Overview

What the Paspo ID Android SDK does and what it requires.

The Paspo ID SDK adds "Sign in with Paspo" to your Android app. Users authenticate with their existing Paspo ID account in a couple of taps, and your server receives their verified profile data — phone, e-mail, or national ID — without you building, verifying, or storing those credentials yourself.

Source: github.com/paspoid/android

Overview

Integration requires a single call, authenticate(scope, nonce), which returns a one-time authorization code. Your application forwards this code to your server, which exchanges it with Paspo ID for the user's data. From the user's side, the flow is: tap "Sign in with Paspo ID", confirm on the Paspo ID consent screen, and return to the application.

All communication between the application and Paspo ID is end-to-end encrypted (ECDH P-256 + AES-256-GCM, with ephemeral keys held only in memory) and handled by the SDK; no cryptographic work is required on your side.

Two responsibilities remain on your server and cannot be moved to the client, as they are the basis of the flow's security: generating the nonce, and exchanging the authorization code for user data.

The fastest way to integrate is the ready-made button. For full control over the appearance, use the headless API.

Requirements

minSdk23 (Android 6.0)
compileSdk36
Kotlin2.x
Coroutinesrequired; the entire API consists of suspend functions
Devices below Android 7.0

The SDK integrates into applications with minSdk 23, however the Paspo ID application requires Android 7.0 (API 24). On API 23 devices, Paspo ID cannot be installed, so authenticate returns NotInstalled — this is a normal outcome and should be handled accordingly. The button can be hidden in advance via checkInstallation().

Next steps