Tvarka ID

Lithuanian eID login for your app

Smart-ID, Mobile-ID and the Lithuanian ID card through one standard OpenID Connect integration. The user confirms their identity with their eID, and your app receives a signed ID token.

OpenID Provider: https://id.tvarka.pro

What you get

Three methods, one integration

Smart-ID, Mobile-ID and the ID card in a reader. You choose which methods your users see.

Standard OpenID Connect

Authorization code flow with PKCE, ID tokens signed ES256 or RS256, discovery and JWKS. Any OIDC client library works.

Private by default

Each app gets its own pseudonymous identifier for a person. The personal code goes only to apps with a recorded legal basis.

Your name on the login page

The login page shows your app's name and logo, so the user knows where they are signing in.

How it works

1

We register your app: name, logo, redirect URIs, allowed methods and claims. You receive a client ID.

2

Your app redirects the user to id.tvarka.pro. They pick a method and confirm their identity with their eID.

3

Your app exchanges the code for an ID token with the name, date of birth and login method.

Every login is a fresh eID act, so the authentication time is always real and the flow suits shared and clinical devices.

Built for

Telemedicine and health platforms, e-services and customer self-service, employee, member and partner portals, and age checks from the date of birth. Anywhere you need to know who actually logged in.

Integration

Issuer
https://id.tvarka.pro
Flow
Authorization code (response_type=code) with mandatory PKCE S256, state and nonce; the redirect_uri must match exactly.
Client authentication
private_key_jwt, client_secret_basic, or a public client with PKCE for mobile apps and PWAs.
Scopes and claims
openid: sub, amr. profile: given_name, family_name, birthdate. lt_personal_code: the personal code, for apps with a recorded legal basis.
Login method (amr)
smart_id, mobile_id, id_card.
Tokens
The ID token lives 5 minutes and is signed ES256 (default) or RS256. The access token lives 5 minutes and serves /userinfo. Key rotation is seamless: the JWKS publishes the current and the previous key.
Also
Token revocation (RFC 7009) and RP-Initiated Logout.

Need a qualified signature too? The Tvarka Sign API signs with Smart-ID, Mobile-ID and the ID card.

Price per successful login

EUR 0.12

Smart-ID and Mobile-ID, + VAT

EUR 0.08

Lithuanian ID card, + VAT

Pay for what you use. No subscriptions.

A failed or cancelled login is free. No setup fee and no monthly minimum. Pay from a prepaid balance or on a monthly invoice.

Frequently asked questions

Do users need a Tvarka account?

No. Anyone with Lithuanian Smart-ID, Mobile-ID or a Lithuanian ID card can log in. No Tvarka account is created.

Will I get the personal code?

Yes, if you have a legal basis to process it: we record it when we register your app. Every app receives a stable pseudonymous sub that differs from app to app, plus the name and date of birth.

Which library should I use?

Any OpenID Connect client library that supports the authorization code flow with PKCE. Every parameter is in the discovery document, and the signing keys are in the JWKS.

How do I start?

Write to [email protected] with your app's name, redirect URIs and the methods you want. We register your app and send you its client ID.

Add Lithuanian eID login to your app

[email protected]