MPass integration procedure
IWhat is MPass?
MPass is the governmental authentication service. For citizens, it is the secure way to access online government services with a single identity. For you, as an integrator, it is the way to give your users secure access without having to manage the authentication infrastructure yourself.
One access point, multiple methods: electronic signature, EVOSign, identity card and 2-step authentication.
Established in accordance with Government Decision No. 1090 of 31 December 2013.
IIIntegration into information systems
The cost of integration depends on the type of your institution. Check below what applies to you:
| Institution type | Cost |
|---|---|
| Public institutions | Free |
| Private institutions | 10 800 MDL/year per system |
Steps
- Fill in the connection form;
- Sign the electronic contract via MSign.If you already have a contract with AGE, you only sign the MPass annex;
- Obtain a system certificate from the Information Technology and Cyber Security Service for the test environment and a separate one for the production environment;
- Fill in the integration form;
- Get access to the test environment and check that everything works;
- Pass the integration tests;
- We activate the production environment.
Need technical details? The full documentation (SAML 2.0 configuration, endpoints, code samples and integration libraries) is available on the eGov4Dev developer portal.
IIIBefore you start. What do you need to prepare?
-
System certificate requested from the Information Technology and Cyber Security Service;
Do you already have a certificate used for other government services (MSign, MPower, MNotify)? You can reuse it for all “M” products.
-
Public key (.cer). Send only the
.cerfile. Do not send files containing the private key:.pfx,.key,.pem. - Active contract with AGE. If you already have one, you only sign the MPass annex.
IVHaving difficulties?
- Haven't received the system certificate?
- Check whether your request has been received by the Information Technology and Cyber Security Service. If you already have a certificate used for MSign, MPower or MNotify, it can be used for the test environment.
- Is the certificate invalid or expired?
- Request a new certificate from the Information Technology and Cyber Security Service and send the new public key (.cer) to AGE.
- Is the integration failing the tests?
- AGE will send you the necessary remarks and recommendations. Once the corrections are made, you can request the tests to be run again.
- Can the same certificate be used for test and production?
- No. The test and production environments use separate certificates. After the tests have been completed successfully, a new certificate must be requested for the production environment.
- Is the submitted data incomplete?
- The 5 working day period starts only after all the required information has been received. If the form is incomplete, AGE will ask you to complete it.