Sweden Connect Technical Specifications

This is the overview page for the Sweden Connect specifications. Listed below are the specifications from the latest official version (December 2024), along with the latest updates (drafts).

The section The Sweden Connect Federation presents documents needed for joining the federation.

Overview and Registry

An introduction to the Sweden Connect Framework

Overview documents that describe the different parts of the Sweden Connect Framework. Currently only covers SAML.

Sweden Connect - Registry for identifiers

This document defines the structure for identifiers assigned by the Swedish Agency for Digital Government (Digg) and provides a registry for assigned identifiers.

Version 1.8

Authentication Specifications

The specifications for user authentication are listed below.

SAML

Deployment Profile for the Swedish eID Framework

This is the main SAML specification for the Sweden Connect Framework. It defines a SAML profile including metadata, request and response processing, as well as extensions for signature services.

Version 1.8

Attribute Specification for the Swedish eID Framework

This document specifies a SAML attribute profile for the Sweden Connect Framework. The attribute profile defines attributes for use within the Sweden Connect federation, and a number of defined attribute sets that may be referenced by other documents as a means of specifying attribute release requirements.

Version 1.8

Entity Categories for the Swedish eID Framework

This specification contains the Entity Category definitions that are defined for the Sweden Connect Framework and that should be supported by Service Providers and Identity Providers that are part of the federation.

Version 1.9

eIDAS Constructed Attribute Specification for the Swedish eID Framework

This document provides specifications for constructed attributes.

The concept of constructed attributes is introduced in Swedish national authentication nodes (proxy nodes) delivering identity assertions to Swedish Service Providers based on user authentication with a foreign eID.

Version 1.2

Principal Selection in SAML Authentication Requests

This specification defines an element that may be included in the Extensions element of a SAML AuthnRequest where the requesting Service Provider can specify matching criteria that may be used by the Identity Provider to select the particular user that should be authenticated.

Version 1.0

User Message Extension in SAML Authentication Requests

This specification defines an element that may be included in the Extensions element of a SAML authentication request where the requesting Service Provider can specify a "user message" that is to be displayed for the user by the Identity Provider during the authentication phase.

Version 1.0

Implementation Profile for BankID Identity Providers within the Swedish eID Framework

SAML implementation profile for Identity Providers implementing BankID support.

Version 1.4

eIDAS Identity Binding

This informational document outlines the process for binding an eIDAS-notified electronic identity (eID) to an individual's personal identification number in the Swedish Population Register.

OpenID Connect

OpenID Connect Profile for Sweden Connect

This profile is an extension of The Swedish OpenID Connect Profile for the Sweden Connect identity federation.

The profile aims to establish a baseline level of security and to facilitate interoperability between Relying Parties and OpenID Providers within the Sweden Connect identity federation.

Version 1.0

OpenID Connect Claims and Scopes Specification for Sweden Connect

This specification extends the Claims and Scopes Specification for the Swedish OpenID Connect Profile with OpenID Connect claims and scopes for usage within the Sweden Connect federation.

Version 1.0

OpenID Connect Metadata Requirements

This specification defines the metadata requirements for Relying Parties and OpenID Providers participating in the Sweden Connect OpenID Connect federation. The metadata is published in Entity Configurations according to OpenID Federation 1.0.

The requirements apply to the resolved metadata, meaning the metadata that results once the Trust Chain of an Entity has been applied to the declarations the Entity makes about itself.

Version 1.0

Signature Specifications

The specifications for Federated Central Signing Services are listed below.

Implementation Profile for using OASIS DSS in Central Signing Services

This document specifies an implementation profile for exchange of sign requests and responses using the OASIS DSS protocol, enhanced by the DSS Extensions for Federated Central Signing Services.

Version 1.6

Certificate Profile for Certificates Issued by Central Signing Services

This document specifies a certificate profile for certificates issued by a signature service.

Version 1.2

DSS Extension for Federated Central Signing Services

This specification defines elements that extends the <dss:SignRequest> and <dss:SignResponse> elements of the OASIS DSS protocol.

Version 1.5

Signature Activation Protocol for Federated Signing

This document specifies a Signature Activation Protocol (SAP) and its data elements for implementation of Sole Control Assurance Level 2 (SCAL2) according to the European standard prEN 419241, Trustworthy Systems Supporting Server Signing.

Version 1.2

Signature Validation Tokens

The "Signature Validation Token" draft specifications have been replaced by IETF drafts. See https://github.com/swedenconnect/IETF-SVT.

The Sweden Connect Federation

Common federation rules:

For participants of the Sweden Connect SAML federation, the normative specification Tekniska anslutningsregler för Sweden Connect-federationen should also be read. Currently only in Swedish.

The following documents apply when joining the Sweden Connect Federation for OpenID Connect (OpenID Federation):

GitHub

The specifications for the Sweden Connect Framework are stored on GitHub at https://github.com/swedenconnect/technical-framework. The master branch is where new development is performed, and each official release has its own branch.

Older versions

Feedback and Questions

If you have feedback or questions regarding the Technical Framework, open an Issue.

Copyright © The Swedish Agency for Digital Government (Digg), 2015-2026. All Rights Reserved.