Identity Management
SPID in Italy: Level 2 Is Standard, How to Get It and Integrate It
17 September 2026

SPID (Sistema Pubblico di Identità Digitale) is Italy’s national digital identity system: a single set of credentials that lets citizens and businesses log in to public administration portals and, increasingly, private services. The overseeing authority, AgID, accredits every provider issuing these identities, which means one login replaces dozens of separate accounts across government sites.
TL;DR:
- Almost all government portals require Level 2 security, which uses a password and one-time code, with app-based codes preferred for faster login.
- Applying for SPID requires a valid ID, tax code, personal email, and mobile number registered in your name, with in-person verification as a fallback.
- Credentials are valid indefinitely as long as your contact details stay current and your Identity Provider remains accredited by AgID.
- Support issues mainly stem from outdated contact information or lost second-factor access, requiring updates or re-verification through your provider.
- Integration efforts should prioritize error handling and recovery processes, as dependency on external Identity Providers affects system reliability and user support.
Table of Contents
- What SPID is and who runs it: the ecosystem in plain terms
- How SPID works: credentials and the three security levels
- Who can get SPID and what you need: eligibility and documents checklist
- How to obtain and activate SPID: step-by-step options and timeframes
- Security and privacy: official protections and user responsibilities
- Where you use SPID: common services and real examples
- Validity period of SPID credentials and renewal/maintenance process
- Troubleshooting common issues and support resources for users
- A short engineering perspective: integrating SPID responsibly
- Vicedomini Softworks helps organisations build secure, working SPID integrations
- Sources
- FAQ
What SPID is and who runs it: the ecosystem in plain terms
SPID is not a single app or a government-issued card. It is a federated identity model, and understanding the three roles involved explains almost everything about how the system behaves day to day.
AgID sits at the top as the regulator. It does not issue identities itself. Instead, it accredits private companies, called Identity Providers, and holds them to strict technical and security standards. This structure lets AgID supervise the whole system without running the infrastructure directly, which keeps costs down for the state while still enforcing consistent rules across every provider.
Inside that structure, two roles matter most:
- Identity Provider (IdP): verifies who you are and issues your SPID credentials.
- Service Provider (SP): the website, app, or portal (public or private) that accepts your SPID login instead of building its own registration system.
In practice, users meet this ecosystem through a single, recognisable moment: the “Entra con SPID” button on sites ranging from the tax office to a regional health portal. According to Spid, the whole point of the federated model is that Service Providers never need to manage identity verification themselves. They simply trust the IdP that already did the work.
How SPID works: credentials and the three security levels
Every SPID identity runs on a username and password, but what happens after that depends on which security level the service you’re accessing demands.
SPID defines three security levels, and the Signicat developer documentation confirms that Level 2 is the standard requirement across most Italian government portals.
The three levels break down like this:
- Level 1: username and password only, used for lower-risk services.
- Level 2: password plus a one-time code, sent by SMS or generated through an authenticator app. This is what almost every public administration portal requires.
- Level 3: password plus a physical device, such as a smart card or qualified hardware token, reserved for the highest-risk transactions.
For nearly everyone reading this, Level 2 is the only level that matters in daily practice. Tax filings, healthcare bookings, and university portals all sit at Level 2, and you will rarely, if ever, be asked to set up Level 3 unless your work involves handling especially sensitive data on behalf of an organisation. Choosing an Identity Provider that supports app-based one-time codes rather than SMS alone tends to make day-to-day logins faster and slightly more resistant to interception.
Who can get SPID and what you need: eligibility and documents checklist
Any Italian citizen, resident, or business can apply for SPID, and there is no age floor beyond the general rule that minors need a legal representative to apply on their behalf. Foreign nationals legally resident in Italy with a valid tax code are also eligible.
Before starting, gather these four items:
- A valid identity document (passport, national ID card, or driving licence).
- Your tax code (codice fiscale) or health card, which carries the same number.
- A personal email address you control long term.
- A personal mobile phone number, not a shared or organisational line.
Pro Tip: Register SPID using a mobile number and email address that belong to you personally, not your employer’s. If you change jobs and lose access to a company phone or inbox, recovering your SPID credentials becomes far harder.
If none of your documents pass automated checks, most providers still offer in-person verification through a Registration Authority Officer (RAO), typically at a post office, municipal office, or partner retail point. It takes longer than the digital routes but works when self-service verification fails.
