<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Documentation – EGI Check-in</title><link>/users/aai/check-in/</link><description>Recent content in EGI Check-in on Documentation</description><generator>Hugo -- gohugo.io</generator><atom:link href="/users/aai/check-in/index.xml" rel="self" type="application/rss+xml"/><item><title>Users: Sign up for an EGI Account</title><link>/users/aai/check-in/signup/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/users/aai/check-in/signup/</guid><description>
&lt;h2 id="why-do-i-have-to-sign-up">Why do I have to sign up?&lt;/h2>
&lt;p>Before accessing EGI services, you’ll first need an account through EGI
Check-in, which is the Identity and Access Management (IAM) system used by EGI.
An Identity Manager (or IAM system) is a secure layer that handles who you are,
how you log in, and what you’re allowed to access across all participating
platforms and services.&lt;/p>
&lt;p>&lt;img src="./check-in-graph.png" alt="Check-in Graph">&lt;/p>
&lt;p>Instead of creating a new username and password for every service, EGI Check-in
allows you to log in using an existing identity you already trust — like your
institutional account, ORCID, Google, or even an X.509 certificate. It does this
by acting as a central gateway that connects your trusted login with the
services and resources you need across the European research ecosystem.&lt;/p>
&lt;p>This approach offers major benefits:&lt;/p>
&lt;ul>
&lt;li>You don’t need to remember another password.&lt;/li>
&lt;li>You can access multiple services with a single, consistent profile.&lt;/li>
&lt;li>Your permissions and roles are automatically applied based on your identity.&lt;/li>
&lt;li>If you later switch institutions or accounts, you can still retain your access
(especially if you link identities, which will be discussed later on).&lt;/li>
&lt;/ul>
&lt;h2 id="how-do-i-sign-up">How do I sign up?&lt;/h2>
&lt;p>Signing up is simple. You don’t create a new account from scratch — instead, you
sign in once using an identity provider (IdP) you already have, and EGI Check-in
creates a secure profile for you.&lt;/p>
&lt;ol>
&lt;li>
&lt;p>Go to &lt;a href="https://aai.egi.eu/signup">https://aai.egi.eu/signup&lt;/a>&lt;/p>
&lt;/li>
&lt;li>
&lt;p>Choose your identity provider: You’ll see a list of login options — such as
“University of X,” “ORCID,” “Google,” and many others. You can use the search
bar to find your institution or provider.&lt;/p>
&lt;p>&lt;img src="./check-in-idp-discovery.png" alt="Check-in IdP discovery">&lt;/p>
&lt;/li>
&lt;li>
&lt;p>Enter your login credentials to authenticate yourself with your Home
Organisation&lt;/p>
&lt;/li>
&lt;li>
&lt;p>After successful authentication, you may be prompted by your Home
Organisation to consent to the release of personal information to the &lt;strong>EGI
AAI Service Provider Proxy&lt;/strong>.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>After successful authentication, you will be redirected to the EGI account
registration form. On the introductory page, click &lt;strong>Sign up&lt;/strong> to start the
registration process.&lt;/p>
&lt;/li>
&lt;li>
&lt;div class="alert alert-warning" role="alert">
&lt;h4 class="alert-heading">Note&lt;/h4>
EGI requires some basic
information from you, depending on the attributes released by your Identity
Provider, you may need to provide the values of the missing attributes.
&lt;/div>
&lt;/li>
&lt;li>
&lt;p>On the registration form, click &lt;strong>Review Terms and Conditions&lt;/strong>
(&lt;a href="https://aai.egi.eu/auth/realms/id/theme-info/terms-of-use">Acceptable Use Policy and Conditions of Use - EGI AUP&lt;/a>)&lt;/p>
&lt;/li>
&lt;li>
&lt;p>If you agree to the Terms of Use, select the &lt;strong>I Agree&lt;/strong> option.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>Finally, click &lt;strong>Submit&lt;/strong> to submit your request.&lt;/p>
&lt;div class="alert alert-warning" role="alert">
&lt;h4 class="alert-heading">Very Important&lt;/h4>
You wont be able to
submit your request until you agree to the terms.
