BankID API in Sweden: direct relying party or broker, a full guide
How a business connects to the BankID API in Sweden: direct via a bank or through a broker, what a sign-in returns, its legal standing for AML and gambling, limits and the document fallback.

In short
The BankID API lets a business identify a Swedish user, or collect a signature, through the BankID app. 8.7 million people used BankID in 2025.[1] You reach the API in one of two ways: buy the service from a bank and integrate it as a direct relying party, or go through a reseller that has already done the integration.[4]
- A sign-in returns the 12-digit personnummer and the name, signed. No address, no portrait.[6]
- BankID sits inside the Swedish eID scheme (notified at Substantial and High), and DIGG lists BankID at Substantial. Prices are not published.[4][10][11]
BankID is Sweden's electronic identification (eID): a private app issued by the banks under common rules[3] and approved by the state's digital agency DIGG.[11] For a business it is the default way to know who a Swedish customer is, with a signed answer instead of a photo of a card.
BankID Sweden at a glance
BankID Sweden
Sweden's bank-issued electronic identification
How many people use BankID
Source: BankID in numbers, figures for 2025.[1]
Use grew from 4.1 billion transactions in 2019 to 7.9 billion in 2025.[1]
| Sector | Share of BankID use, 2025 |
|---|---|
| Bank and finance | 50% |
| Other private services | 27% |
| Mobile payments | 17% |
| Public sector | 6% |
BankID in numbers.[1]
- September 2002FoundedFinansiell ID-Teknik BID is set up.
- June 2011Mobile appMobile BankID launches.
- 14 December 2020NotifiedThe Swedish eID scheme, with BankID, is notified under eIDAS.
- 17 August 2026Face checkFacial recognition step-up becomes available.
- 1 December 2026SverigeIDThe state e-ID opens alongside BankID.
From company founding to the state e-ID.[2][10][7][17]
What the user sees
On a phone, the BankID app opens on the same device. On a computer, the user scans a QR code with the app.[6] According to research on BankID's flow, the user then confirms with a security code or biometrics; BankID's collect reference confirms the code through its error codes.[6]
Choose how to verify
Sign in with the electronic ID you already use.
BankID
Use an ID document instead
1The user picks BankID in your sign-up.
On a computer: scan with BankID
Open the BankID app on your phone and scan this code.
2Computer only: a QR code hands the order to the phone. A phone skips this screen.[6]
Identify yourself
Check who is asking, then enter your security code.
3The user confirms in the app (security code or biometrics, according to research on BankID's flow).[6]
Extra check
Tap your passport or ID card, or take a selfie.
4Optional step-up the service can ask for.[7]
You are verified
- NameShared
- PersonnummerShared
- AddressNot shared
- PortraitNot shared
5Back in your service with the signed result.[6]
Screen 4 is optional: an NFC tap of a passport or ID card, or, since 17 August 2026, facial recognition against the chip photo of a Swedish passport or ID card.[6][7] Driving licences have no chip, so they cannot be used for this step-up.[7]
Video pending: flow-qr-cross-device
A cross-device sign-in with a QR code, start to finish.
What the BankID API returns to a business
Your backend starts an order with /auth (identify) or /sign, then calls /collect every two seconds while it is pending.[6] When the user confirms, the response carries completionData.
