WhatsApp Us

Singapore · Singpass Login · Myinfo · FAPI 2.0 · Your UEN, your approval

Singpass integration for Singapore web and mobile apps: login, Myinfo auto-fill and FAPI 2.0

Singpass integration lets your customers sign in with the national digital identity and, with Myinfo, fill forms with government-verified details instead of typing them and uploading photos of documents. Your company applies on the Singpass Developer Portal with its own UEN and Corppass; BtechWaleTech, three freelance developers in India, then builds the OIDC and FAPI 2.0 flow into your web or mobile app, handles keys and tokens securely, and helps you prepare the user journey for approval. Custom apps with Singpass start from US$900. More on our Singapore work.

  • Web app with Singpass fromUS$900, quoted per scope
  • Mobile app with Singpass fromUS$600
  • Who appliesYour company, with its UEN via Corppass
  • Production approvalCan take up to 2 weeks, per Singpass docs
  • FAPI 2.0 deadline31 Dec 2026 for Singpass APIs
  • QuoteItemised in USD in about 2 working days
  • Singpass Login
  • Myinfo auto-fill
  • FAPI 2.0 with PAR, PKCE, DPoP
  • Web and mobile apps
  • Staging to production
  • Minimal Myinfo scopes
  • PDPA-minded data handling

Three freelance developers in India · WhatsApp replies 7 days a week · Singpass work for Singapore companies

  • 2Weeks Singpass says production approval may take
  • 3Freelance developers on your integration
  • 2Months of free maintenance after launch
  • 7Days a week we reply on WhatsApp

The short answer

How does Singpass integration work for a private company?

Singpass integration starts with your company getting Corppass access to the Singpass Developer Portal under its UEN, creating a staging app, and testing. A developer builds the OIDC and FAPI 2.0 login flow and any Myinfo data requests; you then submit the production app with approved scopes and a user journey. BtechWaleTech builds Singpass-enabled apps from US$900.

Collecting identity data? Read our PDPA compliant website guide on NRIC handling, or see outsourced software development for the wider build.

Last updated

Singpass integration, at a glance
What it addsSingpass sign-in and optional Myinfo data sharing with user consent
EligibilitySingapore-registered entities, onboarding with their own UEN
ProtocolOpenID Connect with the FAPI 2.0 Security Profile
Key piecesPAR, PKCE, DPoP, signed client assertions, encrypted ID tokens
PlatformsWeb apps, and iOS or Android apps using app-claimed HTTPS redirects
Singpass feesPer Singpass pricing plan in the Developer Portal, paid by you
Our buildSingpass-enabled web apps from US$900; mobile from US$600

What we build

Singpass integration work we take on

Your company owns the Singpass application, keys and approvals. We write, test and maintain the code that uses them.

Why choose us

Manual document upload, a third-party eKYC tool, or Singpass integration

Three ways Singapore businesses verify who a customer is online, compared on what matters for a local user base.

Manual document upload, a third-party eKYC tool, or Singpass integration
Aspect Email sign-up plus uploaded ID photos Third-party eKYC service Singpass integration built by BtechWaleTech
Data source Whatever the user uploads Document scan and selfie check Government-verified Myinfo data, with consent
User effort Typing, photos, waiting for review Scan documents, take selfie Sign in with Singpass app, approve sharing
Staff review Manual checks of every upload Some manual review Mostly automatic for approved data items
NRIC copies stored Often, as image files Often, by the vendor Only the items you are approved for, if needed
Works for non-residents Yes Usually No: users without Singpass need an alternative
Approval needed None Vendor contract Singpass production approval under your UEN
Ongoing fees Staff time Per-verification vendor fees Singpass pricing plan, plus maintenance
Build cost Low Integration effort Part of builds from US$900

Singpass serves users who have it; if your customers include tourists or overseas clients, you still need a second path, which Singpass's own onboarding guidance expects you to offer.

