Integration Tips
Unified Identity Service
>
Integration Tips
The Unified Identity Service authenticates consumer users (customers or members of a financial institution). It includes some shared architecture with Banno Online, Jack Henry’s digital banking product (and the reference implementation for the Consumer APIs contained in the Digital Toolkit.)
In order for consumer users to login through UIS, each user must first establish a username and password through an enrollment flow. Each product integrating with UIS is responsible for determining and enforcing that a user is eligible to be established within the product before redirecting the user to UIS enrollment. See New User Enrollment for examples and details.
Decisions / Need to Knows About Your Approach
- Backend For Frontend (BFF) architecture is strongly recommended for everyone (and is required for all JH products to ensure security and session management best practices are followed).
- What scopes do you need, and how will they be enforced?
- How will you determine and enforce user eligibility before redirecting users to UIS enrollment?
- What 2FA security levels are appropriate for users in your product? The Unified Identity Service page in the Jack Henry Knowledge Base lists the verification methods each level (Standard, Enhanced, and High) permits. Is it the same for all users, or will you need a mechanism for FI’s to set different requirements for different users (based on user type, risk/exposure level, or some other criteria specific to your product)? See New User Enrollment for how the level is passed at enrollment.
- Products integrating with UIS will use Client Credentials flow to make requests to the UIS enrollment API. This requires a Jack Henry Identity service account application, plus a separate consumer external application for the Authorization Code flow — see Configuration for what’s needed and who creates it.
- Your product will likely need to store the unique identifer from UIS along with your product’s unique identifier for each user. Note that if one person has two separate users within your product, that person can choose to use a single username and password (i.e. a single identity) to authenticate for both users. Your product will need to expect and handle that a single UIS UUID could be associated to more than one user within your product (
productUserId). - Enabling UIS for an institution and registering your product with Jack Henry isn’t self-service — see Rollout Considerations for the process.
Topics in this section
Have a Question?
- Have a how-to question? Seeing a weird error? Get help on StackOverflow.
- Register for the Developer Office Hours where we answer technical Q&A from the audience.
Did this page help you?
Last updated Wed Sep 2 2026