# Feide documentation > This site contains technical documentation for the Feide project. ## General - [General](https://docs.feide.no/general/index.html.md) - [Feide](https://docs.feide.no/general/feide_overview.html.md): Feide is a centralized identity management solution for the educational sector of Norway and is short for «common electronic identity management» (in Norwegi... - [Multifactor authentication - Deployment guide](https://docs.feide.no/general/mfa_guide.html.md): Document History - [Browser support](https://docs.feide.no/general/browser-support.html.md): This page documents the supported web browser versions in Feide. - [Contact information](https://docs.feide.no/general/contact_information.html.md): The email address for Feide issues, both technical and administrative, is - [FAQ](https://docs.feide.no/general/faq/index.html.md) - [I am making my service available to Norwegian schools through eduGAIN – why do I only see Feide as a organization?](https://docs.feide.no/general/faq/edugain_feide_org.html.md): Since Feide is a centralized login service, the only organization that your service will see in eduGAIN is Feide itself All Norwegian institutions will be av... - [Why is my organization not in the organization drop down list?](https://docs.feide.no/general/faq/org_missing.html.md): Feide is an opt-in federation, meaning the organizations that have joined Feide need to explicitly approve the use of a service before end users can access i... - [Can SAML metadata be dynamically updated?](https://docs.feide.no/general/faq/dynamic_saml_metadata.html.md): SAML metadata is static and must be updated manually in the Feide customer portal. - [I am trying to add SAML Metadata for a service in the customer portal, but getting errors about invalid data. What is wrong?](https://docs.feide.no/general/faq/error_adding_saml_metadata.html.md): If the error says ‘This element is not expected’ it is most likely because there is an XML element in the wrong place. Order is significant in the SAML metad... - [What do we need to do if we change the domain name of our service?](https://docs.feide.no/general/faq/change_service_domain.html.md): This requires adding SAML metadata for the new domain. - [What must be done when changing the certificate of our service?](https://docs.feide.no/general/faq/change_service_certificate.html.md): There may be two certificates in use at services connected to Feide: - [What must be done when changing the certificate of our LDAP server?](https://docs.feide.no/general/faq/change_ldap_certificate.html.md): As long as you switch to a new certificate issued by a public certificate authority, the certificate should already be installed at the Feide login service.... - [What is openidp.feide.no used for?](https://docs.feide.no/general/faq/about_openidp.html.md): It is used only for Feide guest users. Don’t use it if not explicitly told to by the Feide support team. - [How do we allow access to Feide from restricted client networks?](https://docs.feide.no/general/faq/domain_access.html.md): To be able to log into Feide services, end users need to be able to access the following domains from their browser: - [Can Feide modify or tailor the attributes of a user?](https://docs.feide.no/general/faq/modify_attributes.html.md): Feide does not modify attributes it sends to services. - [What are the Feide password requirements?](https://docs.feide.no/general/faq/password_requirements.html.md): Feide has no restrictions on character sets or length of passwords. - [How can I test that two-factor authentication works for my account?](https://docs.feide.no/general/faq/test_twofactor.html.md): You can test it here. - [Where can I look LDAP error codes up for Windows based systems?](https://docs.feide.no/general/faq/ldap_error_codes.html.md): Have a look at the Microsoft documentation. - [What do I as a Service Provider have to do when two organizations merge?](https://docs.feide.no/general/faq/sp_org_merge.html.md): When two organizations merge their Feide user directories, you as a service provider will have to update any references to the users and organization at your... - [What must be done when a municipality changes its municipality number (kommunenummer)?](https://docs.feide.no/general/faq/change_municipality_number.html.md): The municipality does not need to do anything. Feide only uses the municipality number during for invoicing, and we will update the municipality numbers at t... - [What must be done to change the realm (domain) of an organization?](https://docs.feide.no/general/faq/change_org_realm.html.md): Short answer: It is possible, but very painful. - [Feide and Shibboleth](https://docs.feide.no/general/faq/feide_shibboleth.html.md): Feide and Shibboleth federations are based on the same concepts, but Shibboleth federations are somewhat different from Feide. In Shibboleth, it is common to... - [What are the implications of the Chrome 80 SameSite cookie change?](https://docs.feide.no/general/faq/samesite_cookie.html.md): Starting on February 17th 2020 Google will start adjusting how Chrome 80 sends cookies between different sites. This might break services connected to Feide,... - [What does the error “redirect loop detected” / “omdirigeringsløkke oppdaget” mean?](https://docs.feide.no/general/faq/redirect_loop.html.md): The Feide login system shows this error if a user has been sent back and forth between the service they are logging into and the Feide login system many time... - [Do you provide an API to fetch userdata in bulk?](https://docs.feide.no/general/faq/bulk_userdata_api.html.md): Not at the moment, though we recognize that there are legitimate use cases for this that can not be solved in the context of a user/login. If you have such a... - [Problem with access to services activated for individual schools?](https://docs.feide.no/general/faq/individual_school_access.html.md): The