Mobile-ID Digital TrustISO/IEC 27001:2022 · SIS351224I008Published certification scope
View evidence

DEVELOPER

OAuth 2.1 / OIDC Client

Use Authorization Code + PKCE for user-facing clients, confidential credentials only where a protected backend exists, narrow scopes and controlled token lifecycle.

01 / CONCEPT

Integration contract

01

Client types

Public clients cannot safely hold a secret; confidential clients protect credentials in a backend or workload boundary.

02

Authorization flow

Authorization Code + PKCE with state; OIDC clients validate issuer, audience and nonce where applicable.

03

Token lifecycle

Keep access tokens short-lived, protect refresh tokens, revoke on compromise and never log bearer tokens.

04

Redirect URI

Match registered redirect URIs exactly in production; avoid open redirects and wildcard hosts.

02 / WORKFLOW

From sandbox to evidence

  1. 01Build authorization request with PKCE
  2. 02Authenticate user and evaluate consent/policy
  3. 03Exchange code at token endpoint
  4. 04Call API with approved scope
  5. 05Refresh only within policy
  6. 06Revoke/logout and clear local session
  7. 07Handle invalid_grant / insufficient_scope deterministically
03 / SECURITY & PRODUCTION

Production is an evidence decision

OAuth safety depends on the registered client type, exact redirects, PKCE/nonce handling, token storage, revocation and scope policy for the deployed application.

Screen detail

Search all Trusted Care
TRUSTED CARE

09 applications

Governed application access; no unverified login URL is invented.

Patient AppPatients & familiesRequest accessDoctor PortalDoctors & cliniciansRequest accessNurse & Care CoordinatorNurses & care coordinatorsRequest accessAdmin PortalOrganization administratorsRequest accessHealth KioskReception & service pointsRequest accessPharmacy PortalPharmacistsRequest accessLaboratory PortalLaboratory teamsRequest accessCareGiver AppCaregivers & familiesRequest accessTelehealthPatients & care teamsRequest access