Pricing

Singpass integration pricing

A custom web portal with Singpass Login and Myinfo auto-fill starts at US$900; iOS and Android apps with Singpass start at US$600. Adding Singpass to an existing application, or migrating an older integration to FAPI 2.0, is quoted after we review your codebase and the data items you need, because effort depends heavily on how your user accounts and sessions already work. Singpass's own transaction charges follow the pricing plan shown in the Singpass Developer Portal and are billed to your company, separately from our work. After two months of free maintenance, care starts at US$120/mo. All figures are USD starting prices, itemised in writing before any billing.

Starting prices in INR and USD
ServiceIndia (INR)Worldwide (USD)Typical timelineWhat is included
Static website from ₹10,000 from US$150 1 to 2 weeks Up to 100 pages, Responsive design, Contact form and enquiry setup, Basic SEO tags and sitemap
SEO website (299+ pages) from ₹20,000 from US$300 3 to 5 weeks 299+ SEO pages, Keyword and page planning, Schema, sitemap, and internal linking, Design to deployment included
Ecommerce store from ₹50,000 from US$750 4 to 8 weeks Product and category pages, Payment gateway setup, Order and inventory basics, Performance tuning
Android & iOS app from ₹40,000 from US$600 6 to 10 weeks Android and iOS app (Flutter or React Native), Login, forms and push notifications, Admin panel and API connection, Google Play and App Store publishing
Custom web app or software from ₹60,000 from US$900 6 to 12 weeks Custom features and APIs, User accounts and roles, Admin panel, Deployment and handover
AI automation from ₹40,000 from US$600 2 to 4 weeks Workflow mapping, Tool and CRM integrations, AI agent or automation build, Testing and handover
Monthly SEO from ₹10,000/mo from US$150/mo Ongoing, monthly Technical fixes, On-page and content work, Local SEO and listings, Search Console reporting
Maintenance and support from ₹8,000/mo from US$120/mo Ongoing, monthly Content updates, Bug fixes, Backups and security checks, Speed and uptime checks

All prices are starting points, quoted in INR for India and USD for international clients, not fixed quotes. Final cost depends on the number of pages, features, integrations, content, and timelines. Share your requirement and you get an itemised estimate with nothing hidden. See full pricing.

What is Singpass integration, in plain terms?

Singpass integration is connecting your website or app to Singpass, Singapore's national digital identity, so users can sign in with it and, if you use Myinfo, share verified personal data with you after giving consent. Under the hood it follows OpenID Connect, the same family of standards behind many “sign in with” buttons, with extra security from the FAPI 2.0 Security Profile.

There are two main products. Singpass Login authenticates the user and tells you who they are. Myinfo goes further and, with the user's consent, returns specific data items your application is approved for, such as name, address or other details, so forms fill themselves. For users acting on behalf of a company, Myinfo Business returns company data and now runs on the Corppass authorisation API.

Why businesses want Singpass integration: fewer typing errors, less document handling, faster onboarding and data that comes from government sources rather than from a phone photo of a card. The trade-off is an approval process, stricter technical requirements than a social login, and responsibility for protecting the data you receive.

Who can use Singpass integration, and what do you need first?

A Singapore-registered entity, onboarding with its own UEN through Corppass. According to the Singpass developer documentation, organisations in regulated industries may need to provide their licences or permits, and applications should request only the data directly needed, with justification for each Myinfo scope, user consent and an alternative for people who cannot use Singpass.

That last point shapes your product. Tourists, many foreign workers and overseas customers do not have Singpass, so a Singpass integration normally sits beside another sign-up path rather than replacing it.

This is also why we cannot apply on your behalf. The Singpass application, the service agreement and the production client belong to your company. Our role starts once your Corppass administrator has granted Singpass Developer Portal access to someone in your team, who can then create the staging app we build against.

  • Company UEN and a Corppass administrator who can grant portal access.
  • A clear use case: why you need Singpass Login, and why each Myinfo item.
  • Any licence or permit relevant to your regulated activity.
  • A non-Singpass path for users without Singpass.
  • A privacy notice and data handling plan for what you receive.

