# Direct Vipps login (without 3. party)

**URL:** <https://community.appfarm.io/t/direct-vipps-login-without-3-party/431>\
**Category:** Ask the community\
**Tags:** login, web-request\
**Created:** [April 21, 2023, 7:51am UTC](https://community.appfarm.io/t/direct-vipps-login-without-3-party/431 "2023-04-21T07:51:45Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sondre](https://dub1.discourse-cdn.com/flex013/user_avatar/community.appfarm.io/sondre/32/105_2.png) [@Sondre](https://community.appfarm.io/u/Sondre)\
**Post date:** [April 21, 2023, 7:51am UTC](https://community.appfarm.io/t/direct-vipps-login-without-3-party/431/1 "2023-04-21T07:51:45Z")

</div>

Hi, we want to setup a direct vipps login not using a 3. party. our setup is as follows:  
 ![image](https://europe1.discourse-cdn.com/flex013/uploads/appfarm/original/1X/4afe79e607d9a82bcf17e077ce00e9f6bf88f588.png)

Upon login we get the vipps popup as expected but then get a “jwt token missing” error after phone check.

What are we missing? 🙂

---

<div class="post-metadata">

**Author:** ![kristian](https://dub1.discourse-cdn.com/flex013/user_avatar/community.appfarm.io/kristian/32/58_2.png) [@kristian](https://community.appfarm.io/u/kristian)\
**Post date:** [April 21, 2023, 12:39pm UTC](https://community.appfarm.io/t/direct-vipps-login-without-3-party/431/2 "2023-04-21T12:39:51Z")

</div>

Hi! Do you have a screenshot (including the URL to the login page) from when this occurs?

---

<div class="post-metadata">

**Author:** ![Sondre](https://dub1.discourse-cdn.com/flex013/user_avatar/community.appfarm.io/sondre/32/105_2.png) [@Sondre](https://community.appfarm.io/u/Sondre)\
**Post date:** [April 21, 2023, 1:09pm UTC](https://community.appfarm.io/t/direct-vipps-login-without-3-party/431/3 "2023-04-21T13:09:07Z")

</div>

![image](https://europe1.discourse-cdn.com/flex013/uploads/appfarm/original/1X/748fd9ae58d9d1422db2e5e1d841af0567dd82b1.png)

---

<div class="post-metadata">

**Author:** ![ReodorMagnus](https://dub1.discourse-cdn.com/flex013/user_avatar/community.appfarm.io/reodormagnus/32/1473_2.png) [@ReodorMagnus](https://community.appfarm.io/u/ReodorMagnus)\
**Post date:** [August 28, 2023, 11:04am UTC](https://community.appfarm.io/t/direct-vipps-login-without-3-party/431/4 "2023-08-28T11:04:34Z")

</div>

Hello 🙂

Trying to set up a direct vipps login not using a 3. party.

How did this go for you @Sondre?

Im stuck at getting this error:

 ![Skjermbilde 2023-08-28 kl. 13.04.00](https://europe1.discourse-cdn.com/flex013/uploads/appfarm/original/1X/d515a537df3d449b1a4aab39f38a2bd1c2255f54.png)

---

<div class="post-metadata">

**Author:** ![Sondre](https://dub1.discourse-cdn.com/flex013/user_avatar/community.appfarm.io/sondre/32/105_2.png) [@Sondre](https://community.appfarm.io/u/Sondre)\
**Post date:** [August 28, 2023, 12:00pm UTC](https://community.appfarm.io/t/direct-vipps-login-without-3-party/431/5 "2023-08-28T12:00:08Z")

</div>

Hey, this seems to be an error with the redirect URL in Vipps that is not pointing to your Appfarm solution. Let me know if that is the case 🙂

In addition we had to build a script outside Appfarm to fetch an email address to be able to create a user. I’m unsure if that is required in all cases.

---

<div class="post-metadata">

**Author:** ![ReodorMagnus](https://dub1.discourse-cdn.com/flex013/user_avatar/community.appfarm.io/reodormagnus/32/1473_2.png) [@ReodorMagnus](https://community.appfarm.io/u/ReodorMagnus)\
**Post date:** [August 28, 2023, 1:39pm UTC](https://community.appfarm.io/t/direct-vipps-login-without-3-party/431/6 "2023-08-28T13:39:18Z")

</div>

Thanks that was the case! Had to add [account.appfarm.io/callback](http://account.appfarm.io/callback) to the URI list 🙂

Now im here with a test user phone number from vipps which is not working. Did you also experince this?

