Custom eIDAS integration development
Appfront integrates your digital service with the Dutch eIDAS node, so that citizens and businesses from other EU countries can log in with their own national eID. We connect you via a recognised eHerkenning broker over the same SAML 2.0 chain as eHerkenning, at the correct assurance level. This way you meet your European obligation to accept foreign eIDs and make your service accessible across borders.
What is an eIDAS integration?
eIDAS stands for "Electronic Identification And Trust Services", the European regulation that enables mutual recognition of national login means. A Spaniard with a Spanish eID, a Belgian with itsme or a German with the Personalausweis can thereby log in to a Dutch digital service without that person having a DigiD. For many government services, accepting these European means is a legal obligation.
In the Netherlands you do not connect directly to the eIDAS node, but via a recognised broker within the governance framework, in practice an eHerkenning broker. The broker is linked to the national node, which is managed under the direction of Logius, RvIG and RVO, among others. Your application communicates with that broker via SAML 2.0: the same technical chain you may already know from eHerkenning or DigiD.
Appfront handles the complete technical connection in line with the eIDAS documentation from Logius and the OWASP ASVS security standard: metadata exchange, PKIoverheid certificates, the SAML flow and the secure processing of the returned identity attributes. We tailor the integration to the required assurance level and to your existing login and user model.
Cross-border eID
Residents and businesses from other EU countries log in with their own nationally recognised eID. Your service receives a verified identity, without the user needing a Dutch DigiD or eHerkenning.
Levels of assurance
eIDAS has three uniform levels: low, substantial and high. We configure your integration so that the required level is enforced and lower-assurance means are properly refused.
Connection via a broker
Connecting goes through an accredited eHerkenning broker that is linked to the national eIDAS node. We take care of the SAML metadata, the certificates and the full technical integration with your application.
Our process for an eIDAS integration
We work with a proven method that removes uncertainty early and delivers a stable connection. From an initial analysis of your acceptance obligation and the required assurance level through to go-live and ongoing maintenance, every step is aimed at an integration that your own team can understand and trust.
We establish whether an acceptance obligation applies, which level of assurance your service requires, which identity attributes you need and which broker best fits your situation.
We design the SAML architecture, arrange the connection with the broker, the metadata exchange and the PKIoverheid certificates, and define a clear error-handling strategy.
Implementation of the SAML flow and attribute mapping with automated tests, structured logging and monitoring. We test in the chain's pre-production environment before going live.
Controlled go-live with validation of the chain and a safety net, followed by ongoing management, including timely certificate renewal and monitoring of the SAML chain.
What an eIDAS integration delivers in practice
Every eIDAS integration is set up specifically for your service, the required assurance level and your existing login landscape. Below are the features we most often deliver for organisations that must or want to accept European eIDs.
SAML 2.0 connection
A complete SAML 2.0 integration with the recognised broker: signed and encrypted authentication requests, validation of the returned assertion, and correct handling of the redirect flow between your service, the broker and the eIDAS node.
Attribute mapping
We securely map the returned identity attributes, such as a unique person identifier, name and date of birth, onto your own user model. This includes linking or matching with an existing account where that is necessary and permitted.
Assurance-level enforcement
Per service, or even per action, we set the minimum required level of assurance: low, substantial or high. Login attempts with a lower-assurance means are rejected cleanly and clearly, with a plain message for the user.
Certificate & metadata management
Management of PKIoverheid certificates and SAML metadata, with timely alerts and renewal before certificates expire. This prevents the login chain from failing unexpectedly due to an expired key or outdated metadata.
Combining with DigiD & eHerkenning
A single login screen offering DigiD, eHerkenning and eIDAS side by side. Users choose their means of identification, and your service receives a consistent, verified identity regardless of the channel used to log in.
Logging & error handling
Traceable, GDPR-compliant logging of authentication events in line with the relevant frameworks, plus robust error handling for situations such as an aborted login, an invalid assertion or a temporarily unavailable chain, with clear feedback to the user.
Typical use cases in practice
An eIDAS integration works out differently for every organisation. There are a number of contexts we see time and again, and for each of them we have a working setup that takes into account the acceptance obligation, the right assurance level and the connection via an accredited broker.
Government with an acceptance obligation
Municipalities, implementing bodies and other public authorities with a legal obligation to accept recognised European eID means for digital applications. We connect your service to the eIDAS node alongside your existing DigiD and eHerkenning login. See also our software for municipalities and DigiD integration.
Cross-border service delivery
Organisations in border regions that serve residents and businesses just across the border: German or Belgian citizens who work, live or run a business in the Netherlands. With an eIDAS integration they can log in with their own trusted national means, without needing to request DigiD.
Education with EU students
Universities of applied sciences and universities with international students from other EU countries who need access to digital student services. Via eIDAS, or the related federation SURFconext, they gain access with a recognised identity.
Pensions & insurers
Pension funds, insurers and financial service providers with customers living elsewhere in the EU who want to view their records or policy online. An eIDAS integration at the right assurance level gives these customers secure access to their own file.
Technology we use
An eIDAS integration runs on the SAML 2.0 chain of the trust framework, using PKIoverheid certificates and the message profiles of the recognised broker. We build the backend in the stack that suits you, so your own team can manage or further develop the implementation.
Why choose Appfront for your eIDAS integration?
Appfront has extensive experience with government and identity integrations for a wide range of organisations in the Netherlands. We always begin with a thorough analysis of your acceptance obligation, the required assurance level and your existing login landscape. An integration must not only work technically, it must also fit your way of working and the requirements of the trust framework.
For every integration, we write clear documentation and make sure your own team, or any future supplier, can understand and manage it. No black box, just transparent code and clear agreements on monitoring, alerting and maintenance.