How does onboarding on the Singpass Developer Portal work?

In short: portal access through Corppass, a staging app, testing, a production app with scopes and a user journey, then approval and activation. The Singpass documentation describes the steps for private companies roughly as follows.

  • Get Corppass authorisation under your UEN and request Singpass Developer Portal access from your Corppass admin.
  • Log in to the portal and select your company's UEN.
  • Create a staging application with the right product (Singpass Login or Myinfo) and scopes.
  • Build and test the integration in the staging environment.
  • Switch the portal to production and accept the Singpass service agreement if you do not already have one.
  • Create the production app, choose the Myinfo data scopes (openid is mandatory) and upload your user journey document.
  • Submit for approval; once approved, the production app is activated and its client ID works.

The documentation says production approval may take up to two weeks. For Singpass integration projects, we plan the build so that staging work finishes, and the user journey document is ready, well before your launch date, leaving room for questions from the Singpass team.

Singpass Login, Myinfo or Myinfo Business: which do you need?

Choose Singpass Login when you only need to know that the user is who they say they are; add Myinfo when you need verified personal data for a form; use Myinfo Business when the user is acting for a company and you need company data.

A tenant portal for an existing landlord might only need Login. A financial services application form, where accurate personal details matter, might use Myinfo to pre-fill them. A B2B onboarding flow for trade accounts might use Myinfo Business so the company's registered details arrive verified.

Singpass's documentation notes that Myinfo Business v3 is built on the Corppass authorisation API with FAPI 2.0, and that a new Myinfo Business v3 app is created on the Singpass Developer Portal; older client IDs are not interchangeable with it. If your Singpass integration mixes personal and business flows, we map which screens use which product before any code is written.

How does the Singpass FAPI 2.0 login flow work technically?

Your server first pushes the authorisation request to Singpass over a back channel, the user authenticates in Singpass, and your server exchanges the returned code for tokens using proof that it holds specific keys. According to the Singpass integration guide, the flow uses Pushed Authorization Requests, PKCE, DPoP and signed client assertions.

Pushed Authorization Request (PAR)

Your backend posts the authorisation parameters to Singpass's PAR endpoint and receives a short-lived request URI, which the documentation says expires in 60 seconds. The browser or app is then sent to Singpass with that reference instead of a long, tamperable URL.

PKCE

For each login your server generates a fresh random code verifier and sends only its SHA-256 hash (method S256) at the start. The verifier is revealed at token exchange, so an intercepted code is useless on its own.

DPoP

Proof-of-possession tokens are required for the PAR call, the token exchange and the userinfo request, signed with the same ephemeral key pair within one session, so stolen tokens cannot be replayed from another machine.

Client assertion

Instead of a shared secret, your server authenticates with a short-lived JWT signed by your private key, with a unique ID and an expiry no more than two minutes after issue.

Encrypted ID token

Singpass returns the ID token as an encrypted JWT, so your server decrypts it with your encryption key and then verifies the inner signature before trusting any claim.

Singpass recommends OpenID-certified relying party libraries rather than hand-written cryptography, and we follow that advice in every Singpass integration we build.

Do existing Singpass integrations need to migrate to FAPI 2.0?

Yes. Singpass's developer documentation states that all Singpass APIs must be fully compliant with FAPI 2.0 by 31 December 2026. If your integration was built before these requirements, it likely needs changes before that date.

The good news, according to the same documentation, is that because Singpass was already OIDC-compliant, migration usually means updating parts of the integration rather than rebuilding it. Typical changes are adding the PAR step, switching to PKCE with S256, adding DPoP proofs to token and userinfo calls, and updating client authentication.

For a migration, we start by reading your current code and configuration, list the exact gaps, test the updated flow in staging and plan a production switch that does not log everyone out at once. Leave time: approvals and testing on your side, plus any app store review for mobile apps, can stretch a small code change into several weeks.