&lt;/div>
&lt;/li>
&lt;li>
&lt;p>You will receive an email to confirm your new identity linked to EGI
Check-in. Confirm your identity to continue:&lt;/p>
&lt;p>&lt;img src="./check-in-email-verification.png" alt="Check-in Email verification">&lt;/p>
&lt;div class="alert alert-warning" role="alert">
&lt;h4 class="alert-heading">Important&lt;/h4>
&lt;pre>&lt;code>- You do not need a new password for EGI Check-in — it always uses your existing
account's login system.
- If you don’t see your institution in the list, check whether they are part of
the eduGAIN federation, or consider using ORCID or another supported identity.
- If you plan to use certificates, make sure they are installed in your browser
before logging in.
&lt;/code>&lt;/pre>
&lt;/div>
&lt;/li>
&lt;/ol>
&lt;h2 id="viewing-user-profile-information">Viewing user profile information&lt;/h2>
&lt;p>The profile includes all the information related to the user. This information
can be categorised as follows:&lt;/p>
&lt;h3 id="basic-profile">Basic profile&lt;/h3>
&lt;p>Includes the basic information about your profile:&lt;/p>
&lt;ul>
&lt;li>Name&lt;/li>
&lt;li>Identifiers&lt;/li>
&lt;li>Email addresses&lt;/li>
&lt;/ul>
&lt;p>&lt;img src="./check-in-profile-basic.png" alt="User profile">&lt;/p>
&lt;h3 id="vogroup-membership-and-roles">VO/Group membership and roles&lt;/h3>
&lt;p>Includes information about the Virtual Organisations (VOs) and groups the user
is member of and the roles assigned to the user within those VOs. Check the
&lt;a href="../vos">guide about VOs&lt;/a> for more details.&lt;/p>
&lt;p>&lt;img src="./check-in-profile-vos.png" alt="VO/Group membership">&lt;/p>
&lt;h3 id="linked-identities">Linked identities&lt;/h3>
&lt;p>Information about linked identities to your account. Check the
&lt;a href="../linking">guide for linking accounts&lt;/a> for more information.&lt;/p>
&lt;p>&lt;img src="./check-in-profile-linked.png" alt="Linked identities">&lt;/p>
&lt;h2 id="next-steps">Next steps&lt;/h2>
&lt;p>Once your Check-in account is ready you can check
&lt;a href="../linking">how to link it with different identities&lt;/a> or
&lt;a href="../vos/#how-to-join-a-virtual-organisation">how to join an existing Virtual Organisation (VO)&lt;/a>.&lt;/p></description></item><item><title>Users: Linking Identities</title><link>/users/aai/check-in/linking/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/users/aai/check-in/linking/</guid><description>
&lt;!--
// jscpd:ignore-start
-->
&lt;h2 id="what-does-identity-linking-mean">What does identity linking mean?&lt;/h2>
&lt;p>Linking identities allows you to associate multiple login methods — such as your
university account, ORCID, a Google account, or a certificate — with a single
EGI Check-in account. This means that no matter which identity you use to log
in, you will access the same EGI profile, with the same permissions, group
memberships, and project access.&lt;/p>
&lt;h2 id="what-happens-when-your-identities-are-linked">What Happens When Your Identities Are Linked?&lt;/h2>
&lt;ul>
&lt;li>
&lt;p>You can log in with any linked identity and always reach the same services and
projects.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>You only need to manage one identity no matter how many login options you
have.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>If one identity becomes unavailable (e.g., your university account expires),
you can still access your work using another linked identity.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>You have a more consistent and secure experience across platforms.&lt;/p>
&lt;/li>
&lt;/ul>
&lt;div class="alert alert-warning" role="alert">
&lt;h4 class="alert-heading">Warning&lt;/h4>
Important: While your EGI profile
remains the same, access to specific services may depend on the identity
assurance level of the login option used. Some services require identities with
higher levels of assurance (e.g., issued by academic institutions). If you log
in with an identity that does not meet these requirements, access to those
services may be restricted.