How to obtain and activate SPID: step-by-step options and timeframes
Getting SPID activated follows a predictable sequence, though the exact verification step you choose changes how long the whole process takes.
- Choose an accredited Identity Provider. AgID publishes the list; each one offers slightly different verification tools and, in some cases, different fees for optional services.
- Prepare your documents (identity document, tax code, personal email, personal mobile number).
- Pick a verification method to prove your identity matches your documents.
- Complete the registration form on the IdP’s platform.
- Receive your credentials once verification clears.
The verification method you choose at step three is where things diverge most:
- Webcam verification: a live video call with an operator, usually completed within minutes and available at almost any hour.
- In-person RAO verification: face-to-face confirmation at a post office or municipal desk, useful if webcam checks fail or you prefer a human interaction.
- CIE (electronic identity card): if you hold Italy’s chip-based ID card, some IdPs let you self-verify using a card reader or NFC-enabled phone.
- Digital signature or CNS (National Services Card): if you already hold a qualified digital signature or CNS, you can often skip manual verification entirely.
According to the AgID user guide, availability of each method varies by provider, so check before you start. Webcam and CIE routes are typically instant or same day; RAO appointments can take longer depending on local demand. SPID itself is free for citizens, though some providers charge for expedited or optional verification channels.
Security and privacy: official protections and user responsibilities
The system’s structural security rests on accreditation. AgID does not simply approve an Identity Provider once and walk away. Every accredited IdP operates under continuous technical and procedural standards, and the federated trust model means no single company holds a monopoly on your identity data. If one provider had a problem, the damage would not automatically extend to every SPID user across every provider.
That structural protection only goes so far, though. The weakest point in almost any identity system is the user, not the infrastructure. A few habits matter more than most people realise:
- Use credentials, a phone number, and an email address that belong to you personally, never a shared or workplace account.
- Keep the device holding your authenticator app or receiving OTP messages locked and updated.
- Never share a one-time code with anyone, including someone claiming to be from your Identity Provider or a public office.
- Treat unexpected SPID login prompts as a warning sign, not routine.
Pro Tip: If you lose access to the phone number or email registered to your SPID account, recovery can be slow and sometimes requires re-verification from scratch. Update your registered contact details with your Identity Provider the moment either one changes, rather than waiting until you need to log in.
Where you use SPID: common services and real examples
SPID has become the default login across a wide stretch of Italian public administration, and its reach into private services keeps expanding. The OECD’s case note on SPID documents this as a deliberate policy push: public bodies are required to make services available through SPID rather than building parallel login systems.
The most common uses fall into a few clear categories:
- Tax and social security: filing with Agenzia delle Entrate, checking pension and benefit records through INPS.
- Healthcare: booking appointments and viewing results through regional health portals.
- Education and employment: university enrolment services and public competition (concorsi pubblici) applications, most of which now mandate SPID rather than a local username and password.
- Private services: a growing number of banks, insurers, and utility providers accept SPID to speed up onboarding, cutting out repetitive identity checks.
For services where SPID is mandatory, such as most concorsi pubblici applications, there is no alternative login route. For everything else, SPID mainly saves time: one set of credentials replaces a dozen separate account registrations across separate portals.
Validity period of SPID credentials and renewal/maintenance process
SPID credentials do not expire in the way a passport or driving licence does. Once activated, your identity stays valid indefinitely, provided your registered contact details remain accurate and your Identity Provider keeps operating under AgID accreditation. There is no annual renewal fee and no periodic re-verification requirement for most users.
What does change over time is the practical maintenance side. If your mobile number or email address changes, you need to update those details with your Identity Provider promptly, since they are the recovery route if you ever lose access to your second factor. Some IdPs also periodically prompt users to confirm their details are current, particularly after long periods of inactivity, though this varies by provider rather than following a single national rule.
A separate scenario worth flagging: if your chosen Identity Provider ever loses its AgID accreditation or exits the market, your credentials issued through that provider would stop working, and you would need to register with a different accredited IdP. This has happened rarely in practice, but it is worth knowing that your SPID identity is tied to a specific provider’s continued accreditation, not to AgID directly.
For businesses managing SPID access across multiple employees, maintenance becomes more involved. Staff turnover means credentials tied to individual staff members need deactivation when someone leaves, and any organisation integrating SPID login into its own systems needs a clear internal process for tracking which employees hold active credentials tied to company-related services.

