MPass integration procedure
What is MPass?
MPass is the governmental authentication and access control service. For citizens, it is the secure way to access online government services with a single identity. For you, the one integrating with MPass, it is the way to give your users secure access without having to take care of the authentication infrastructure yourself.
A single access point, multiple methods: electronic signature, EVOSign, identity card and 2-step authentication.
Legal basis: Government Decision No. 1090 of 31 December 2013.
IDo you want to connect an information system to MPass?
The cost of the integration depends on the type of your institution. Check below what applies in your case:
| Institution type | Cost |
|---|---|
| Public service providers | Free |
| Private sector electronic service providers that own information systems | 10 800 MDL/year per system |
Steps
- You fill in the connection form;
- You sign the electronic contract via MSign.If you already have a contract with AGE, you sign only the annex; see the contract template here;
- You obtain a system certificate from the Information Technology and Cyber Security Service for the test environment and a separate one for the production environment;
- You fill in the technical integration form;
- You get access to the test environment and check that everything works;
- You pass the functional and security tests;
- We activate the production environment;
Need technical details? The full documentation (SAML 2.0 configuration, endpoints, code samples and integration libraries) is available on the eGov4Dev developer portal.
Before you start. What do you need to prepare?
-
System certificate requested from the Information Technology and Cyber Security Service;
Do you already have a certificate used for other government services (MSign, MPower, MNotify)? You can reuse it for all “M” products.
-
Public key (.cer). Send only the
.cerfile. Do not send files that contain the private key:.pfx,.key,.pem. - Active contract with AGE. If you already have one, you sign only the annex for MPass.
Facing difficulties?
- Haven’t received the system certificate?
- Check whether the request has been received by the Information Technology and Cyber Security Service. If you already hold a certificate used for MSign, MPower or MNotify, it can be used for the test environment.
- Is the certificate invalid or expired?
- Request the issuance of a new certificate from the Information Technology and Cyber Security Service and send the new public key (.cer) to AGE.
- Is the integration failing the tests?
- AGE will send the necessary remarks and recommendations. Once the corrections have been made, you can request the tests to be run again.
- Can the same certificate be used for test and production?
- No. The test and production environments use separate certificates. After the tests have been completed successfully, a new certificate must be requested for the production environment.
- Is the submitted data incomplete?
- The 5 working day period starts only after all the required information has been received. If the form is incomplete, AGE will ask you to complete it.
IIFor digital identity providers
If you are an identity provider and want to integrate an automated identity proofing mechanism into MPass, follow the steps below:
- You fill in the integration request form;
- You send the technical documentation to servicii@egov.md;
- You sign the contract electronically via MSign;
- AGE reviews the documentation and plans the integration work;
- AGE performs the configuration in the test environment;
- You receive the AGE confirmation to start the testing;
- You pass the functional tests;
- AGE confirms the technical acceptance;
- We activate the production environment;
Need technical details? The technical documentation is available on the eGov4Dev developer portal.
What the technical documentation must contain
Before starting the integration, send to servicii@egov.md:
- information on the issued certificates and on the CA used – certificate profile, OIDs, type of the signature creation device (QSCD), compliance with the legislation of the Republic of Moldova on electronic signature;
- the description of the technical mechanism for accessing the certificate – remote API or local driver/component, including the protocol/SDK required to integrate MPass with this mechanism;
- a dedicated API for certificate validation – direct OCSP without a dedicated API is not accepted;
- the endpoint and the access for the TEST environment, including the client components required for testing;
- the mechanism for handling the cancellation and the expiry of the operation;
- the specific error codes and messages, including the notifications/callbacks for asynchronous operations;
- the data/identities required for testing;
- the details of the responsible technical person;
- the name and the logo of the QTSP operator that will be displayed in MPass.