
| oidf-structure | August 2026 | |
| Lindström | Informational | [Page] |
The Sweden Connect identity federation for OpenID Connect is built upon OpenID Federation [OpenID.Federation] and profiled by the "Swedish OpenID Federation Deployment and Interoperability Profile" [OIDC.Sweden.Federation]. This document specifies the Sweden Connect OpenID Federation structure and provides registration information for connecting parties.¶
Sweden Connect is an identity federation operated by the Swedish Agency for Digital Government (Digg). It connects organizations that offer electronic identification services with organizations that need to authenticate the users of their services, so that a Relying Party can obtain authentication of a user from an OpenID Provider that Digg has approved, without having to establish a separate relationship with each individual provider.¶
The federation is built upon OpenID Federation 1.0 [OpenID.Federation], and profiled by the "Swedish OpenID Federation Deployment and Interoperability Profile" [OIDC.Sweden.Federation]. OpenID Federation gives the federation a common root of trust, the Trust Anchor, whose federation key every participant configures. Starting from that root, trust in an individual Entity is established by collecting and validating a chain of signed Entity Statements, and the metadata that a participant needs in order to interact with that Entity is carried in the same chain. Approvals that an Entity holds, such as the levels of assurance an OpenID Provider may issue tokens under, are expressed as Trust Marks. Registration and metadata discovery are in this way automated, so that participants do not need to exchange configuration out of band.¶
Registering an Entity in the Production or QA environments requires that the organization has a contract or an agreement with Digg. The Sandbox environment carries no such requirement, and is open to any organization that wants to test or develop against the federation. See Sweden Connect Federation Environments for the environments themselves, and Sweden Connect Contract Trust Marks for how a signed contract is reflected within the federation.¶
This document describes how the Sweden Connect OpenID Connect federation is put together, and provides the information a party needs in order to connect to it. It does not itself define protocol requirements; those are found in the profiles it references. The intended audience is organizations that are joining, or have joined, the Sweden Connect OpenID Connect federation, together with the developers and operators of their Relying Parties and OpenID Providers.¶
The reader will find the Entities that act as federation services within the federation, and the role each of them has, in Federation Structure. How a Relying Party or an OpenID Provider is registered is described in Joining the Federation, and the Trust Mark types defined for the federation are documented in Trust Marks. Finally, Sweden Connect Federation Environments gives the Entity Identifiers, endpoints, and Trust Anchor keys for each of the environments.¶
This document uses the terms "OpenID Provider (OP)" and "Relying Party (RP)" as defined by OpenID Connect Core 1.0 [OpenID.Core], and the terms "Entity", "Entity Configuration, "Subordinate Statement", "Intermediate Entity", "Subordinate Entity", "Superior Entity", "Trust Anchor", "Trust Mark", and "Trust Mark Issuer" defined in OpenID Federation 1.0 [OpenID.Federation].¶
The Sweden Connect OpenID Federation structure can be visualized as shown below:¶
