Digital Identity & VNeID
A model that separates authentication/SSO from QR-based data sharing and consent. Unverified endpoints, scopes and payloads are not presented as production contracts.
Trusted Care → RAR / VNeID → Session
Capability-level flow; callback and mapping specifics remain integration dependent.
QR at reception, kiosk or onboarding
Used where the applicable RAR/VNeID specification supports data-sharing transactions; unverified technical parameters are marked integration dependent.
Who requests what, for which purpose and duration
RAR QR ShareInfo transaction and consent
RS-HUB connects Trusted Care to RAR/VNeID for distinct purposes
Three journeys remain separate: SSO authentication, QR-based information sharing, and remote signing only where a verified integration applies.
Trusted Care → RS-HUB → RAR/VNeID → authentication → account mapping → session → audit trail.
Trusted Care or kiosk → RS-HUB → QR creation → citizen approval or decline in VNeID → status → result → consent evidence.
Only where an approved integration applies; identity, consent, authorization and signature remain separate controls.