How to implement the sign-out function
Suomi.fi e-Identification is a single sign-on service to all digital services in public administration that have been connected to the identification service.
Sign-out must be carried out in the front channel
Services linked to Suomi.fi e-Identification require sign-out in a manner that the user is given a summary of their sign-out from Suomi.fi e-Identification. After being given the summary, users can confirm their sign-out separately. The sign-out return call can only be sent to the online service after user action.
Due to the operating logic within Suomi.fi e-Identification, back-channel sign-out is not possible. The online service must send the sign-out request through the user’s browser and direct them to the sign-out page.
Sign-out from your service should be done before sending the SLO message
We would like to remind you that the local session must be closed before the sign-out request is sent in order to make sure any possible error does not prevent sign-out from the service that needs it first.
The user interface must support end-user sign-off
Successful sign-off is important, even if the end user is using only one online service. Pay close attention to the location of the ‘Sign out’ button or link in your service’s user interface. It needs to be easy to find. If the button is not easy to locate, many users will only close the browser or tab without signing out. Simply closing the tab will keep the Suomi.fi e-Identification session open.