Sign In With BankID via OpenID Connect
Offer Swedish BankID (and other eIDs from the same broker) through OpenID Connect in Skillhabit.
What This Is For
To offer Swedish BankID in Skillhabit, connect an OpenID Connect broker (or your own identity provider that already fronts BankID). People complete BankID with the broker; Skillhabit treats it like any other OpenID Connect login.
Your organization (with the broker) owns the BankID agreement and certificate. Skillhabit is not the BankID relying party in this setup.
The same pattern works for other electronic identities the broker supports—not only BankID. Many brokers also offer Norwegian BankID, Danish MitID, Finnish Trust Network / FTN, Freja eID, and similar methods. Enable the method in the broker, then point Skillhabit’s OpenID Connect login at that issuer the same way. Claim names and button text differ by method; the Skillhabit configuration stays OpenID Connect.
Who This Is For
Workspace administrators, often together with your identity provider or BankID broker contact.
Before You Start
- Your workspace has the SSO capability (required for OpenID Connect). Ask Skillhabit if OpenID Connect is missing under Authentication Methods.
- You have (or will create) an account with a BankID-capable OpenID Connect provider—for example Criipto / Idura, Signicat, Nets / E-Ident, or your company IdP if it already offers BankID.
- Decide how new people get Skillhabit accounts: pre-create them in Users & Groups (or via provisioning), or turn on auto-create under OpenID Connect More options.
Skillhabit matches OpenID Connect users by the stored OpenID identity, then by email. Your broker must release at least one of email, preferred_username, or upn so sign-in can complete. Prefer a real email claim when people should receive Skillhabit mail. Details: SSO and Email Addresses.
Personnummer (and other fields) are stored with Attribute mappings after sign-in—they are not the primary login match key. See User Provisioning → Map Directory Attributes.
When There Is No Email
BankID does not always provide a mailbox. When Skillhabit cannot use a real email address from the broker claims, it still creates (or updates) the account with a unique placeholder address on @noemail.skillhabit.com.
- Skillhabit never sends system email to that domain (no login codes, magic links, assignments, or other notifications to the placeholder).
- The person can still sign in with BankID / OpenID Connect.
- After they are signed in, they can change to a real email on their own profile (or an administrator can update it in Users & Groups). From then on, Skillhabit can deliver mail to that address like any other user.
More detail: SSO and Email Addresses and Bulk Actions and Email.
Steps
1. Set Up the Broker (or Your IdP)
In the broker (or IdP) admin console:
- Enable Swedish BankID for the application.
- Create an OpenID Connect application suitable for a browser sign-in (SPA / public client is typical).
- Copy the issuer URL (the base that serves OpenID discovery—not including
/.well-known/openid-configuration). - Copy the client ID.
- Register the redirect URI you will copy from Skillhabit in the next step (pattern:
https://{your-workspace-host}/auth/verify/open-id-connect). - Ensure tokens include a stable subject (
sub), an email-capable claim, and—if you want it in Skillhabit—your personnummer / SSN claim (exact claim names are broker-specific). - Finish production BankID certificate onboarding with the broker when you leave their test environment.
Commercial fees and timelines are between you and the broker (or bank). Skillhabit does not install BankID keystores for this path.
2. Add OpenID Connect in Skillhabit
- Open Configure → Connections → Authentication Methods.
- Add OpenID Connect.
- Set:
- Issuer URI — broker issuer (as shown in Configure; follow on-screen hints)
- Client ID — from the broker
- Button text — for example
BankIDorLogga in med BankID - Under More options, turn on automatic account creation only if new users should be created on first BankID sign-in
- Copy the Redirect URI from the dialog into the broker application.
- Save so the method is enabled.
BankID is configured as OpenID Connect—use the button text so people recognize it as BankID on the login page.
3. Map Claims (Optional but Common)
To store personnummer (or other broker fields) on the user:
- Open Configure → Connections → Attribute mappings.
- Add a mapping with source OpenID Connect claim.
- Set the source path to the claim name your broker documents (examples vary:
ssn,se_ssn, or a namespaced URI). - Map it onto the Skillhabit attribute you use for personal identity number (or another attribute).
- Choose Match existing only or Create if missing for list attributes as needed.
Release the claim from the broker first if it is not in the token by default—same idea as Add Attributes to IdP Tokens and Profiles.
4. Test
- Open the workspace login page and confirm the OpenID Connect / BankID button appears.
- Complete BankID in the broker’s test environment.
- Confirm the person is signed in and that mapped attributes appear on their profile when you configured mappings.
- Repeat against the broker’s production issuer after their production certificate is live.
What People See
- On the Skillhabit login page: your OpenID Connect button (button text you chose).
- During sign-in: the broker’s BankID experience (QR / same device, depending on the broker).
- In the BankID app: your organization’s relying-party display name from the broker certificate—not “Skillhabit” as the BankID merchant, unless you arranged that separately.
Related
- SSO and Authentication — OpenID Connect and other login methods
- User Provisioning — attribute mappings
- SSO and Email Addresses — email claims and
@noemail.skillhabit.com - Add Attributes to IdP Tokens and Profiles
- Introduction