Attribute enrichment
Roadmap: optional enriched claims beyond standard OIDC profile - organisation, age brackets, residency, postal address - each requiring explicit user consent.
Roadmap: optional enriched claims beyond standard OIDC profile - organisation, age brackets, residency, postal address - each requiring explicit user consent.
LuxID checks passwords against breach intelligence at registration and reset, blocking compromised credentials before they reach your users' accounts.
LuxID's own certifications and accreditations, and Partner certification expectations by sector for high-assurance and regulated integrations.
How LuxID communicates platform changes to Partners: change categories, notification windows, deprecation policy, communication channels and roadmap visibility.
Shared vocabulary and mental model for architects, senior developers, and security engineers integrating with LuxID.
How the LuxID consent screen works, what your application name and logo contribute, per-claim labelling, and tone-of-language guidance.
Overview of LuxID value-add features beyond basic OIDC login: MFA, passkeys, identity verification, SSO, security signals, and more.
Frequently asked questions about integrating LuxID: onboarding, protocol support, tokens, claims, MFA, LuxID Verified, LuxID Pro, compliance, and operations.
GDPR guidance for LuxID Partners: controller and processor roles, lawful basis, data minimisation, user rights, breach notification and cross-border transfers.
Orientation for developers and IT leads integrating with LuxID: what this section covers, two integration ramps, and where to begin.
Overview of LuxID's legal structure, trust framework, compliance obligations and Partner governance for enterprise and regulated integrations.
Mental model for navigating the LuxID developer documentation: five layers, persona-based reading paths, and one-sentence summary per top-level section.
LuxID Agreement structure, why no separate DPA is needed, privacy notice template and brand usage terms for LuxID integrations.
The official LuxID sign-in button: the four modes, sizes and spacing, allowed text in each language, contrast rules, and CSS patterns.
LuxID acts as an OpenRoaming Wi-Fi identity provider, letting users roam onto participating networks in Luxembourg without re-authentication.
Overview of the LuxID Console - the operational portal for Partner administrators to manage Applications, credentials, logs, and branding.
Landing page for the LuxID developer documentation: positioning, supported standards, top-level navigation, and persona entry points.
What LuxID is, its governance structure, ecosystem role in Luxembourg, and the use cases it is designed for.
LuxID Verified confirms a user's name and date of birth via LuxTrust: verification process, token claims, use cases, and relay-only LoA provenance.
How to connect LuxID to your application: link users on the stable sub claim, keep your own internal user ID, and treat the IdP as a pluggable component.
LuxID MFA methods (OTP, TOTP, passkeys, LuxTrust), token claims amr and acr, minimum assurance configuration, step-up flows, and recovery paths.
Decision matrix and flowchart to help IT admins choose between OpenID Connect and SAML 2.0 when integrating LuxID with an off-the-shelf tool.
What the Quick Integrations section covers, the 5-step template every guide follows, and how to know you are in the right place.
WebAuthn/FIDO2 passkeys on LuxID: device binding, platform and roaming authenticators, token claims, fallback behaviour, and phishing resistance.
Architectural decisions to make before writing production code: protocol, required auth_level, MFA, Sphere, session strategy, logout, and branding.
Data minimisation, explicit consent, revocability, Sphere-based pseudonymisation, and GDPR alignment in LuxID.
Add LuxID login to Odoo, WordPress, Drupal, Microsoft 365, Salesforce, and other off-the-shelf tools in 10-30 minutes without writing code.
The LuxID domain model: User, Organisation, Partner, Application, Sphere, Subscription, Group, Claim, Consent, and Federation explained with worked examples.
Entry point for security and compliance officers assessing LuxID: responsibility split, key controls, retention, and where each claim is documented.
LuxID evaluates each sign-in against contextual security signals and surfaces a qualitative risk indicator as an ID Token claim for Partner use.
End-to-end journey for becoming a LuxID Partner: from first contact through KYB, agreement, UAT integration, go-live review to production credentials.
Consumer SSO across LuxID-enabled apps and LuxID Pro enterprise federation: Sphere boundaries, domain routing, corporate IdP integration, token claims.
LuxID service-level commitments for Partners: availability targets, maintenance windows, incident severities, support channels, and DORA considerations.
LuxID's legal entity structure, responsibility allocation between operator, Partners and users, assurance model, audit obligations and security baseline.
LuxID's hosted login page: redirect-based authentication, branding boundaries, session reuse, and why Partners should never build their own login form.
Why redirect-based login is safer, what the LuxID hosted page guarantees, branding boundaries, mobile/desktop differences, and session reuse behaviour.
End-to-end sequence diagrams for first-time sign-in, returning sign-in, MFA challenge, LuxID Verified, LuxID Pro federation, account linking, and logout.
Design and branding guidelines for integrating LuxID sign-in consistently, accessibly, and in a way users across Luxembourg recognise and trust.