Skip to content

ESP APIs (26.0.0)

ESP APIs provide authentication flows via SPID, CIE, CNS, and EIDAS. Use these endpoints to obtain a session key, initiate a login, and retrieve a JWT containing the user's identity attributes.

Download OpenAPI description
Overview
License
Languages
Servers
Development and testing environment
https://esp-saas.test.namirialtsp.com
Production environment
https://esp-saas.namirialtsp.com

Get Key

Returns a session key (authnKey) to initiate an authentication flow with SPID, CIE, or EIDAS.

Operations

Login

Initiates the authentication flow with SPID/EIDAS, CIE, or CNS.

Operations

Login with SPID/EIDAS with a browser

Request

Path
environment_namestringrequired

The environment path provided by Namirial during the assessment phase

Example: myintegration
Query
referencestring<= 50 characters^[A-Za-z0-9]{1,50}$

Client reference for billing purposes.

Example: reference=mycustomer
finalstringrequired

Redirect URL called at the end of the authentication process. Provided during the assessment phase.

Example: final=http://localhost
authnKeystringrequired

The authn key obtained from the getKey endpoint

Example: authnKey=c1BUQkJ4d3hYUWV6ZEQ4TktlSWV6ZmozVy9HNzNrQlcyRFlvMTB1TTlGKzE3dWNjdHNLV2RUN0pVNTNJQnhsVnNMMWhBS0lucGNxMC9qY0c3U3BWYlc5dktOMXFvVkhyYUIrdDFBd1VBWGM5bERzS1RnVzd1V251R3pWUEpiUmc
curl -i -X GET \
  'https://esp-saas.test.namirialtsp.com/myintegration/spidlogin?reference=mycustomer&final=http%3A%2F%2Flocalhost&authnKey=c1BUQkJ4d3hYUWV6ZEQ4TktlSWV6ZmozVy9HNzNrQlcyRFlvMTB1TTlGKzE3dWNjdHNLV2RUN0pVNTNJQnhsVnNMMWhBS0lucGNxMC9qY0c3U3BWYlc5dktOMXFvVkhyYUIrdDFBd1VBWGM5bERzS1RnVzd1V251R3pWUEpiUmc'

Responses

Redirects the browser to the identity provider login page. After successful authentication, the user is redirected to the final URL with sessionid and sessionkey query parameters. Pass them to the Get user token endpoint to retrieve the JWT.

Login with CIE with a browser

Request

Path
environment_namestringrequired

The environment path provided by Namirial during the assessment phase

Example: myintegration
Query
finalstringrequired

Redirect URL called at the end of the authentication process. Provided during the assessment phase.

Example: final=http://localhost
authnKeystringrequired

The authn key obtained from the getKey endpoint

Example: authnKey=c1BUQkJ4d3hYUWV6ZEQ4TktlSWV6ZmozVy9HNzNrQlcyRFlvMTB1TTlGKzE3dWNjdHNLV2RUN0pVNTNJQnhsVnNMMWhBS0lucGNxMC9qY0c3U3BWYlc5dktOMXFvVkhyYUIrdDFBd1VBWGM5bERzS1RnVzd1V251R3pWUEpiUmc
curl -i -X GET \
  'https://esp-saas.test.namirialtsp.com/myintegration/cielogin?final=http%3A%2F%2Flocalhost&authnKey=c1BUQkJ4d3hYUWV6ZEQ4TktlSWV6ZmozVy9HNzNrQlcyRFlvMTB1TTlGKzE3dWNjdHNLV2RUN0pVNTNJQnhsVnNMMWhBS0lucGNxMC9qY0c3U3BWYlc5dktOMXFvVkhyYUIrdDFBd1VBWGM5bERzS1RnVzd1V251R3pWUEpiUmc'

Responses

Redirects the browser to the identity provider login page. After successful authentication, the user is redirected to the final URL with sessionid and sessionkey query parameters. Pass them to the Get user token endpoint to retrieve the JWT.

Login with CNS with a browser

Request

Path
environment_namestringrequired

The environment path provided by Namirial during the assessment phase

Example: myintegration
Query
finalstringrequired

Redirect URL called at the end of the authentication process. Provided during the assessment phase.

