| connectid-identity-assurance-profile-08 | October 2025 | |
| Postnikov | Standards Track | [Page] |
This specification is a part of standards and specifications necessary to meet the requirements and obligations of the Australian Payments Plus ConnectID Scheme. There is a possibility that some of the elements of this document may be the subject to patent rights. Australian Payments Plus shall not be held responsible for identifying any or all such patent rights.¶
The ConnectID specifications consist of the following parts:¶
The ConnectID Identity Assurance profile aims to provide specific implementation guidelines for regarding the provision of identity information in the ConnectID ecosystem.¶
The key words "shall", "shall not", "should", "should not", "may", and "can" in this document are to be interpreted as described in ISO Directive Part 2. These key words are not used as dictionary terms such that any occurrence of them shall be interpreted as key words and are not to be interpreted with their natural language meanings.¶
This document specifies the method of:¶
This document is applicable to all participants engaging in ConnectID.¶
The following referenced documents are indispensable for the application of this document. For dated references, only the edition cited applies. For undated references, the latest edition of the referenced document (including any amendments) applies.¶
ConnectID-FAPI - ConnectID FAPI Security Profile¶
ConnectID-Id-Assurance ConnectID Identity Assurance Profile¶
ConnectID-Cert-Std - ConnectID Certificate Standards¶
ConnectID-Client-Reg - ConnectID Client Registration Profile¶
OAuth2-Purpose - Oauth 2 Purpose extension (individual draft)¶
ISODIR2 - ISO/IEC Directives Part 2¶
RFC3966 - The tel URI for Telephone Numbers¶
RFC4627 - JavaScript Object Notation (JSON)¶
E.164 - The international public telecommunication numbering plan¶
OIDC - OpenID Connect Core 1.0 incorporating errata set 1¶
OIDI - OpenID Connect for Identity Assurance 1.0¶
RFC4122 - A Universally Unique IDentifier (UUID) URN Namespace¶
For the purpose of this document, the terms defined in OIDC and ISO29100 apply.¶
Customer - An End-User or a user utilising the services of Relying Party and authenticating with an OP.¶
acr - Authentication Context Class Reference¶
API – Application Programming Interface¶
FAPI - FAPI Security Profile¶
OIDF - OpenID Foundation¶
OP - OpenID Provider¶
PII - Personally Identifiable Information¶
PPID - Pairwise Pseudonymous Identifier¶
The Confidential Client:¶
acr claim value using either an individual acr claim request or acr_values request parameter;¶
id_token;¶
id_token;¶
user_info endpoint;¶
purpose for each authorisation as defined in OAuth 2 Purpose extension. Purpose parameter should be limited to ASCII character set only;¶
au_connectid value in trust_framework as per the OpenID for Identity Assurance Specification, if verified_claims are requested. trust_framework should be requested as JSON request object (as defined in OpenID Connect Core 5.5.1. Individual Claims Requests);¶
au_connectid value in trust_framework string in verified_claims, if verified claims are requested.¶
We would like to thank Dave Hyland, Mark Haine, Ralph Bragg, Paul Ruskin, Igor Janicijevic, Erik Pragt and everyone for their valuable feedback and contributions that helped to evolve this specification.¶
We would also like to thank OpenID Foundation, IETF and many others who have set up the foundations for secure and safe data sharing.¶
Copyright (c) 2025 Australian Payments Plus (ConnectID)¶
Published: 31st of July 2025¶
Changes:¶
Published: 8th of July 2025¶
Changes:¶
Published: 8th of May 2024¶
Changes:¶
Published: 7th of December 2023¶
Changes:¶
Published: 21st March 2023¶
Changes:¶
Published: 10th February 2023¶
Changes:¶
purpose clarification¶
over16 and over21¶
address clarification - residential address¶
Published: 16th January 2023¶
Changes:¶
Published: 16th January 2023¶
Changes:¶
purpose per claim - the only way this currently can be done in OIDI.¶
Published: 15th November 2022¶
Changes:¶
Published: 30th September 2022¶
Changes:¶
digitalid-financial-api-04.md specification into this standalone spec¶