How does Singpass integration work in a mobile app?

The app sends the user to Singpass and receives them back through a redirect URL that the app has claimed as its own. Singpass's documentation says native apps should use app-claimed HTTPS URLs, meaning Universal Links on iOS and App Links on Android, not custom URL schemes.

That requirement closes a known gap: with custom schemes, another app on the phone could register the same scheme and intercept the redirect. Claimed HTTPS links are verified against files hosted on your domain, so only your app receives the response.

We build mobile apps in Flutter or React Native and keep the sensitive steps, such as the client assertion and token exchange, on your backend rather than in the app, since anything shipped in an app can be extracted. The app handles the user journey; the server holds the keys. Mobile builds with Singpass integration start at US$600, and our mobile app development page covers publishing on both stores.

Which Myinfo data scopes should you request?

Only the ones your process genuinely needs, with a reason for each. Singpass's onboarding guidance asks for justification per scope, and requesting less makes approval smoother and your data protection burden lighter.

We work through your form field by field: does this field need a verified value, or would the user's own entry do? Is a full date of birth required, or only confirmation of age? Must you keep the NRIC number, or only confirm that the person is who they claim to be? Each “no” removes a scope, a column in your database and a risk.

The user journey document you upload with the production app should show where each item is used. We help draft it with screenshots from staging, so the Singpass team sees exactly what the user sees. A Singpass integration that asks for five well-justified items is easier to explain, maintain and protect than one that asks for twenty just in case.

What happens to customers who already signed up with email?

They link their existing account to Singpass once, after proving they own it, and from then on can sign in either way. Getting this step right matters more than the login button itself, because a careless design creates duplicate profiles or, worse, lets one person take over another's account.

Our usual pattern: an existing customer signs in with their password as normal, opens account settings and chooses to connect Singpass. After the Singpass round trip, the stable identifier Singpass returns for that person is stored against their account. Next time, choosing Singpass finds the linked account directly. We never link accounts automatically by matching names or email addresses, since those are not unique enough to trust.

New customers who start with Singpass get an account created on the spot, with any approved Myinfo items filled in. If someone later tries to register by email with details that look like an existing Singpass-linked profile, the system asks them to sign in instead of creating a second record. Support staff get a simple screen to unlink an identity when a customer asks, with the action written to the audit log.

How much does Singpass integration cost?

There are two parts: the build and Singpass's own charges. With BtechWaleTech, custom web apps with Singpass start at US$900 and mobile apps at US$600; adding Singpass to an existing system or migrating to FAPI 2.0 is quoted after a code review. Singpass's transaction pricing is shown in the Singpass Developer Portal and billed to your company.

Quotes for Singpass integration vary widely because the Singpass part is only one piece. Connecting a login button to a fresh app is modest. Linking Singpass identities to existing customer accounts, handling people who already signed up by email, adding Myinfo to several forms, supporting both web and mobile and passing a security review is considerably more.

Ask any developer what their quote includes: staging and production setup, key management, account linking, Myinfo mapping, the non-Singpass path, user journey documentation, security testing and maintenance. Missing items tend to reappear later as change requests.

  • Login only, or Login plus Myinfo or Myinfo Business.
  • New application, or integration into existing accounts and sessions.
  • Web only, or web plus iOS and Android.
  • Number of forms using Myinfo data.
  • Security review, penetration test support and audit logging.
  • FAPI 2.0 migration of an older integration.

What security does a Singpass integration need?

Careful key management, strict token validation, secure sessions and full logging. Singpass integration moves sensitive identity data, so the weakest point is usually not the Singpass flow but what happens around it.

