Skip to main content
Didit Raises $7.5M to Build the Infrastructure for Identity and Fraud
Didit
Back to blog
Blog · October 6, 2026

Smart-ID API: a developer's guide to RP API v3

The Smart-ID API (RP API v3) for developers: endpoints, device link and notification flows, response verification, demo testing, what you receive, assurance level, AML rules and prices.

By DiditUpdated
smart-id-api-cover.png

In short

The Smart-ID API is the Relying Party (RP) API that SK ID Solutions publishes for logging users in and collecting signatures with the Smart-ID app. Version 3 adds QR and same-device links next to push notifications.[12]

  • 3,853,329 people in Estonia, Latvia and Lithuania use Smart-ID (counter, 5 October 2026).[1]
  • The API returns a signed certificate with the user's name and country-prefixed personal code. No address, no portrait.[15][5]

Last reviewed: 5 October 2026 · Not legal advice

This is the code-first guide to the Smart-ID API: endpoints, sessions, response checks, demo testing and legal standing. For contracts and AML rules by country, read our Smart-ID integration guide.

Smart-ID at a glance

Smart-ID is a mobile app from SK ID Solutions AS; through SK's Relying Party API, a service uses it to log a user in or to collect a signature.[13] Part of each key sits on SK's server, which Estonia's Information System Authority (RIA) calls the "Smart-ID key management server service".[4]

Smart-ID

App-based electronic identity in the Baltics and Belgium

Live on Didit
CountryEstonia, Latvia, Lithuania; assessed at high in Belgium[1][2]
OperatorSK ID Solutions AS[11][12]
LaunchedNovember 2016, according to Wikipedia; current API version 3.2.3[20]
Users3,853,329 in the three Baltic states (smart-id.com counter, 5 October 2026)[1]
CredentialSmartphone app with a split key; the user confirms each login or signature request with a PIN in the app[4][36]
Level of assuranceHigh under national assessments in Estonia, Latvia and Lithuania; not on the EU list of notified eID schemes[4][6]
Data returnedCertificate with names and personal code, plus a signature; date of birth depends on the code[15][5][16]
Legal basisNational assessments in Estonia, Latvia and Lithuania[4][25][27]
Didit statusLive, labelled High

Adoption: users and transactions

Lithuania is the largest Smart-ID market with 1,857,471 users, then Latvia with 1,198,463 and Estonia with 797,395, according to the live counter on smart-id.com on 5 October 2026.[1] SK reports "almost a 100 million of transactions each month".[2]

3,853,329Smart-ID users in Estonia, Latvia and Lithuania (5 October 2026)
~100 millionTransactions each month (SK, January 2026)
1,100+Services that accept Smart-ID (SK, 2026)[3]

In Estonia, Smart-ID has "a market share of nearly 60 percent" of authentications, according to ERR News. The counter gives totals only; no primary source gives Smart-ID's share of each country's adults (5 October 2026).

What the user sees

RP API v3 reaches the app three ways: a dynamic QR code across devices, a Web2App or App2App link on the same phone, or a push notification.[12] SK markets the QR and app-to-app experience as Smart-ID+, which "no longer relies on entering your personal ID code on a website".[8]

Your service

Log in with Smart-ID

Scan the code with the Smart-ID app.

1The site shows a dynamic QR code, redrawn every second.[18]

Smart-ID app

Scan to log in

Point the camera at the code on screen.

2The app can only scan Smart-ID login QR codes, and only when the user starts the login.[9]

Smart-ID app

Your service

Log in to Your service. Continue only if you started this.

Continue

3The app always shows your service name with the request text.[36] Notification flows, unlike this QR flow, also show a four-digit code, or three to pick from, before the PIN.[17][10]

Smart-ID app

Enter PIN1

Confirm the log in to Your service.

Confirm

4Only then does the user enter PIN1, in the app, never on your site.[8]

Your service

You are logged in

  • Full nameShared
  • Personal codeShared
  • AddressNot shared
  • PortraitNot shared

5Your backend reads name and personal code from the certificate.[15]

Video pending: flow-app-code

An app sign-in with a comparison code, start to finish.