&lt;/div>
&lt;h2 id="what-happens-if-you-dont-link-them">What Happens If You Don’t Link Them?&lt;/h2>
&lt;ul>
&lt;li>
&lt;p>Each login creates a separate EGI account, treated as a different person.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>You may not have access to the projects, roles, or services you used under
your other login.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>Services and collaborators won’t recognize you if you log in a different way.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>If one identity is lost, you might lose access completely or need support to
recover it.&lt;/p>
&lt;/li>
&lt;/ul>
&lt;h2 id="step-by-step-guide">Step by step guide&lt;/h2>
&lt;ol>
&lt;li>
&lt;p>Enter the following URL in a browser:
&lt;a href="https://aai.egi.eu/auth/realms/id/account/#/security/linked-accounts">https://aai.egi.eu/auth/realms/id/account/#/security/linked-accounts&lt;/a>&lt;/p>
&lt;/li>
&lt;li>
&lt;p>Click &lt;strong>Login&lt;/strong> and authenticate using any of the login credentials &lt;em>already&lt;/em>
linked to your EGI account&lt;/p>
&lt;/li>
&lt;li>
&lt;p>You will see the EGI Check-in profile management. Select “Linked Identities”
under the Account security section.&lt;/p>
&lt;p>&lt;img src="./check-in-my-identity.png" alt="Check-in my identity">&lt;/p>
&lt;/li>
&lt;li>
&lt;p>Under the &lt;strong>&amp;ldquo;Account security&amp;rdquo;&lt;/strong> section of your profile page, expand
&lt;strong>Linked identities&lt;/strong> menu.&lt;/p>
&lt;p>&lt;img src="./check-in-link-new.png" alt="Link new identity">&lt;/p>
&lt;/li>
&lt;li>
&lt;p>Search for your desired identity. In case you cannot see it at first glance,
you can use the search box.&lt;/p>
&lt;p>&lt;img src="./search_identity.png" alt="Search my identity">&lt;/p>
&lt;/li>
&lt;li>
&lt;p>Click on the “Link account” blue link on the right side of the identity to
link it.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>You will be taken into the identity login page. Proceed with the login, it
will take you back directly to the EGI Check-in site once done.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>Once done, your new login will be listed under “Linked accounts”.&lt;/p>
&lt;p>&lt;img src="./check-in-link-intro.png" alt="Link new identity intro">
&lt;div class="alert alert-warning" role="alert">
&lt;h4 class="alert-heading">Warning&lt;/h4>
You will need to sign in using
the login credentials from the institutional/social identity provider you
want to link to your account.
&lt;/div>
&lt;/p>
&lt;/li>
&lt;li>
&lt;p>After successful authentication, the new Identity Provider will be available
under the Organizational Identities tab and you&amp;rsquo;ll be able to access EGI
resources with your existing personal EGI ID using the login credentials of
the identity provider you selected.&lt;/p>
&lt;/li>
&lt;/ol>
&lt;h2 id="linking-your-certificate-to-your-egi-account">Linking your certificate to your EGI Account&lt;/h2>
&lt;p>Certificate linking allows you to add the subject DN of your certificate to your
existing personal EGI ID. For this you need to import your certificate to your
browser.&lt;/p>
&lt;p>To link a subject DN to your EGI account:&lt;/p>
&lt;ol>
&lt;li>
&lt;p>Make sure your certificate is already imported in your browser.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>Follow the same steps as above: go to &amp;ldquo;Account Security&amp;rdquo; and click on &amp;ldquo;Linked
identities&amp;rdquo;.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>You will need to link the &lt;strong>IGTF Certificate Proxy&lt;/strong> service. Find it and
click &amp;ldquo;Link Account&amp;rdquo;.&lt;/p>
&lt;div class="alert alert-warning" role="alert">
&lt;h4 class="alert-heading">Warning&lt;/h4>
It is very important to escape
the identity provider selection, cached in the discovery page, before picking
the new one.
