SPID integration: how businesses accept Italy's SPID login
How a business accepts SPID: the user flow, the attributes and tax code you receive, AgID prices per unique user, levels and AML rules, aggregators vs direct conventions, and fallbacks for foreigners.

In short
SPID (Sistema Pubblico di Identità Digitale) is Italy's federated public digital identity: private identity providers accredited by AgID issue the logins, and any service that signs AgID's convention can accept them.[1][3] There is no single SPID API: a business connects through the federation's SAML2 or OpenID Connect rules, directly or through an aggregator, and pays identity providers per unique user.[4][6]
- EU-notified at Low, Substantial and High.[2]
- SPID at level 2 or above counts as remote identification under Italian anti-money laundering (AML) law.[8]
- It returns name, family name, place and date of birth, gender, tax code and SPID code; no portrait.[5]
If you searched for a SPID API, the short answer is that SPID is not one endpoint. It is a federation run by AgID (Agenzia per l'Italia Digitale), where a dozen private identity providers (IdPs) hold the user accounts and every service provider plugs into the same rules.[1][2] Public administrations must accept SPID, and private companies may join.[4]
This guide is for a business that wants to accept SPID as a relying party (RP): the user flow, the data, the law, the routes, the prices and the fallbacks.
What SPID is
SPID is a login, not a card. A person opens an identity with one accredited provider and uses it to sign in anywhere in the federation.[1] The provider asks for a valid identity document plus the health card or the tax-code card.[1]
SPID
Italy's public system of digital identity
Adoption: how many people use SPID
Logins grew from 143,872,687 in 2020 to 1,220,153,029 in 2025.[1] New identities have slowed, from about 262,000 a week in late 2020 to about 46,000 a week in March 2026.[1]
AgID's page gives no total of identities and no share of adults as of 5 October 2026. According to SmartWorld, citing AgID data, over 41 million citizens hold SPID.
What the user sees
Screens vary by identity provider. The strip shows the usual pattern, not any one provider's design.
Verify your identity
Sign in with your public digital identity.
Entra con SPID
Use an ID document instead
1The user taps "Entra con SPID" on your sign-up page.
Choose your provider
Pick the provider that issued your SPID.
- Provider ASelect
- Provider BSelect
- Provider CSelect
2The user picks their identity provider from the standard list.
Sign in
Enter your SPID username and password.
Sign in
3The user enters their username and password on the provider's page.
Confirm sign-in
Confirm with your provider's second step.
Confirm
4At level 2, the user confirms with the provider's second step.
Share your data
- NameShared
- Date of birthShared
- Tax codeShared
Allow
5The user allows the requested data and returns with a signed response.
No cross-device variant is documented for SPID as a whole; it depends on the provider.
Video pending: flow-redirect
A redirect sign-in with a national eID, start to finish.
What a SPID service provider receives
AgID's attribute table (version 1.3, 24 June 2022) splits the data into an identity set and extra attributes.[5] The split matters for price: asking only for identity attributes is "authentication"; asking for any extra attribute is "registration" and costs more.[6]
| Group | Attributes (AgID names) | When you get them |
|---|---|---|
| Identity set | spidCode, name, familyName, placeOfBirth, countyOfBirth, dateOfBirth, gender, fiscalNumber | Authentication mode |
| Contact | mobilePhone, email, digitalAddress (certified email, PEC) | Registration mode, if requested |
| Residence and document | address, domicile, idCard (type, number, issuer, expiry), expirationDate | Registration mode, if requested |
| Company | companyName, companyFiscalNumber, registeredOffice, ivaCode | Registration mode, if requested |
| Portrait | None: no photo attribute in the table | Never |
SPID attributes by group.[5][6]
The national identifier is the Italian tax code, returned as fiscalNumber. The spidCode identifies the SPID identity itself. Version 1.3 also introduced the OpenID Connect scopes "profile" and "email".[5] With no portrait, a face match needs a separate document and selfie step.
