curl --request POST \
--url https://verification.didit.me/v3/id-verification/wallets/vipps/ \
--header 'x-api-key: YOUR_API_KEY' \
--header 'Idempotency-Key: your-unique-attempt-key' \
--header 'Content-Type: application/json' \
--data '{
"country": "NOR",
"vendor_data": "your-customer-reference",
"metadata": {
"reference": "example"
},
"return_url": "https://app.example.com/identity/complete"
}'import os
import requests
headers = {
"x-api-key": os.environ["DIDIT_API_KEY"],
"Idempotency-Key": "your-unique-attempt-key"
}
payload = {'country': 'NOR',
'vendor_data': 'your-customer-reference',
'metadata': {'reference': 'example'},
'return_url': 'https://app.example.com/identity/complete'}
response = requests.post(
"https://verification.didit.me/v3/id-verification/wallets/vipps/",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
const options = {
method: 'POST',
headers: {'x-api-key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
country: 'NOR',
vendor_data: 'your-customer-reference',
metadata: {reference: 'example'},
return_url: 'https://app.example.com/identity/complete'
})
};
fetch('https://verification.didit.me/v3/id-verification/wallets/vipps/', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://verification.didit.me/v3/id-verification/wallets/vipps/",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'country' => 'NOR',
'vendor_data' => 'your-customer-reference',
'metadata' => [
'reference' => 'example'
],
'return_url' => 'https://app.example.com/identity/complete'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://verification.didit.me/v3/id-verification/wallets/vipps/"
payload := strings.NewReader("{\n \"country\": \"NOR\",\n \"vendor_data\": \"your-customer-reference\",\n \"metadata\": {\n \"reference\": \"example\"\n },\n \"return_url\": \"https://app.example.com/identity/complete\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("x-api-key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://verification.didit.me/v3/id-verification/wallets/vipps/")
.header("x-api-key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"country\": \"NOR\",\n \"vendor_data\": \"your-customer-reference\",\n \"metadata\": {\n \"reference\": \"example\"\n },\n \"return_url\": \"https://app.example.com/identity/complete\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://verification.didit.me/v3/id-verification/wallets/vipps/")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["x-api-key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"country\": \"NOR\",\n \"vendor_data\": \"your-customer-reference\",\n \"metadata\": {\n \"reference\": \"example\"\n },\n \"return_url\": \"https://app.example.com/identity/complete\"\n}"
response = http.request(request)
puts response.read_body{
"request_id": "00000000-0000-4000-8000-000000000001",
"wallet_verification": {
"wallet": {
"id": "vipps",
"name": "Vipps",
"issuing_authority": "Vipps MobilePay / BankID NO"
},
"country": "NOR",
"status": "Not Finished",
"outcome": "pending",
"error": null,
"interaction": "redirect",
"simulated": false,
"expires_at": "2026-01-01T10:10:00Z",
"next_action": {
"type": "redirect",
"url": "https://wallet.example.com/authorize"
},
"identity": null,
"attributes": null,
"level_of_assurance": null,
"verified_at": null,
"signature_valid": null,
"credential_type": "person_identification"
},
"vendor_data": "your-customer-reference",
"metadata": {
"reference": "example"
},
"created_at": "2026-01-01T10:00:00Z"
}{
"error": "<string>",
"detail": "<string>"
}{
"detail": "Forbidden - User doesn't have permission"
}{
"error": "<string>",
"detail": "<string>"
}{
"error": "<string>",
"detail": "<string>"
}{
"error": "<string>",
"detail": "<string>"
}Vipps Plus
Start Vipps Plus identity verification through the standalone API, without a workflow.