You work with a dedicated point of contact who understands both the SAML technology and the rules of the eIDAS chain. This keeps communication short, prevents misunderstandings and speeds up decisions when choices need to be made during the connection.
Also see our related services on eHerkenning integrations, municipality websites, AI for government and custom software. Or get in touch directly for tailored advice.
- Experience with SAML 2.0 and the trust framework (eIDAS, eHerkenning, DigiD)
- Experienced in connecting via a recognised broker to the eIDAS node
- Implementing and enforcing the correct assurance levels
- Secure by default: PKIoverheid certificates, signing, encryption, scoped permissions
- Structured error handling for aborted or invalid authentications
- GDPR-compliant logging and monitoring of the chain from day one
- Clear documentation your team can read and manage
- A fixed point of contact, no account managers passed around
- Ongoing management, including timely certificate renewal
- Keeping pace with eIDAS 2.0 and EUDI wallet developments
Security and privacy in eIDAS integrations
A login integration inherently processes personal data: an eIDAS authentication returns a verified identity. The chain itself is built around PKIoverheid certificates, signed and encrypted SAML messages and strict trust agreements between the links. Appfront builds on top of this according to the OWASP ASVS: certificates and keys in secure vaults, validation of every assertion and least-privilege access to identity attributes.
We apply data minimisation and process only the attributes your service genuinely needs. We document the data flows, certificates and attribute mapping so that your record of processing activities is complete and you can demonstrate compliance with the GDPR. We configure logging in line with the standards frameworks of the trust scheme, so authentication events remain traceable without recording unnecessary data.
More on our security approach: information security policy and CVD policy.
The integration on this page concerns the existing node, through which citizens and businesses can reach you with their own national login means. The next step under the same regulation is the digital identity wallet; what is needed to accept it is set out in accepting the EUDI wallet in your software.
- GDPR-compliant data processing and data minimisation
- PKIoverheid certificates, SAML signing and encryption
- Validation of every returned assertion
- Role-based access and least-privilege principles
- Traceable logging in line with the standards frameworks
- Monitoring and alerting for chain anomalies
- Timely certificate and metadata renewal
- Documentation for your record of processing activities
Frequently asked questions about eIDAS integrations
Answers to the questions we most often receive about connecting to the eIDAS node.
An eIDAS integration lets citizens and businesses from other EU countries log in to your Dutch service with their own national eID. eIDAS is the European regulation on electronic identification and trust services, which enables mutual recognition of national login methods. In the Netherlands, you connect to the eIDAS node via an accredited eHerkenning broker, over the same SAML 2.0 chain as eHerkenning. Users log in with their own country's eID, and your service receives a verified identity at the agreed assurance level.
You need an eIDAS integration when your digital service must be accessible to residents or businesses from other EU countries. For many government services, there is a legal obligation to accept recognised European eID means. An integration is also valuable for cross-border services, educational institutions with EU students, and organisations such as pension funds and insurers with customers abroad. We will work with you to determine whether an acceptance obligation applies and which levels of assurance your service requires.
Dutch service providers do not connect directly, but through an accredited broker within the trust framework, which in practice means an eHerkenning broker. That broker is linked to the national eIDAS node, which is managed under the direction of Logius, RvIG and RVO, among others. Your application communicates with the broker via SAML 2.0, just as with an eHerkenning or DigiD integration. Appfront handles the technical connection: metadata exchange, certificate management, the SAML flow and the processing of the returned identity attributes.
eIDAS uses three uniform European levels of assurance: low, substantial and high. The level determines how certain it is that a person really is who they claim to be. Each service has a minimum required level, depending on the sensitivity of the data and the legal framework. A service set to substantial or high only accepts EU means notified at that level or higher. We configure your integration so that the correct level is enforced and lower-level means are cleanly rejected.
The eIDAS chain runs on SAML 2.0, the same standard as eHerkenning and DigiD Machtigen via the routing service. We work with SAML metadata, XML signing and encryption, PKIoverheid certificates and the message profiles of the trust framework. We build the backend integration in the stack that suits you: Node.js, Python, PHP, .NET, Java or Go. We process the returned attributes (such as a unique person or organisation identifier) and map them securely to your own user model.
The revised eIDAS 2.0 regulation was formally adopted in 2024 and introduces the European Digital Identity Wallet (EUDI wallet), which in the Netherlands is in development as the NL Wallet under the direction of the Ministry of the Interior and Kingdom Relations (BZK). The idea is that citizens will manage identity data in a wallet and share it selectively. The exact rollout, certification and acceptance timelines were still in motion in 2026 and partly postponed. We therefore build your integration on the current, production-ready SAML chain and keep an eye on wallet developments for you, so you can connect as soon as that is realistic. Always verify the current status at logius.nl.
Yes. The eIDAS chain is built around PKIoverheid certificates, signed and encrypted SAML messages and strict trust agreements between the links. Appfront builds on top of this in line with the OWASP ASVS: certificates and keys in secure vaults, validation of every SAML assertion, and least-privilege access to identity attributes. We process only the data your service genuinely needs (data minimisation), document the data flows for your record of processing activities, and set up logging that complies with the relevant standards frameworks, so you can demonstrably meet your obligations under the GDPR.
Yes. Appfront regularly takes over existing integrations with the national identity scheme, even where another party originally set them up. We review the SAML configuration, certificates and expiry dates, the attribute mapping and error handling, document the current setup and draw up a list of improvements. From that point on, we handle changes and extensions, such as a higher assurance level or an additional broker, along with monitoring, including timely certificate renewal.
Ready to build your eIDAS integration?
Tell us which service needs to accept European eID means and at which assurance level. We are happy to advise on connecting via a recognised broker, the SAML chain, and how this combines with your existing DigiD and eHerkenning login. A no-obligation first conversation will quickly give you a clear picture of the possibilities.