Level of assurance and legal standing
On the European Commission's list of notified schemes, SPID levels 1, 2 and 3 map to the eIDAS (electronic identification, authentication and trust services regulation) levels Low, Substantial and High. Italy notified SPID on 10 September 2018 (Official Journal 2018/C 318/02, amended three times since).[2]
In national law, SPID is the public system for managing digital identities under Article 64 of the Digital Administration Code (CAD, Legislative Decree 82/2005).[8]
SPID and AML customer due diligence in Italy
Article 19(1)(a)(2) of Legislative Decree 231/2007 treats a customer who holds a digital identity of at least "significativo" (Substantial) level in the CAD Article 64 system as identified without being physically present.[8]
Article 19(1)(a)(2)Legislative Decree 231/2007
"L'obbligo di identificazione si considera assolto, anche senza la presenza fisica del cliente, nei seguenti casi: [...] 2) per i clienti in possesso di un'identità digitale, con livello di garanzia almeno significativo, nell'ambito del Sistema di cui all'articolo 64 del predetto decreto legislativo n. 82 del 2005 [...]"
Source: Normattiva, Legislative Decree 231/2007, Article 19[8]
The same provision covers Substantial identities from EU-notified schemes and qualified signature certificates.[8] SPID level 1 does not qualify, so request level 2 or 3.
The AMLR from 10 July 2027
The EU Anti-Money Laundering Regulation (AMLR, Regulation (EU) 2024/1624) applies from 10 July 2027.[9] Article 22(6)(b) allows verification through "electronic identification means which meet the requirements of Regulation (EU) No 910/2014 with regard to the assurance levels 'substantial' or 'high'".[9] Our reading, not a regulator's: SPID at level 2 or 3 fits. In its final report of 30 September 2026 on draft standards, not yet law, the AMLA (Anti-Money Laundering Authority) states that both Article 22(6) means, document and eID, "are still the default option with alternative verification methods only to be used when neither of the two means required by AMLR can be used".[10]
- 10 September 2018NotifiedSPID enters the EU list at three levels.
- 10 September 2019EU-wideUsable for every EU public administration.
- 12 November 2025Age rulesAGCOM age checks start for Italian and non-EU sites; other Member States follow on 1 February 2026.
- 16 to 18 January 2026RegistryThe SPID Registry moves to the cloud.
- 10 July 2027AMLREU-wide eID route for customer due diligence.
SPID milestones that matter to a business.[1][2][9][12]
How a business connects: the SPID API routes
A private company becomes a SPID service provider in four steps: implement the AgID technical rules (SAML2), send its metadata to AgID for checks and testing, implement the eIDAS node where levels 2 or 3 are used, and have its legal representative sign the SPID convention with AgID, which then informs the identity providers.[4] AgID's SPID page also lists Determination 71/2025, on the "SPID OpenID Connect Federation" rules.[1]
Every federation role except the user signs a convention with AgID, including aggregators, which connect service providers.[3] Certified brokers that offer several eIDs behind one integration also exist.
Direct
Your own service provider convention
- You run SAML2 or OpenID Connect yourself
- AgID checks and tests your metadata
- Your legal representative signs with AgID
Fits high volume and in-house teams
Aggregator
Connect through a SPID aggregator
- The aggregator holds the federation link
- It signs its own convention with AgID
- You sign a contract with the aggregator
Fits small teams with one scheme
Multi-eID broker
One integration, many eIDs
- SPID next to other national eIDs
- One response format across schemes
- Document fallback in the same flow
Fits cross-border onboarding
Three ways to connect to SPID.[3][4]
What SPID costs a business
AgID's Annex 4 (DT 166/2019) uses a "pay per user" model: each unique user is billed once a year, per identity provider and per service provider.[6] The first 1,000 unique users in authentication mode are free for each service provider and identity provider pair.[6]
| Unique users a year, per IdP | Authentication, levels 1 and 2 | Registration, levels 1 and 2 | Authentication, level 3 | Registration, level 3 |
|---|---|---|---|---|
| 0 to 1,000 | €0 | €3.50 | €0 | €7 |
| Over 1,000 | €0.40 | €3.50 | €7 | €7 |
AgID public prices for private service providers, VAT excluded.[6]
AgID does not publish aggregator or broker prices, or an onboarding lead time, as of 5 October 2026.
