ACR Values
Use parameter acr_values to filter what options you want to allow in UI for your own Application
/connect/authorize endpoint can be sent values to be sent in the OIDC parameter acr_values method to specify which bank(s) to use as sign-in option.
Separate each acr_value with a space.
Main ACR value: urn:idp:fbid
Example with method: &acr_values=urn:idp:fbid:method:fbid-saml.op.1 urn:idp:fbid:method:fbid-oidc.nordea.1 urn:idp:fbid:method:fbid-oidc.pop.1
Login option | acr_value |
Mobiilivarmenne | fbid-mpki.telia.1 |
Nordea | fbid-oidc.nordea.1 |
Danske Bank | fbid-oidc.danskebank.1 |
Handelsbanken | fbid-oidc.handelsbanken.1 |
Aktia | fbid-oidc.aktia.1 |
Ålandsbanken | fbid-oidc.alandsbanken.1 |
S-Pankki | fbid-oidc.spankki.1 |
OP | fbid-saml.op.1 (fbid-saml.op.fi in staging) |
Säästöpankki | fbid-oidc.sp.1 |
POP | fbid-oidc.pop.1 |
OmaSP | fbid-oidc.omasp.1 |
Hightrust ID | fbid-oidc.hightrust.id.1 |
Ensure you check “amr” values in the ID-token after Authentication
Do not trust the acr_values parameter coming from the client. It can be modified by an attacker.
Instead, you must validate the amr claims in the ID Token.
The ID Token is signed by the IdP, so the amr values reliably indicate how the user actually authenticated.
Test environment - Stage
Test users (all users are shared and used for testing purposes, do not link them to any accounts)
Provider | User | Credential | Description |
Mobiilivarmenne | Only live credentials normally apply | ||
Nordea | DEMOUSER1 DEMOUSER2 DEMOUSER3 DEMOUSER4 DEMOUSER5 (legal person) DEMOUSER6 (legal person) | 010200A9618 291292-918R 030883-925M 170677-924F - - | See Nordea's login page. Click the question mark |
Danske Bank | 78985110 / 4545 | 280453-111A | |
Handelsbanken | 11111111 / 123456 | 010100A001N | Use option "Avaintunnuskortilla / Med nyckelkodskortet" |
Aktia | Credentials are pre-filled | 010170-999R | See Aktia's login page |
Ålandsbanken | Only live credentials apply | ||
S-Pankki | 12345678 / 123456 / OTP: 1234 | ||
OP | Credentials are pre-filled | 070770-905D | |
Säästöpankki | 11111111 / 123456 | 010100A001N | Use option "Avaintunnuskortilla / Med nyckelkodskortet" |
POP | 11111111 / 123456 | 010100A001N | Use option "Avaintunnuskortilla / Med nyckelkodskortet" |
OmaSP | 11111111 / 123456 | 010100A001N | Use option "Käytä avaintunnuskorttia" |