An organization that has signed any of the contracts that give access to Sweden Connect can join the federation. For joining the Sandbox federation, no contract is required, see Section 3.1, Joining the Sandbox Federation, below.¶
A Relying Party can join in one of two ways:¶
An OpenID Provider can only join the federation by providing its Entity Identifier, from which its published Entity Configuration can be retrieved.¶
Note: The Sweden Connect Registration Intermediates will check the parties that join the federation. This includes manual checks of display names and similar claims, and automated checks that verify compliance with the underlying standards.¶
Until the self-service portal has been launched, joining the Sandbox federation is done manually, by sending an email to operations@swedenconnect.se and requesting access to the Sandbox federation.¶
This section specifies the Trust Marks that are defined within the Sweden Connect federation.¶
Level of Assurance Trust Marks are assigned to OpenID Providers according to the Level of Assurance for which they have been approved by the Swedish Agency for Digital Government (Digg). Approval is primarily granted under Digg's Assurance Framework, see Tillitsramverk för Svensk e-legitimation.¶
When validating an ID Token issued by an OpenID Provider, a Relying Party may check that the OP has been assigned a Trust Mark that corresponds to the ACR-value of the ID Token.¶
| Trust Mark Type | Description |
|---|---|
https://id.swedenconnect.se/loa/loa2
|
A holder of this Trust Mark has been approved by the Swedish Agency for Digital Government (Digg) for Level of Assurance 2 (LoA 2). |
https://id.swedenconnect.se/loa/loa3
|
A holder of this Trust Mark has been approved by the Swedish Agency for Digital Government (Digg) for Level of Assurance 3 (LoA 3). |
https://id.swedenconnect.se/loa/loa4
|
A holder of this Trust Mark has been approved by the Swedish Agency for Digital Government (Digg) for Level of Assurance 4 (LoA 4). |
https://id.swedenconnect.se/loa/eidas
|
A holder of this Trust Mark has been approved to act as an official eIDAS Connector towards countries participating in the eIDAS 1 federation. This means that the holder may issue ID Tokens containing any of the eIDAS Authentication Context URIs specified in Section 3.1.1 of [SC.Registry]. |
https://id.swedenconnect.se/loa/nonresident
|
A holder of this Trust Mark has been approved to issue ID Tokens containing the special-purpose Authentication Context URIs for Swedish non-residents specified in Section 3.1.1.1 of [SC.Registry]. This Trust Mark is always combined with a Trust Mark stating the Level of Assurance approved for the holder, see above. |
Note: ACR-values used in OpenID Connect requests and responses are defined in Section 3.1.1 of [SC.Registry]. For historical reasons, these values do not correspond to the defined Trust Mark types.¶
Contract Trust Marks are used to indicate which Sweden Connect contracts a Relying Party has signed, and under which contract or contracts an OpenID Provider delivers its services.¶
An OpenID Provider may check that a Relying Party holds a specific Contract Trust Mark before accepting a request from the Relying Party.¶
| Trust Mark Type | Description |
|---|---|
https://id.swedenconnect.se/contract/sc/eid-authorization-system
|
A Trust Mark type assigned to all Relying Parties that have signed the Auktorisationssystem för elektronisk identifiering contract, and the OpenID Providers that deliver authentication services according to this contract. |
https://id.swedenconnect.se/contract/sc/prepaid-auth-2021
|
