Get verified signer identities
The identity each eID actually verified, per signature — as opposed to the signer details the sender entered when creating the document.
Why this is a separate endpoint: signer.ssn is what the sender supplied. It is never overwritten with what the eID returned, so the two can differ, and this is where you read the verified one.
One shape for every eID. Keys are always present and null when a scheme issues nothing, so you never branch on provider to find where the identity lives:
identity.nationalId— the national identity number, masked per the workspace’s SSN display setting. Null for schemes that issue none: MitID without CPR scope, MitID Erhverv, and iDIN, which may never expose a BSN.identity.serialNumber— always present. A stable, non-sensitive reference for this person at your organization. Use it to recognise a returning signer without ever handling a national id. Scoped per organization, so the same person yields a different value for a different customer.identity.match— whether the verified identity matched the intended signer. Computed before masking, so it stays meaningful even whennationalIdis hidden by policy.
identity is null for drawn and click-to-sign signatures: nothing verified an identity.
Permissions: requires the READ_DOCUMENT workspace permission and the signatures:read scope. documents:read alone never returns a national identity number.
Auditing: every call is recorded on the organization audit log — who read a verified identity and when. The identity values themselves are never logged.

