curl -X GET 'https://connect.hopae.com/v2/userinfo?provenance=true&missing_claims=true' \
-H 'Authorization: Bearer eyJhbGciOiJSUzI1NiIs...'
{
"user": {
"given_name": "OK",
"family_name": "TESTNUMBER",
"name": "OK TESTNUMBER",
"birthdate": "1905-04-04",
"nationality": "LT",
"source_id": "PNOLT-40504040001"
},
"missing_claims": [
"email"
],
"acr": "urn:hopae:loa:4",
"hopae_loa": 4,
"hopae_loa_label": "high",
"verification_model": "disclosure",
"provenance": {
"presentation": {
"credentials": [
{
"claims": {
"documentNumber": "PNOLT-40504040001-MOCK-Q",
"birthdate": "1905-04-04",
"countryCode": "LT",
"givenName": "OK",
"surname": "TESTNUMBER"
},
"evidence": {
"token": {
"id_token": "<BASE64_ID_TOKEN>",
"expires_at": "2026-09-03T10:19:52.000Z",
"access_token": "<OPAQUE_ACCESS_TOKEN>",
"token_type": "Bearer"
},
"names": "id_token;expires_at;access_token;token_type"
}
}
]
},
"_metadata": {
"verification_id": "019bc4f2-8a31-7c5e-9d02-4f7a1b3e60d8",
"verified_at": "2026-09-03T09:19:52.110Z",
"status": "completed",
"provider_id": "smart-id",
"connection_id": "smart-id",
"credential_id": "smart-id",
"connection_instance_id": "conn_01J8XK2P4M9QR3TV"
}
},
"sub": "019bc4f2-8a31-7c5e-9d02-4f7a1b3e60d8"
}
{
"sub": "019bc4f2-8a31-7c5e-9d02-4f7a1b3e60d8",
"acr": "urn:hopae:loa:4",
"hopae_loa": 4,
"hopae_loa_label": "high",
"verification_model": "disclosure"
}
UserInfo
Returns the verified claims and match outcome, and on request the provenance and missing claims. Requires a valid Bearer access token.
curl -X GET 'https://connect.hopae.com/v2/userinfo?provenance=true&missing_claims=true' \
-H 'Authorization: Bearer eyJhbGciOiJSUzI1NiIs...'
{
"user": {
"given_name": "OK",
"family_name": "TESTNUMBER",
"name": "OK TESTNUMBER",
"birthdate": "1905-04-04",
"nationality": "LT",
"source_id": "PNOLT-40504040001"
},
"missing_claims": [
"email"
],
"acr": "urn:hopae:loa:4",
"hopae_loa": 4,
"hopae_loa_label": "high",
"verification_model": "disclosure",
"provenance": {
"presentation": {
"credentials": [
{
"claims": {
"documentNumber": "PNOLT-40504040001-MOCK-Q",
"birthdate": "1905-04-04",
"countryCode": "LT",
"givenName": "OK",
"surname": "TESTNUMBER"
},
"evidence": {
"token": {
"id_token": "<BASE64_ID_TOKEN>",
"expires_at": "2026-09-03T10:19:52.000Z",
"access_token": "<OPAQUE_ACCESS_TOKEN>",
"token_type": "Bearer"
},
"names": "id_token;expires_at;access_token;token_type"
}
}
]
},
"_metadata": {
"verification_id": "019bc4f2-8a31-7c5e-9d02-4f7a1b3e60d8",
"verified_at": "2026-09-03T09:19:52.110Z",
"status": "completed",
"provider_id": "smart-id",
"connection_id": "smart-id",
"credential_id": "smart-id",
"connection_instance_id": "conn_01J8XK2P4M9QR3TV"
}
},
"sub": "019bc4f2-8a31-7c5e-9d02-4f7a1b3e60d8"
}
{
"sub": "019bc4f2-8a31-7c5e-9d02-4f7a1b3e60d8",
"acr": "urn:hopae:loa:4",
"hopae_loa": 4,
"hopae_loa_label": "high",
"verification_model": "disclosure"
}
/token. With hopae/idv, the response follows the same data model as Get Verification UserInfo on the REST API.
user, provenance, match, and missing_claims are only returned here, and only when the authorization request included the hopae (or idv) scope. With openid alone you receive sub, the available LoA fields, and verification_model. provenance (which carries the connection identity) and missing_claims are also opt-in per request: add provenance=true and missing_claims=true.Headers
/token (valid for 10 minutes).Query Parameters
Send these on the query string of aGET, or in the form body of a POST.
true (or 1) adds the provenance block, including the connection identity under provenance._metadata. Omitted or any other value leaves it out.true (or 1) adds the missing_claims list. Omitted or any other value leaves it out.Response
OIDC filters fields by the granted scopes. Unlike REST, it does not expose a top-levelerror. Assurance failures are available under provenance._metadata.error.