The user confirms in the BankID app
A direct BankID integration, simplified. Hint codes tell you what to show the user.[6]
| Field | When | What it is |
|---|---|---|
| personalNumber | Always | Swedish national identification number, 12 digits |
| name, givenName, surname | Always | Full name and its parts |
| signature | Always | Base 64 encoded XML signature |
| ocspResponse | Always | Signed certificate status for the signature |
| device.ipAddress, device.uhi | Returned | IP seen by BankID, unique hardware identifier |
| bankIdIssueDate | Returned | Date the BankID was issued |
| stepUp.mrtd, stepUp.face | If a step-up ran | Whether the chip or face check was done |
| risk | Only if requested | low, moderate or high |
| Address, nationality, portrait | Never | Not part of the response |
The collect response for a complete order.[6]
The date of birth is encoded in the personnummer, so an age check comes with every sign-in.[3]
Level of assurance and legal standing
Sweden notified one umbrella scheme under eIDAS, "Swedish eID", on 14 December 2020, listing BankID, Freja eID and EFOS as its means at levels Substantial and High.[10] DIGG's own table of notified Swedish e-IDs places Mobile BankID, BankID on file and BankID on card at Substantial.[11] Under the Swedish trust framework it sits at trust level 3.[3][11]
| Instrument | What it means for BankID |
|---|---|
| DIGG trust framework for Swedish e-ID | BankID approved at trust level 3, alongside the other e-IDs DIGG lists at that level[11] |
| eIDAS, Regulation (EU) No 910/2014 | Notified inside the Swedish eID scheme; BankID states that a BankID signature is an advanced electronic signature[3][10] |
| PSD2 | An identification meets strong customer authentication; a signature meets dynamic linking[3] |
| Lag (2017:630), ch. 3, s. 7 | eIDAS eID means may verify identity for anti-money laundering checks[13] |
| Spellagen (2018:1138), ch. 12, s. 2 | Gambling licensees must check identity by reliable electronic identification[14] |
| Criminal Code, chapter 15, section 12 | Using someone else's BankID is misuse of documents[3] |
| Lag (2026:1358) | State e-ID law, applies from 1 December 2026[12] |
For customer due diligence, the Swedish anti-money laundering act reads:
Chapter 3, section 7Lag (2017:630) om åtgärder mot penningtvätt och finansiering av terrorism
"När första stycket tillämpas får man använda medel för elektronisk identifiering och betrodda tjänster enligt ... (EU) nr 910/2014"
Source: Sveriges riksdag, SFS 2017:630[13]
In English: eIDAS eID means may verify identity. Due diligence as a whole stays risk-based.
From 10 July 2027 the EU Anti-Money Laundering Regulation (AMLR) applies. Its Article 22(6)(b) accepts eID means at "the assurance levels 'substantial' or 'high'", so BankID meets the bar.[15] The final draft standards of the EU anti-money laundering authority (AMLA) were sent to the Commission on 30 September 2026 and are not yet law. Under that draft, eID means "should be used wherever possible" and remote document checks are a fall-back for customers who cannot use them. It counts the EU Digital Identity Wallet (EUDI Wallet) among those means.[16]
Note
SverigeID, a state e-ID issued by the Swedish Police Authority, opens on 1 December 2026. DIGG has approved it at Swedish trust level 4, the highest. It is not yet on the EU list of notified schemes, as of 5 October 2026. It is a complement to BankID and Freja eID, not a replacement.[11][17]
How to connect to the BankID Sweden API: direct or through a broker
BankID's answer: "You can purchase the BankID service from a bank or through a retailer."[4]
Direct relying party
Buy from a bank, build it yourself
- Contract with a bank that sells BankID
- Order your relying-party (FP) certificate through BankID Keygen
- Build start, QR, collect, user messages and cancel handling
- Price per identification and signature, agreed with the bank
Best for one-country services with an in-house team
Through a broker or reseller
One contract, one integration
- Contract with the reseller, which buys the BankID service
- You call the reseller's API instead of BankID's
- The reseller's integration, not yours, talks to BankID
- Price per check, set by the reseller
Best for multi-country onboarding
Both routes work under the same BankID rules.[4]
Prices are not published on either route. The cost "is commonly based on how many identifications and signatures that are made", and private-sector prices are set by competition.[4] Onboarding lead times are not published either, as of 5 October 2026.
Some rules bind you on both routes. BankID's contract rules forbid "ID switching": using a sign-in to issue a password or other credential, or keeping a user logged in by cookie past two hours of inactivity.[4] New hint codes may appear "without prior notice", and a direct integration must handle unknown ones.[6]
Public bodies pay a fixed price through DIGG's authorisation system; private companies can only join DIGG's eIDAS node.[4][12] The commercial side is in BankID for business in Sweden.