  • Private signing and decryption keys held in a secrets manager or hardware-backed store, never in code or app bundles.
  • A JWKS containing only public signing and encryption keys, provided to Singpass as an object or a public URL.
  • Key rotation planned and tested, with overlapping keys so logins keep working.
  • Every ID token decrypted and its signature, issuer, audience, nonce and expiry verified.
  • Short, server-side sessions with secure, HTTP-only cookies after login.
  • Audit logs of logins, Myinfo requests and admin access to identity data.
  • Rate limits and monitoring for unusual login patterns.

For larger organisations, we support your security team or an external tester with documentation and fixes. We do not issue security certifications ourselves.

How should Myinfo data be handled under the PDPA?

Collect only approved, necessary items, tell users why, store them securely, keep them only as long as needed, and restrict who can see them. Myinfo data is personal data, and Singapore's Personal Data Protection Act applies to how you use it once it reaches your systems.

NRIC numbers deserve special care. The PDPC's advisory guidelines on NRIC numbers say private organisations should collect them only when required by law or when needed to verify identity to a high degree of accuracy. A Singpass integration often lets you verify identity without storing the full number at all, or store it encrypted with tightly limited access.

We build retention rules into the database, mask identity fields in admin screens by default, and log every view or export. Your privacy notice, written or approved by your counsel, should describe the Singpass and Myinfo data you receive. Our PDPA website guide explains consent, notices and breach readiness in more detail. Compliance remains your company's responsibility, confirmed by your own adviser.

How do you test a Singpass integration before launch?

In Singpass's staging environment first, with test accounts, then with a small controlled rollout in production. For local development, the open-source MockPass project published by Open Government Products on GitHub provides a mock Singpass, Corppass and Myinfo server, which helps developers work without hitting staging constantly.

Our test plan covers the happy path and the ugly ones: a user cancelling at the Singpass screen, an expired request URI, a replayed DPoP proof, a token with the wrong audience, a Myinfo response missing an optional item, a user who already has an email-based account, and a phone switching apps mid-login.

We also test the non-Singpass path, because that is often where real users get stuck. Once staging passes, you submit the production app; after activation, we usually enable Singpass for a share of users or a single form first, watch logs for a few days and then open it fully.

Singpass integration with a remote team in India: who holds what

Your company holds the Singpass application, Corppass roles, production keys and approvals; we hold none of them. That split makes a remote Singpass integration straightforward and keeps control where the regulator and Singpass expect it.

We build against the staging app your team creates, using staging keys. Production keys are generated in your cloud account or secrets manager, and the production client is configured by your team or by us through access you grant and can revoke. India is two and a half hours behind Singapore, so your 10 am call is our 7:30 am, and we stay online through your afternoon for testing sessions.

The first two weeks typically include a scoping call, a written list of Singpass products and Myinfo items with a reason for each, staging app setup by your team, a first working staging login, and a draft user journey document. Quotes are in USD; invoices come from India and are paid by Wise or bank wire. See the guide to hiring Indian developers for how this model works more broadly.

Example: Myinfo auto-fill for a hypothetical tenancy application

Imagine a hypothetical property management company whose rental application form asks tenants to type personal details and upload photos of identity documents, which staff then check by hand. This scenario is illustrative, not a real client.

The Singpass integration would add a “Retrieve Myinfo with Singpass” button at the top of the form. After consent in Singpass, the approved items fill the form; the applicant reviews them, adds the fields Myinfo does not cover, such as preferred move-in date, and submits. Applicants without Singpass would continue with the existing manual path. Identity fields would be masked in the staff portal, and applications would be deleted after a retention period the company's counsel sets.

As part of a custom portal starting from US$900, a build like this might take six to ten weeks, including staging, the user journey document and up to two weeks for production approval. For property sites more generally, see our property agent website guide.

Singpass integration checklist and red flags

Go through this before submitting your production app, whoever builds your Singpass integration.