Use cases and sector rules
| Use case | What the rules say | Source |
|---|---|---|
| KYC (Know Your Customer) and AML onboarding | Level 2 or above counts as remote identification | Normattiva[8] |
| Online gambling accounts | According to Informazione Fiscale, the customs and monopolies agency (ADM) allows accounts opened with SPID or the electronic identity card (CIE) from 13 November 2025 | Informazione Fiscale |
| Age checks for adult sites | SPID as it stands is not fully compliant with AGCOM's double-anonymity rule | AGCOM[11] |
Age checks. Decree-Law 123/2023 (Article 13-bis) obliges porn sites serving Italy to verify that users are adults; AGCOM Resolution 96/25/CONS sets the method.[11] Obligations apply from 12 November 2025 for sites in Italy or outside the EU and from 1 February 2026 for sites in other Member States.[12] The resolution requires "double anonymity": the age-proof provider must not learn which site is visited.[11] AGCOM's Annex A says SPID is not fully compliant, because the request sent to the identity provider "contiene il nome a dominio del sito visitato" (contains the domain name of the visited site).[11] AGCOM's list of covered services held 79 entries on 29 September 2026.[13] Elsewhere, SPID's signed date of birth proves age without a document photo; see what eID verification is.
Limits and fallbacks
- Minors. All adults can activate SPID. A parent with level 2 SPID can request one for a minor under AgID Determination 133/2022.[7]
- Foreigners and non-residents. The provider asks for an Italian identity document (identity card, passport or driving licence), the health card or tax-code card, an email and a personal mobile.[7]
- Provider fees for users. According to CorCom, some identity providers started charging users an annual fee in 2025.
- Convention horizon. According to SmartWorld, the identity provider conventions were renewed in October 2025 for 24 months, extendable by up to 36 months.
- Security. AgID Determination 241/2025 tightened the tax-code check at issuance.[1]
CIE is notified at Low, Substantial and High, and a private company already admitted to SPID can rely on that admission for the CIE federation's fit-and-proper requirements.[2][14] See CIE ID integration. The IT-Wallet, opened with CieID or SPID, reached 10.1 million activations by 17 February 2026; see the EU Digital Identity (EUDI) Wallet page and IT-Wallet for businesses.[15]
For everyone else, the document route reads the passport or ID card chip over NFC (near-field communication), checks liveness and matches the face. AMLA's draft standards keep alternative solutions for customers who cannot be verified through either Article 22(6) means, and the firm must justify why.[10] How NFC chip verification works explains the chip check.
1Offer SPID first to Italian users
Request level 2 or above for AML onboarding.
The user completes SPID at the level you asked for
Use the signed attributes
Name, date of birth and tax code from the provider.
Fall back to the document route
NFC chip reading, liveness and face match; record why.
2Screen and decide
Sanctions and politically exposed person (PEP) screening, then your decision.
eID first, document route as fallback.
SPID API integration checklist
- Decide the route: direct convention, aggregator or multi-eID broker.[3]
- Set the minimum level: level 2 for AML onboarding.[8]
- List the attributes you need and stay in authentication mode where you can.[6]
- Budget per unique user, per identity provider, per year.[6]
- Submit your metadata to AgID for checks and testing.[4]
- Add CIE for users who hold the card but no SPID.[14]
- Build a document fallback for users without SPID.
- Keep SPID out of adult-content age gates unless the double-anonymity rule is met.[11]
How Didit helps with eID verification in Italy
Didit adds SPID on request. In Italy today, Didit verifies users with the document route: NFC chip reading, liveness and face match, plus AML screening against sanctions, PEP and watchlists, in one workflow. A full KYC check costs $0.33, NFC verification $0.15 and AML screening $0.20. The digital ID wallets docs show how national eIDs sit next to the document route.
Didit provides
- Document checks with NFC chip reading, liveness and face match
- AML screening against sanctions, PEP and watchlists
- The evidence of every check
Stays with you
- The risk assessment and the AML policies
- The onboarding decision
- The choice of which eIDs to accept
Bring SPID to your sign-up
Tell us where your users sign in, and start with the document route today.
