Custom eHerkenning integration development
Appfront builds custom eHerkenning integrations that allow businesses and organisations to log in securely to your portal or service. We connect your application via SAML to eHerkenning through a recognised broker, at the right assurance level (EH3 or EH4) and with support for chain authorisation. This way you serve business users (B2G) in a compliant, reliable manner, in line with the Dutch Electronic Access Services framework.
What is an eHerkenning integration?
eHerkenning is the Dutch digital identity service for business owners and organisations. Whereas citizens log in to government services with DigiD, companies, institutions and intermediaries use eHerkenning to log in securely for business purposes (B2G). It forms part of the Elektronische Toegangsdiensten framework, overseen by Logius, which sets out the rules, roles and standards.
In practice, an integration means that your service (the service provider) doesn't connect directly to eHerkenning, but through a recognised identity broker. Communication runs over the SAML protocol via the standardised DV-HM interface. After a successful login, eHerkenning returns structured data: the organisation's Chamber of Commerce number (KvK), the assurance level achieved and, in the case of chain authorisation, details of the intermediary acting on behalf of another party.
Appfront works in accordance with the official eHerkenning documentation and the OWASP ASVS security standard. We align the assurance level, the service catalogue and the authorisation logic with the sensitivity of your service, so the integration meets the requirements of the framework and remains reliable, even during peak periods such as tax filing or subsidy deadlines. If you also want citizens to log in, we combine this with building a DigiD integration.
Login for organisations
Entrepreneurs, businesses and institutions log in securely to your portal or service. eHerkenning identifies the organisation (KVK number) along with the authorised person — the business counterpart to DigiD for citizens.
Levels of assurance
EH2+, EH3 and EH4 correspond to the eIDAS levels Low, Substantial and High. EH3 is the de facto standard; EH4 works with a PKI certificate. Together we determine which level suits your service.
Chain authorisation
Bookkeepers, accountants and intermediaries act on behalf of another party. In addition to the KVK number, eHerkenning returns the intermediary's company name, so your service knows exactly who is logging in on behalf of which organisation.
Our process for an eHerkenning integration
We follow a proven method that removes uncertainty early and delivers a stable connection that complies with the trust framework. From determining the assurance level and choosing an accredited broker to SAML implementation, testing on pre-production and go-live, every step is aimed at an integration that your own team can understand and manage.
We determine which assurance level (EH3 or EH4) suits your service, whether chain authorisation is needed, and which attributes your application must process after login.
We set up the SAML integration with a recognised broker: metadata, certificates, the service catalogue and the DV-HM interface, with a clear error-handling strategy.
Implementation with validation of SAML responses, structured logging and monitoring. We test thoroughly on the broker's pre-production environment before going live.
Controlled go-live with validation and a safety net, followed by ongoing management, timely certificate rotation and further development.
What an eHerkenning integration delivers in practice
Every eHerkenning integration is set up specifically for your service, the required assurance level and your existing application landscape. Below are the features we most often deliver for organisations that want business users to log in securely.
SAML single sign-on
Login via eHerkenning based on the SAML protocol over the DV-HM interface. We handle metadata exchange, signing and validation of AuthnRequests and responses, and management of the SAML session within your application.
Enforcing assurance levels
For each service we configure the required level (EH2+, EH3 or EH4) and verify that the login actually took place at that level. This ensures your service meets the requirements that apply to the sensitivity of the data and transactions.
Handling chain authorisation
Intermediaries logging in on behalf of another party are correctly recognised. We process both the KvK number of the represented organisation and the details of the intermediary, so your authorisation logic grants the right permissions.
Attribute and session management
We securely link the returned attributes (KvK number, assurance level, authorisations) to your user model and sessions. We apply data minimisation so that only what is necessary is stored and processed.
Certificate & metadata management
PKIoverheid certificates and SAML metadata have expiry dates. We set up management and monitoring so that rotation happens on time and your integration doesn't fail unexpectedly, including migration to another approved broker if you prefer.
Logging, monitoring & error handling
Clear error handling for aborted or failed login attempts, with user-friendly messages and structured logging without unnecessary personal data. Monitoring and alerting detect disruptions at the broker or elsewhere in the chain.
Typical use cases in practice
An eHerkenning integration plays out very differently for each organisation. We see a number of recurring scenarios, and for each one we pay close attention to the right assurance level, mandate chains and a smooth login experience for business users.
Business portals & municipalities
Municipalities and implementing bodies with a digital business portal where companies handle their affairs. Business owners log in with eHerkenning at the appropriate level. A good fit alongside building a municipality website or software for municipalities.
Subsidy & permit portals
Portals where businesses apply for subsidies or arrange permits. Often at EH3 or higher with chain authorisation, so advisory firms and intermediaries can act on behalf of the applicant — with the right permissions and a complete audit trail for each application.
Healthcare & education (B2G)
Healthcare and education institutions that log in to government services on behalf of their organisation, or that offer portals to affiliated organisations. eHerkenning handles organisation identification; we link it to your roles and permissions model with data minimisation built in.
Business filing & registration services
Services where organisations are legally required to file returns or register, such as tax, RVO or water board services. Often at EH3/EH4 under strict regulatory frameworks. See also our custom water board software.
Technology we use
We build an eHerkenning integration using the SAML protocol over the DV-HM interface, combined with the backend stack that suits you. The exact choice depends on your existing application and the accredited broker, so that your own team can manage or further develop the connection.
Why choose Appfront for your eHerkenning integration?
Appfront has extensive experience building integrations for government and public organisations in the Netherlands. We always start with a thorough analysis of your service, the required assurance level and your existing systems. An integration must not only work technically but also comply with the Electronic Access Services Framework and work well in practice for your users.
