Smart-ID API: a developer's guide to RP API v3
The Smart-ID API (RP API v3) for developers: endpoints, device link and notification flows, response verification, demo testing, what you receive, assurance level, AML rules and prices.

In short
The Smart-ID API is the Relying Party (RP) API that SK ID Solutions publishes for logging users in and collecting signatures with the Smart-ID app. Version 3 adds QR and same-device links next to push notifications.[12]
- 3,853,329 people in Estonia, Latvia and Lithuania use Smart-ID (counter, 5 October 2026).[1]
- The API returns a signed certificate with the user's name and country-prefixed personal code. No address, no portrait.[15][5]
This is the code-first guide to the Smart-ID API: endpoints, sessions, response checks, demo testing and legal standing. For contracts and AML rules by country, read our Smart-ID integration guide.
Smart-ID at a glance
Smart-ID is a mobile app from SK ID Solutions AS; through SK's Relying Party API, a service uses it to log a user in or to collect a signature.[13] Part of each key sits on SK's server, which Estonia's Information System Authority (RIA) calls the "Smart-ID key management server service".[4]
Smart-ID
App-based electronic identity in the Baltics and Belgium
Adoption: users and transactions
Lithuania is the largest Smart-ID market with 1,857,471 users, then Latvia with 1,198,463 and Estonia with 797,395, according to the live counter on smart-id.com on 5 October 2026.[1] SK reports "almost a 100 million of transactions each month".[2]
In Estonia, Smart-ID has "a market share of nearly 60 percent" of authentications, according to ERR News. The counter gives totals only; no primary source gives Smart-ID's share of each country's adults (5 October 2026).
What the user sees
RP API v3 reaches the app three ways: a dynamic QR code across devices, a Web2App or App2App link on the same phone, or a push notification.[12] SK markets the QR and app-to-app experience as Smart-ID+, which "no longer relies on entering your personal ID code on a website".[8]
Log in with Smart-ID
Scan the code with the Smart-ID app.
1The site shows a dynamic QR code, redrawn every second.[18]
Scan to log in
Point the camera at the code on screen.
2The app can only scan Smart-ID login QR codes, and only when the user starts the login.[9]
Your service
Log in to Your service. Continue only if you started this.
Continue
3The app always shows your service name with the request text.[36] Notification flows, unlike this QR flow, also show a four-digit code, or three to pick from, before the PIN.[17][10]
Enter PIN1
Confirm the log in to Your service.
Confirm
4Only then does the user enter PIN1, in the app, never on your site.[8]
You are logged in
- Full nameShared
- Personal codeShared
- AddressNot shared
- PortraitNot shared
5Your backend reads name and personal code from the certificate.[15]
Video pending: flow-app-code
An app sign-in with a comparison code, start to finish.
How the Smart-ID API v3 works
The API is REST over HTTPS with UTF-8 JSON.[19] Four POST endpoint families open a session and return a sessionID; one GET returns the result.[13]
| Endpoint family | What it does |
|---|---|
POST v3/authentication/device-link/anonymous | Log in by QR or same-device link, no personal code typed |
POST v3/authentication/notification/etsi/{id} | Push a login to a user identified by personal code |
POST v3/signature/... | Sign a document digest (ASiC-E or PAdES) |
POST v3/signature/certificate/{document-number} and certificate-choice | Fetch the signing certificate first |
GET v3/session/{sessionID} | Read status and result |
The RP API v3 endpoint families, from SK's overview.[13]
The user enters PIN1
Simplified cross-device login with a device link.[12][18]
Pitfalls:
- Every initial v3 request carries a random
rpChallengeyou generate; it replaced the v2nonceagainst replay attacks.[20] - The
sessionSecretmust never reach your frontend, and one flow gets one session request, even when you show QR and link together.[18] - In notification flows you compute the four-digit code from the SHA-256 of
rpChallenge.[17] - SK authenticates you by source IP plus
relyingPartyUUID, and requires HTTPS key pinning.[19] - SK's documentation says a user with no account gets HTTP 404, and asks you to show one message for all error cases, against enumeration.[19]
What a business receives from the Smart-ID API
A finished session returns state, result.endResult, the user's certificate in cert and a signature object. The subject's serialNumber holds the identity code, for example PNOEE-30001010004, the prefix giving the country.[15]
| Attribute | Returned (session COMPLETE, result OK) | Where |
|---|---|---|
| Personal code with country prefix | Yes | Certificate subject serialNumber[15] |
| Given name and surname | In the certificate subject | Per the subject fields listed in SK's certificate profile |
| Certificate level | Yes | cert.certificateLevel, for example ADVANCED or QUALIFIED[15] |
| Signature over your challenge or digest | Yes; none if refused or timed out | signature object[15] |
| Date of birth | Depends on the code | Documented for Estonian codes; Latvian test accounts exist with and without a date field[5][16] |
| Address, nationality, portrait | Never | Not in the certificate or the response[5] |
SK's response verification requires you to:[15]
- Check
stateisCOMPLETE,endResultisOK, protocolACSP_V2(login) orRAW_DIGEST_SIGNATURE. - Validate the chain against SK's CAs only, with OCSP or CRL.
