Skip to main content

Overview

Level of Assurance (LoA) indicates the confidence level of an identity verification. Based on the OIDC acr (Authentication Context Class Reference) claim, Hopae returns:
  • hopae_loa: integer level from 1 to 5 for programmatic checks
  • hopae_loa_label: human-readable label (e.g., substantial)
  • acr: the urn:hopae:loa:{level} URN, present when the provider asserted the level explicitly

LoA levels

Every connection advertises the levels its credential can reach as credential.loa[] in Get Connections and in the Console’s Connections table.

Require a minimum LoA

When no level is requested, the connection’s minimum supported LoA applies.

When the achieved LoA is lower than requested

This can occur when the user chooses a weaker authentication method than expected, or the provider downgrades the session through a fallback mechanism. The verification is still finished and the result is returned, so you can decide what to do. REST userinfo carries the achieved level in hopae_loa and a top-level error. In OIDC, check the achieved level and provenance._metadata.error. The top-level error is not included in the OIDC claims whitelist:
Over REST, Get Verification Status reports status: "failed" with error.code: "loa_insufficient". The userinfo endpoint still serves this one failed state.

Response example

LoA fields are included in both the ID token and the userinfo response:
Always validate hopae_loa server-side before granting access to sensitive operations.

See also