customer portal fetches information from Brønnøysundregisteret. The organization numbers in the user directory for the host organization must match. If t... ## Home Organizations - [Home Organizations](https://docs.feide.no/home_organizations/index.html.md): Home organizations include universities, colleges, municipalities and county councils, private schools and Sikt members. - [My groups](https://docs.feide.no/home_organizations/groups.html.md): Audience for this information is administrators and IT staff at home organizations. - [Editing login methods](https://docs.feide.no/home_organizations/editing_login_methods.html.md): The host organization can manage which login methods the organization’s users will be able to choose in Feide’s login window. This allows the organization to... - [Feide login with Entra ID](https://docs.feide.no/home_organizations/feide_login_with_entra_id.html.md): Entra ID is Microsoft’s login solution, and this is used for authentication on services like Office 365, Teams, and Outlook. To access these services, users... - [Feide login with Google](https://docs.feide.no/home_organizations/feide_login_with_google.html.md): Google login is used for authentication on services like Google Workspace for Education, Google Classroom, and Google Drive. To access these services, users... - [Feide login with ID-porten](https://docs.feide.no/home_organizations/feide_login_with_idporten.html.md): ID-porten is a common national login solution in Norwegian for online public digital services. It consists of several different known login methods, includin... - [Feide login with Passkeys](https://docs.feide.no/home_organizations/feide_login_with_passkeys.html.md): Passkeys is a login method that uses the WebAuthn standard to provide passwordless authentication. It allows users to log in using biometric data (like finge... - [How to activate a service in Feide](https://docs.feide.no/home_organizations/how_to_activate_services_in_feide.html.md): To give users access to a service, it needs to get activated by one of the Feide administrators of the organization. ## Service Providers - [Service Providers](https://docs.feide.no/service_providers/index.html.md): As a service provider, users can log in to your service with Feide. - [Getting started](https://docs.feide.no/service_providers/getting_started/index.html.md): This document outlines the process for getting started with Feide for service providers. - [Getting access to the customer portal](https://docs.feide.no/service_providers/getting_started/customer_portal.html.md): To registerer and manage your organizations integrations with Feide, your organization needs access to the Feide customer portal. If your organization is not... - [Adding Feide login to a service](https://docs.feide.no/service_providers/getting_started/add_feide_login.html.md): The process for adding Feide login to a service varies greatly between different services. Some services have built-in support for federated login / single s... - [Getting started with OpenID connect](https://docs.feide.no/service_providers/getting_started/openid_connect.html.md): The customer portal allows Feide administrators to register and manage applications. - [Manage services connected to Feide](https://docs.feide.no/service_providers/manage/index.html.md): This document describes how you can use the Feide customer portal to mange your service integrations with Feide. - [Manage SAML 2.0 services](https://docs.feide.no/service_providers/manage/saml2/index.html.md): SAML 2.0 metadata is the configuration information that tells the Feide login system how to talk to your service. See our reference documentation for more in... - [Registering and managing OpenID Connect services](https://docs.feide.no/service_providers/manage/openid_connect/index.html.md): Here you will find documentation about how to get started for application developers. - [Managing OpenID Connect applications](https://docs.feide.no/service_providers/manage/openid_connect/managing_applications.html.md): After registered the service you can add OAuth details to configure the service by clicking “Add OIDC-configuration” under the tab configurations. - [Login providers](https://docs.feide.no/service_providers/manage/openid_connect/login_providers.html.md): Using Feide, you probably want to authenticate people using your service. Through Feide you can enable several login providers. You - as a service provider -... - [Redirection after logout](https://docs.feide.no/service_providers/manage/openid_connect/redir_etter_logout.html.md): It is possible to designate a page the user will be redirected to after logging out from a Feide service using OpenID Connect (OIDC). - [How to manage access to services through Feide](https://docs.feide.no/service_providers/manage/access_to_services/activation.html.md): Does your service need to identify and authenticate international users or people outside the education sector? When using OpenID Connect, a service can enab... - [Test users](https://docs.feide.no/service_providers/test_users.html.md): When developing services with Feide login, you often need test users to test the login process. We have some standard test users that can be used for testing... - [Multifactor Authentication](https://docs.feide.no/service_providers/mfa/index.html.md): This document describes how services can ask Feide to initiate MFA and how to verify that MFA was used. - [Service-initiated MFA using SAML 2.0](https://docs.feide.no/service_providers/mfa/saml.html.md): When using SAML 2.0 the service will need to send a saml:AuthnContextClassRef element as part of the authentication request: - [Service-initiated MFA using OpenID Connect](https://docs.feide.no/service_providers/mfa/openid_connect.html.md): When using OAuth/OpenID Connect the service will need to send the following parameter as part of the authentication request: - [Provide and protect