On this page you will find the root CA certificates used to issue all signing and encryption keys used in BankID OIDC.
Download the certificates below for the given environment and use it to validate the certificate chain of all JWK keys received by BankID OIDC.
We will always announce when it is time for CA certificates to be renewed. The new certificates will always be published on this page.
x5c Certificate chain
The JWKs endpoints will return keys with the claims x5t, x5t#S256 and x5c. for the x5c chain are published below per environment.
- The downloaded certificate shall be equal to the value found in the last entry in the certificate chain.
- The first entry in the chain shall contain the key defined by the JWK itself.