&lt;/div>
&lt;/li>
&lt;li>
&lt;p>Then select the certificate you want to link to your account from the popup
window.&lt;/p>
&lt;p>&lt;img src="./check-in-select-certificate.png" alt="Select certificate">&lt;/p>
&lt;/li>
&lt;li>
&lt;p>After successful authentication you will be redirected back to your EGI
Account. Also, you&amp;rsquo;ll be able to access EGI resources with your existing
personal EGI ID using &lt;strong>IGTF Certificate Proxy&lt;/strong> and your certificate.&lt;/p>
&lt;/li>
&lt;/ol>
&lt;!--
// jscpd:ignore-end
--></description></item><item><title>Users: Obtaining Access/Refresh Tokens</title><link>/users/aai/check-in/obtaining-tokens/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/users/aai/check-in/obtaining-tokens/</guid><description>
&lt;h2 id="overview">Overview&lt;/h2>
&lt;p>This page includes all the available ways to obtain OAuth tokens from EGI
Check-in.&lt;/p></description></item><item><title>Users: Virtual Organisations</title><link>/users/aai/check-in/vos/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/users/aai/check-in/vos/</guid><description>
&lt;p>A &lt;a href="https://ims.egi.eu/display/EGIG/Virtual+organisation">Virtual Organisation&lt;/a>
(VO) represents a research community and, in practice, it is just &lt;strong>a group of
users&lt;/strong>. VOs are created to organise a community of researchers, who can share
resources across the EGI Federation and other services to achieve a common goal,
as part of a scientific collaboration.&lt;/p>
&lt;p>&lt;img src="./VOs.png" alt="Virtual Organisations">&lt;/p>
&lt;h2 id="see-the-list-of-virtual-organisations">See the list of Virtual Organisations&lt;/h2>
&lt;p>Existing VOs can be found in the
&lt;a href="https://operations-portal.egi.eu/vo/a/list">EGI Operations Portal&lt;/a>.&lt;/p>
&lt;p>Click on the icon under the “Details” column to access more detailed information
of the VO.&lt;/p>
&lt;p class="img-screenshot">&lt;img src="./OP_VO_details.png" alt="List of VOs in the Operations Portal">&lt;/p>
&lt;h2 id="how-to-join-a-virtual-organisation">How to join a Virtual Organisation&lt;/h2>
&lt;p>There are different ways to join a VO:&lt;/p>
&lt;ul>
&lt;li>Contact the administrators of the VO (the VO Managers). They can send you an
invitation or a link to apply for membership in a VO.&lt;/li>
&lt;li>Some community services provide a link on their Websites to grant access to
their respective VOs.&lt;/li>
&lt;li>Use the enrolment URL that can be found in the detailed information of the
specific VO, in the
&lt;a href="https://operations-portal.egi.eu/vo/a/list">EGI Operations Portal&lt;/a>.&lt;/li>
&lt;/ul>
&lt;p class="img-screenshot">&lt;img src="./OP_VO_enrolment_url.png" alt="Enrolment URL of a VO in the Operations Portal">&lt;/p>
&lt;p>Often, your request to apply for VO membership will be evaluated by a VO Manager
before you are accepted in the VO.&lt;/p>
&lt;h2 id="how-to-create-your-own-virtual-organisation">How to create your own Virtual Organisation&lt;/h2>
&lt;p>To register a new VO, access the
&lt;a href="https://operations-portal.egi.eu/vo/registration">VO registration page&lt;/a> of the
Operations Portal. You will need to log in via Check-in and fill in the &lt;strong>VO ID
card&lt;/strong>, which is the basic information for the VO.&lt;/p>
&lt;p>The VO registration process is detailed in the procedure
&lt;a href="https://confluence.egi.eu/display/EGIPP/PROC14+VO+Registration">PROC14 VO Registration&lt;/a>.&lt;/p>
&lt;p>The person registering a VO is considered the administrator of the VO, also
known as &lt;strong>VO Manager&lt;/strong>. Additional VO Managers do not need to be included at
the time of the VO creation, they
&lt;a href="keycloak/admins#adding-administrators-to-a-group">can be added later&lt;/a>.&lt;/p>
&lt;h2 id="manage-a-virtual-organisation">Manage a Virtual Organisation&lt;/h2>
&lt;p>A VO is managed by its VO Managers. VOs can have more than one administrator,
and they are responsible for the correct operation of the VO. The functions of
the VO Managers include:&lt;/p>
&lt;ul>