data](https://docs.feide.no/service_providers/provide_and_protect_data/index.html.md) - [Accessing data using JWT Token Exchange](https://docs.feide.no/data_sharing/data_consumer/jwt_token_exchange.html.md): Data sources protected by Feide are normally configured in the customer portal. The customer portal is used to configure policies for access to data sources... - [Legacy API Gatekeeper](https://docs.feide.no/service_providers/provide_and_protect_data/legacy_api_gatekeeper.html.md): Access to the legacy API gatekeeper could only be managed through Dataporten Dashboard, which is no longer available. If you need to make changes regarding A... - [Using SAML 2.0](https://docs.feide.no/service_providers/saml/index.html.md): One of the methods that can be used to authenticate users in Feide is the SAML 2.0 protocol. - [OpenID Connect/OAuth technical details](https://docs.feide.no/service_providers/openid_connect/index.html.md): In these pages you will find detailed technical documentation about how to use our OpenID Connect and OAuth implementation. - [Security considerations](https://docs.feide.no/service_providers/openid_connect/security.html.md): The community now has long experience with OIDC and OAuth 2.0 in practice, and recommendations have evolved. One important change concerns the implicit flow.... - [Obtaining tokens with Feide](https://docs.feide.no/service_providers/openid_connect/feide_obtaining_tokens.html.md): Most of the APIs of the Feide platform require that you have obtained a token with OpenID Connect (OIDC). You need to register your application/client and im... - [Obtaining user information](https://docs.feide.no/service_providers/openid_connect/obtaining_userinfo.html.md): Your application can receive user information as OpenID Connect claims in two ways: - [Mobile applications](https://docs.feide.no/service_providers/openid_connect/mobile_applications.html.md): OIDC/OAuth is designed to work well with mobile applications. - [Using Feide with Client Credentials Flow](https://docs.feide.no/service_providers/openid_connect/client_credentials_flow.html.md): OIDC/OAuth defines many different flows, depending on the use case. One of these flows does not include an authenticated end-user. This is called the Client... - [More OpenID Connect details](https://docs.feide.no/service_providers/openid_connect/oidc_authentication.html.md): You can find more details about OpenID Connect at the link below: - [Check user existence](https://docs.feide.no/service_providers/checkuser/index.html.md): Checking whether a user has an account at an organization is possible with the dedicated check user existence endpoints. Users can be looked up by Feide ID (... - [eduGAIN](https://docs.feide.no/service_providers/edugain/index.html.md): The eduGAIN interfederation connects federations in different countries and allows users from one federation to access services in different federations. Fei... - [Enable eduGAIN for a Feide service](https://docs.feide.no/service_providers/edugain/feide_service/index.html.md): If you have a service connected to Feide, you can make that service available in eduGAIN. This allows users from other federations in different countries to... - [Enabling eduGAIN login when using OpenID Connect](https://docs.feide.no/service_providers/edugain/feide_service/openid_connect.html.md): All OpenID Connect services in Feide appear as a single service provider in eduGAIN. To allow users to log into your service using eduGAIN, you need to enabl... - [Enabling eduGAIN login when using SAML 2.0](https://docs.feide.no/service_providers/edugain/feide_service/saml2.html.md): The eduGAIN interfederation service connects identity federations around the world, simplifying access to content, services and resources for the global rese... - [Enabling Feide-users to log into an eduGAIN service provider](https://docs.feide.no/service_providers/edugain/edugain_service.html.md): Feide operates a centralized login service for the Norwegian research and education organizations. Feide is connected to eduGAIN, but due to the architecture... - [Metadata Registration Practice Statement for Feide](https://docs.feide.no/service_providers/edugain/feide_metadata_registration_practice.html.md): Version 1.0.2, last edited November 5th 2021. - [Provisioning users and groups](https://docs.feide.no/service_providers/provisioning/index.html.md): Traditionally, Feide has only provided user and group data in the context of an actual authenticated user. However, there are a lot of use cases for provisio... - [Finding the organization domain name of a school](https://docs.feide.no/service_providers/finding_domain_name.html.md): Feide uses the domain name (realm) of an organization to identify it. The domain name is chosen by the organization and can be something like eksempel.kommun... ## Data sharing - [Data sharing](https://docs.feide.no/data_sharing/index.html.md): Data sharing in Feide Customer Portal makes it possible to share data between a data source (API) and Feide services in a secure way, with access control and... - [Available data sources](https://docs.feide.no/data_sharing/available_data_sources.html.md): Feide allows data owners to make new data sources available in a way that make them easy to use by service providers. - [Data Provider](https://docs.feide.no/data_sharing/data_provider/index.html.md) - [Creating new data source](https://docs.feide.no/data_sharing/data_provider/creating_new_data_source.html.md): Only create data sources using the Customer Portal for which you are the provider. - [Managing access to a data source](https://docs.feide.no/data_sharing/data_provider/managing_access_to_a_data_source.html.md): It is now possible to create and manage access to data sources using our Customer Portal. - [Deleting a data source](https://docs.feide.no/data_sharing/data_provider/delete_data_source.html.md): If you want to