User attributes
Login.gov user accounts are either identity proofed or self-asserted.
Here are the possible attributes that can be requested at a given IAL. This table contains the available user attributes, the IAL they are associated with, and how they can be accessed in OpenID Connect (OIDC) and SAML.
It is important to expect any number of characters in the (string)
datatype unless directly followed by a number such as (string36)
. Strings are encrypted and stored in a text datatype with a maximum length of 65,535 bytes.
Attribute | IAL1 | ID Proofed | OpenID Connect | SAML |
---|---|---|---|---|
UUID |
|
|
|
|
Email |
|
|
Requires the |
|
All emails |
|
|
|
|
IAL |
|
|
|
See SAML IAL values |
AAL |
|
|
|
See SAML AAL values |
First name |
|
Requires |
|
|
Last name |
|
Requires |
|
|
Address |
|
The address claim, containing: |
|
|
Phone* |
|
Requires the |
|
|
Date of birth |
|
Requires |
|
|
Social security number |
|
Requires the |
|
|
Verification timestamp* |
|
|
Seconds since the Unix Epoc Requires the |
|
x509 |
|
|
Requires the |
n/a |
x509 Issuer |
|
|
Requires the |
|
x509 Subject |
|
|
Requires the |
|
x509 Presented |
|
|
Requires the |
|
* Please note that only phone
and verified_at
idV user attributes may be returned as null.