- Require every Smart-ID policy identifier, so other SK certificates fail.
- Compare
certificateLevelwith your required level. - Rebuild the signed payload and verify the signature.
- Verify the callback URL values in same-device flows.
Level of assurance and legal standing
Smart-ID is not on the EU list of notified eID schemes; Estonia's notified scheme (High, 7 November 2018) covers the ID card and Mobile-ID.[6]
| Country | Assessment | Source |
|---|---|---|
| Estonia | "high" for persons with an Estonian personal code (RIA expert group) | RIA[4] |
| Latvia | Qualified eID provider, local qualified status from May 2023 | Ministry of Defence, SK[25][26] |
| Lithuania | High Level of Assurance (SK news of 19 December 2024) | SK, citing RRT[27] |
| Belgium | "formally assessed at the high assurance level" | SK[2] |
Caveat: e-residents "are not distinguishable from residents".[5]
Estonian AML customer due diligence
Estonia's Money Laundering and Terrorist Financing Prevention Act (RahaPTS) sets the remote routes in § 31(3).[23]
§ 31(3)RahaPTS (Estonia)
"1) e-identimise süsteemi, millest on teatatud ... (EL) nr 910/2014 ... artikli 9 kohaselt ja mis vastab ... artikli 8 lõike 2 punktis b või c sätestatud usaldusväärsuse tasemele" or "2) kvalifitseeritud usaldusteenust"
Source: Riigi Teataja, RahaPTS[23]
In English: a notified eID scheme at substantial or high, or a qualified trust service. Route 1 does not fit; whether Smart-ID's qualified certificates fit route 2 has no official statement as of 5 October 2026, so ask Finantsinspektsioon or counsel. Lithuania's AML law (Art. 11) and Latvia's Cabinet Regulation No. 392 (p. 7.1) list a qualified or secure electronic signature among several remote routes.[28][29]
From 2027: AMLR Article 22(6)
The Anti-Money Laundering Regulation (AMLR) applies from 10 July 2027; Article 22(6)(b) accepts "electronic identification means which meet the requirements of Regulation (EU) No 910/2014 with regard to the assurance levels 'substantial' or 'high' and relevant qualified trust services".[30] The Anti-Money Laundering Authority (AMLA) final draft standards of 30 September 2026, not yet law, accept eID at substantial or high "regardless of whether they are notified under Article 9".[31] Our EUDI Wallet page covers the eIDAS 2 timeline.
How a business connects: direct RP contract or broker
SK's process: test free with no agreement, choose security measures, send your IP addresses and service name, sign, receive your RP UUID, go live "within days of your first inquiry".[21] Certified brokers also resell Smart-ID, and Estonian public bodies can use RIA's TARA gateway.[5]
Direct
RP contract with SK
- You call the RP API
- IP allow-list, RP UUID
- You build verification
Published price list
Through a broker
Aggregator or eID hub
- One API, several eIDs
- Broker holds the contract
- Verification done for you
Prices not published in one place
Public sector
TARA (Estonia)
- OpenID Connect, run by RIA
- Register, demo, then live
- Private firms: cross-border only
State institutions
Three ways to reach Smart-ID.[21][5]
SK's price list (from 1 June 2026) bills each "Smart-ID authentication or signing request": €0.109 with a €60 monthly minimum, down to €0.0106 on the 3 million plan, and a personal agreement above 5 million.[11] SK states that Smart-ID+ "comes at no additional cost" for existing RPs.[7]
Testing against the demo environment
Demo: https://sid.demo.sk.ee/smart-id-rp/v3/, relyingPartyUUID 00000000-0000-4000-8000-000000000000, name DEMO. Live: https://rp-api.smart-id.com/v3/.[14] Test accounts by outcome:[16]
| End result | Example document number (Estonia) | Tests |
|---|---|---|
OK | PNOEE-40504040001-DEM2-Q | Success |
USER_REFUSED | PNOEE-30403039917-MOCK-Q | User cancels |
WRONG_VC | PNOEE-30403039972-MOCK-Q | Wrong code picked |
TIMEOUT | PNOEE-30403039983-MOCK-Q | No answer |
Use cases and sector rules
- KYC and AML onboarding. Signed name and personal code; AML fit varies by country.[23][28][29]
- Gambling and age. Estonia's Gambling Act bars under-21s from games of chance (§ 34(2)) and requires remote operators to verify every player and register the personal code (§ 53(1)).[24] We found no age-only claim in the API.