delete a data source, contact the service providers using your data source beforehand, as deleting the data source could cause the service to... - [Working with Feide JWT tokens](https://docs.feide.no/data_sharing/data_provider/using_jwt_tokens.html.md): When a data source has been created and the appropriate access levels/scopes have been configured in the Customer Portal, the service or API providing the da... - [Accessing Feide data from a data source](https://docs.feide.no/data_sharing/data_provider/accessing_feide_from_data_source.html.md): A data source may need Feide data, such as user and group information, when processing a request from a service. To access the Feide data, the data source ca... - [Data Consumer](https://docs.feide.no/data_sharing/data_consumer/index.html.md) - [Getting access to data through data source](https://docs.feide.no/data_sharing/data_consumer/getting_access_to_data_through_data_source.html.md): In order to connect your service to a data source (API), the service needs to be using OIDC for integrating with Feide. - [Disconnecting a data source from a service](https://docs.feide.no/data_sharing/data_consumer/disconnect_data_source.html.md): If you no longer need or want to use the data source, simply access the data source tab from the relevant service and disconnect it from the data source as s... ## Reference - [Reference](https://docs.feide.no/reference/index.html.md) - [TLS requirements for LDAP servers](https://docs.feide.no/reference/tls-requirements-ldap.html.md): This document describes the requirements for the SSL/TLS configuration of LDAP servers connected to Feide - [Information models and object specification](https://docs.feide.no/reference/schema/index.html.md): These documents describe the information models used in higher and lower education in Feide. Detailed information about the LDAP object classes and attribute... - [Attribute groups](https://docs.feide.no/reference/schema/attributegroups/index.html.md): What information the service can receive about the end user is defined in the attribute groups that the service provider sets for the service in the customer... - [Attributes](https://docs.feide.no/reference/schema/attributes/index.html.md): Short description - [cn](https://docs.feide.no/reference/schema/attributes/cn.html.md): Common name. General name on the person object. This attribute should not be considered unique across the educational sector. - [displayName](https://docs.feide.no/reference/schema/attributes/displayname.html.md): The preferred name of a person to be used when displaying the person’s name. - [eduPersonAffiliation](https://docs.feide.no/reference/schema/attributes/edupersonaffiliation.html.md): Specifies the person’s role at the organization in broad categories such as student, staff, employee etc. - [eduPersonAssurance](https://docs.feide.no/reference/schema/attributes/edupersonassurance.html.md): Specifies the person’s identity assurance profiles (IAPs), which are the set of standards that are met by an identity assertion, based on the Home Organizati... - [eduPersonEntitlement](https://docs.feide.no/reference/schema/attributes/edupersonentitlement.html.md): URI (either URN or URL) that indicates a set of rights to specific resources. - [eduPersonOrcid](https://docs.feide.no/reference/schema/attributes/edupersonorcid.html.md): ORCID iDs are persistent digital identifiers for individual researchers. Their primary purpose is to unambiguously and definitively link them with their scho... - [eduPersonOrgDN:eduOrgLegalName](https://docs.feide.no/reference/schema/attributes/edupersonorgdn-eduorglegalname.html.md): The legal corporate name of the home organization. - [eduPersonOrgDN:mail](https://docs.feide.no/reference/schema/attributes/edupersonorgdn-mail.html.md): The home organization’s mail address. - [eduPersonOrgDN:norEduOrgNIN](https://docs.feide.no/reference/schema/attributes/edupersonorgdn-noreduorgnin.html.md): The organization number assigned by the Norwegian Register of Business Enterprises (Brønnøysundregistrene, Foretaksregisteret) of the organization the user b... - [eduPersonOrgDN:norEduOrgSchemaVersion](https://docs.feide.no/reference/schema/attributes/edupersonorgdn-noreduorgschemaversion.html.md): This is the version number of the norEdu* specification that is used at the home organization. The version number has impact on which attributes one should a... - [eduPersonOrgDN:o](https://docs.feide.no/reference/schema/attributes/edupersonorgdn-o.html.md): For primary and secondary school this is the name of the school owner with which this person is associated. For primary school this is the name of the munici... - [eduPersonOrgUnitDN](https://docs.feide.no/reference/schema/attributes/edupersonorgunitdn.html.md): This attribute contains the internal “distinguished name” (DN) of the user’s schools in the home organizations user directory. - [eduPersonOrgUnitDN:mail](https://docs.feide.no/reference/schema/attributes/edupersonorgunitdn-mail.html.md): For primary and secondary schools, this attribute contains the email address of the user’s schools. - [eduPersonOrgUnitDN:norEduOrgUnitUniqueIdentifier](https://docs.feide.no/reference/schema/attributes/edupersonorgunitdn-noreduorgunituniqueidentifier.html.md): For primary and secondary schools, this attribute contains the unique identifier of the user’s schools. - [eduPersonOrgUnitDN:ou](https://docs.feide.no/reference/schema/attributes/edupersonorgunitdn-ou.html.md): For primary and secondary schools, this attribute contains the official name of the user’s schools. - [eduPersonPrimaryAffiliation](https://docs.feide.no/reference/schema/attributes/edupersonprimaryaffiliation.html.md): Specifies the person’s primary role at the home organization in broad categories such as student, faculty, staff, alum, etc. See also saml-attribute-eduperso... - [eduPersonPrimaryOrgUnitDN](https://docs.feide.no/reference/schema/attributes/edupersonprimaryorgunitdn.html.md): This