  • Your company, not the developer, owns the Singpass Developer Portal apps and keys.
  • Each Myinfo scope has a written reason tied to a form field.
  • A non-Singpass path exists and has been tested.
  • PAR, PKCE, DPoP and client assertions follow the current Singpass specification.
  • ID tokens are decrypted and fully validated before use.
  • Mobile apps use Universal Links and App Links, not custom schemes.
  • Private keys sit in a secrets manager, with a rotation plan.
  • Identity data is masked, logged, encrypted and deleted on schedule.
  • The user journey document matches what users actually see.
  • Red flag: a developer offering to apply using their own UEN or Corppass.
  • Red flag: requesting every available Myinfo item “in case it is useful later”.

Products

Singpass Login vs Myinfo vs Myinfo Business

Summarised from Singpass and Corppass developer documentation; check current product terms in the portal.

Singpass Login vs Myinfo vs Myinfo Business
ProductWhat you getTypical useWho signs in
Singpass Login Verified identity of the userAccount sign-in, returning customersIndividuals with Singpass
Myinfo Approved personal data items, with consentApplications and onboarding formsIndividuals with Singpass
Myinfo Business Company data for the entityB2B onboarding, trade accountsUsers acting for a company via Corppass
Login plus Myinfo Sign-in and auto-fill in one journeyAccount opening with verified detailsIndividuals with Singpass
Non-Singpass path Your own sign-up and checksTourists, overseas users, anyone opting outEveryone else

FAPI 2.0

FAPI 2.0 pieces in a Singpass integration

From the Singpass integration guide. Singpass states all its APIs must be FAPI 2.0 compliant by 31 December 2026.

FAPI 2.0 pieces in a Singpass integration
ComponentWhat it doesWhere it runs
Pushed Authorization Request Sends login parameters over a back channel; returns a 60-second request URIYour backend
PKCE (S256) Binds the authorisation code to a fresh secret per loginYour backend
DPoP proofs Proves the caller holds the key for PAR, token and userinfo callsYour backend
Client assertion JWT Authenticates your client with a short-lived signed tokenYour backend
Encrypted ID token Delivers identity claims readable only by youDecrypted on your backend
JWKS Publishes your public signing and encryption keysObject or public URL
App-claimed HTTPS redirect Returns users safely to native appsiOS and Android app plus your domain

Timeline

Singpass integration project timeline

Typical for a new web portal with Login and Myinfo; migrations and mobile apps vary.

Singpass integration project timeline
StageWho does itTypical duration
Portal access via Corppass Your Corppass adminDays, depending on your team
Scoping and scope justification You and us togetherWeek 1
Staging app and build Your team creates app; we buildWeeks 1 to 4
Testing and user journey document Us, reviewed by youWeeks 3 to 5
Production submission and approval Your team submits; Singpass reviewsUp to 2 weeks, per Singpass
Controlled rollout Us, with your sign-off1 to 2 weeks

Across Singapore

Where Singpass integration projects come up

We work remotely with Singapore companies whose products depend on verified identity. These areas host many of them.

  • Raffles Place

    Financial advisers, insurers and wealth platforms whose onboarding forms benefit from verified personal details instead of manual document checks.

  • Marina Bay

    Fintech and digital banking teams building account opening journeys where Singpass Login and Myinfo cut drop-off during sign-up.

  • one-north

    Start-ups building consumer apps in health, education and finance that plan Singpass into their first release rather than retrofitting it.

  • Tanjong Pagar

    Tech companies and HR platforms onboarding workers and customers online, often mixing Singpass users with those who need another path.

  • Novena

    Healthcare providers and health-tech firms near the medical cluster adding secure patient sign-in to portals that hold sensitive records.

  • Orchard

    Property management, lifestyle and membership businesses using Myinfo to speed up applications and memberships.

  • Paya Lebar

    Service companies and SaaS firms in the eastern hub adding Singpass sign-in to customer portals for account security.

  • Jurong Lake District

    Training providers and employers in the west handling course registrations and applications that need accurate personal details.

  • Changi Business Park

    Insurance, logistics and shared-service operations running high-volume customer portals where verified identity reduces fraud checks.