&lt;li>Evaluate membership requests and approve or reject them. This is an important
point, since membership in a VO may grant access to data or resources, so
normally a VO Manager should not accept members arbitrarily.&lt;/li>
&lt;li>Attend security recommendations, provide information requested by the EGI
security teams and maintain the resources and users of the VO secure.&lt;/li>
&lt;li>Provide information about the VO activities for EGI and for VO members (to
both people and sites).&lt;/li>
&lt;/ul>
&lt;p>VOs can be structured in &lt;strong>groups&lt;/strong>, to organise the different permissions that
users have inside a community. For example, inside a VO there can be a group for
users that will manage cloud infrastructure, another group for users that access
a specific application, other group for users that will attend a workshop and
need access to Notebooks, etc.&lt;/p>
&lt;p>Check-in offers two tools to organise a community:&lt;/p>
&lt;ul>
&lt;li>&lt;a href="keycloak">Keycloak&lt;/a>.&lt;/li>
&lt;li>&lt;a href="perun">Perun&lt;/a>.&lt;/li>
&lt;/ul>
&lt;p>Follow the links for detailed information on how to manage VO groups.&lt;/p></description></item><item><title>Users: Frequently Asked Questions</title><link>/users/aai/check-in/faq/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/users/aai/check-in/faq/</guid><description>
&lt;h2 id="getting-help">Getting help&lt;/h2>
&lt;p>Requests for technical assistance and other issues related to Check-in can be
obtained by sending an email to:&lt;/p>
&lt;blockquote>
&lt;p>&lt;strong>&lt;a href="mailto:checkin-support@mailman.egi.eu">checkin-support@mailman.egi.eu&lt;/a>&lt;/strong>&lt;/p>
&lt;/blockquote>
&lt;p>Alternatively, if you already have a Check-in account, the &lt;a href="https://helpdesk.ggus.eu/">EGI Helpdesk&lt;/a>
can be used. More information can be found in the
&lt;a href="https://docs.egi.eu/internal/helpdesk/user-guide/">Helpdesk documentation&lt;/a>. In that case,
submit a new ticket and make sure that the support unit is assigned to &amp;ldquo;Check-in (AAI)&amp;rdquo;.&lt;/p>
&lt;p>&lt;img src="./check-in-support-unit.png" alt="Check-in support unit in HelpDesk">&lt;/p>
&lt;h2 id="connect-to-check-in-an-idp-federated-in-an-hub-and-spoke-federations">Connect to Check-in an IdP federated in an hub and spoke federations&lt;/h2>
&lt;!-- markdownlint-disable line-length -->
&lt;h3 id="i-get-an-error-similar-to-error---egi-check-in-service-not-accessible-through-your-institution-surfconext-example">I get an error similar to: &amp;ldquo;Error - EGI Check-in Service not accessible through your institution&amp;rdquo; (SURFconext example)&lt;/h3>
&lt;!-- markdownlint-enable line-length -->
&lt;p>In case of a &amp;ldquo;hub and spoke&amp;rdquo; federation the federation coordinator may require
that the IdP administrators explicitly request to connect to a SP and let their
users to authenticate on these SP.&lt;/p>
&lt;p>In most of the cases this is not a configuration problem neither for the
Check-in service nor for the Identity provider. The connection needs to be
implemented in the hub and spoke IdP Proxy.&lt;/p>
&lt;p>One example of such federation is SURFconext, the national IdP federation for
research and education in the Netherlands operated by SURFnet. If you are using
credentials from a Dutch IdP in eduGAIN, the SURFconext administrator of your
institute needs to request the connection.&lt;/p>
&lt;h2 id="authentication-error-with-adfs-based-identity-providers">Authentication error with ADFS-based Identity Providers&lt;/h2>
&lt;h3 id="why-do-i-get-the-error-below-after-successfully-authenticating-at-my-home-idp">Why do I get the error below after successfully authenticating at my Home IdP?&lt;/h3>
&lt;div class="highlight">&lt;pre tabindex="0" style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-plaintext" data-lang="plaintext">&lt;span style="display:flex;">&lt;span>opensaml::FatalProfileException at (https://aai.egi.eu/registry.sso/SAML2/POST)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>SAML response reported an IdP error.