attribute contains the internal “distinguished name” (DN) of the user’s primary school in the home organizations user directory. - [eduPersonPrincipalName](https://docs.feide.no/reference/schema/attributes/edupersonprincipalname.html.md): This attribute identifies the user that logged in to Feide. This attribute is guaranteed unique across the educational sector. - [eduPersonPrincipalNamePrior](https://docs.feide.no/reference/schema/attributes/edupersonprincipalnameprior.html.md): This attribute may contain eduPersonPrincipalNames the user have previously had at the same legal organization, either because the principal name has been ch... - [eduPersonScopedAffiliation](https://docs.feide.no/reference/schema/attributes/edupersonscopedaffiliation.html.md): Specifies the person’s role and home organization or school. See also saml-attribute-edupersonaffiliation. - [eduPersonTargetedID](https://docs.feide.no/reference/schema/attributes/edupersontargetedid.html.md): This is a persistent, non-reassigned, privacy-preserving identifier for a person. Feide recommends using this as an identifier. - [eduPersonUniqueId](https://docs.feide.no/reference/schema/attributes/edupersonuniqueid.html.md): A long-lived, non re-assignable identifier for a person at an organization. It remains the same even if the username of the person changes. - [feideSchoolList](https://docs.feide.no/reference/schema/attributes/feideschoollist.html.md): A list of the organization number of all the schools the person belongs to. The primary school is listed first. - [feideYearOfBirth](https://docs.feide.no/reference/schema/attributes/feideyearofbirth.html.md): The year of birth for this person. - [givenName](https://docs.feide.no/reference/schema/attributes/givenname.html.md): Contains names that are part of the person’s first name (not their surname). - [mail](https://docs.feide.no/reference/schema/attributes/mail.html.md): A personal email address. This attribute should not be considered unique across the educational sector. - [mobile](https://docs.feide.no/reference/schema/attributes/mobile.html.md): A personal mobile telephone number. The attribute is not recommended used when sending out one-time password etc. - [norEduPersonLegalName](https://docs.feide.no/reference/schema/attributes/noredupersonlegalname.html.md): The person’s full formal name as registered by public authorities. - [norEduPersonNIN](https://docs.feide.no/reference/schema/attributes/noredupersonnin.html.md): This is a unique personal identity number issued by the National Registry (Folkeregisteret), Norwegian Directorate of Immigration (Utlendingsdirektoratet, UD... - [preferredLanguage](https://docs.feide.no/reference/schema/attributes/preferredlanguage.html.md): The preferred written or spoken language for a person. - [schacHomeOrganization](https://docs.feide.no/reference/schema/attributes/schachomeorganization.html.md): Specifies a person’s home organization using the realm of the organization. The realm must be identical to the suffix in the person’s eduPersonPrincipalName. - [sn](https://docs.feide.no/reference/schema/attributes/sn.html.md): This is the person’s surname or family name. - [uid](https://docs.feide.no/reference/schema/attributes/uid.html.md): This is the person’s local username at the home organization. This attribute is not unique across the educational sector, and should therefore not be used as... - [Person and account identifiers in Feide](https://docs.feide.no/reference/schema/identifiers/index.html.md): This is an overview of the key identifiers in Feide used to identify a user or an account. - [The Feide information model for lower education](https://docs.feide.no/reference/schema/info_go/index.html.md): Usage of norEdu* Object Class Specification v.2.0 for lower education - [Overview of the Feide LDAP structure](https://docs.feide.no/reference/schema/info_go/go_attributter_ch01.html.md): The structural requirements that Feide sets for the organization’s LDAP-catalogue are based on «norEdu* Object Class Specification». - [Person](https://docs.feide.no/reference/schema/info_go/go_attributter_ch02.html.md): Students grouped in year of the education they are attending to. Example is after kindergarten the persons starts in årstrinn 1. Then proceeds to årstrinn 2... - [Organization](https://docs.feide.no/reference/schema/info_go/go_attributter_ch03.html.md): Note that norEduOrgNIN shall be the organization number from Brønnøysundregisteret which is the registered school-owner in National school register. It shall... - [Organizational unit](https://docs.feide.no/reference/schema/info_go/go_attributter_ch04.html.md): Every school affiliated to the school owner is originally its own organization unit. - [Optional attributes - person and organization](https://docs.feide.no/reference/schema/info_go/go_attributter_ch05.html.md): Here is an overview of attributes from norEdu*-specification that is not mandatory or recommended in Feide. For more information about each attribute, see «n... - [Changelog](https://docs.feide.no/reference/schema/info_go/go_attributter_ch06.html.md): norEduPersonNIN is changed from “mandatory” to “mandatory if a valid value exists”. Guidelines for what types of numbers that can be added to norEduPersonNIN... - [Appendix 1 - LDIF-example](https://docs.feide.no/reference/schema/info_go/go_attributter_chA1.html.md): Example on filled out LDAP-objects that satisfies Feide demands. - [Appendix 2 - Registration of Grep-codes within eduPersonEntitlement](https://docs.feide.no/reference/schema/info_go/go_attributter_chA2.html.md): Students grouped in what year of the education they are attending. Example is after kindergarten the persons starts in årstrinn 1. Then proceeds to årstrinn... - [Appendix 3 - Registration of group information within