  • Bugis

    Education and co-working businesses with membership or enrolment flows that can use Myinfo to pre-fill applications.

  • Alexandra

    Regional offices of consumer businesses adding Singpass alongside email sign-in for Singapore customers.

  • Toa Payoh

    Community and social service organisations with online applications where accurate details and lower typing effort matter for older users.

  • Kallang

    Sports, events and ticketing operators exploring verified sign-in for memberships and high-demand bookings.

How it works

How we deliver a Singpass integration

  1. Scoping and scope list

    We agree the Singpass products and each Myinfo item with a reason, plus the non-Singpass path, in a short written document.

  2. Itemised quote

    Within about two working days you receive a USD quote covering build, testing, documentation and maintenance. Nothing is billed before approval.

  3. Staging access and build

    Your team creates the staging app via Corppass; we build the FAPI 2.0 flow, account linking and Myinfo mapping against it.

  4. Security and journey review

    Keys, token validation, logging and data handling are tested, and the user journey document is drafted with real staging screenshots.

  5. Production approval

    Your team submits the production app; we answer technical questions and prepare the production configuration in your infrastructure.

  6. Controlled rollout and care

    Singpass is enabled for a share of users first, then fully; two months of free maintenance and key-rotation support follow.

Questions

Singpass integration: frequently asked questions

What is Singpass integration?

Singpass integration connects a website or app to Singpass, Singapore's national digital identity, so users can sign in with it and optionally share verified personal data through Myinfo after giving consent. It uses OpenID Connect with the FAPI 2.0 Security Profile, and private companies onboard through the Singpass Developer Portal using their own UEN and Corppass.

Can a private company integrate Singpass?

Yes. Singpass documentation says Singapore-registered entities, government or private, can onboard. You need Corppass access under your UEN, a clear use case, justification for each Myinfo data item, any relevant licence if you are in a regulated industry, and an alternative path for users who cannot use Singpass.

How much does Singpass integration cost?

With BtechWaleTech, custom web apps with Singpass start at US$900 and mobile apps with Singpass at US$600. Adding Singpass to an existing system or migrating to FAPI 2.0 is quoted after a code review. Singpass's own transaction charges follow the pricing plan in the Singpass Developer Portal and are billed to your company separately.

How long does Singpass integration take?

A new web portal with Singpass Login and Myinfo typically takes six to ten weeks, including staging, testing and the user journey document. Singpass says production approval may take up to two weeks after submission. Adding Singpass to an existing app can be quicker or slower, depending on how user accounts and sessions already work.

Who applies for Singpass: us or the developer?

Your company applies. The Singpass Developer Portal is accessed through Corppass under your UEN, and your team creates the staging and production apps and accepts the service agreement. We build against the apps you create. Be cautious of any developer offering to apply under their own UEN on your behalf.

What is the difference between Singpass Login and Myinfo?

Singpass Login verifies who the user is so they can sign in. Myinfo, with the user's consent, returns specific personal data items your application is approved for, so forms can be pre-filled with government-verified details. Many services use both in one journey: sign in with Singpass, then retrieve Myinfo for an application form.

What is FAPI 2.0 and why does Singpass require it?

FAPI 2.0 is a security profile built on OAuth 2.0 and OpenID Connect, originally designed for high-value financial APIs. Singpass requires elements such as Pushed Authorization Requests, PKCE, DPoP and signed client assertions to make token theft and request tampering much harder. Singpass states all its APIs must be FAPI 2.0 compliant by 31 December 2026.

Does my existing Singpass integration need updating?

If it was built before the FAPI 2.0 requirements, very likely. Singpass says all its APIs must comply by 31 December 2026. Because Singpass was already OIDC-based, migration usually means updating parts of the flow, such as adding PAR, PKCE, DPoP and new client authentication, rather than rebuilding everything. Start early to leave time for testing.

Can Singpass work in a mobile app?

