Connectors

ConnectID Connector

The ConnectID connector lets you request verification of a customer’s identity through ConnectID in your PingOne DaVinci flow.

ConnectID is an identity exchange accredited by the Australian Government that lets customers prove who they are using an organization they already trust, such as their bank. Customers verify themselves with a trusted institution, and their data is shared with your business through a secure API. ConnectID doesn’t see or store personal information. The connector is a FAPI compliant OpenID Connect (OIDC) connector that lets you participate as a relying party in the ConnectID ecosystem.

Setup

Resources

You can find more information and setup help in the following:

Requirements

To use the connector, you’ll need:

  • A PingOne account.

  • A ConnectID account with administrator access.

  • The client ID, KID, and CA certificate issued to you by ConnectID.

  • A PingOne signing key ID and PingOne outbound mTLS key ID.

Configuring the ConnectID connector

Add the connector in PingOne DaVinci as shown in Adding a connector, then configure it as follows.

Connector configuration

Setting Description

Redirect URL

The PingOne DaVinci callback URL for this connector. This value is provided automatically as a read-only field and allows ConnectID to continue the flow. Copy it into your ConnectID configuration.

Client ID

The client ID provided to you by ConnectID.

PingOne Signing Key ID

The UUID of the PingOne signing key used to sign requests.

PingOne mTLS Key ID

The UUID of the PingOne outbound mTLS key used for mutual TLS connections.

ConnectID CA Certificate

The ConnectID certificate authority certificate.

ConnectID KID

The key ID provided to you by ConnectID.

Scope

The scopes to send to ConnectID to customize the verification process. The default is openid.

Application Redirect URL

Optional. Your application’s redirect URL, such as https://app.yourorganization.com/. Enter this URL if you embed the PingOne DaVinci widget in your application so that PingOne DaVinci can redirect the browser back to your application.

Using the connector in a flow

Verifying a customer’s identity as a relying party

The Verify as a Relying Party capability requests verification of a customer’s identity through the ConnectID service and returns the verified claims to your flow.

At a high level:

  1. The Verify as a Relying Party capability sends an authorization request to ConnectID with the well-known configuration endpoint and claims object you specify in the node. The claims object is a JSON value that can include PingOne DaVinci parameters, which are replaced at runtime.

  2. The customer verifies their identity with a trusted institution, such as their bank, and consents to share the requested data.

  3. ConnectID redirects back to PingOne DaVinci and the capability outputs the verified claims, including the token response, that you can evaluate in your flow.

Test the flow by clicking Save, Deploy, and Try Flow.

Capabilities

Verify as a Relying Party

This capability allows you to participate as a Relying Party in the ConnectID ecosystem for verification purposes.

Show details
  • Properties

  • Output Schema

Well-Known Configuration Endpoint textField required

ConnectID Well-Known Configuration Endpoint

Claims Object (JSON) textArea

This property needs to be a properly formatted JSON value. It can contain DaVinci parameters, which will be replaced at runtime. If you are using DaVinci parameters that are of type 'string', you will need to put string quotes around it.

Default:

{
 "id_token": {
 "verified_claims": {
 "verification": {
 "trust_framework": "au_connectid"
 },
 "claims": {
 "over18": {
 "essential": true
 }
 }
 },
 "txn": {
 "essential": true
 },
 "name": {
 "essential": true
 },
 "given_name": {
 "essential": true
 },
 "middle_name": {
 "essential": true
 },
 "family_name": {
 "essential": true
 },
 "email": {
 "essential": true
 },
 "birthdate": {
 "essential": true
 },
 "phone_number": {
 "essential": true
 },
 "address": {
 "essential": true
 }
 }
}
  • output object

    • statusCode integer

    • rawResponse object

    • tokenResponse object

      • id_token object

      • access_token string

      • token_type string

      • expires_in number