A Trust Mark type assigned to all Relying Parties that have signed the Förlitandeavtal - Förbetald e-legitimering contract, and the OpenID Providers that deliver authentication services according to this contract. |
This section provides information about the different Sweden Connect environments.¶
https://fed.swedenconnect.se/trustanchorhttps://fed.swedenconnect.se/trustanchor/resolveTrust Anchor Federation Key:¶
https://qa.fed.swedenconnect.se/trustanchorhttps://qa.fed.swedenconnect.se/trustanchor/resolveTrust Anchor Federation Key:¶
As PEM-encoded key file:¶
-----BEGIN PUBLIC KEY----- MIGbMBAGByqGSM49AgEGBSuBBAAjA4GGAAQA0aliFcJ5cpnNjTz87tX6jLdoKTFr bjLiiwGNBCJrDJWUpPcZtQ36yIXBUqu9p3oe7Og1LZD1kIjIht+myoIlLScA90D5 1nGPdiEsLJlXGgXNsEbhLCOFOul29PcCLp0Vw/t2EpvSVfBXIsa1GigOSKt68iF7 7Ep5V/gWjmlyvYs+2uQ= -----END PUBLIC KEY-----¶
As JWK:¶
{
"crv": "P-521",
"kty": "EC",
"x": "ANGpYhXCeXKZzY08_O7V-oy3aCkxa24y4osBjQQiawyVlKT3GbUN-siFwVKrvad6HuzoNS2Q9ZCIyIbfpsqCJS0n",
"y": "APdA-dZxj3YhLCyZVxoFzbBG4SwjhTrpdvT3Ai6dFcP7dhKb0lXwVyLGtRooDkirevIhe-xKeVf4Fo5pcr2LPtrk",
"kid": "TfbPleG2EedBwk48xweaD4PMJUtJfkTUlpJBX1EWmJM=",
"alg": "ES512",
"use": "sig"
}
¶
As PEM-encoded X.509 certificate:¶
-----BEGIN CERTIFICATE----- MIICCDCCAWmgAwIBAgIUc82lOuDXQzjP469OkjwBntUig6wwCgYIKoZIzj0EAwIw QDELMAkGA1UEBhMCU0UxFzAVBgNVBAoMDlN3ZWRlbiBDb25uZWN0MRgwFgYDVQQD DA9RQSBUcnVzdCBBbmNob3IwHhcNMjYwNjE3MTAzMTA5WhcNNDYwNjE3MTAzMTA5 WjBAMQswCQYDVQQGEwJTRTEXMBUGA1UECgwOU3dlZGVuIENvbm5lY3QxGDAWBgNV BAMMD1FBIFRydXN0IEFuY2hvcjCBmzAQBgcqhkjOPQIBBgUrgQQAIwOBhgAEANGp YhXCeXKZzY08/O7V+oy3aCkxa24y4osBjQQiawyVlKT3GbUN+siFwVKrvad6Huzo NS2Q9ZCIyIbfpsqCJS0nAPdA+dZxj3YhLCyZVxoFzbBG4SwjhTrpdvT3Ai6dFcP7 dhKb0lXwVyLGtRooDkirevIhe+xKeVf4Fo5pcr2LPtrkMAoGCCqGSM49BAMCA4GM ADCBiAJCAXzzLJpLhiwd13cITm3UEmbDS74zI9p55q0reME8VY/nit4f2U4EbwyT 8Md1OVWorflf7ajh6mCnlSSbn6+j840eAkIBqXnuoH3vrZuUycO/clrYb0UNPByY ogmRYB1V92oqa8iVh1lo9Kum917vyqqtCalNP7X4dHOdhsOQlfU7wGXEiQw= -----END CERTIFICATE-----¶
https://fed.sandbox.swedenconnect.se/trustanchorhttps://fed.sandbox.swedenconnect.se/trustanchor/resolveTrust Anchor Federation Key:¶
As PEM-encoded key file:¶
-----BEGIN PUBLIC KEY----- MIGbMBAGByqGSM49AgEGBSuBBAAjA4GGAAQAythak2N9X+iWmumBTIpVyfxnFk5T LFMyBe6SrKj6ZXaY3KSZpN25nsneEtGZsJACmo8cC7iCHvkJY8dJge44yQUBCk97 K3liYsy1/BYYQ4YZIqGo9ZAEhb4Fshb0qMnjgqzXjjF0BFIfwRfdZ50eo+kl9H/o F8Lhw1F3eNYbZsY9dp8= -----END PUBLIC KEY-----¶
As JWK:¶
{
"crv": "P-521",
"kty": "EC",
"x": "AMrYWpNjfV_olprpgUyKVcn8ZxZOUyxTMgXukqyo-mV2mNykmaTduZ7J3hLRmbCQApqPHAu4gh75CWPHSYHuOMkF",
"y": "AQpPeyt5YmLMtfwWGEOGGSKhqPWQBIW-BbIW9KjJ44Ks144xdARSH8EX3WedHqPpJfR_6BfC4cNRd3jWG2bGPXaf",
"kid": "a1AS1po4oSDsTlUQ579XSeEjslh3lrVlFDhVmNyiIiQ=",
"alg": "ES512",
"use": "sig"
}
¶
As PEM-encoded X.509 certificate:¶
-----BEGIN CERTIFICATE----- MIICEjCCAXOgAwIBAgIUdRPcpnV3mGKmcK7r0ZgBnA5WnWswCgYIKoZIzj0EAwIw RTELMAkGA1UEBhMCU0UxFzAVBgNVBAoMDlN3ZWRlbiBDb25uZWN0MR0wGwYDVQQD DBRTYW5kYm94IFRydXN0IEFuY2hvcjAeFw0yNjAxMzAwOTU4MDNaFw0zNjAxMzAw OTU4MDNaMEUxCzAJBgNVBAYTAlNFMRcwFQYDVQQKDA5Td2VkZW4gQ29ubmVjdDEd MBsGA1UEAwwUU2FuZGJveCBUcnVzdCBBbmNob3IwgZswEAYHKoZIzj0CAQYFK4EE ACMDgYYABADK2FqTY31f6Jaa6YFMilXJ/GcWTlMsUzIF7pKsqPpldpjcpJmk3bme yd4S0ZmwkAKajxwLuIIe+Qljx0mB7jjJBQEKT3sreWJizLX8FhhDhhkioaj1kASF vgWyFvSoyeOCrNeOMXQEUh/BF91nnR6j6SX0f+gXwuHDUXd41htmxj12nzAKBggq hkjOPQQDAgOBjAAwgYgCQgFX0+3h5IvfN6pb+1xEVrpept3a64mjg+apgMRRtvBg i91yP4yJ1YhMEtrd6OdY9WSsTTYIu1vIrHLcJLGGtn4x4wJCAPaUg1+vBh3y7Z9M n6xpVgkeur9oX0Orc9zTloZqMjLPC0m2qx+mYwQrCzd97T++AqbWVKLe1/mqF+JD WdHa51qR -----END CERTIFICATE-----¶
Copyright (c) The Swedish Agency for Digital Government (Digg), 2015-2026. All Rights Reserved.¶