Yes. Singpass documentation says native apps should use app-claimed HTTPS redirect URLs, meaning Universal Links on iOS and App Links on Android, rather than custom URL schemes. We keep keys and token exchange on your backend, not inside the app. Flutter or React Native apps with Singpass start at our mobile app starting price.

Which Myinfo data items can we request?

Only those your process genuinely needs, justified item by item in your production application. Singpass reviews the scopes and your user journey before approval. Requesting fewer items usually makes approval smoother and reduces what you must protect under the PDPA. We help you work through your form field by field to decide.

Do we still need a non-Singpass sign-up option?

Almost always. Tourists, many foreign residents and overseas customers do not have Singpass, and Singpass onboarding guidance expects an alternative for users who cannot use it. The alternative can be email sign-up with your own verification steps. We build and test both paths so neither group gets stuck.

Can we store NRIC numbers from Myinfo?

Only if you have a valid reason and approval for that item. The PDPC's NRIC advisory guidelines say private organisations should collect NRIC numbers only when required by law or when needed to verify identity to a high degree of accuracy. If you store them, encrypt them, mask them in admin screens and log every access. Your counsel should confirm.

How is Myinfo data kept secure?

Through encrypted storage, keys in a secrets manager, strict token validation, role-based admin access with masked identity fields, audit logs of every view and export, and retention rules that delete data when it is no longer needed. The Singpass flow itself is secure; most risk sits in how your own systems store and expose the data afterwards.

Can we test Singpass without affecting real users?

Yes. Singpass provides a staging environment where you create a staging app and test with test accounts before going to production. For local development, the open-source MockPass project on GitHub, published by Open Government Products, mocks Singpass, Corppass and Myinfo. We use staging for integration testing and roll out production gradually.

What is Myinfo Business?

Myinfo Business returns data about a company to users acting on its behalf, which helps B2B onboarding. According to Singpass and Corppass documentation, Myinfo Business v3 is built on the Corppass authorisation API with FAPI 2.0, and a new Myinfo Business v3 app is created on the Singpass Developer Portal; older client IDs cannot be reused.

Is it safe to have a team in India build our Singpass integration?

Yes, if control stays with you. Your company owns the Singpass apps, Corppass roles and production keys, which are generated and stored in your own infrastructure. We build against staging and work through access you grant and can revoke. India is two and a half hours behind Singapore, so our hours overlap most of your day.

Who owns the code and keys after the project?

You do. The code repository, hosting, secrets manager, keys and every Singpass Developer Portal app belong to your company, and all documentation is handed over. We keep no copies of identity data. You can maintain the integration in-house, pass it to another developer or keep us on a care plan.

What maintenance does a Singpass integration need?

Key and certificate rotation, library and dependency updates, adjustments when Singpass changes its specifications or deadlines, log reviews and help if users report login problems. The first two months after launch are free; after that, care plans start at US$120/mo. Specification changes are planned with you before they take effect.

Can you give legal advice on Singpass or PDPA obligations?

No. We are developers. We explain what Singpass documentation and PDPC guidance say so you can brief your adviser, and we build what your team and counsel approve. Decisions about your use case, data items, retention periods and privacy notice belong to your company and its legal advisers.

How do we pay for Singpass integration work?

You receive an itemised quote in USD and invoices from India, payable by Wise or bank wire in milestones agreed before work begins. Nothing is billed until you approve the quote in writing. Singpass's own charges are billed to your company by Singpass. Ask your accountant how the overseas invoice should be recorded.

Can Singpass be added to an ecommerce or booking site?

It can, for example to verify age for restricted products or to secure accounts, but most ecommerce and booking sites do not need it and approval requires a clear justification. Singpass fits best where verified identity is central, such as financial, property, healthcare or regulated services. Ecommerce builds start at US$750 if you need a store as well.

Next step

Add Singpass to your web or mobile app

Tell us what your app does, which details you need from users and whether you already have Singpass Developer Portal access. We reply with questions and an itemised USD quote in about two working days.