- Signing. Qualified accounts sign through
v3/signature; "4 out of 10 Lithuanians used a qualified e-signature in 2025".[13][33] - Telecom. No Baltic rule names Smart-ID for SIM registration (5 October 2026).
Limits and fallbacks
"In Estonia and Latvia, Smart-ID is currently limited to people with an Estonian or Latvian national ID-numbers"; Lithuanian non-residents can get Smart-ID Basic at two banks.[22] Smart-ID has no age limit, but registration paths do (Latvian ID card from 14), and under-18 accounts need parent authorisation.[32]
We found no documented outage as of 5 October 2026; phishing is the risk. Nearly €23 million was stolen from Estonian bank accounts in 2025 by PIN scams, according to ERR News. Since 29 April 2026, Estonian registration reads the ID card over NFC instead of a card reader.[34]
1Offer Smart-ID first
Baltic personal code holders.
The session ends COMPLETE with result OK
Verify and store the result
All checks pass.
Switch to a document
NFC chip reading, liveness and face match.
2Screen and decide
AML screening, then your decision.
eID first, document fallback; record why each fallback was needed.[31]
Smart-ID API implementation checklist
Build on SK's free demo first, so the contract waits until your code works.[21] Response verification is the core of the work.[15]
- Build against the demo URL and the published test accounts.[14][16]
- Prefer device link flows; allow notification only on known devices.[13]
- Generate a fresh random
rpChallengefor every login.[20] - Pin SK's HTTPS key and keep
sessionSecreton the server.[19][18] - Run every step of SK's response verification.[15]
- Send SK your IPs and service name, then sign.[21]
- Write down your legal basis for AML use in each country.[23]
- Add a document route for users without Smart-ID.
How Didit helps with Smart-ID
Smart-ID is live on Didit for eID verification in Estonia, Latvia, Lithuania and Belgium. Didit holds the SK connection, so you skip the RP contract, the IP allow-list and the certificate code.
In the console, go to Workflows, the ID Verification step, Countries, pick the country and tick Smart-ID under "Wallets accepted". By API, set methods.EST.wallet, create a session, and read GET /v3/session/{id}/decision/ or the webhook: verification_method is "wallet" with a wallet_verification object, per the digital ID wallets docs.[35] The user approves a comparison code in the Smart-ID app. Didit never asks for the PIN.
Screenshot pending: hosted-flow-wallet-chooser
The method chooser in the Didit hosted flow.
Screenshot pending: hosted-flow-smartid-code
The comparison code the user matches in the Smart-ID app.
Screenshot pending: console-wallets-accepted
Turning Smart-ID on in the Didit console.
You get full name, date of birth, Baltic personal code, level of assurance (labelled High) and a signature check; no address, no portrait. Users without Smart-ID fall back to document verification with NFC chip reading ($0.15), liveness and face match; full KYC is $0.33 and AML screening $0.20. Only completed eID sign-ins are billed; a completed Smart-ID verification costs $0.20 (pricing page), every eID on the digital ID wallets page.
Didit provides
- The Smart-ID connection and signature check
- The document route
- AML screening and evidence of every check
Stays with you
- The risk assessment and AML reading
- The onboarding decision
- The reason for each fallback
Skip the RP contract and ship Smart-ID
Smart-ID and the document route in one API; pay only for completed checks.
Key takeaways
- The Smart-ID API (RP API v3) opens sessions with
POSTand reads them withGET. - SK recommends device link flows (QR or same-device link) over push notifications.
- You get a certificate with name and personal code, never an address or portrait.
- Rated high nationally, not EU-notified: AML fit differs by country.
Frequently asked questions
Is there a public Smart-ID API?
Yes. SK publishes the Relying Party API documentation openly; the current version is 3.2.3.[20] Live calls need an agreement, an RP UUID and allowed IP addresses.[21][19]
How much does the Smart-ID API cost?
SK's price list from 1 June 2026 starts at €0.109 per request with a €60 monthly minimum and falls to €0.0106 on the 3 million plan.[11] Broker prices are not published in one place. On Didit, a completed Smart-ID verification costs $0.20.
What data does the Smart-ID API return?
A signed certificate with the user's names and a personal code such as PNOEE-30001010004, plus a signature.[15] No address, nationality or portrait.[5]
How do I test the Smart-ID API?
Use the demo environment with SK's public demo RP UUID; it is free and needs no agreement.[14][21] Test accounts for Estonia, Latvia, Lithuania and Belgium return success, refusal, wrong code or timeout.[16]
What changed in Smart-ID RP API v3?
