GET https://connect.hopae.com/v2/auth?client_id=xhdh8a13&redirect_uri=https%3A%2F%2Fapp.example.com%2Fcallback&response_type=code&scope=openid%20hopae&state=rf9Xy1&nonce=n-0S6_WzA2Mj&workflow_id=wf_01J8XJ4Q2R7TPX9K
HTTP/1.1 302 Found
Location: https://app.example.com/callback?code=SplxlOBeZQQYbYS6WxSbIA&state=rf9Xy1&iss=https%3A%2F%2Fconnect.hopae.com
OIDC
Start Authorization
Initiates the OIDC Authorization Code flow. Front-channel redirect. No Authorization header.
GET
/
auth
GET https://connect.hopae.com/v2/auth?client_id=xhdh8a13&redirect_uri=https%3A%2F%2Fapp.example.com%2Fcallback&response_type=code&scope=openid%20hopae&state=rf9Xy1&nonce=n-0S6_WzA2Mj&workflow_id=wf_01J8XJ4Q2R7TPX9K
HTTP/1.1 302 Found
Location: https://app.example.com/callback?code=SplxlOBeZQQYbYS6WxSbIA&state=rf9Xy1&iss=https%3A%2F%2Fconnect.hopae.com
Start a verification by redirecting the user’s browser to the shared
/v2/auth endpoint with your app’s client_id. Hopae hosts the verification UI, runs the eID flow, and returns the user to your redirect_uri with an authorization code.
Query Parameters
string
required
Your App ID.
string
required
Exact match to a redirect URI registered for this app (Console → Developers → API Settings → Redirect URL Allowlist). Saving the app’s allowlist takes effect immediately. See Apps & Environments.
string
default:"code"
required
Must be
code.string
default:"openid hopae"
required
Space-delimited scopes. Include
openid and hopae (or the equivalent idv). Without hopae/idv, the userinfo response contains no user, provenance, match, or missing_claims.string
Opaque value echoed back on the redirect. Use it for CSRF protection.
string
Bound into the ID token. Recommended for browser-based clients.
string
login forces a fresh verification. Hopae never reuses a previous verification, so this is mainly for client libraries that expect it.string
The workflow to run (Console → Workflow → copy the workflow ID). Defaults to the app’s default workflow. The workflow decides which connections are offered and which claims are requested. An unknown explicit workflow produces
invalid_request. An app with no workflow shows a hosted error page (WORKFLOW_NOT_CONFIGURED) and does not redirect back.string
Filter enabled connections by a minimum supported Level of Assurance:
urn:hopae:loa:{level} (1 to 5). Hopae records the achieved level in acr / hopae_loa. If it is lower than requested, the verification is still finished, and userinfo requested with provenance=true carries provenance._metadata.error.code = "loa_insufficient" so you can decide. A filter leaving no eligible connection finishes with invalid_request. The v1 urn:hopae:id:{providerId} token is ignored on /v2: it neither narrows nor rejects. Use the ui_* pre-selection hints instead. See Level of Assurance.string
Pre-select a connection so the user skips country and credential selection. Use the catalog connection id (for example
smart-id) of a connection enabled in the workflow. An id that is not enabled simply means no pre-selection. Replaces the v1 ui_provider parameter. ui_connection_instance_id with the instance id (conn_…) is also accepted.string
Catalog provider id. Pre-selects its single enabled connection. If none or several match, the hosted selection screen remains visible. Unlike REST creation, ambiguity does not return a 400.
string
Use with
ui_provider_id to narrow to one credential. Hint precedence is instance → connection → provider. An unmatched connection hint does not fall through to the provider hint.string
Pre-select the country step (ISO 3166-1 alpha-2).
boolean
true skips the hosted intro screen and lands on the selection step.boolean
true hides the back button in the hosted UI.boolean
true runs the verification but blocks token and userinfo issuance (403 AUTH_DATA_PROTECTED). Use it when you only need the result recorded on Hopae’s side.The v1 parameters
ui_provider, ui_auth_flow, ui_hide_header, and ui_need_consent have no effect on v2. The hosted flow always runs country → credential → provider.Behavior
- On success, responds with
302 Foundto yourredirect_uriwithcodeandstatequery params. The code is single-use and expires after 5 minutes. - On failure or cancellation, redirects with
error=access_deniedand anerror_description, plusstateif provided. A missing or unregisteredredirect_uricannot be redirected and shows a hosted error page instead.
Examples
GET https://connect.hopae.com/v2/auth?client_id=xhdh8a13&redirect_uri=https%3A%2F%2Fapp.example.com%2Fcallback&response_type=code&scope=openid%20hopae&state=rf9Xy1&nonce=n-0S6_WzA2Mj&workflow_id=wf_01J8XJ4Q2R7TPX9K
HTTP/1.1 302 Found
Location: https://app.example.com/callback?code=SplxlOBeZQQYbYS6WxSbIA&state=rf9Xy1&iss=https%3A%2F%2Fconnect.hopae.com
HTTP/1.1 302 Found
Location: https://app.example.com/callback?error=access_denied&error_description=Authentication%20cancelled%20by%20user&state=rf9Xy1
Authorizations
Basic authentication header of the form Basic <encoded-value>, where <encoded-value> is the base64-encoded string username:password.
Query Parameters
Your App ID.
A redirect URI registered for the app.
Must be code.
Available options:
code Include openid and hopae.
Echoed back on the redirect. Use it for CSRF protection.
Bound into the ID token.
Workflow to run. Defaults to the app's default workflow.
Minimum Level of Assurance, urn:hopae:loa:{1-5}.
Pre-select a connection by catalog id, for example smart-id.
Pre-select the country (ISO 3166-1 alpha-2).
Skip the intro screen.
Hide the back button.
Response
302
Redirect to redirect_uri with code and state, or with error=access_denied.

