FI Tupas address lookup (Finnish Market)

What is the change?

FI Tupas/BankID FI can perform address lookup for an end-user during identification for any bank supported in E-Ident FTN. The identity provider will lookup for the address and return the address in JSON format in idToken.

To use this feature address scope must be provided with ssn scope and optionally login_hint parameter in the request. Once the required request parameters are provided then address of the end user will be fetched and returned in the idToken with AUTHENTICATION_RESULT as pass, if address is available.

If address data is not available for the end user or if some error occurs while fetching address data then it will return RESULT_EXPLANATION with reason and AUTHENTICATION_RESULT as fail. All the other claims will still be returned as it is.


What this means to customers?

Customer will be able to request for address of end user in idToken in JSON format using address scope along with ssn scope and optionally login_hint parameter in the request.

IDToken examples when address lookup is not requested (No changes in idToken)

{
  "sub" : "fi_tupas:aktia:xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx",
  "amr" : [ "fi_tupas" ],
  "iss" : "https://www-ident-test.nets.no/oidc",
  "pid" : "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx",
  "nonce" : "xxxxxxxxxx",
  "ssn" : "xxxxxxxxxx",
  "fi_ssn" : "xxxxxxxxxx",
  "aud" : "****",
  "fi_tupas_pid" : "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx",
  "fi_tupas_bank" : "aktia",
  "ssn_issuing_country" : "FI",
  "exp" : 1789660745,
  "iat" : 1789659845,
  "jti" : "09iafa4d53264e0b73053gh02721320f"
}


IDToken examples with address

{
  "sub" : "fi_tupas:aktia:xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx",
  "address" : {
    "street_address" : "Jousikatu 3",
    "country" : "Suomi",
    "locality" : "Kauniainen",
    "postal_code" : "02700"
  },
  "authentication_result" : "pass",
  "amr" : [ "fi_tupas" ],
  "iss" : "https://www-ident-test.nets.no/oidc",
  "pid" : "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx",
  "nonce" : "xxxxxxxxxx",
  "ssn" : "xxxxxxxxxx",
  "fi_ssn" : "xxxxxxxxxx",
  "aud" : "****",
  "fi_tupas_pid" : "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx",
  "fi_tupas_bank" : "aktia",
  "ssn_issuing_country" : "FI",
  "exp" : 1789660745,
  "iat" : 1789659845,
  "jti" : "73aafa4d53264e0b83053fa02721320f"
}


IDToken examples when address lookup fails
{
"sub" : "fi_tupas:aktia:xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx",
"result_explanation" : "Person not found",
"authentication_result" : "fail",
"amr" : [ "fi_tupas" ],
"iss" : "https://www-ident-test.nets.no/oidc",
"pid" : "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx",
"nonce" : "xxxxxxxxxx",
"ssn" : "xxxxxxxxxx",
"fi_ssn" : "xxxxxxxxxx",
"aud" : "****",
"fi_tupas_pid" : "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx",
"fi_tupas_bank" : "aktia",
"ssn_issuing_country" : "FI",
"exp" : 1789660745,
"iat" : 1789659845,
"jti" : "98aafa4d53264e0b83053fa027989320f"
}


Planned date for pre-production: In Pre-Prod

Planned date for production: 14-Oct-2026

Need help/Have questions: Please reach out to https://ingroupe.com/in-trust-services-support-contact-page/