Example: final=http://localhost
authnKeystringrequired

The authn key obtained from the getKey endpoint

Example: authnKey=c1BUQkJ4d3hYUWV6ZEQ4TktlSWV6ZmozVy9HNzNrQlcyRFlvMTB1TTlGKzE3dWNjdHNLV2RUN0pVNTNJQnhsVnNMMWhBS0lucGNxMC9qY0c3U3BWYlc5dktOMXFvVkhyYUIrdDFBd1VBWGM5bERzS1RnVzd1V251R3pWUEpiUmc
curl -i -X GET \
  'https://esp-saas.test.namirialtsp.com/myintegration/cnslogin?final=http%3A%2F%2Flocalhost&authnKey=c1BUQkJ4d3hYUWV6ZEQ4TktlSWV6ZmozVy9HNzNrQlcyRFlvMTB1TTlGKzE3dWNjdHNLV2RUN0pVNTNJQnhsVnNMMWhBS0lucGNxMC9qY0c3U3BWYlc5dktOMXFvVkhyYUIrdDFBd1VBWGM5bERzS1RnVzd1V251R3pWUEpiUmc'

Responses

Redirects the browser to the identity provider login page. After successful authentication, the user is redirected to the final URL with sessionid and sessionkey query parameters. Pass them to the Get user token endpoint to retrieve the JWT.

Login with SPID with a browser
Deprecated

Request

Path
environment_namestringrequired

The environment path provided by Namirial during the assessment phase

Example: myintegration
Query
levelinteger

Authentication level. Accepted values: 1, 2, 3.

Default 1
Enum123
Example: level=2
attributesstringrequired

Attribute set to request. Accepted values: Base, Full.

Enum"Base""Full"
Example: attributes=Full
finalstringrequired

It's the redirect url called at the end of the authentication process (It should be communicated during the assessment phase)

Example: final=http://localhost
authnKeystringrequired

The authn key obtained from the getKey endpoint

Example: authnKey=c1BUQkJ4d3hYUWV6ZEQ4TktlSWV6ZmozVy9HNzNrQlcyRFlvMTB1TTlGKzE3dWNjdHNLV2RUN0pVNTNJQnhsVnNMMWhBS0lucGNxMC9qY0c3U3BWYlc5dktOMXFvVkhyYUIrdDFBd1VBWGM5bERzS1RnVzd1V251R3pWUEpiUmc
curl -i -X GET \
  'https://esp-saas.test.namirialtsp.com/myintegration/spidlogin.php?level=2&attributes=Full&final=http%3A%2F%2Flocalhost&authnKey=c1BUQkJ4d3hYUWV6ZEQ4TktlSWV6ZmozVy9HNzNrQlcyRFlvMTB1TTlGKzE3dWNjdHNLV2RUN0pVNTNJQnhsVnNMMWhBS0lucGNxMC9qY0c3U3BWYlc5dktOMXFvVkhyYUIrdDFBd1VBWGM5bERzS1RnVzd1V251R3pWUEpiUmc'

Responses

Redirects the browser to the identity provider login page. After successful authentication, the user is redirected to the final URL with sessionid and sessionkey query parameters. Pass them to the Get user token endpoint to retrieve the JWT.

Login with CIE with a browser
Deprecated

Request

Path
environment_namestringrequired

The environment path provided by Namirial during the assessment phase

Example: myintegration
Query
levelinteger

Authentication level. Accepted values: 1, 2, 3.

Default 1
Enum123
Example: level=2
attributesstringrequired

Attribute set to request. Accepted values: Base, Full.

Enum"Base""Full"
Example: attributes=Full
finalstringrequired

Redirect URL called at the end of the authentication process. Provided during the assessment phase.

Example: final=http://localhost
authnKeystringrequired

The authn key obtained from the getKey endpoint

Example: authnKey=c1BUQkJ4d3hYUWV6ZEQ4TktlSWV6ZmozVy9HNzNrQlcyRFlvMTB1TTlGKzE3dWNjdHNLV2RUN0pVNTNJQnhsVnNMMWhBS0lucGNxMC9qY0c3U3BWYlc5dktOMXFvVkhyYUIrdDFBd1VBWGM5bERzS1RnVzd1V251R3pWUEpiUmc
curl -i -X GET \
  'https://esp-saas.test.namirialtsp.com/myintegration/cielogin.php?level=2&attributes=Full&final=http%3A%2F%2Flocalhost&authnKey=c1BUQkJ4d3hYUWV6ZEQ4TktlSWV6ZmozVy9HNzNrQlcyRFlvMTB1TTlGKzE3dWNjdHNLV2RUN0pVNTNJQnhsVnNMMWhBS0lucGNxMC9qY0c3U3BWYlc5dktOMXFvVkhyYUIrdDFBd1VBWGM5bERzS1RnVzd1V251R3pWUEpiUmc'

Responses

Redirects the browser to the identity provider login page. After successful authentication, the user is redirected to the final URL with sessionid and sessionkey query parameters. Pass them to the Get user token endpoint to retrieve the JWT.

Logout

Initiates the SPID logout flow. Not required for Level 2 authentications.

Operations

Get user

Exchanges the session id and key (returned after login) for a JWT containing the user's identity attributes.

Operations