Troubleshooting common issues and support resources for users
Most SPID problems fall into one of three categories: a failed login, a lost second factor, or a verification step that will not complete.
If your one-time code never arrives, check first that the mobile number registered with your Identity Provider is still active and matches the one physically in your hand. SMS delivery delays happen, but a persistent failure usually means the registered number is out of date, which loops back to the same advice covered earlier: keep your contact details current before you need them.
If you have lost the phone or lost access to the authenticator app tied to your account, most IdPs offer an identity re-verification process rather than a simple password reset, since the second factor is deliberately hard to bypass. This is by design. It protects you from someone else recovering your identity, but it does mean the process takes longer than a typical “forgot password” flow. Expect to repeat some form of the original verification step, whether that is webcam, RAO, or CIE-based.
For anything the standard recovery flow does not solve, AgID’s own frequently asked questions page covers a wide range of scenarios, from changing Identity Provider to handling accessibility needs during verification. Your Identity Provider’s own support channel is usually the fastest route for account-specific issues, since AgID sets the rules but does not manage individual accounts directly.
One quiet but common issue: users forget which IdP they registered with, particularly if it has been years since activation. There is no central AgID lookup for this by design, since AgID does not hold your credentials. Checking old confirmation emails or your browser’s saved logins is usually the quickest way to recover that information.

A short engineering perspective: integrating SPID responsibly
Organisations building SPID login into their own platforms tend to underestimate two things: error handling and support load. SPID’s federated model is secure, but it also means your system depends on an external IdP’s uptime and response format, and that dependency needs to be tested thoroughly in staging before it ever reaches production users.
The insight from OECD’s review is worth taking seriously here: integrating SPID improves onboarding because you inherit pre-verified identities, but it shifts the support burden toward recovery workflows for users who lose access to their second factor. Design for that from day one, with minimal data retention and careful key management around whatever session tokens your integration generates.
Our team works with organisations on exactly this kind of architecture. If your team is planning a SPID integration, get the error handling and recovery paths reviewed before launch, not after the first support ticket arrives.
— Pepe F.
Vicedomini Softworks helps organisations build secure, working SPID integrations
Our company offers identity integration work where clients work directly with the engineers designing their SPID authentication flow, rather than through an account manager relaying requirements back and forth. That direct line matters most when a login system touches sensitive citizen or customer data and every architecture decision needs to trace back to a real security rationale, not a generic template.

We provide services covering architecture and integration planning, security review of authentication flows, API development for connecting Service Provider systems to accredited Identity Providers, and testing of recovery paths before real users use them. Teams writing user-facing SPID copy in Italian for onboarding screens may also find the Italian content generation tools from Babylovegrowth useful for localisation work alongside the technical build.
If your organisation is planning a SPID integration or reviewing an existing one for security gaps, explore Vicedomini Softworks’s services or get in touch to scope the work with an engineer directly.
Sources
FAQ
What is SPID and how do you get it?
SPID is Italy’s national digital identity system, a single login for public administration and participating private services, and it is free for citizens to obtain. You get it by choosing an accredited Identity Provider, submitting your documents, completing identity verification through webcam, in-person RAO, CIE, or digital signature, and receiving your credentials once that verification clears.
How do I find out which SPID provider I registered with?
There is no central AgID lookup tool for this, since AgID accredits providers but does not hold individual credentials itself. Check old confirmation emails from your original registration or your browser’s saved login details, as these usually reveal which Identity Provider issued your account.
Where do you activate SPID and how much does it cost?
You activate SPID directly through an accredited Identity Provider’s website, choosing whichever verification method they offer, such as webcam, in-person RAO, or CIE-based checks. SPID itself carries no cost for citizens, though some providers charge fees for optional expedited verification channels.
How do you activate SPID step by step?
Activation follows a fixed sequence: pick an accredited Identity Provider, gather your identity document, tax code, personal email, and personal mobile number, choose a verification method, complete the registration form, and receive your credentials. Webcam and CIE-based verification are usually the fastest routes, often completing within the same day.
What security level does SPID require for most services?
Most Italian public administration portals require Level 2, which combines your password with a one-time code sent by SMS or generated through an authenticator app. Level 2 is the standard requirement across the majority of government services, while Level 3 is reserved for higher-risk transactions that few individual users ever encounter.