diff --git a/src/server/auth/idporten/verifyIdportenToken.ts b/src/server/auth/idporten/verifyIdportenToken.ts index 2ad4f84a0..4972e8fa4 100644 --- a/src/server/auth/idporten/verifyIdportenToken.ts +++ b/src/server/auth/idporten/verifyIdportenToken.ts @@ -38,8 +38,11 @@ export async function validateToken(bearerToken: string): Promise { return false; } - if (verified.payload.acr !== "Level4") { - logger.warn("token does not have acr Level4"); + if ( + verified.payload.acr !== "Level4" && + verified.payload.acr !== "idporten-loa-high" + ) { + logger.warn("token does not have acr Level4 or idporten-loa-high"); return false; }