eduPersonEntitlement](https://docs.feide.no/reference/schema/info_go/go_attributter_chA3.html.md): Services are facing an increasing demand for information about users basis-groups/classes, teaching groups and other groups. Based on this, students and teac... - [Appendix 4 - Registration of group-IDs in eduPersonEntitlement](https://docs.feide.no/reference/schema/info_go/go_attributter_chA4.html.md): To be able to retrieve all members within a group, group-IDs have to be registered on person objects to all that are members of the group. In Feide, the fiel... - [Feides information model for higher education](https://docs.feide.no/reference/schema/info_uh/index.html.md): The usage of norEdu* Object class Specification v.2.0 for higher education - [Overview of the Feide LDAP structure](https://docs.feide.no/reference/schema/info_uh/uh_attributter_ch01.html.md): Sector covering higher education such as universities. - [Person](https://docs.feide.no/reference/schema/info_uh/uh_attributter_ch02.html.md): eduPersonPrincipalName Is per definition non case sensitive. - [Organization](https://docs.feide.no/reference/schema/info_uh/uh_attributter_ch03.html.md): Note that norEduOrgNIN shall be the organization number from Brønnøysundregisteret It shall be comprised of nine digits that are prefixed with NO, and it sha... - [Organizational unit](https://docs.feide.no/reference/schema/info_uh/uh_attributter_ch04.html.md): Feide does not demand that organizational units within higher education are registered. It will still be allowed to register information about affiliations w... - [Optional attributes - person and organization](https://docs.feide.no/reference/schema/info_uh/uh_attributter_ch05.html.md): Here is an overview of attributes from norEdu*-specification that are not mandatory or recommended in Feide. For more information about each attribute, see «... - [Changelog](https://docs.feide.no/reference/schema/info_uh/uh_attributter_ch06.html.md): norEduPersonNIN is changed from “mandatory” to “mandatory if a valid value exists”. Guidelines for what types of numbers that can be added to norEduPersonNIN... - [Appendix 1 - LDIF-example](https://docs.feide.no/reference/schema/info_uh/uh_attributter_chA1.html.md): Example of populated LDAP-objects that satisfies Feide demands. - [norEdu* Object Class Specification](https://docs.feide.no/reference/schema/noredu/index.html.md): Version 2.0, March 2018 - [Status of this document](https://docs.feide.no/reference/schema/noredu/noredu_ch01.html.md): This document is the updated version of the norEdu* object class specification. - [Introduction](https://docs.feide.no/reference/schema/noredu/noredu_ch02.html.md): RFC 4519 “Lightweight Directory Access Protocol (LDAP): Schema for User Applications” adopts a selection of X.520 attributes for use in LDAP. The schema defi... - [Attribute specifications (normative)](https://docs.feide.no/reference/schema/noredu/noredu_ch03.html.md): The table in this chapter summarizes all norEdu* attributes as well as the attributes of other classes that are assumed to be available. The table also provi... - [Document information](https://docs.feide.no/reference/schema/noredu/noredu_ch04.html.md): This chapter is informative only, and does not form part of the norEdu* specification. - [Appendix A: Object classes (normative)](https://docs.feide.no/reference/schema/noredu/noredu_chAA.html.md): This appendix is normative, to be considered an integral part of the norEdu* specification. - [Appendix B: Attribute definitions (normative)](https://docs.feide.no/reference/schema/noredu/noredu_chAB.html.md): This appendix is normative, to be considered an integral part of the norEdu* specification. Attributes defined by norEdu* - [Appendix C: Obsolete attributes](https://docs.feide.no/reference/schema/noredu/noredu_chAC.html.md): This appendix is informative only, and does not form part of the norEdu* specification. - [LDAP validator](https://docs.feide.no/reference/ldap_validator/index.html.md): In Feide we have a LDAP validator. This validator checks user directories for common problems and errors. - [Running the LDAP validator](https://docs.feide.no/reference/ldap_validator/running.html.md): The LDAP validator is used in two locations: - [Validator errors](https://docs.feide.no/reference/ldap_validator/errors/index.html.md): There are many different warnings and errors that can be emitted by the LDAP validator. This document attempts to document some of the common errors. - [Duplicate identifier in norEduOrgUnitUniqueIdentifier](https://docs.feide.no/reference/ldap_validator/errors/duplicate_noreduorgunituniqueidentifier.html.md): Users can be associated with one or more organization units. For universities and university colleges, this is typically faculties and departments. For prima... - [Group ID not in canonical form](https://docs.feide.no/reference/ldap_validator/errors/groupid_not_canonical.html.md): This error only applies to primary and secondary schools. - [Group IDs without a corresponding group](https://docs.feide.no/reference/ldap_validator/errors/groupid_without_group.html.md): This error only applies to primary and secondary schools. - [Group with invalid code](https://docs.feide.no/reference/ldap_validator/errors/group_invalid_code.html.md): This error only applies to primary and secondary schools. - [Group without code](https://docs.feide.no/reference/ldap_validator/errors/group_without_code.html.md): This error only applies to primary and secondary schools. - [Groups without a corresponding group ID](https://docs.feide.no/reference/ldap_validator/errors/group_without_groupid.html.md): This error only applies to primary and secondary schools. - [Missing basis group for pupil](https://docs.feide.no/reference/ldap_validator/errors/missing_basis_groups.html.md): This error only applies to primary and secondary schools. - [Missing Grep codes for student](https://docs.feide.no/reference/ldap_validator/errors/missing_grep_codes.html.md): This