OAuth2.0 configuration

Basic parameters for OAuth 2.0 Service Configuration

ParameterDescription
Integration platform domain name HostURL for authentication and authorization requestsTest environment: eidas-demo.eparaksts.lvProduction: eidas.eparaksts.lv
Client_IDService provider ID generated by LVRTC
Client_secretService provider Access Password generated by LVRTC
Scopes
  • urn:lvrtc:fpeil:aa* – For electronic identification
  • urn:lvrtc:fpeil:aa:age_18* - For electronic identification with age parameter (Restricted access, contact LVRTC for more information) Available ranges - age_14 / age_16 / age_18 / age_19 / age_20 / age_21 / age_24 / age_25
  • urn:safelayer:eidas:sign:identity:profile* - to get signing identity
  • urn:safelayer:eidas:sign:identity:use:server* - to request signature from the HSM.
Authorization Endpointhttps://{Host}/trustedx-authserver/oauth/{as}?response_type=code&
client_id=...&
state=...&
redirect_uri=...&
scope=...&
prompt=...&
acr_values=...&
ui_locales=...
Access Token Endpointhttps://{Host}/trustedx-authserver/oauth/{as}/token

Important! Refresh token functionality is not supported, the expired session must be restored using the full authentication process.
User Info Endpointhttps://{Host}/trustedx-resources/openid/v1/users/me
\{as}
  • lvrtc-eipsign-as* (default authorization server for authentification and access to signing services)
  • lvrtc-eips-as*_ (for identification with age parameter only. Restricted access, contact LVRTC for more information.)


Did this page help you?