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>Error from identity provider:
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>Status: urn:oasis:names:tc:SAML:2.0:status:Responder
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>The Responder error status is typically returned from ADFS-based IdP
implementations (notably Microsoft ADFS 2.0 and ADFS 3.0) that cannot properly
handle
&lt;a href="https://docs.microsoft.com/en-za/azure/active-directory/develop/active-directory-single-sign-on-protocol-reference#scoping%3E">Scoping elements&lt;/a>.
Check-in can be configured to omit the scoping element from the authentication
requests sent to such IdPs in order to allow successful logins. Please send an
email to the Check-in Support team using &lt;code>checkin-support&lt;/code> &lt;code>&amp;lt;AT&amp;gt;&lt;/code>
&lt;code>mailman.egi.eu&lt;/code> and include a screenshot of your error.&lt;/p>
&lt;!-- markdownlint-disable line-length -->
&lt;h2 id="i-have-linked-an-igtf-x509-certificate-to-my-check-in-identity-but-the-information-is-inaccurate-or-incomplete">I have linked an IGTF X.509 certificate to my Check-in identity but the information is inaccurate or incomplete&lt;/h2>
&lt;!-- markdownlint-enable line-length -->
&lt;h3 id="what-can-i-do">What can I do?&lt;/h3>
&lt;p>To update your certificate information, follow these steps to log into your
Check-in profile page using your IGTF certificate:&lt;/p>
&lt;ol>
&lt;li>Click
&lt;a href="https://aai.egi.eu/proxy/saml2/idp/SingleLogoutService.php?ReturnTo=https%3A%2F%2Faai.egi.eu%2Fregistry%2Fauth%2Flogin">here&lt;/a>
to access your profile page&lt;/li>
&lt;/ol>
&lt;p>
&lt;div class="alert alert-warning" role="alert">
&lt;h4 class="alert-heading">Warning&lt;/h4>
This may log you out of any
service you have accessed with Check-in on this browser!
&lt;/div>
2. On
the Check-in identity provider discovery page, select &lt;strong>IGTF&lt;/strong>&lt;/p>
&lt;div class="alert alert-warning" role="alert">
&lt;h4 class="alert-heading">Warning&lt;/h4>
If prompted to log in with a
different identity provider, click &lt;strong>CHOOSE ANOTHER ACCOUNT&lt;/strong> and then select
&lt;strong>IGTF&lt;/strong>. Alternatively, you can click
&lt;a href="https://aai.egi.eu/registry/auth/login?idphint=https%3A%2F%2Fedugain-proxy.igtf.net%2Fsimplesaml%2Fsaml2%2Fidp%2Fmetadata.php">here&lt;/a>
for your convenience
&lt;/div>
&lt;p>&lt;img src="./check-in-discovery-igft.png" alt="Check-in IdP discovery IGTF">&lt;/p></description></item></channel></rss>