BankID API use cases
| Use case | What BankID gives you | Rule behind it |
|---|---|---|
| KYC and AML onboarding | Verified identity from a notified eID | Lag (2017:630) ch. 3 s. 7[13] |
| Online gambling | Reliable electronic identification at registration | Spellagen ch. 12 s. 2[14] |
| Age checks | Date of birth from the personnummer | Collect response[6] |
| Payments | Strong customer authentication and dynamic linking | PSD2[3] |
| Contracts and credit | Advanced electronic signature | eIDAS, Regulation (EU) No 910/2014[3] |
Gambling adds two rules: online registration is limited to residents of Sweden, and licences may not cover people under 18.[14]
Limits and fallbacks
A BankID needs a Swedish personnummer and an issuing bank.[5]
- Minors: the bank sets the age limit, "most commonly ... either 13 or 18 years old", and minors need parental consent.[5]
- Swedes abroad can lose eligibility when they are removed from the SPAR register.[5]
- Foreign citizens: BankID's news list announces renewal with EU passports for registered non-Swedish citizens since 5 May 2026; visitors and non-residents without a personnummer cannot get one.[5][9]
According to Computer Sweden, police reported a 90% fall in phone scams around BankID logins after QR codes arrived. In 2026 BankID added a payment warning and the face step-up.[9]
For everyone else, the fallback is a document check: read the passport or ID card chip over NFC (see NFC eID verification and chip security), check liveness and match the face.
1Offer BankID first to Swedish users
Same-device app or QR on a computer.
The user completes a BankID order
Accept the signed result
Personnummer, name, signature, OCSP.
Verify with a document
NFC chip reading, liveness and face match.
2Add the address from another source
BankID does not return it.
3Screen and decide
Sanctions and PEP checks; the decision stays with you.
eID first, document as the fallback, one decision at the end.
BankID integration checklist
- Decide between a direct bank contract and a reseller.
- List the attributes your policy needs and the address source.
- Support same-device launch and the QR code on desktop.
- Poll collect every two seconds and stop on failed.[6]
- Map every hint code to a user message, unknown ones included.[6]
- Decide on the risk indicator and a step-up.
- Store the signature and OCSP response for audit.[6]
- End idle sessions within the two-hour rule.[4]
- Build the document fallback for users without BankID.
- Test in BankID's test environment before you go live.
How Didit helps with BankID Sweden verification
BankID Sweden is live on Didit. The user picks BankID in the hosted flow or the SDK and signs in on the same phone or by QR code. Didit never asks for the BankID security code (PIN).
Turn it on in the console under Workflows, ID Verification, Countries, Wallets accepted, or with the workflows API. A sign-in returns the full name, the date of birth, the Swedish personnummer, the level of assurance (labelled Substantial) and a signature check (a verdict, not the raw signature). No address, no portrait. Users without BankID fall back to document capture with NFC chip reading, liveness and face match in the same workflow. A full KYC check costs $0.33, NFC verification $0.15 and AML screening $0.20.
Only completed BankID sign-ins are billed; cancelled, timed-out and failed ones are free. Document checks are priced per check. BankID costs $0.20 (pricing); the live eIDs are on the digital ID wallets page.
Screenshot pending: hosted-flow-wallet-chooser
The user picks BankID in the Didit flow.
Screenshot pending: hosted-flow-qr
On a computer, a QR code hands the sign-in to the phone.
Screenshot pending: console-wallets-accepted
Turning BankID Sweden on in the Didit console.
Didit provides
- BankID Sweden sign-in in the hosted flow or the SDK
- The document route for users without BankID
- The signed attributes and the evidence of every check
Stays with you
- The risk assessment and the policies
- The onboarding decision
- The source for the customer's address
Accept BankID Sweden in your sign-up today
Turn on BankID and the document route in one workflow, and pay only for completed eID sign-ins.
Key takeaways
- 8.7 million people used BankID in 2025, and 99.9% of registered Swedes aged 18 to 67 have one.