error only applies to primary and secondary schools. - [Missing group IDs](https://docs.feide.no/reference/ldap_validator/errors/missing_group_ids.html.md): This error only applies to primary and secondary schools. - [Missing groups for teacher or pupil](https://docs.feide.no/reference/ldap_validator/errors/missing_groups.html.md): This error only applies to primary and secondary schools. - [Missing organization unit](https://docs.feide.no/reference/ldap_validator/errors/missing_organization_unit.html.md): There are two attributes that are used to indicate which organization units (schools in primary and secondary education) the user is associated with. - [Missing required attribute](https://docs.feide.no/reference/ldap_validator/errors/missing_required_attribute.html.md): Many attributes are mandatory to register. If the LDAP validator is missing one of the required attributes, it will log this error with information about whi... - [Missing teaching groups for teacher or pupil](https://docs.feide.no/reference/ldap_validator/errors/missing_teaching_groups.html.md): This error only applies to primary and secondary schools. - [APIs](https://docs.feide.no/reference/apis/index.html.md) - [Feide API](https://docs.feide.no/reference/apis/feide-api/index.html.md): The Feide API provides access to various data about organizations and services connected to Feide. It is available at https://api.feide.no/. - [URL structure](https://docs.feide.no/reference/apis/feide-api/url-structure.html.md): The URL structure for the Feide API is: https://api.feide.no/VERSION/API - [Rate limit](https://docs.feide.no/reference/apis/feide-api/rate-limit.html.md): If accessing the API without an access token, there is a rate limit that restricts you to 15 requests per 15 minutes. This is a per-IP address limit. - [Access token](https://docs.feide.no/reference/apis/feide-api/access-token.html.md): By providing a valid access token to the API, you can get a higher rate limit for fetching data. The default rate limit with an access token is 180 requests... - [Select fields in response](https://docs.feide.no/reference/apis/feide-api/select-fields.html.md): All APIs have a set of fields that are included in the response by default. Many APIs allow you to override this set. This can be used to: - [Multifactor authentication](https://docs.feide.no/reference/apis/feide-api/mfa.html.md): The multifactor authentication API can be used to generate and encrypt TOTP secrets. - [Organization information](https://docs.feide.no/reference/apis/feide-api/organizations.html.md): The organization information API provides access to information about organizations connected to Feide. This includes both host organizations (organizations... - [Service information](https://docs.feide.no/reference/apis/feide-api/services.html.md): This API provides access to information about services connected to Feide. - [Statistics](https://docs.feide.no/reference/apis/feide-api/statistics.html.md): The statistics API gives access to information about the number of logins in Feide. - [Passkey administration](https://docs.feide.no/reference/apis/feide-api/passkey-management.html.md): This API provides endpoints for managing passkeys registered by users in your organization. You can list and delete passkeys for users in your own organizati... - [Groups API](https://docs.feide.no/reference/apis/groups_api/index.html.md): A user belongs to a number of groups of various types. Types of groups include: - [Data model for groups](https://docs.feide.no/reference/apis/groups_api/groups_data_model.html.md): There are two main object types in the groups API data model: - [Group types](https://docs.feide.no/reference/apis/groups_api/group_types/index.html.md): The available groups depend on the organization type. - [School owner group](https://docs.feide.no/reference/apis/groups_api/group_types/pse_school_owner.html.md): All Feide user accounts are associated with a single school owner. The school owner group contains information about the school owner. - [School group](https://docs.feide.no/reference/apis/groups_api/group_types/pse_school.html.md): A Feide user account is associated with one or more schools. Each school group contains information about the school. - [Basis group](https://docs.feide.no/reference/apis/groups_api/group_types/pse_basis.html.md): A basis group (basisgruppe) represents a group of students who are taught together. This typically represents a class (e.g. 10A). The basis group also contai... - [Teaching group](https://docs.feide.no/reference/apis/groups_api/group_types/pse_teaching.html.md): A group of students who are taught together in a specific subject. This group also contains the teacher of the subject. - [Other education group](https://docs.feide.no/reference/apis/groups_api/group_types/pse_other.html.md): In addition to creating groups for classes and courses, schools can create groups for other purposes. These groups can be used for any purpose and there is n... - [Grep group](https://docs.feide.no/reference/apis/groups_api/group_types/pse_grep.html.md): Groups representing subjects, curricula, etc. from the national Grep database. - [Organization group](https://docs.feide.no/reference/apis/groups_api/group_types/he_organization.html.md): The user’s organization. - [Organization unit group](https://docs.feide.no/reference/apis/groups_api/group_types/he_organization_unit.html.md): Information about organization units in higher education. These groups can provide information about organization units in higher education, such as institut... - [FS program of study](https://docs.feide.no/reference/apis/groups_api/group_types/fs_program_of_study.html.md): Group representing a program of study (studieprogram) in Felles Studentsystem (FS). - [FS cohort](https://docs.feide.no/reference/apis/groups_api/group_types/fs_cohort.html.md): Group