Key takeaways
- SPID is a federation, not one API: connect under AgID's SAML2 or OpenID Connect rules, directly or through an aggregator.
- Private service providers pay per unique user a year, and the first 1,000 authentication users per identity provider and service provider are free.
- SPID at level 2 or above counts as remote identification under Article 19 of Legislative Decree 231/2007.
- SPID returns no portrait and, per AGCOM, does not fully meet double anonymity for adult-site age checks.
Frequently asked questions
How much does SPID cost for a business?
In authentication mode, the first 1,000 unique users a year per identity provider and per service provider are free, then €0.40 per unique user at levels 1 and 2; requesting extra attributes costs €3.50 per user. Level 3 costs €7 per user, except authentication for the first 1,000. Prices exclude VAT.[6]
What data does SPID return?
Name, family name, place and county of birth, date of birth, gender, tax code and SPID code. Contact, address, document and company data come only in registration mode. There is no portrait.[5]
Does SPID satisfy AML customer due diligence in Italy?
Yes, at level 2 or above. Article 19(1)(a)(2) of Legislative Decree 231/2007 treats a digital identity of at least Substantial level in the SPID system as remote identification.[8]
What level of assurance does SPID have?
SPID levels 1, 2 and 3 map to the eIDAS levels Low, Substantial and High. Italy notified the scheme to the European Commission on 10 September 2018.[2]
Can minors use SPID?
SPID is for adults by default. A parent with level 2 SPID can request an identity for a minor under AgID Determination 133/2022.[7]
Can foreigners get SPID?
Only with Italian papers: an Italian identity document plus the health card or tax-code card.[7] Plan a document route for foreign customers.
Can I use SPID for age verification on adult sites in Italy?
Not as it stands. AGCOM Resolution 96/25/CONS requires double anonymity, and AGCOM found SPID not fully compliant because the request to the identity provider contains the site's domain name.[11]
How long does a SPID integration take?
AgID does not publish a lead time as of 5 October 2026. The steps are implementing the technical rules, AgID's metadata checks and testing, and signing the convention.[4]
How do I test a SPID integration?
You submit your service provider metadata to AgID, which checks and tests it before the convention is signed.[4] AgID's provider page does not publish a timetable for that testing.
Will SPID count under the AMLR from 2027?
Our reading is yes at level 2 or 3: from 10 July 2027, Article 22(6)(b) accepts eIDAS means at Substantial or High.[9]
Sources
- SPID, AgID, updated 13 April 2026.
- Overview of pre-notified and notified eID schemes under eIDAS, European Commission, updated 2 February 2026.
- SPID, Convenzioni, AgID.
- Diventa fornitore di servizi, spid.gov.it.
- Tabella attributi SPID, version 1.3, AgID, 24 June 2022.
- Allegato 4, Corrispettivi (DT 166/2019), AgID.
- Identità digitale, FAQ, AgID.
- Legislative Decree 231/2007, Article 19, Normattiva.
- Regulation (EU) 2024/1624 (AMLR), Articles 22 and 90, EUR-Lex.
- Final Report, draft RTS under Article 28(1) AMLR, AMLA, 30 September 2026.
- Delibera 96/25/CONS and Annex A, AGCOM, 8 April 2025.
- Tutela minori, age verification, AGCOM.
- Comunicazione 30 ottobre 2025, list version 5, AGCOM, 29 September 2026.
- Federazione CIE, Manuale operativo, Ministry of the Interior.
- IT-Wallet supera quota 10 milioni di attivazioni, Department for Digital Transformation, 17 February 2026.
Compare SPID with every other national eID on the eID verification page.
Verify Italian users today
Start with chip reading, liveness and face match, and add SPID when your volume calls for it.
Related articles
- Cl@ve integration in Spain: who can connect and what to use instead
- PhilSys verification: how businesses check the National ID
- OpenID4VP verifier guide: accepting the EUDI Wallet
- eIDAS regulation explained: what eIDAS 2 (2024/1183) changes
- Smart-ID API: a developer's guide to RP API v3
- National digital identity worldwide: models, leaders, standards