How the Smart-ID API v3 works

The API is REST over HTTPS with UTF-8 JSON.[19] Four POST endpoint families open a session and return a sessionID; one GET returns the result.[13]

Endpoint familyWhat it does
POST v3/authentication/device-link/anonymousLog in by QR or same-device link, no personal code typed
POST v3/authentication/notification/etsi/{id}Push a login to a user identified by personal code
POST v3/signature/...Sign a document digest (ASiC-E or PAdES)
POST v3/signature/certificate/{document-number} and certificate-choiceFetch the signing certificate first
GET v3/session/{sessionID}Read status and result

The RP API v3 endpoint families, from SK's overview.[13]

User Your backend Smart-ID RP API Smart-ID app
1Clicks log in
2POST with rpChallenge
3sessionID, sessionToken
4Dynamic QR code
5App scans the code

The user enters PIN1

6GET session status
7Certificate and signature

Simplified cross-device login with a device link.[12][18]

Pitfalls:

  • Every initial v3 request carries a random rpChallenge you generate; it replaced the v2 nonce against replay attacks.[20]
  • The sessionSecret must never reach your frontend, and one flow gets one session request, even when you show QR and link together.[18]
  • In notification flows you compute the four-digit code from the SHA-256 of rpChallenge.[17]
  • SK authenticates you by source IP plus relyingPartyUUID, and requires HTTPS key pinning.[19]
  • SK's documentation says a user with no account gets HTTP 404, and asks you to show one message for all error cases, against enumeration.[19]

What a business receives from the Smart-ID API

A finished session returns state, result.endResult, the user's certificate in cert and a signature object. The subject's serialNumber holds the identity code, for example PNOEE-30001010004, the prefix giving the country.[15]

AttributeReturned (session COMPLETE, result OK)Where
Personal code with country prefixYesCertificate subject serialNumber[15]
Given name and surnameIn the certificate subjectPer the subject fields listed in SK's certificate profile
Certificate levelYescert.certificateLevel, for example ADVANCED or QUALIFIED[15]
Signature over your challenge or digestYes; none if refused or timed outsignature object[15]
Date of birthDepends on the codeDocumented for Estonian codes; Latvian test accounts exist with and without a date field[5][16]
Address, nationality, portraitNeverNot in the certificate or the response[5]

SK's response verification requires you to:[15]

  • Check state is COMPLETE, endResult is OK, protocol ACSP_V2 (login) or RAW_DIGEST_SIGNATURE.
  • Validate the chain against SK's CAs only, with OCSP or CRL.
  • Require every Smart-ID policy identifier, so other SK certificates fail.
  • Compare certificateLevel with your required level.
  • Rebuild the signed payload and verify the signature.
  • Verify the callback URL values in same-device flows.

Level of assurance and legal standing

Smart-ID is not on the EU list of notified eID schemes; Estonia's notified scheme (High, 7 November 2018) covers the ID card and Mobile-ID.[6]

CountryAssessmentSource
Estonia"high" for persons with an Estonian personal code (RIA expert group)RIA[4]
LatviaQualified eID provider, local qualified status from May 2023Ministry of Defence, SK[25][26]
LithuaniaHigh Level of Assurance (SK news of 19 December 2024)SK, citing RRT[27]
Belgium"formally assessed at the high assurance level"SK[2]

Caveat: e-residents "are not distinguishable from residents".[5]

Estonian AML customer due diligence

Estonia's Money Laundering and Terrorist Financing Prevention Act (RahaPTS) sets the remote routes in § 31(3).[23]

§ 31(3)RahaPTS (Estonia)

"1) e-identimise süsteemi, millest on teatatud ... (EL) nr 910/2014 ... artikli 9 kohaselt ja mis vastab ... artikli 8 lõike 2 punktis b või c sätestatud usaldusväärsuse tasemele" or "2) kvalifitseeritud usaldusteenust"

Source: Riigi Teataja, RahaPTS[23]