Version 3 adds device link flows (QR, Web2App and App2App) with their own endpoints, next to push notifications.[13][20] It also makes a random rpChallenge mandatory in every initial request, replacing the v2 nonce, against replay.[20] Version 3.2 supports both HTTP/1.1 and HTTP/2 and returns error details in the RFC 9457 format.[20]
Should I use device link or notification flows?
Device links everywhere give the most phishing protection. Across devices, device links on new devices plus push on known ones is also recommended; push alone is not.[12]
What level of assurance does Smart-ID have?
High under national assessments in Estonia, Latvia and Lithuania.[4][25][27] It is not on the EU list of notified eID schemes.[6]
Is Smart-ID enough for AML customer due diligence in Estonia?
RahaPTS § 31(3) allows a notified eID at substantial or high, or a qualified trust service.[23] No official statement says whether Smart-ID counts as the second (5 October 2026). Ask Finantsinspektsioon or counsel.
Can foreigners use Smart-ID?
In Estonia and Latvia only holders of a local personal code can register. In Lithuania, non-residents can get Smart-ID Basic at two banks; residence-permit holders and e-residents register like citizens.[22]
Can minors use Smart-ID?
Smart-ID has no age limit; the registration path sets it, for example from 6 with a passport in Estonia.[32] Under-18 accounts need parent authorisation, and SK's test accounts include minors.[32][16]
How long does a Smart-ID API integration take?
SK says "within days of your first inquiry".[21] Developer effort is not published.
Sources
- Smart-ID home page, live user counter, SK ID Solutions, read 5 October 2026.
- 2025: advancing digital trust beyond borders, SK ID Solutions, 19 January 2026.
- Trust and competition in digital identity in Europe, e-Estonia, 2026.
- Electronic identity (eID), Information System Authority (RIA).
- TARA technical specification, RIA.
- Overview of pre-notified and notified eID schemes under eIDAS, European Commission, read 5 October 2026.
- Smart-ID+, SK ID Solutions.
- How does the new Smart-ID protect me from fraud, Smart-ID FAQ.
- Estonia's government adopts Smart-ID+ to strengthen security, SK ID Solutions, 28 January 2026.
- Why do I sometimes see one confirmation code and sometimes three, Smart-ID FAQ.
- Price list, SK ID Solutions, valid from 1 June 2026.
- Relying Party API: introduction, SK ID Solutions, version 3.2.3.
- Relying Party API: overview of API endpoints, SK ID Solutions.
- Environment technical parameters, SK ID Solutions.
- Relying Party API: response verification, SK ID Solutions.
- Test accounts for automated testing, SK ID Solutions.
- Relying Party API: notification based flows, SK ID Solutions.
- Relying Party API: device link flows, SK ID Solutions.
- Relying Party API: API technical description, SK ID Solutions.
- Relying Party API: changelog, SK ID Solutions.
- Integration process for e-service providers, Smart-ID.
- Can foreigners and non-residents use Smart-ID, Smart-ID FAQ.
- Rahapesu ja terrorismi rahastamise tõkestamise seadus (RahaPTS), § 31, Riigi Teataja.
- Hasartmänguseadus (Gambling Act), Riigi Teataja.
- Elektroniskā identifikācija, Ministry of Defence of Latvia.
- Smart-ID has acquired local qualified status for authentication in Latvia, SK ID Solutions, 29 May 2023.
- Smart-ID and Mobile-ID recognised as state-approved tools in Lithuania, SK ID Solutions, 19 December 2024.
- Law on the Prevention of Money Laundering and Terrorist Financing, Art. 11, Lithuania, INFOLEX consolidated text.
- Cabinet Regulation No. 392, Latvia, likumi.lv.
- Regulation (EU) 2024/1624 (AMLR), EUR-Lex, Official Journal of 19 June 2024.
- Final Report, draft RTS under Article 28(1) AMLR, AMLA, 30 September 2026.
- Age limitations for using Smart-ID, Smart-ID FAQ.
- SK ID Solutions issued almost three million certificates in Lithuania in 2025, SK ID Solutions, 7 May 2026.
- Smart-ID registration with Estonian ID card now available via NFC, Smart-ID, 29 April 2026.
- Digital ID wallets, Didit documentation.
- Relying Party API: interactions, SK ID Solutions.
Smart-ID is one of five eIDs live in Didit's eID verification. See also what eID verification is and the BankID Sweden API guide.
Accept Smart-ID without writing certificate code
One workflow for Smart-ID, Mobile-ID and documents, billed per completed check.
Related articles
- Cl@ve integration in Spain: who can connect and what to use instead
- PhilSys verification: how businesses check the National ID
- OpenID4VP verifier guide: accepting the EUDI Wallet
- eIDAS regulation explained: what eIDAS 2 (2024/1183) changes
- National digital identity worldwide: models, leaders, standards
- National eID schemes by country: the 2026 reference list