This page has been translated using TexTra by NICT. Please note that the translation may not be completely accurate.If you find any mistranslations, we appreciate your feedback on the "Request form for improving the automatic translation ".

MyKey platform (authentication platform for local governments, etc.)

It is one of the platforms that enable certification by by utilizing the My Number Card Japanese Public Key Infrastructure (JPKI) in administrative services. It introduces the supported function and procedures for introducing the service.

Table of Contents

1. What is My Key Platform (PPID method)?

1. 1. Overview

The MyKey platform (PPID method) ensures the security of function usage by providing a My Number Card that pays out a unique user identification (PPID (*)) for each service and enables the use of My Number Card for multiple services.
In order for Japanese Public Key Infrastructure (JPKI) to be used in various situations for administrative services, we provide services in two categories with different function and features.

  • *PPID (Pairwise Pseudonymous Identifier) is a unique pseudo nymous identifier (different from MyKeyID) generated by the MyKey platform for each linked system and linked to a My Number Card.

1.2. Characteristics of each type

The MyKey platform (PPID method) has the following two usage patterns.

  • Type (1) APIs: In response to the use of a smartphone by scanning over the Internet without the need to enter a My Number Card security code, the MyKey platform provides local governments with a card scanning function and a scanning screen that support face-to-face use. The validity of the electronic certificate for user certification to Japanese Public Key Infrastructure (JPKI) can be confirmed.
  • Type 2 (APIs): Instead of municipalities having to prepare a card reading function and a reading screen, it is possible to confirm the validity of the electronic certificate for the user identification to Japanese Public Key Infrastructure (JPKI) in a wide range of scenes including non-face-to-face environments.

By selecting either or a combination of both, it is possible to customize the service to match the content of the administrative services provided by each local government. The characteristics of each type are as follows.

1. 2.1. Type (1) API, Type (2) Common API

  • It is possible to issue PPID (pseudonym identifier) which is given identifier for each administrative service
  • For municipal systems that provide administrative services, by linking PPIDs (pseudonymous identifiers) to the user number of the municipal system in cooperation with the My Key platform, it is possible to operate authentication by My Number Card and administrative services in an integrated manner
  • It is possible to confirm the revocation status of the signature electronic certificate associated with the user identification electronic certificate and to confirm whether or not there has been a change in basic four information (name, address, date of birth, gender) (*)
  • * Keep in mind that it is not a electronic certificate that reads the signature function from the My Number Card to confirm its validity.

1.2. 2. Type ①

  • Mainly face-to-face services such as over-the-counter services
  • CARD-READING SCREEN AND CARD-READING function
  • Support for "Hold"
  • Provision of basic four information (name, address, date of birth, gender) scanned from a app for assisting input of card information to a local public system
  • System terminals are WindowsOS.
  • Verification by smartphone is available (Type 1 in cooperation with Digital Verification Service (when using APIs ))

1.2.3. Type ② API

  • Validity of electronic certificate to Japanese Public Key Infrastructure (JPKI) for user identification can be confirmed using APIs
  • The OS of the system terminal does not matter.

Please see Table 1 below for a comparison of MyKey platform services. For details on each type of service, please contact Inquiry Form (Digital Agency MyKey Platform) .

Table 1 Comparison of Mikey Platforms

ItemMy Key Platform (PPID method) Type 1 APIMy Key Platform (PPID method) Type (ii) APIDigital certificate service Digital Verification Service (when using APIs
Usage ScenariosEnable Public Personal Authentication by embedding in counter terminals for face-to-face servicesCertified function only (PPID issuance and Public Personal Authentication are possible)By installing the app on users' smartphones, Public Personal Authentication can be performed on the smartphone.Public Personal Authentication is possible by embedding it in the counter terminals of face-to-face services. In addition, by installing an application on the user's smartphone, Public Personal Authentication can be performed on the smartphone.
Available OrganizationsExecutive branchExecutive branchGovernment / private sectorExecutive branch
Reader terminalPC terminal (Windows)- (Developed by service provider) * 1Smartphone (iOS/Android)PCs (windows), Smartphones (iOS/Android)
Scanning screen and scanning function provided by Digital AgencyWindows Apps- (Developed by service provider) * 1iOS app / Android app, computer browser * 2Windows app, iOS app / Android app, personal computer browser * 2
PPID DisbursementCorrespondenceCorrespondenceCorrespondenceCorrespondence
Use of KazashiCorrespondenceNot SupportedNot SupportedCorrespondence
Function provided by basic four informationCorrespondence- (Developed by service provider) * 1CorrespondenceCorrespondence
Response to the Signing electronic certificateNot SupportedNot SupportedCorrespondenceNot Supported
Response to electronic certificate for IdentificationCorrespondenceCorrespondenceCorrespondenceCorrespondence
  • * 1 We can also develop by incorporating the "Kazashi scanning client software" (DLL file for Windows, iOS / Android library) provided by Digital Agency into the service.
  • * 2 For authentication on a computer browser, by displaying a QR Code on the browser and having the smartphone read it, the My Number Card can be read via the smartphone.

