1. Access Code

Access Code Steps:

Step 1: Login page

For Standard Citizen/Resident Integration Flow:

Open the below url to authenticate


For Visitor Integration:

SP need to use the below scopes to their first authentication call to retrieve the desired attributes of the user profile:

scope=urn:uae:digitalid:profile:general urn:uae:digitalid:profile:general:profileType urn:uae:digitalid:profile:general:unifiedId


https://stg-id.uaepass.ae/idshub/authorize?redirect_uri=https://localhost:8080&client_id={client_id}&response_type=code&state=pd3PgezRwk596u2yfRwqOgru&scope=urn:uae:digitalid:profile:general urn:uae:digitalid:profile:general:profileType urn:uae:digitalid:profile:general:unifiedId&acr_values=urn:safelayer:tws:policies:authentication:level:low

Step 2: Authenticate

Page will redirect to UAEPASS login page.

Step 3: Access Code

Provide the login identifier and confirm the push notification on the mobile. SP should use below code to pass to Access token Call.

https://stg-selfcare.uaepass.ae/?code={Access Code}&state={State value}

Note: Copy the {Access Code} to be used in next step to get the access token


{your redirect_uri}?code={access_code}&state={state value}

Authentication Request

GET https://stg-id.uaepass.ae/idshub/authorize

Once the authentication or SSO of the user is complete, and the user has granted authorization, the application receives an HTTP GET request of the following type from the user’s browser. This HTTP request is an OAuth 2.0 authorization response or an OpenID Connect authentication response. The application receives this request at the redirect URL specified in the authorization or authentication request message (the redirect_uri parameter) or in the registered redirect URL.

Query Parameters




Must take the value, which indicates that an code authorization code is requested.



Redirect URI to the application.

The application waits to receive at this URI the authorization or authentication response message with the authorization code.



Identifier of the client application. (To be shared by UAEPASS Team)



We recommend using this parameter to safeguard against CSRF attacks. The application can also include additional information in this parameter, such as the URL to which the browser is to be redirected when the authorization or authentication finishes. (To include multiple data in the value of this parameter, the application must serialize it as it sees fit.)



List of values, separated by spaces, that represent the scope of the authorization that the application wants to obtain. It queries the scopes required for accessing the resources or services in question. (To be shared by UAEPASS Team if its value is other than specified in sample above)



Defines conditions for authenticating the user (minimum levels or specific flows) who must authorize the access. (To be used as specified in sample or check with UAEPASS team for more details)



Language parameter to be sent to render English or Arabic login pages of UAEPASS and below are the possible values: English page : en Arabic page : ar

GET {redirection_uri_path}?code={code}&state={state}
HTTP/1.1 Host: {redirection_uri_host}

Last updated