In English: a notified eID scheme at substantial or high, or a qualified trust service. Route 1 does not fit; whether Smart-ID's qualified certificates fit route 2 has no official statement as of 5 October 2026, so ask Finantsinspektsioon or counsel. Lithuania's AML law (Art. 11) and Latvia's Cabinet Regulation No. 392 (p. 7.1) list a qualified or secure electronic signature among several remote routes.[28][29]

From 2027: AMLR Article 22(6)

The Anti-Money Laundering Regulation (AMLR) applies from 10 July 2027; Article 22(6)(b) accepts "electronic identification means which meet the requirements of Regulation (EU) No 910/2014 with regard to the assurance levels 'substantial' or 'high' and relevant qualified trust services".[30] The Anti-Money Laundering Authority (AMLA) final draft standards of 30 September 2026, not yet law, accept eID at substantial or high "regardless of whether they are notified under Article 9".[31] Our EUDI Wallet page covers the eIDAS 2 timeline.

How a business connects: direct RP contract or broker

SK's process: test free with no agreement, choose security measures, send your IP addresses and service name, sign, receive your RP UUID, go live "within days of your first inquiry".[21] Certified brokers also resell Smart-ID, and Estonian public bodies can use RIA's TARA gateway.[5]

Direct

RP contract with SK

  • You call the RP API
  • IP allow-list, RP UUID
  • You build verification

Published price list

Through a broker

Aggregator or eID hub

  • One API, several eIDs
  • Broker holds the contract
  • Verification done for you

Prices not published in one place

Public sector

TARA (Estonia)

  • OpenID Connect, run by RIA
  • Register, demo, then live
  • Private firms: cross-border only

State institutions

Three ways to reach Smart-ID.[21][5]

SK's price list (from 1 June 2026) bills each "Smart-ID authentication or signing request": €0.109 with a €60 monthly minimum, down to €0.0106 on the 3 million plan, and a personal agreement above 5 million.[11] SK states that Smart-ID+ "comes at no additional cost" for existing RPs.[7]

Testing against the demo environment

Demo: https://sid.demo.sk.ee/smart-id-rp/v3/, relyingPartyUUID 00000000-0000-4000-8000-000000000000, name DEMO. Live: https://rp-api.smart-id.com/v3/.[14] Test accounts by outcome:[16]

End resultExample document number (Estonia)Tests
OKPNOEE-40504040001-DEM2-QSuccess
USER_REFUSEDPNOEE-30403039917-MOCK-QUser cancels
WRONG_VCPNOEE-30403039972-MOCK-QWrong code picked
TIMEOUTPNOEE-30403039983-MOCK-QNo answer

Use cases and sector rules

  • KYC and AML onboarding. Signed name and personal code; AML fit varies by country.[23][28][29]
  • Gambling and age. Estonia's Gambling Act bars under-21s from games of chance (§ 34(2)) and requires remote operators to verify every player and register the personal code (§ 53(1)).[24] We found no age-only claim in the API.
  • Signing. Qualified accounts sign through v3/signature; "4 out of 10 Lithuanians used a qualified e-signature in 2025".[13][33]
  • Telecom. No Baltic rule names Smart-ID for SIM registration (5 October 2026).

Limits and fallbacks

"In Estonia and Latvia, Smart-ID is currently limited to people with an Estonian or Latvian national ID-numbers"; Lithuanian non-residents can get Smart-ID Basic at two banks.[22] Smart-ID has no age limit, but registration paths do (Latvian ID card from 14), and under-18 accounts need parent authorisation.[32]

We found no documented outage as of 5 October 2026; phishing is the risk. Nearly €23 million was stolen from Estonian bank accounts in 2025 by PIN scams, according to ERR News. Since 29 April 2026, Estonian registration reads the ID card over NFC instead of a card reader.[34]

1Offer Smart-ID first

Baltic personal code holders.

The session ends COMPLETE with result OK

Yes

Verify and store the result

All checks pass.

No

Switch to a document

NFC chip reading, liveness and face match.