1.3. Specifications

My Key Platform (PPID method) usage patterns and supported regions / function are as follows.

1. 3.1. Assumed Usage Patterns

  • Use in face-to-face environments using Windows PCs (Type 1)
  • Can be used regardless of the type of OS and usage environment (face-to-face or non-face-to-face) (Type II)

1.3.2. Types of electronic certificate that can be validated

  • Electronic certificate for Identification (Compatible with both Types 1 and 2)
    • It is something that proves the identity of the user online.

1.3. 3. Methods of electronic certificate validation

  • OCSP Responder Method (Both Types 1 and 2 Supported) (* 1)
    In an online environment, the validity of each electronic certificate is inquired and authenticated. This system makes it possible to check the revocation status in real time.
  • CRL Provision Method (Only Type ② is supported (* 2))
    This method confirms the validity of a electronic certificate from a revocation list that is issued periodically (once a day, etc.), making it possible to process requests quickly and in batches.
  • * 1 When using private sector (JPKI), which uses OCSP responder method with Japanese Public Key Infrastructure as the signature verifier, in principle, a fee will be charged for providing electronic certificate revocation information (however, it will be free of charge for the next three years from January 1, 2023). On the other hand, when using the MyKey platform, no fee is charged because the administrative agency becomes the signature verifier.
  • * 2 If the OCSP responder method cannot be used due to maintenance, etc., validity confirmation is also performed in the CRL provision method even in Type (1).

For details, please refer to the validity confirmation method for the electronic certificate.

1.3.4. Using My Number Card's Kazashi application (Type 1: APIs only)

With the amendment to the Public Personal Authentication Act, a provision has been established regarding a method that does not require the entry of a personal identification number (PIN) for identity verification by the City of My Number Card. For details, please visit , Client Software for in-person use of My Number Card without PIN, .

1.3.5 Types of collaboration with digital authentication services (1) APIs

Type (1) In the linkage of digital authentication services of API, the same PPID is issued for Type (1) API and digital authentication services of My Key Platform, so authentication using smartphones is possible.

  • *For more information on digital certification services, see "Digital Certification Services Digital Agency Web Service Application."

1.4 Implementation Steps

The installation procedure is as follows.

  • 1. Inquiry Form (Digital Agency MyKey Platform)
  • 2. Receive application forms, etc. from Digital Agency
  • 3. Submit the application form, etc. * After submitting the application form, etc., approximately three weeks are required until the specifications are provided, due to the procedures required for the disclosure of technical information, etc.
  • 4. Mykey Receive information necessary for development, such as platform specifications
  • 5. Renovate or develop the system of providing administrative services to link with the system of the My Key platform
  • 6. Perform an integration test
  • *Type ② If you use API, you can skip steps 1 to 3. Start checking from step 4.
  • *When using Type (1) API, which is linked to digital authentication services, you need to apply for digital authentication services, in addition to the Type (1) API introduction procedure. You will be informed after applying from the inquiry form.

2. What is My Key Platform (My Key ID method)?

2.1. Overview

The MyKey Platform (MyKey IDmethod) is a platform that utilizes the function of Japanese Public Key Infrastructure (JPKI) to utilize My Number Card in administrative services using Internet connection systems.
Currently, the My Key platform is used to register My Key IDs (* 1) linked to library user numbers on the My Key platform, allowing My Number Card to be used as a library card.

  • * 1 Unique IDs issued to users of the MyKey platform. Issued in response to the issuance number of the My Number Card for electronic certificate user certification, it is used as a key to identify users in order to provide various services and Individual Number Card Point on the MyKey platform.

2. 2. Features of the MyKey platform (MyKey ID method)

The Mikey platform (Mikey ID method) has the following characteristics.

  • For municipal library services only
  • Can be used by introducing the "My Key Platform Utilization Software" provided by Digital Agency, and no need to renovate systems providing existing administrative services (WindowsOS only)
  • Response to Use of Kazashi on the My Number Card

2.3. Implementation Steps

The installation procedure is as follows.

  • 1. In order to obtain the information necessary for the introduction procedure (IDs, passwords, etc.), please contact via the inquiry form (Digital Agency My Key Platform).
  • 2. Please refer to the pages in the "Getting Started" guide we will send you from Digital Agency to obtain the operation manual and to confirm the necessary procedures and manuals.
  • 3. Download the "software for use with MyKey Platform, etc."
  • 4. Install the "MyKey Platform Utilization Software" on the local government's terminal and perform the necessary settings.
  • *It is possible to use without modifying the system that provides administrative services.

3. Terms of Use and Privacy Policy

4. Inquiry

For inquiries related to the MyKey platform, please contact the Inquiry Form (Digital Agency MyKey Platform) .