Overview
Level of Assurance (LoA) indicates the confidence level of an identity verification. Based on the OIDCacr (Authentication Context Class Reference) claim, Hopae returns:
hopae_loa: integer level from 1 to 5 for programmatic checkshopae_loa_label: human-readable label (e.g.,substantial)acr: theurn:hopae:loa:{level}URN, present when the provider asserted the level explicitly
LoA levels
Every connection advertises the levels its credential can reach as
credential.loa[] in Get Connections and in the Console’s Connections table.
Require a minimum LoA
- Workflow (recommended)
- OIDC
- REST API
Add a The userinfo response then carries
check-min-loa node after the verification step so the requirement travels with the workflow and applies to both OIDC and REST:metLoa so you can branch on it. See Workflow Nodes.When the achieved LoA is lower than requested
This can occur when the user chooses a weaker authentication method than expected, or the provider downgrades the session through a fallback mechanism. The verification is still finished and the result is returned, so you can decide what to do. REST userinfo carries the achieved level inhopae_loa and a top-level error. In OIDC, check the achieved level and provenance._metadata.error. The top-level error is not included in the OIDC claims whitelist:
status: "failed" with error.code: "loa_insufficient". The userinfo endpoint still serves this one failed state.
Response example
LoA fields are included in both the ID token and the userinfo response:See also
- OIDC Integration Guide:
acr_valuesparameter usage - Workflow Nodes: the
check-min-loanode - Get Connections:
credential.loa[]per connection

