Registration and Transmission
Registration overview
ID.me requires two bits of information to create a stream:
- Receiver URL: The public URL to which ID.me should stream events.
Example: https://example.com/api/v1/events - Audience String: What to use as the value of the aud claim for events.
Example: http://example.com
It is the responsibility of the receiver organization to provide this information to ID.me in an email to your Customer Success Manager (CSM)
Transmission overview
The following steps represent the transmission flow.
Transmit supported events
ID.me will begin transmitting supported events to the receiver url. Events will be signed by the private key corresponding to the public key published at the ID.me SSF JWKS URL. Events will not be encrypted. Exactly one event will be included in each request.
Receive events
The receiver will receive the events from ID.me as an HTTP request and respond with a 2xx HTTP code to confirm the request was successfully received. If ID.me receives an error code, event transmission will be automatically retried in accordance with preset retry logic (default: 3 retries, then abort).
Verify signature
The receiver should verify the signature on the event, parse the iss claim and ensure that it matches https://events.id.me exactly. This confirms that the event was transmitted by ID.me.
Key information
A private key will be used to sign all event tokens. A corresponding public key will be published at the following locations.
Keys will use the RSA SHA256 algorithm for signing.
Supported events
ID.me supports six events that are part of the RISC specification.
Expected volume
The volume of the events varies from customer to customer. Please work with your CSM to develop an estimate of the frequency and volume of events.
The table below shows a brief description of the supported events. The next section describes details of ID.me’s implementation of these events.
Event specifications
Default event specifications
All events will have the following:
HTTP request
Standard SET claims
The following will adhere to SET specifications.
Additional information
- Subject will be provided in both the header and the body, for convenience and compatibility
- Subject will always be in the iss_sub format: subject{format,iss,sub}
- format will always be “iss_sub”
- iss will always be
“https://events.id.me” - sub will always be the UUID for the subject ID.me account
Individual event specifications
Account disabled
This event is fired when an ID.me account is suspended for any reason.
Properties
- reason
Account enabled
This event is fired when an ID.me account is reinstated, for example, as a result of a recovery process or negative fraud investigation.
Properties
- reason
Account credential change required
This event is fired when an ID.me authority determines that the account owner must reset their password.
Properties
- reason
Account purged
This event is fired when a Member’s ID.me account is permanently deleted.
RISC Spec
Signals that the account identified by the subject has been permanently deleted.
URI: https://schemas.openid.net/secevent/risc/event-type/account-purged
When it’s fired
- User-Requested Erasure via GDPR/CCPA right-to-erasure flows
- PII Retention Expiry (e.g., 3 years after account closure)
- Biometric Retention Expiry (e.g., 35 months post-inactivity)
Properties
Recovery activated
This event is fired when a user initiates the process to recover their account (examples: password reset, MFA recovery).
RISC Spec
Signals that the account identified by the subject activated a recovery flow.
URI: https://schemas.openid.net/secevent/risc/event-type/recovery-activated
When it fires
- Forgot Password flow initiation (user clicks “Forgot password”)
- Forgot MFA flow (lost device / de-registered authenticator)
- Support-Initiated Reset or account unlock by an agent
- Fraud Rule automatically resets an authenticator
Properties
Recovery information changed
This event is fired when a user updates the authenticator(s) on their ID.me account.
RISC Spec:
Recovery Information Changed signals that the account identified by the subject has changed some of its recovery information. For example a recovery email address was added or removed.
URI: https://schemas.openid.net/secevent/risc/event-type/recovery-information-changed
Properties