curl --request POST \
--url https://verification.didit.me/v3/id-verification/wallets/vipps/ \
--header 'x-api-key: YOUR_API_KEY' \
--header 'Idempotency-Key: your-unique-attempt-key' \
--header 'Content-Type: application/json' \
--data '{
"country": "NOR",
"vendor_data": "your-customer-reference",
"metadata": {
"reference": "example"
},
"return_url": "https://app.example.com/identity/complete"
}'import os
import requests
headers = {
"x-api-key": os.environ["DIDIT_API_KEY"],
"Idempotency-Key": "your-unique-attempt-key"
}
payload = {'country': 'NOR',
'vendor_data': 'your-customer-reference',
'metadata': {'reference': 'example'},
'return_url': 'https://app.example.com/identity/complete'}
response = requests.post(
"https://verification.didit.me/v3/id-verification/wallets/vipps/",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
const options = {
method: 'POST',
headers: {'x-api-key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
country: 'NOR',
vendor_data: 'your-customer-reference',
metadata: {reference: 'example'},
return_url: 'https://app.example.com/identity/complete'
})
};
fetch('https://verification.didit.me/v3/id-verification/wallets/vipps/', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://verification.didit.me/v3/id-verification/wallets/vipps/",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'country' => 'NOR',
'vendor_data' => 'your-customer-reference',
'metadata' => [
'reference' => 'example'
],
'return_url' => 'https://app.example.com/identity/complete'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://verification.didit.me/v3/id-verification/wallets/vipps/"
payload := strings.NewReader("{\n \"country\": \"NOR\",\n \"vendor_data\": \"your-customer-reference\",\n \"metadata\": {\n \"reference\": \"example\"\n },\n \"return_url\": \"https://app.example.com/identity/complete\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("x-api-key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://verification.didit.me/v3/id-verification/wallets/vipps/")
.header("x-api-key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"country\": \"NOR\",\n \"vendor_data\": \"your-customer-reference\",\n \"metadata\": {\n \"reference\": \"example\"\n },\n \"return_url\": \"https://app.example.com/identity/complete\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://verification.didit.me/v3/id-verification/wallets/vipps/")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["x-api-key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"country\": \"NOR\",\n \"vendor_data\": \"your-customer-reference\",\n \"metadata\": {\n \"reference\": \"example\"\n },\n \"return_url\": \"https://app.example.com/identity/complete\"\n}"
response = http.request(request)
puts response.read_body{
"request_id": "00000000-0000-4000-8000-000000000001",
"wallet_verification": {
"wallet": {
"id": "vipps",
"name": "Vipps",
"issuing_authority": "Vipps MobilePay / BankID NO"
},
"country": "NOR",
"status": "Not Finished",
"outcome": "pending",
"error": null,
"interaction": "redirect",
"simulated": false,
"expires_at": "2026-01-01T10:10:00Z",
"next_action": {
"type": "redirect",
"url": "https://wallet.example.com/authorize"
},
"identity": null,
"attributes": null,
"level_of_assurance": null,
"verified_at": null,
"signature_valid": null,
"credential_type": "person_identification"
},
"vendor_data": "your-customer-reference",
"metadata": {
"reference": "example"
},
"created_at": "2026-01-01T10:00:00Z"
}{
"error": "<string>",
"detail": "<string>"
}{
"detail": "Forbidden - User doesn't have permission"
}{
"error": "<string>",
"detail": "<string>"
}{
"error": "<string>",
"detail": "<string>"
}{
"error": "<string>",
"detail": "<string>"
}workflow_id.
The start response describes the next authentication action; it is not an approved identity result.
Coverage and activation
| Property | Value |
|---|---|
| Wallet | Vipps Plus |
| Wallet ID | vipps |
| Countries | |
| Production wallet activation | ⏳ Coming soon |
| Published wallet price | $0.25 per completed verification |
What the person does
Follow the next action returned by the start request. The wallet’s authentication experience determines whether the person uses a browser, another device or an app.Receive the result
Follow the Digital ID wallet API guide to track the verification and retrieve its result. Treat only a completed, verified result as proof that the wallet authenticated the person. Returned identity attributes vary by wallet; do not assume an address, portrait or every requested attribute is present.Related
Authorizations
Your application's API key, from Developers -> API keys in the Business Console. The primary key has full access. A named key can be scoped: none, read or write per resource, limited to some workflows or to approved sessions, to a list of IP addresses, and to an expiry date. 401 means the key is missing, wrong, revoked or expired; 403 means the key has no access to this resource or action, or the request came from an address outside its IP list; 404 on a session route means the session is outside the key's workflows or statuses. A key without media access receives image, video and PDF URLs as null, and a key without sessions write receives session links and tokens as null. See https://docs.didit.me/console/api-keys.
Headers
Optional retry-safety key (max 255 characters). Retrying with the same key, wallet and body returns the original verification without starting a second sign-in; the same key with another wallet or body returns 409 idempotency_key_reused.
Body
Start a Vipps verification (NOR).
https URL the user's browser returns to after the wallet, with request_id and result appended. Its host must be registered in the application's allowed_return_hosts (or be its white-label domain). Never trust result on its own: read the outcome with GET .../verifications/{request_id}/ or the webhook.
1 - 2048Your own reference for this verification (e.g. your user id). Returned in results and webhooks.
Optional JSON object stored with the verification and returned in results and webhooks.
Show child attributes
Show child attributes
Sandbox applications only: the simulated outcome - 'wallet_cancelled', 'wallet_timeout' or 'wallet_provider_error'; any other scenario (or none) verifies. Rejected on live applications. The full catalog is available at GET /v1/sandbox/scenarios/.
1ISO 3166-1 alpha-3 country of the Vipps identity. Defaults to NOR, the only country it serves.
NOR- NOR
NOR same_device when the user signs in on the device showing your page, cross_device when they use another one (e.g. BankID's QR code).
same_device- same_devicecross_device- cross_device
same_device, cross_device Response
One standalone wallet verification, as every wallet endpoint answers it.