- You buy BankID from a bank and integrate it yourself, or go through a reseller; prices are not published.
- A sign-in returns the personnummer and the name, signed, but no address and no portrait.
- DIGG lists BankID at Substantial, which meets AMLR Article 22(6)(b) from 10 July 2027.
Frequently asked questions
How much does the BankID API cost?
BankID does not publish prices. The cost is usually based on the number of identifications and signatures, and private-sector prices are set by competition.[4] Didit charges $0.20.
What data does BankID return?
The 12-digit personnummer, the full name, given name and surname, the signature and an OCSP response, plus device data and an optional risk level. No address, nationality or portrait.[6]
Can BankID check a user's age?
Yes. The personnummer encodes the date of birth, so every sign-in tells you the user's age. BankID itself is available to minors only where their bank allows it, usually from 13 or 18 and with parental consent.[5][6]
Can foreigners use BankID?
Only with a Swedish personnummer and an account at an issuing bank. BankID's news list announces renewal with EU passports for registered non-Swedish citizens since 5 May 2026. Visitors without a personnummer need another route, such as a document check.[5][9]
What level of assurance is BankID?
Substantial. BankID is part of the Swedish eID scheme notified under eIDAS on 14 December 2020; the scheme is notified at Substantial and High, and DIGG lists BankID's means at Substantial and at Swedish trust level 3.[10][11]
Is BankID enough for AML customer due diligence in Sweden?
It is an accepted means. The anti-money laundering act, chapter 3, section 7, lets you use eIDAS electronic identification to verify identity. Screening, risk assessment and monitoring are still required on top.[13]
How long does a BankID integration take?
BankID does not publish onboarding lead times, as of 5 October 2026. A direct integration needs a bank contract, a relying-party certificate from BankID Keygen and your own QR, polling and hint-code handling; a reseller replaces that with one API.[4][6]
Can I test BankID before going live?
Yes. BankID's developer site has a test portal next to the API reference.[6] Going live still needs a contract with a bank or a reseller and, on the direct route, a relying-party certificate ordered through BankID Keygen.[4] Test your handling of unknown hint codes too, because BankID may add new ones without prior notice.[6]
Does SverigeID replace BankID?
No. SverigeID, the state e-ID that opens on 1 December 2026, is a complement to BankID and Freja. It is approved at Swedish trust level 4 but is not yet on the EU list of notified schemes, as of 5 October 2026.[11][17]
Sources
- BankID in numbers, BankID, figures for 2025.
- History, BankID.
- Laws and regulations, BankID.
- Connect your business, BankID.
- Get BankID, BankID.
- /collect API reference, BankID Developers, read 5 October 2026.
- Facial recognition as an extra control, BankID news, August 2026.
- Digital ID card at the voting location, BankID news, 2026.
- News, BankID, 2026 entries.
- Overview of pre-notified and notified eID schemes under eIDAS, European Commission, read 5 October 2026.
- Approved e-IDs and attestation functions, DIGG.
- About e-identification, DIGG.
- Lag (2017:630) om åtgärder mot penningtvätt och finansiering av terrorism, Sveriges riksdag.
- Spellagen (2018:1138), statute text on lagen.nu.
- Regulation (EU) 2024/1624 (AMLR), Article 22, EUR-Lex.
- Final Report, draft RTS under Article 28(1) AMLR, AMLA, 30 September 2026.
- Statlig e-legitimation, SverigeID, Swedish Police Authority.
Compare every national eID on the eID verification page, or start with what eID verification is.
One workflow for Sweden and beyond
Start with BankID, add the eIDs your users already have, and keep documents as the fallback.
Related articles
- Cl@ve integration in Spain: who can connect and what to use instead
- PhilSys verification: how businesses check the National ID
- OpenID4VP verifier guide: accepting the EUDI Wallet
- eIDAS regulation explained: what eIDAS 2 (2024/1183) changes
- Smart-ID API: a developer's guide to RP API v3
- National digital identity worldwide: models, leaders, standards