SkyWinOne — Login with BankID
Let your members log in to SkyWinOne with Swedish BankID, through your club's own Idura account
How it works
With BankID switched on, the login page of SkyWinOne shows a BankID QR code beside the usual username and password. On a mobile phone there is also an Open BankID button, which opens the BankID app on the same phone.
When a member has identified themselves, SkyWinOne looks up the member whose personal identity number matches, logs them in with their personal login and shows their personal page — account balance, log book, transactions and jump queue.
- A member who has no personal login yet is given one automatically at their first BankID login. Nobody has to create logins in advance.
- Only personal logins are used. Staff logins — administrators, manifest, finance — still log in with username and password, even when they belong to the same person.
- When BankID is switched on, the start page and the jump queue also show a QR code that takes a phone straight to the login page: Want to see your account balance and jumps?
The identification itself is done by Idura, who connect to BankID on the club's behalf. Each club needs an Idura account of its own. The five steps below take you from signing up at Idura to the first member logging in — allow two to three weeks, most of it waiting for the BankID certificate.
Before you start
| Group | What | Description |
|---|---|---|
| SkyWinOne | ||
| SkyWinOne version 26.3 or higher, with support for BankID login | See the release notes. | |
grails.serverURL |
Must be the address your members reach SkyWinOne on from the internet, e.g. https://skywin.yourclub.se. The QR codes on the start page and the jump queue point there, so a phone must be able to open it. |
|
| Access to Idura | The server running SkyWinOne must be able to make outgoing HTTPS connections (port 443) to your Idura domain, e.g. yourclub.idura.broker. |
|
| Personal identity numbers | A member is found by the personal identity number (PID) on their member record. Swedish personnummer and samordningsnummer are recognised however they are written — 10 or 12 digits, with or without a hyphen. A member without one cannot log in with BankID. | |
| Your club | ||
| An EU VAT ID | Idura require one to order the BankID certificate in step 3. | |
Step 1 — Create an Idura account and buy a subscription
Sign up at Idura and create a tenant — your club's own space at Idura. Idura's own guide is Set up the Dashboard.
- Switch the Idura Dashboard to Production (top left). Everything in the steps below is done there.
- On the Billing tab, buy a subscription. Idura charges for successful logins only — see their price list.
Step 2 — Register a domain
Open the Domains tab and register a domain, for example yourclub.idura.broker.
This is the Idura domain you enter in SkyWinOne in step 5.
Step 3 — Order the BankID certificate
Before BankID can be used, Idura must install a certificate that identifies your club. Order it now: it is the step that takes longest, and steps 4 and 5 can be done while you wait.
- Open the Swedish BankID page in the Idura Dashboard and fill in the order form. You need the club's EU VAT ID and the domain from step 2.
- Idura review the order and forward it to Swedbank for approval, then install the certificate in your tenant. Allow 8–15 working days; the Dashboard shows how the order stands.
Idura's own guide is Swedish BankID, under Order Swedish BankID.
Step 4 — Create an application
Open the Applications tab and create a new Verify application:
| Group | Field | Description |
|---|---|---|
| Application | ||
| Name | SkyWinOne |
|
| Domain | The domain from step 2. | |
| Client ID / Realm | Keep the generated one, e.g. urn:my:application:identifier:906768. This is the eID Client ID in SkyWinOne. |
|
| Redirect URL | Your SkyWinOne address followed by /eidCallback, e.g. https://skywin.yourclub.se/eidCallback. |
|
| Application type | Regular Web Application — SkyWinOne talks to Idura from the server, and this type is given a client secret. | |
When the application is created, Idura shows the client secret once. Copy it straight away and keep it somewhere safe: Idura only keeps a scrambled copy, and if you navigate away without copying it you have to generate a new one (OpenID Connect section of the application, Enable OAuth2 Code Flow).
Step 5 — Configure SkyWinOne
The client secret goes in the properties file, where it never appears on any page. The domain and the Client ID are set inside SkyWinOne, by an administrator.
| Where | Name | Description |
|---|---|---|
| Property file — skywinone.properties | ||
skywin_eid_client_secret |
The client secret from step 4. Takes effect when the SkyWinOne service is restarted. | |
| Settings | System settings — card Login with eID | ||
| Idura domain | The domain from step 2, e.g. yourclub.idura.broker. With or without https://. Takes effect as soon as it is saved. |
|
| eID Client ID | The Client ID from step 4. | |
| eID provider | Shows SE BankId and cannot be changed. Other eIDs might be added later. |
|
| eID Client Secret | Only says whether the secret is set in the properties file — it is never shown. | |
When all three — domain, Client ID and secret — are in place, the login page shows the BankID QR code. Until then SkyWinOne works exactly as before.
Check it: once Idura has installed the certificate, log in once with your own BankID — as a member whose record carries your personal identity number. You should land on that member's personal page.
Which login a member gets
| Group | Situation | What happens |
|---|---|---|
| Logged in | ||
| The member has a personal login | Logged in with it, and shown their personal page. | |
| The member has no personal login | One is created — the same kind Add personal logins for Members on the users page makes, with the personal role only — and they are logged in with it. It gets a random password nobody is told; the member can choose one of their own with Forgot password? if they ever want to log in without BankID. | |
| The member also has a staff login | The staff login is left alone. BankID only ever uses the personal login. | |
| Refused | ||
| No member has the personal identity number | Refused. Add the number to the member's record. | |
| Several members have it | Refused, since there is no telling which one it is. Merge the duplicates. | |
| Several personal logins belong to it | Refused. Remove the logins that should not be there. | |
Troubleshooting
| Group | What is seen | What to do |
|---|---|---|
| The login page | ||
| No BankID on the login page | One of the three is missing: the Idura domain, the Client ID, or skywin_eid_client_secret — the secret needs a restart. The card Login with eID shows which. The page also offers no way in at all while the database version or the license is not valid. |
|
| Unknown error. Please try again. straight away | Idura refused to start the login. Check that the domain, the Client ID and the secret all belong to the same application, that Idura has installed the BankID certificate (step 3), and that the server can reach the Idura domain. The SkyWinOne log says eID: Idura refused to start a BankID login, with Idura's reason. |
|
| Too many failed login attempts from this address. | The brute-force protection has blocked the address for 15 minutes; BankID is blocked along with passwords. | |
| After identifying | ||
| You were identified, but you are not in the club's member register. | No member has that personal identity number. Add it to the member's record. | |
| More than one member in the register has your personal identity number. | Merge the duplicate members. | |
| More than one login is connected to your personal identity number. | The member has several personal logins. Remove the extra ones. | |
| You were identified, but a login could not be made for you. | Usually another login already has the username the new one would take. The log says eID: no personal login could be made, and why. |
|
| Your login is disabled, locked or expired. | Open the member's personal login and put it right. | |
| The QR codes | ||
| The QR code on the start page or the jump queue leads nowhere | grails.serverURL is not the address the members' phones can reach. |
|
| The BankID QR code disappears and Show new QR code appears | Nothing is wrong: a code nobody scans runs out after two minutes, and the page waits to be asked for a new one rather than keep asking Idura. | |
Privacy
SkyWinOne uses the personal identity number BankID returns only to find the member; it does not store it or anything else from the identification. The identification itself passes through Idura, so the club's agreement with Idura covers how they handle it.