Skip to main content
POST
cURL
Start BankID Norway verification from your backend using your application API key. You do not need a workflow or a workflow_id. The start response describes the next authentication action; it is not an approved identity result.

Coverage and activation

Wallet activation is separate from API deployment and your application’s eligibility. A documented endpoint does not activate a wallet that is marked Coming soon. For current published rates, see digital ID wallet pricing.

What the person does

Follow the next action returned by the start request. The wallet’s authentication experience determines whether the person uses a browser, another device or an app.

Receive the result

Follow the Digital ID wallet API guide to track the verification and retrieve its result. Treat only a completed, verified result as proof that the wallet authenticated the person. Returned identity attributes vary by wallet; do not assume an address, portrait or every requested attribute is present.

Authorizations

x-api-key
string
header
required

Your application's API key, from Developers -> API keys in the Business Console. The primary key has full access. A named key can be scoped: none, read or write per resource, limited to some workflows or to approved sessions, to a list of IP addresses, and to an expiry date. 401 means the key is missing, wrong, revoked or expired; 403 means the key has no access to this resource or action, or the request came from an address outside its IP list; 404 on a session route means the session is outside the key's workflows or statuses. A key without media access receives image, video and PDF URLs as null, and a key without sessions write receives session links and tokens as null. See https://docs.didit.me/console/api-keys.

Headers

Idempotency-Key
string

Optional retry-safety key (max 255 characters). Retrying with the same key, wallet and body returns the original verification without starting a second sign-in; the same key with another wallet or body returns 409 idempotency_key_reused.

Body

Start a BankID verification (NOR).

return_url
string<uri>
required

https URL the user's browser returns to after the wallet, with request_id and result appended. Its host must be registered in the application's allowed_return_hosts (or be its white-label domain). Never trust result on its own: read the outcome with GET .../verifications/{request_id}/ or the webhook.

Required string length: 1 - 2048
vendor_data
string | null

Your own reference for this verification (e.g. your user id). Returned in results and webhooks.

metadata
object | null

Optional JSON object stored with the verification and returned in results and webhooks.

sandbox_scenario
string

Sandbox applications only: the simulated outcome - 'wallet_cancelled', 'wallet_timeout' or 'wallet_provider_error'; any other scenario (or none) verifies. Rejected on live applications. The full catalog is available at GET /v1/sandbox/scenarios/.

Minimum string length: 1
country
enum<string>
default:NOR

ISO 3166-1 alpha-3 country of the BankID identity. Defaults to NOR, the only country it serves.

  • NOR - NOR
Available options:
NOR
device
enum<string>
default:same_device

same_device when the user signs in on the device showing your page, cross_device when they use another one (e.g. BankID's QR code).

  • same_device - same_device
  • cross_device - cross_device
Available options:
same_device,
cross_device

Response

One standalone wallet verification, as every wallet endpoint answers it.

request_id
string<uuid>
required
wallet_verification
object
required
vendor_data
string | null
required
metadata
object | null
required

The metadata object sent at start, or null.

created_at
string<date-time>
required