# Login.gov

**Canonical:** https://apis.io/providers/login-gov/  
**Website:** https://www.login.gov  
**APIs profiled:** 7

Login.gov is the U.S. federal government's secure single sign-on and identity verification service for the public, operated by the General Services Administration's Technology Transformation Services (GSA TTS). Relying parties — federal, and in some cases state and local — federate user authentication to Login.gov via OpenID Connect (iGov profile) or SAML 2.0, with support for IAL1 (auth-only) and IAL2 (identity-verified) assurance and AAL2 multi-factor authentication including phishing-resistant and PIV/CAC authenticators.

## Kin Score — 56.0 / 100 (strong)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 56.0).

| Facet | Score |
|---|---|
| Discoverability | 74.1 |
| Contract Quality | 66.5 |
| Governance | 25.0 |
| Contract Governance | 25.0 |
| Operational Transparency | 44.7 |
| Developer Ergonomics | 50.0 |
| Commercial Clarity | 44.7 |
| Access Clarity | 44.7 |

Regulatory layer — **Government & Public Sector**: 50.0 (matched via tags).

## Agent readiness — 29.1 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Freemium · Self-serve signup — onboarding: self-serve, pricing: freemium, trial: no (confidence: high).

## APIs (7)

- **Login.gov Authentication API** — SAML SSO request endpoint.
- **Login.gov Authorization API** — OAuth 2.0 authorization endpoint where the user authenticates.
- **Login.gov Discovery API** — OIDC discovery and public key endpoints.
- **Login.gov Logout API** — RP-initiated logout and session termination.
- **Login.gov Metadata API** — SAML 2.0 IdP metadata.
- **Login.gov Token API** — Token exchange using private_key_jwt or PKCE.
- **Login.gov UserInfo API** — User attribute retrieval with a bearer access token.

## Agentic access (1)

- **Login Gov Agentic Access** — 9 operations · 2 acting

## Security (3)

- **Login Gov Authentication** — http · 1 scheme
- **Login Gov Domain Security** — TLSv1.3 · HSTS · DNSSEC · DMARC
- **Login Gov Vulnerability Disclosure** — Hackerone · security.txt · contact published

## Plans (1)

- **Login Gov Plans Pricing**

## Tags

Government, Federal, GSA, Identity, Authentication, SSO, OIDC, SAML, IAL2, AAL2

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/login-gov/). Scores are computed from the provider's own public artifacts under a published rubric.