representing a cohort (kull) in a program of study (studieprogram). - [FS class](https://docs.feide.no/reference/apis/groups_api/group_types/fs_class.html.md): Group representing a class (klasse) within a cohort (kull) in a program of study (studieprogram). - [FS course](https://docs.feide.no/reference/apis/groups_api/group_types/fs_course.html.md): A group for students and instructors in a particular course / subject. - [FS field of study](https://docs.feide.no/reference/apis/groups_api/group_types/fs_field_of_study.html.md): Group representing a field of study (studieretning) in Felles Studentsystem (FS). - [Ad hoc groups](https://docs.feide.no/reference/apis/groups_api/group_types/adhoc.html.md): Ad hoc groups allow end users to create their own groups. These groups can consist of users within one organization, or they can consist of users across orga... - [Groups API endpoints](https://docs.feide.no/reference/apis/groups_api/groups_endpoints.html.md): The protocol is a simple, lightweight REST-ish protocol. The group endpoints require that you provide a valid access token with scopes for appropriate attrib... - [OpenID Connect userinfo](https://docs.feide.no/reference/apis/userinfo.html.md): The userinfo endpoint is an OIDC/OAuth protected resource where client applications can retrieve claims, or assertions, about the logged in end-user. Clients... - [Feide user attributes](https://docs.feide.no/reference/apis/attributes_feide/index.html.md): Feide provides APIs for retrieving user attributes and checking whether a user exists: - [Available user attributes](https://docs.feide.no/reference/apis/attributes_feide/available_attributes.html.md): The extended userinfo and user lookup APIs return user attributes for Feide accounts. Which attributes are available to a service depends on the attribute gr... - [Attributes for the current user](https://docs.feide.no/reference/apis/attributes_feide/extended_userinfo.html.md): Attributes for the logged in user are available through this API, which is also called “extended userinfo”. It is only available for users logged in with a F... - [Attributes for specific users](https://docs.feide.no/reference/apis/attributes_feide/user_lookup.html.md): Attributes for specific Feide users is available through this API. In order to access the API, a number of requirements have to be met. - [Check user existence](https://docs.feide.no/reference/apis/attributes_feide/check_user_existence.html.md): The check user existence API allows a service to check whether a Feide user exists at an organization, without the user needing to be logged in and without r... - [Guardian API](https://docs.feide.no/reference/apis/guardianapi.html.md): An API for information about students a given parent/guardian is responsible for. - [Deprecated APIs](https://docs.feide.no/reference/apis/deprecated/index.html.md): These endpoint are deprecated and will be phased out. New applications should avoid them, and existing applications should migrate off them. - [Legacy check user existence](https://docs.feide.no/reference/apis/deprecated/checkuser.html.md): This endpoint is deprecated and will be shut down in the future. Services should migrate to the check user existence endpoints using the system-check-user-ex... - [Legacy OAuth userinfo endpoint](https://docs.feide.no/reference/apis/deprecated/legacy_userinfo.html.md): This endpoint is deprecated and will be phased out. New applications should use OpenID Connect userinfo instead, and existing applications should migrate off... - [MFA](https://docs.feide.no/reference/mfa/index.html.md) - [Technical specification](https://docs.feide.no/reference/mfa/technical_reqs.html.md): All the information related to the usage of multifactor authentication by a certain user must be stored directly in the user’s entry at the institutional dir... - [MFA Examples](https://docs.feide.no/reference/mfa/examples.html.md): The following are valid phone numbers to be used with SMS authentication: - [OpenID Connect and OAuth 2.0](https://docs.feide.no/reference/oauth_oidc/index.html.md) - [User IDs](https://docs.feide.no/reference/oauth_oidc/userids.html.md): How to identify users, people, and accounts within Feide. - [OpenID Connect details](https://docs.feide.no/reference/oauth_oidc/openid_connect_details.html.md): OpenID Connect (OIDC) is a simple standardized identity (authentication) layer on top of OAuth 2.0. - [Logout](https://docs.feide.no/reference/oauth_oidc/logout.html.md): If your application uses OpenID Connect, you can use the logout mechanism described in OpenID Connect logout. It lets you control which page the user is redi... - [SAML 2.0](https://docs.feide.no/reference/saml/index.html.md) - [Introduction](https://docs.feide.no/reference/saml/saml2_technical_guide.html.md): This document is a companion to the Feide Integration Guide. It is recommended to read that document for a conceptual and architectural introduction to Feide. - [Technical requisites](https://docs.feide.no/reference/saml/saml2_technical_requisites.html.md): Here is the list of technical requisites that all Service Providers must meet in order to connect to Feide. You can use it as a checklist to verify that you... - [Selecting the user organization](https://docs.feide.no/reference/saml/selectorg.html.md): If the service knows what organization the user is going to use on the login page, it is possible to prepopulate the organization choice on the login page. T... - [Tokens used in Feide](https://docs.feide.no/reference/tokens.html.md): This page describes the types of tokens used by Feide, their format and use. The key used to sign our JWT tokens may be obtained here: - [Feide test users](https://docs.feide.no/reference/testusers.html.md): Feide has a number of test users that can be used to test services. They all exist in the testusers.feide.no realm, and to use them your service must be expl...