 ![image](https://europe1.discourse-cdn.com/flex013/uploads/appfarm/original/1X/0a268c33b2a1acd20d024573055ae75e5a26efc8.png)

---

<div class="post-metadata">

**Author:** ![Sondre](https://dub1.discourse-cdn.com/flex013/user_avatar/community.appfarm.io/sondre/32/105_2.png) [@Sondre](https://community.appfarm.io/u/Sondre)\
**Post date:** [August 28, 2023, 2:13pm UTC](https://community.appfarm.io/t/direct-vipps-login-without-3-party/431/7 "2023-08-28T14:13:29Z")

</div>

You can find documentation here: [The Vipps MobilePay test environment | Vipps MobilePay Technical Documentation](https://developer.vippsmobilepay.com/docs/test-environment/)

In this case I think you are missing to download and login to the test app, maybe with a test user 🙂

---

<div class="post-metadata">

**Author:** ![ReodorMagnus](https://dub1.discourse-cdn.com/flex013/user_avatar/community.appfarm.io/reodormagnus/32/1473_2.png) [@ReodorMagnus](https://community.appfarm.io/u/ReodorMagnus)\
**Post date:** [August 29, 2023, 11:39am UTC](https://community.appfarm.io/t/direct-vipps-login-without-3-party/431/8 "2023-08-29T11:39:27Z")

</div>

Thanks!

Now im at this point. I guess this is why you created the script? Any tips is to how you went about that is much appreciated

 ![image](https://europe1.discourse-cdn.com/flex013/uploads/appfarm/original/1X/e361ce7d259e3ccc052351e7e393a8c4ce39360b.png)

---

<div class="post-metadata">

**Author:** ![Sondre](https://dub1.discourse-cdn.com/flex013/user_avatar/community.appfarm.io/sondre/32/105_2.png) [@Sondre](https://community.appfarm.io/u/Sondre)\
**Post date:** [August 29, 2023, 12:13pm UTC](https://community.appfarm.io/t/direct-vipps-login-without-3-party/431/9 "2023-08-29T12:13:36Z")

</div>

Yes that is the case. Our script decoded the initial token, then used Appfarms graphql API to fetch the email connected to the phone number from Vipps, then compiled a JSON including the email claim, then re-encoded the JSON as a signed jwt token and returned it to Appfarm as the signed in User 🙂

---

<div class="post-metadata">

**Author:** ![ReodorMagnus](https://dub1.discourse-cdn.com/flex013/user_avatar/community.appfarm.io/reodormagnus/32/1473_2.png) [@ReodorMagnus](https://community.appfarm.io/u/ReodorMagnus)\
**Post date:** [August 29, 2023, 12:37pm UTC](https://community.appfarm.io/t/direct-vipps-login-without-3-party/431/10 "2023-08-29T12:37:00Z")

</div>

Thanks! @Sondre

@simon Please check out this thread regarding vipps login without 3rd party 🙂 Why is this setup causing the “email” claim not to be included in the ID token when its in the scope? Is there anything you guys can do?

 ![Skjermbilde 2023-08-29 kl. 14.32.30](https://europe1.discourse-cdn.com/flex013/uploads/appfarm/original/1X/8e341bc17b51442c64be3d623431226697357585.png)

---

<div class="post-metadata">

**Author:** ![kgreodor](https://avatars.discourse-cdn.com/v4/letter/k/5e9695/32.png) [@kgreodor](https://community.appfarm.io/u/kgreodor)\
**Post date:** [August 29, 2023, 12:50pm UTC](https://community.appfarm.io/t/direct-vipps-login-without-3-party/431/11 "2023-08-29T12:50:55Z")

</div>

Just to confirm. You had to put this script as a “middleman” between AppFarm and Vipps to ensure the id token were returned in the “right format”. Something like this if you add a lot of salt

```auto
| AppFarm | +++++++++ | MW | +++++++++ | Vipps |
     | | |
     |---login----------->| |
     | |---login----------->|
     | |<--token t1---------|
     |<--token t2---------| |

```

Or more concretely

 ![image](https://europe1.discourse-cdn.com/flex013/uploads/appfarm/original/1X/ca0dd9872ff3f98ce409fc922d11391c15a07e74.png)

Intercept step 6 and make sure the right `state` is returned. But don’t you then need to own the signing key as well. Seems like a lot to do to get things right?

I’m I missing something.

---

<div class="post-metadata">

**Author:** ![Sondre](https://dub1.discourse-cdn.com/flex013/user_avatar/community.appfarm.io/sondre/32/105_2.png) [@Sondre](https://community.appfarm.io/u/Sondre)\
**Post date:** [August 29, 2023, 1:03pm UTC](https://community.appfarm.io/t/direct-vipps-login-without-3-party/431/12 "2023-08-29T13:03:30Z")

</div>

Yes we intercepted in step 6 and created a new ID token including email. Vipps/Bankid login does not require you to have an email attached to your user. So the email should be matched from somewhere else. In our case form Appfarm as it was required to login with a company email as a first login to create the User.

This also can be achieved by building a custom login in Appfarm btw.

---

<div class="post-metadata">

**Author:** ![kgreodor](https://avatars.discourse-cdn.com/v4/letter/k/5e9695/32.png) [@kgreodor](https://community.appfarm.io/u/kgreodor)\
**Post date:** [August 29, 2023, 1:20pm UTC](https://community.appfarm.io/t/direct-vipps-login-without-3-party/431/13 "2023-08-29T13:20:38Z")

</div>

We actually were able to make Vipps require that email is added in order to login. But the email is not sent through the JWT token but one has to fetch it from the `userinfo` endpoint to get the data. But AppFarm does not seem to do the last step if email is not part of the token.

We will look a bit more into it. Thanks for taking the time to answer.