2Screen and decide

AML screening, then your decision.

eID first, document fallback; record why each fallback was needed.[31]

Smart-ID API implementation checklist

Build on SK's free demo first, so the contract waits until your code works.[21] Response verification is the core of the work.[15]

  • Build against the demo URL and the published test accounts.[14][16]
  • Prefer device link flows; allow notification only on known devices.[13]
  • Generate a fresh random rpChallenge for every login.[20]
  • Pin SK's HTTPS key and keep sessionSecret on the server.[19][18]
  • Run every step of SK's response verification.[15]
  • Send SK your IPs and service name, then sign.[21]
  • Write down your legal basis for AML use in each country.[23]
  • Add a document route for users without Smart-ID.

How Didit helps with Smart-ID

Smart-ID is live on Didit for eID verification in Estonia, Latvia, Lithuania and Belgium. Didit holds the SK connection, so you skip the RP contract, the IP allow-list and the certificate code.

In the console, go to Workflows, the ID Verification step, Countries, pick the country and tick Smart-ID under "Wallets accepted". By API, set methods.EST.wallet, create a session, and read GET /v3/session/{id}/decision/ or the webhook: verification_method is "wallet" with a wallet_verification object, per the digital ID wallets docs.[35] The user approves a comparison code in the Smart-ID app. Didit never asks for the PIN.

Screenshot pending: hosted-flow-wallet-chooser

The method chooser in the Didit hosted flow.

Screenshot pending: hosted-flow-smartid-code

The comparison code the user matches in the Smart-ID app.

Screenshot pending: console-wallets-accepted

Turning Smart-ID on in the Didit console.

You get full name, date of birth, Baltic personal code, level of assurance (labelled High) and a signature check; no address, no portrait. Users without Smart-ID fall back to document verification with NFC chip reading ($0.15), liveness and face match; full KYC is $0.33 and AML screening $0.20. Only completed eID sign-ins are billed; a completed Smart-ID verification costs $0.20 (pricing page), every eID on the digital ID wallets page.

Didit provides

  • The Smart-ID connection and signature check
  • The document route
  • AML screening and evidence of every check

Stays with you

  • The risk assessment and AML reading
  • The onboarding decision
  • The reason for each fallback

Skip the RP contract and ship Smart-ID

Smart-ID and the document route in one API; pay only for completed checks.

Start freeTalk to usRead the docs

Key takeaways

  • The Smart-ID API (RP API v3) opens sessions with POST and reads them with GET.
  • SK recommends device link flows (QR or same-device link) over push notifications.
  • You get a certificate with name and personal code, never an address or portrait.
  • Rated high nationally, not EU-notified: AML fit differs by country.

Frequently asked questions

Is there a public Smart-ID API?

Yes. SK publishes the Relying Party API documentation openly; the current version is 3.2.3.[20] Live calls need an agreement, an RP UUID and allowed IP addresses.[21][19]

How much does the Smart-ID API cost?

SK's price list from 1 June 2026 starts at €0.109 per request with a €60 monthly minimum and falls to €0.0106 on the 3 million plan.[11] Broker prices are not published in one place. On Didit, a completed Smart-ID verification costs $0.20.

What data does the Smart-ID API return?

A signed certificate with the user's names and a personal code such as PNOEE-30001010004, plus a signature.[15] No address, nationality or portrait.[5]

How do I test the Smart-ID API?

Use the demo environment with SK's public demo RP UUID; it is free and needs no agreement.[14][21] Test accounts for Estonia, Latvia, Lithuania and Belgium return success, refusal, wrong code or timeout.[16]

What changed in Smart-ID RP API v3?

Version 3 adds device link flows (QR, Web2App and App2App) with their own endpoints, next to push notifications.[13][20] It also makes a random rpChallenge mandatory in every initial request, replacing the v2 nonce, against replay.[20] Version 3.2 supports both HTTP/1.1 and HTTP/2 and returns error details in the RFC 9457 format.[20]

Should I use device link or notification flows?

Device links everywhere give the most phishing protection. Across devices, device links on new devices plus push on known ones is also recommended; push alone is not.[12]

What level of assurance does Smart-ID have?

High under national assessments in Estonia, Latvia and Lithuania.[4][25][27] It is not on the EU list of notified eID schemes.[6]

Is Smart-ID enough for AML customer due diligence in Estonia?