Connection identity appears only under provenance._metadata, never as top-level userinfo fields, so request provenance=true to read it. The IDs are snapshotted when the session is created.
user.source_id to recognise a returning person.substantial).smart-id).google-wallet-us-mdl). Opaque. Read provider_id and credential_id for its parts.us-mdl). Requires the hopae scope.conn_…). Requires the hopae scope.disclosure or match.missing_claims=true. Requested claims the source could not provide (including source_id when it could not be derived).match, the verified subset of the values you submitted. See Normalized User Data.matched, granularity, submitted_fields, details). Present only for match connections.provenance=true. What the source returned: presentation.credentials[] (each with the provider’s raw claims and, when issued, evidence) and _metadata. See Return Data Model.code: "loa_insufficient").metLoa, hasClaim, computed.*). Dynamic evaluate outputs that are not on the OIDC claims whitelist are only available through the REST userinfo endpoint.Example
curl -X GET 'https://connect.hopae.com/v2/userinfo?provenance=true&missing_claims=true' \
-H 'Authorization: Bearer eyJhbGciOiJSUzI1NiIs...'
{
"user": {
"given_name": "OK",
"family_name": "TESTNUMBER",
"name": "OK TESTNUMBER",
"birthdate": "1905-04-04",
"nationality": "LT",
"source_id": "PNOLT-40504040001"
},
"missing_claims": [
"email"
],
"acr": "urn:hopae:loa:4",
"hopae_loa": 4,
"hopae_loa_label": "high",
"verification_model": "disclosure",
"provenance": {
"presentation": {
"credentials": [
{
"claims": {
"documentNumber": "PNOLT-40504040001-MOCK-Q",
"birthdate": "1905-04-04",
"countryCode": "LT",
"givenName": "OK",
"surname": "TESTNUMBER"
},
"evidence": {
"token": {
"id_token": "<BASE64_ID_TOKEN>",
"expires_at": "2026-09-03T10:19:52.000Z",
"access_token": "<OPAQUE_ACCESS_TOKEN>",
"token_type": "Bearer"
},
"names": "id_token;expires_at;access_token;token_type"
}
}
]
},
"_metadata": {
"verification_id": "019bc4f2-8a31-7c5e-9d02-4f7a1b3e60d8",
"verified_at": "2026-09-03T09:19:52.110Z",
"status": "completed",
"provider_id": "smart-id",
"connection_id": "smart-id",
"credential_id": "smart-id",
"connection_instance_id": "conn_01J8XK2P4M9QR3TV"
}
},
"sub": "019bc4f2-8a31-7c5e-9d02-4f7a1b3e60d8"
}
{
"sub": "019bc4f2-8a31-7c5e-9d02-4f7a1b3e60d8",
"acr": "urn:hopae:loa:4",
"hopae_loa": 4,
"hopae_loa_label": "high",
"verification_model": "disclosure"
}
Errors
| HTTP | When |
|---|---|
401 invalid_token | The access token is missing, expired (10 minutes), or is not valid for this OIDC provider |
403 AUTH_DATA_PROTECTED | The authorization request used private_mode=true |
Authorizations
Access token from /token.
Query Parameters
true (or 1) adds the provenance block, including the connection identity under provenance._metadata. Off by default. On POST /userinfo, send it in the form body.
true (or 1) adds the missing_claims list. Off by default. On POST /userinfo, send it in the form body.
Response
Verified data.
Verified attributes, limited to the claims the workflow requested. source_id appears only when selected in the workflow and the source provided it. See Normalized User Data.
Returned only with missing_claims=true. Requested claims the source could not provide (may include source_id).
Authentication Context Class Reference.
Numeric Level of Assurance, 1 to 5.
LoA label.
disclosure or match.
disclosure, match Match outcome: matched, granularity, submitted_fields, details. Match connections only.
Present when the achieved LoA was lower than requested (loa_insufficient).
Returned only with provenance=true. What the source returned, plus verification metadata. See Return Data Model.
Show child attributes
Show child attributes
The verification id. New for every verification, so it is not a stable user identifier. Use user.source_id to recognise a returning person. Always the last key.

