRfdZ50eo+kl9H/o
F8Lhw1F3eNYbZsY9dp8=
-----END PUBLIC KEY-----

As JWK:

{
  "crv": "P-521",
  "kty": "EC",
  "x": "AMrYWpNjfV_olprpgUyKVcn8ZxZOUyxTMgXukqyo-mV2mNykmaTduZ7J3hLRmbCQApqPHAu4gh75CWPHSYHuOMkF",
  "y": "AQpPeyt5YmLMtfwWGEOGGSKhqPWQBIW-BbIW9KjJ44Ks144xdARSH8EX3WedHqPpJfR_6BfC4cNRd3jWG2bGPXaf",
  "kid": "a1AS1po4oSDsTlUQ579XSeEjslh3lrVlFDhVmNyiIiQ=",
  "alg": "ES512",
  "use": "sig"
}

As PEM-encoded X.509 certificate:

-----BEGIN CERTIFICATE-----
MIICEjCCAXOgAwIBAgIUdRPcpnV3mGKmcK7r0ZgBnA5WnWswCgYIKoZIzj0EAwIw
RTELMAkGA1UEBhMCU0UxFzAVBgNVBAoMDlN3ZWRlbiBDb25uZWN0MR0wGwYDVQQD
DBRTYW5kYm94IFRydXN0IEFuY2hvcjAeFw0yNjAxMzAwOTU4MDNaFw0zNjAxMzAw
OTU4MDNaMEUxCzAJBgNVBAYTAlNFMRcwFQYDVQQKDA5Td2VkZW4gQ29ubmVjdDEd
MBsGA1UEAwwUU2FuZGJveCBUcnVzdCBBbmNob3IwgZswEAYHKoZIzj0CAQYFK4EE
ACMDgYYABADK2FqTY31f6Jaa6YFMilXJ/GcWTlMsUzIF7pKsqPpldpjcpJmk3bme
yd4S0ZmwkAKajxwLuIIe+Qljx0mB7jjJBQEKT3sreWJizLX8FhhDhhkioaj1kASF
vgWyFvSoyeOCrNeOMXQEUh/BF91nnR6j6SX0f+gXwuHDUXd41htmxj12nzAKBggq
hkjOPQQDAgOBjAAwgYgCQgFX0+3h5IvfN6pb+1xEVrpept3a64mjg+apgMRRtvBg
i91yP4yJ1YhMEtrd6OdY9WSsTTYIu1vIrHLcJLGGtn4x4wJCAPaUg1+vBh3y7Z9M
n6xpVgkeur9oX0Orc9zTloZqMjLPC0m2qx+mYwQrCzd97T++AqbWVKLe1/mqF+JD
WdHa51qR
-----END CERTIFICATE-----

5.3.2. Trust Mark Issuers

5.3.2.1. Level of Assurance Trust Mark Issuer
Entity Identifier

https://fed.sandbox.swedenconnect.se/tmi-loa
Trust Mark Endpoint (for issuance)

https://fed.sandbox.swedenconnect.se/tmi-loa/trust_mark
Trust Mark Status Endpoint (for status check)

https://fed.sandbox.swedenconnect.se/tmi-loa/trust_mark_status
5.3.2.2. Sweden Connect Contracts Trust Mark Issuer
Entity Identifier

https://fed.sandbox.swedenconnect.se/tmi-contracts
Trust Mark Endpoint (for issuance)

https://fed.sandbox.swedenconnect.se/tmi-contracts/trust_mark
Trust Mark Status Endpoint (for status check)

https://fed.sandbox.swedenconnect.se/tmi-contracts/trust_mark_status

5.3.3. Registration Intermediate Entities

5.3.3.1. RP Registration Intermediate
Entity Identifier

https://fed.sandbox.swedenconnect.se/im-reg-sc
Federation List Endpoint

https://fed.sandbox.swedenconnect.se/im-reg-sc/subordinate_listing
5.3.3.2. OP Registration Intermediate
Entity Identifier

https://fed.sandbox.swedenconnect.se/im-reg-sc-op
Federation List Endpoint

https://fed.sandbox.swedenconnect.se/im-reg-sc-op/subordinate_listing

6. Normative References

[OIDC.Sweden.Federation]
Lindström, M. and S. Santesson, "Swedish OpenID Federation Deployment and Interoperability Profile 1.0", , <https://www.oidc.se/specifications/swedish-openid-federation-profile.html>.
[OIDC.Sweden.Hosting]
Lindström, M. and S. Santesson, "OpenID Federation Entity Configuration Hosting 1.0", , <https://www.oidc.se/openid-federation-hosting/main.html>.
[OpenID.Core]
Sakimura, N., Bradley, J., Jones, M., de Medeiros, B., and C. Mortimore, "OpenID Connect Core 1.0 incorporating errata set 2", , <http://openid.net/specs/openid-connect-core-1_0.html>.
[OpenID.Federation]
Hedberg, R., Jones, M. B., Solberg, A., Bradley, J., Marco, G. D., and V. Dzhuvinov, "OpenID Federation 1.0", , <https://openid.net/specs/openid-federation-1_0.html>.
[SC.Registry]
Lindström, M. and S. Santesson, "Sweden Connect - Registry for identifiers", , <https://docs.swedenconnect.se/technical-framework/latest/03_-_Registry_for_Identifiers.html>.

Appendix A. Notices

Copyright (c) The Swedish Agency for Digital Government (Digg), 2015-2026. All Rights Reserved.

Appendix B. Document History

2026-08-31
Initial version

Author's Address

Martin Lindström
The Swedish Agency for Digital Government (Digg)