RahaPTS § 31(3) allows a notified eID at substantial or high, or a qualified trust service.[23] No official statement says whether Smart-ID counts as the second (5 October 2026). Ask Finantsinspektsioon or counsel.

Can foreigners use Smart-ID?

In Estonia and Latvia only holders of a local personal code can register. In Lithuania, non-residents can get Smart-ID Basic at two banks; residence-permit holders and e-residents register like citizens.[22]

Can minors use Smart-ID?

Smart-ID has no age limit; the registration path sets it, for example from 6 with a passport in Estonia.[32] Under-18 accounts need parent authorisation, and SK's test accounts include minors.[32][16]

How long does a Smart-ID API integration take?

SK says "within days of your first inquiry".[21] Developer effort is not published.

Sources

  1. Smart-ID home page, live user counter, SK ID Solutions, read 5 October 2026.
  2. 2025: advancing digital trust beyond borders, SK ID Solutions, 19 January 2026.
  3. Trust and competition in digital identity in Europe, e-Estonia, 2026.
  4. Electronic identity (eID), Information System Authority (RIA).
  5. TARA technical specification, RIA.
  6. Overview of pre-notified and notified eID schemes under eIDAS, European Commission, read 5 October 2026.
  7. Smart-ID+, SK ID Solutions.
  8. How does the new Smart-ID protect me from fraud, Smart-ID FAQ.
  9. Estonia's government adopts Smart-ID+ to strengthen security, SK ID Solutions, 28 January 2026.
  10. Why do I sometimes see one confirmation code and sometimes three, Smart-ID FAQ.
  11. Price list, SK ID Solutions, valid from 1 June 2026.
  12. Relying Party API: introduction, SK ID Solutions, version 3.2.3.
  13. Relying Party API: overview of API endpoints, SK ID Solutions.
  14. Environment technical parameters, SK ID Solutions.
  15. Relying Party API: response verification, SK ID Solutions.
  16. Test accounts for automated testing, SK ID Solutions.
  17. Relying Party API: notification based flows, SK ID Solutions.
  18. Relying Party API: device link flows, SK ID Solutions.
  19. Relying Party API: API technical description, SK ID Solutions.
  20. Relying Party API: changelog, SK ID Solutions.
  21. Integration process for e-service providers, Smart-ID.
  22. Can foreigners and non-residents use Smart-ID, Smart-ID FAQ.
  23. Rahapesu ja terrorismi rahastamise tõkestamise seadus (RahaPTS), § 31, Riigi Teataja.
  24. Hasartmänguseadus (Gambling Act), Riigi Teataja.
  25. Elektroniskā identifikācija, Ministry of Defence of Latvia.
  26. Smart-ID has acquired local qualified status for authentication in Latvia, SK ID Solutions, 29 May 2023.
  27. Smart-ID and Mobile-ID recognised as state-approved tools in Lithuania, SK ID Solutions, 19 December 2024.
  28. Law on the Prevention of Money Laundering and Terrorist Financing, Art. 11, Lithuania, INFOLEX consolidated text.
  29. Cabinet Regulation No. 392, Latvia, likumi.lv.
  30. Regulation (EU) 2024/1624 (AMLR), EUR-Lex, Official Journal of 19 June 2024.
  31. Final Report, draft RTS under Article 28(1) AMLR, AMLA, 30 September 2026.
  32. Age limitations for using Smart-ID, Smart-ID FAQ.
  33. SK ID Solutions issued almost three million certificates in Lithuania in 2025, SK ID Solutions, 7 May 2026.
  34. Smart-ID registration with Estonian ID card now available via NFC, Smart-ID, 29 April 2026.
  35. Digital ID wallets, Didit documentation.
  36. Relying Party API: interactions, SK ID Solutions.

Smart-ID is one of five eIDs live in Didit's eID verification. See also what eID verification is and the BankID Sweden API guide.

Accept Smart-ID without writing certificate code

One workflow for Smart-ID, Mobile-ID and documents, billed per completed check.

Start freeTalk to us

Infrastructure for identity and fraud.

One API for KYC, KYB, Transaction Monitoring, and Wallet Screening. Integrate in 5 minutes.

Ask an AI to summarise this page