For every integration, we write clear documentation and make sure your own team, or any future supplier, can understand and manage it. No black box, just transparent code and clear agreements on monitoring, alerting and maintenance.
You work with a dedicated point of contact who understands both the technical and the functional side. This keeps communication short, prevents misunderstandings and speeds up decisions when choices need to be made during development.
See also our wider services in custom software, AI for municipalities and government, and related integrations such as a MijnOverheid integration and SURFconext integration.
- Experience with SAML integrations and the DV-HM interface
- Familiar with the Electronic Access Services Framework
- Knowledge of assurance levels EH2+/EH3/EH4 and eIDAS
- Support for chain authorisation and intermediary scenarios
- Secure by default: PKIoverheid certificates, signature validation, scoped permissions
- Connecting via an approved broker, with testing in pre-production
- Structured error handling and clear user messages
- Comprehensive logging and monitoring with data minimisation
- Clear documentation your team can read and manage
- A fixed point of contact and ongoing management, including certificate rotation
Security and privacy for eHerkenning integrations
Logging in to government directly involves identity, authorisations and sensitive business data. eHerkenning is therefore built around strict standards within the Electronic Access Services Framework, and works with signed, encrypted SAML messages and PKIoverheid certificates. Appfront builds on top of this in line with the OWASP ASVS: certificates and keys in secure vaults, validation of signatures on all SAML responses, separated environments and regular audits of the login and authorisation flows.
We apply data minimisation: only the attributes your service genuinely needs, such as the Chamber of Commerce number, the assurance level and relevant authorisations, are processed and stored. We document the data flows so that your record of processing activities is complete and you can demonstrate compliance with the GDPR. We configure logging so that faults are traceable without recording unnecessary personal data.
We often combine an eHerkenning integration with adjacent custom work, such as housing association software or a secure Azure AD integration for staff. Questions about your situation? Get in touch.
For organisations looking ahead: the European digital identity wallet will also get a variant for legal entities, allowing matters such as signing authority to be demonstrated. What this means for your application is set out in accepting the EUDI wallet in your software.
- GDPR-compliant data processing and data minimisation
- Encryption in transit (TLS 1.2+) and at rest
- Role-based access and least-privilege principles
- Audit logs with traceable data flows
- Validation of SAML signatures and assurance level
- Monitoring and alerting for anomalies
- PKIoverheid certificate and key management with timely rotation
- Documentation for your record of processing activities
Frequently asked questions about eHerkenning integrations
Answers to the questions we are asked most often about eHerkenning connections.
An eHerkenning integration is a technical connection that lets businesses and organisations log in securely and reliably to your digital service or portal. eHerkenning is part of the Electronic Access Services trust framework, which is overseen by Logius. The integration runs through an accredited eHerkenning broker using the SAML protocol: your service sends an authentication request, the broker handles authentication and, after a successful login, returns the KVK number, the requested assurance level and the relevant authorisations.
DigiD is intended for citizens (B2C/C2G): individuals who log in to government services as private persons. eHerkenning is its business counterpart (B2G): entrepreneurs, companies and organisations that log in on behalf of a legal entity or business. Whereas DigiD identifies a person, eHerkenning identifies an organisation plus the person authorised to act for it. Many government services offer both. If you also want citizens to log in, we often combine the eHerkenning integration with a DigiD integration build.
eHerkenning has the assurance levels EH2+, EH3 and EH4. These correspond to the eIDAS levels Low, Substantial and High. EH3 (Substantial) is the most widely used level in practice and is effectively the standard for most government services. EH4 (High) works with a PKI certificate and the strictest identity verification. The required level is determined by the service provider based on the sensitivity of the service; always verify the exact level with eHerkenning.nl.
Chain authorisation allows someone to act on behalf of another party, for example an accountant, bookkeeper or intermediary logging in to a government service on behalf of an entrepreneur. The eHerkenning integration can support this: alongside the KvK number, eHerkenning also returns the business name of the intermediary, so your service knows which organisation is logging in on behalf of which party. We configure your authorisation logic so that chain authorisations are processed correctly.
Connecting does not happen directly to eHerkenning but through a recognised identity broker (herkenningsmakelaar). Your service provider application communicates via the standardised DV-HM interface (service provider to identity broker) using SAML. We handle the SAML metadata, drafting and validating AuthnRequests and responses, certificate management, setting up the service catalogue and processing the returned attributes. We first connect to a pre-production environment and test thoroughly before going live.
Yes. eHerkenning is built around strict standards within the Electronic Access Services framework and works with encrypted, signed SAML messages and PKIoverheid certificates. Appfront builds according to the OWASP ASVS: certificates and keys are kept in secure vaults, signatures are validated on all SAML responses, environments are kept separate, and logging is careful and free of unnecessary personal data. We document the data flows so that your record of processing activities is complete and you can demonstrably comply with the GDPR.
Yes. Appfront regularly takes over existing integrations, even those originally set up by another party. We review the SAML configuration, certificates, service catalogue, the assurance level used and error handling, document the current setup and propose improvements. From then on we handle changes, extensions, timely certificate rotation and monitoring, for example when migrating to a different recognised broker.
An eHerkenning integration suits any organisation offering a digital service that entrepreneurs or organisations must log in to: municipalities, provinces, water boards, implementing bodies, healthcare and education institutions, and private parties with a public task. Think of business counters, subsidy and permit portals, and business filing or registration services. Together with you, we assess which assurance level and authorisation forms fit your service.
Ready to get your eHerkenning integration built?
Tell us which service you want to connect to eHerkenning and which assurance level it requires. We are happy to help you choose a recognised broker, chain authorisation and the SAML implementation. If you want to serve both citizens and organisations, we can combine this with a DigiD integration. Book a no-obligation consultation.