generated: '2026-07-19' method: searched source: https://docs.id.me/guides/oidc/overview standards: - id: oauth2 conforms: true evidence: OAuth 2.0 authorization code flow with authorize/token endpoints. - id: oidc conforms: true evidence: OpenID Connect discovery at https://api.id.me/oidc/.well-known/openid-configuration. - id: oauth2-pkce conforms: true evidence: PKCE (RFC 7636) documented for OAuth 2.0 and OIDC authorization code flow. - id: saml-2.0 conforms: true evidence: SAML 2.0 federation guides for Okta, Keycloak, and IAM platforms. - id: openid-shared-signals-framework conforms: true evidence: SSF 1.0 transmitter delivering fraud/verification Security Event Tokens. - id: rfc8417-set conforms: true evidence: Security Event Token (SET) delivery via SSF. - id: nist-800-63-3-ial2-aal2 conforms: true evidence: >- Identity proofing aligned to NIST 800-63-3 IAL2/AAL2; documented on docs.id.me/guides/learn-more/digital-wallet/nist-ial-2. - id: rfc9116-security-txt conforms: true evidence: /.well-known/security.txt published with Contact and Canonical. - id: rfc9457-problem-details conforms: false evidence: Services API uses a custom {code, message} error envelope, not application/problem+json. notes: >- ID.me is a NIST 800-63-3 IAL2/AAL2 credential service provider used across US federal and state agencies. Formal certifications (FedRAMP, SOC 2) are not machine-verifiable from the developer docs and are not asserted here.