Why Digital ID?
Many Californians submit Personally Identifiable Information (PII) to access government services, often through burdensome processes that require them to upload and share more personal information than needed. This process often excludes those without an established government identity, like a state-issued ID.
To process these requests, each State department must independently verify eligibility attributes from identity providers and data sources that hold personal information. The lack of shared infrastructure across departments results in increased costs, less efficiency, and a greater risk of data breaches and fraud.
The California Digital Identity program helps by making it easier, more secure, and private for people to access California government services online.
The California Identity Gateway (IDG) is a secure platform that helps state and local entities verify an individual’s identity when they apply for services online. It acts as a central point that connects to ways of confirming who an individual is and their attributes that make them eligible for a specific benefit or service. This approach simplifies the process for individuals and makes it more secure and private for everyone involved.
Benefits at a glance
The California Identity Gateway offers several advantages for Californians and state government.
- Increases Efficiency and Reduces Administrative Burden: Verifying identity and eligibility attributes online streamlines processes, reduces paperwork and office visits, saving time and effort.
- Inclusive and Equitable for Californians: Multiple ways to verify identity, even for those without official documents or a DMV-issued ID.
- Privacy-by-Design: Personal data is not stored and only used for real-time verification with user consent.
- Saves Costs: Shared infrastructure eliminates duplicate verification across agencies and results in cost savings.
- Reduces Fraud: Verifies identity and eligibility attributes before services or benefits are provided
- Open and Transparent: Open-source, vendor-agnostic platform ensures all departments receive new features, security upgrades, and easily adapts to emerging technologies
When should I use the California Identity Gateway?
The California Identity Gateway is the State’s primary platform for delivering digital identity services and eligibility attribute verification. It helps agencies easily connect to approved identity and authorization services.
Consider using the California Identity Gateway if your agency provides digital services that require:
- Checking a person’s identity.
- Verifying eligibility requirements for a program or service.
- Using digital identification or credentials.
- A shared login system.
What’s included?
The California Identity Gateway is a secure, statewide platform managed by the California Department of Technology, its core services include:
Identity Verification: The California Identity Gateway can verify a person’s identity through multiple ways, including:
- Through approved identity providers (such as Login.gov, ID.me etc.) where the user has set up a verified account.
- Through a user submission of personally identifiable information shared to an identity verification service through the California Identity Gateway. They do not need an account established at a third party provider.
Optional features
Here are some optional services you may request as a part of your service request:
- Attribute Verification: The California Identity Gateway checks specific qualities like age category, if someone receives CalFresh, disability status, Medicare enrollment, California residency status or veteran status. It removes personal information and simply returns a “yes” or “no” answer about an individual’s eligibility qualifiers in order to receive a service or benefit.
Roles & responsibilities
| Responsibility | CDT | State / Local entity | Vendor |
|---|---|---|---|
| Lead statewide efforts and digital identity guidelines | X | ||
| Establish technical, privacy, and guideline standards | X | ||
| Operate the California Identity Gateway | X | ||
| Maintain statewide contracts (IdP, Proofing, Attribute Providers) | X | ||
| Define program-specific requirements and eligibility | X | ||
| Determine level of verification needed | X | ||
| Operate programs and support end-users | X | ||
| Provide alternate means of identity proofing for end users if online verification is not feasible | X | ||
| Build and maintain identity and attribute proofing systems to state standards | X | ||
| Adhere to security, privacy, and accessibility rules and standards | X | ||
| Manage personal digital identity and consent to share attributes through the California Identity Gateway | Users* |
Notes: *Defined as users who seek services from statewide and local agencies who control their own digital identities and agree to share their identity or attribute information. Users must also have clear choices for verification if digital methods don’t work for them.
Rates
The rate schedule represents standard CDT services. If a Customer requires technology solutions that are not part of the standard, CDT will review the Customer’s request and provide customized pricing as necessary.
| Service Description | Service Identifier | Product Name | Unit of Measurement | Rate | Service Code | Notes |
|---|---|---|---|---|---|---|
| Digital ID - Transaction Costs | CA Digital Identity Services | CA Digital Identity Services | Variable | Transaction Cost +15% | P201 | |
| Digital ID - Shared Annual Costs | CA Digital Identity Services | CA Digital Identity Services | Variable | Shared Annual Cost +15% | P202 |
- Specialized Support: For customer support needs that exceed standard service support, CDT will utilize existing consulting rates to recover the cost of additional effort.
- Cloud Hosting: External Cloud Hosting may be required when a customer’s IDG implementation involves CDT-hosted environments or supporting infrastructure that must run on third-party cloud hosting services (e.g., CDT’s contracted cloud services). This may occur when customer onboarding requires dedicated or expanded hosting capacity to support application connectivity to the identity gateway, increased transaction throughput, enhanced availability requirements, or specific security and compliance configurations. In these cases, hosting costs are driven by the level of infrastructure required to support the customer’s onboarding and ongoing usage. These costs will be recorded and recovered as CDT’s contract cloud services charges.
Request service
| Step | What you do | How / Where |
|---|---|---|
| 1 | Start discovery session | Contact your CDT Account Lead to schedule a collaborative conversation with a CDT expert about your goals, constraints, and priorities to identify the right path forward. |
| 2 | Prepare your documents | If possible, prepare documentation that explains the use case(s) or application that requires a digital identity solution. Include this in the request and/or attach it to the Case/Request. |
| 3 | Submit request | Submit a Digital Identity Services Case/Request in the CDT IT Service Portal. Attach relevant documents or a product requirement document (PRD) supporting the request. |
| 4 | Implement California Identity Gateway | Work with the Digital Identity team to implement the California Identity Gateway on your web application with the appropriate solution to meet your needs. |
Optional Add-Ons
Submit only if identified during your Discovery or Design Session(s).
| Add-On | What you do | How / Where |
|---|---|---|
| Professional Services | Submit Professional Services Case/Request | Reference your Digital Identity Services Case/Request # in this request. Attach relevant documents or a product requirement document (PRD) supporting the request. |
| Cloud Hosting (CAMC) | Submit a California Managed Cloud Services Case/Request request | Reference your Digital Identity Services Case/Request # in this request. Attach relevant documents supporting the request. |
FAQs
1. Where can I get more information about Digital Identity Services?
Contact your CDT Account Lead.
2. Can the Digital Identity Program support my application?
The California Identity Gateway is built on the Open ID Connect (OIDC) standard. If your web application is capable of supporting OIDC, the California Identity Gateway is compatible and will be able to support your identity and attribute verification needs.
3. Can the Digital Identity Program provide additional consultation to support my initiative?
Additional consulting services are available as optional services as a part of the Digital Identity services listing to support your initiative.
4. What improvements will my organization see by implementing a digital identity solution?
Implementation of a digital identity solution can result in efficiencies to the way Californians access services in a streamlined, privacy-preserving and secure manner, being able to prove their identity and attributes for eligibility for a particular program. Efficiencies in time, labor and cost are also possible for agencies implementing digital identity solutions on their web applications in order to verify individuals requesting benefits or services from them.
5. Can I request multiple identity services in the same request?
If the services are related to the same application, then yes, they can be included under a single request. However, this is still subject to the overall volume of work. If the services are for different applications or projects, separate service requests will need to be submitted.