Verifying eID (France Identité) (v1)
FRANCE_IDENTITE:v1 is deprecated. Use the Verifying eID (v2) step instead — it supports France Identité alongside other eID providers through a unified configuration. Migrate your existing flows to EIDS:v2.
Verifies a user’s identity using the France Identité mobile app
Provides a secure verification option where users prove their identity through France’s national digital identity app. Ideal for fast, trusted onboarding or identity verification processes.
Key features
- OIDC-based authentication: Secure authentication using France Identité via OpenID Connect.
- Seamless redirection: Redirects users to France Identité for login and returns them post-authentication.
- Ready-to-use: No additional configuration needed for integration.
Configuration
| Option | Type | Required | Default | Description |
|---|---|---|---|---|
enableRetry | boolean | No | false | When true, adds a retry output route that can be used to handle user cancellations. |
Example configuration
{
"enableRetry": false
}
Input data blocks
This step does not consume any input data blocks.
Routes
| Route | Description |
|---|---|
verified | The user's identity has been successfully authenticated by the France Identité wallet. The user has consented to sharing their data, and the OIDC flow has completed with the reception of an ID Token containing the verified attributes. |
not_verified | The authentication attempt failed. The identity could not be verified because the user failed to authenticate with their wallet (e.g., by entering an incorrect PIN). |
retry | Available only when enableRetry is true. Taken when the user clicks the Go back button. Returns a rollback transition to the retry step. |
:::info User cancellation vs. retry
The close button (X) in the header always aborts the session — it is not affected by enableRetry and never routes to retry. Only the Go back button (visible when enableRetry: true) takes the retry route.
:::
Output data blocks
| Route | Data blocks produced |
|---|---|
verified | BasicIdentity, ExtendedIdentity, AuthenticationResult |
not_verified | AuthenticationResult |
retry | AuthenticationResultAvailable only when enableRetry is true. |
Usage name vs birth name
Some users have two last names: a usage name (nom d'usage, e.g. a married surname) and a birth name (nom de naissance). France Identité communicates both when they differ.
The Trust Platform maps them as follows:
| Scenario | basicIdentity.familyName | extendedIdentity.familyNameBirth |
|---|---|---|
| Usage name present | Usage name | Birth name |
| No usage name | Birth name | null |
Always use basicIdentity.familyName for identity comparison. It always reflects the name the
user currently uses, regardless of whether they have changed their surname.
Example payloads
BasicIdentity — verified (no usage name)
{
"givenName": "Jean",
"familyName": "Dupont",
"name": "Jean Dupont",
"birthDate": "1985-03-22",
"birthPlace": "Paris"
}
BasicIdentity — verified (usage name present)
{
"givenName": "Marie",
"familyName": "Martin",
"name": "Marie Martin",
"birthDate": "1990-06-15",
"birthPlace": "Lyon"
}
In this case the usage name is "Martin" and the birth name "Dupont" is surfaced in extendedIdentity.familyNameBirth.
ExtendedIdentity — verified
{
"portrait": {
"$ref": "vault",
"$id": "020ff369-43d8-4b8a-94e7-6814c0bdc35a"
},
"nationality": "FRA",
"personalAdministrativeNumber": null,
"familyNameBirth": "Dupont",
"givenNameBirth": null,
"sex": 1,
"emailAddress": null,
"mobilePhoneNumber": null,
"residentAddress": "24 RUE DANTON 35700 RENNES FRANCE",
"residentStreet": "RUE DANTON",
"residentHouseNumber": "24",
"residentHouseName": null,
"residentCountry": "FR",
"residentState": "Bretagne",
"residentCity": "RENNES",
"residentPostalCode": "35700"
}
familyNameBirth is populated only when a usage name is present. When no usage name is provided,
familyNameBirth is null.
AuthenticationResult — success
{
"result": "success",
"provider": "france-identite",
"credentialId": "cred-7f3a2b1c-4d5e-6f7a-8b9c-0d1e2f3a4b5c",
"credentialType": "eidToken",
"subjectId": "sub-9e8d7c6b-5a4f-3e2d-1c0b-a9f8e7d6c5b4",
"requestId": "req-1a2b3c4d-5e6f-7a8b-9c0d-e1f2a3b4c5d6",
"authenticatedAt": "2026-02-10T14:00:01.000Z"
}