Requirements from Samtrafiken
Common Requirements for the Sale of Public Transport Tickets
Introduction
This is an English version of appendix 1 to the Reseller Agreement – Samtrafiken ACCESS API lokaltrafik.
The purpose is to clarify the requirements placed on resellers (ÅF) when implementing and selling public transport tickets via Samtrafiken. If these requirements are not met, the Regional Public Transport Authority (RKM) has the right to halt ticket sales to the Digital Reseller Platform (DÅFP).
1. Visual Requirements
The following information must be displayed on or in direct connection with the ticket provided to the traveler via the DÅFP:
Product name (ticket type)
Geographic validity
Validity period (when and how long)
Passenger category(ies)
Number of travelers covered by the ticket
RKM’s name
RKM’s ticket ID
2. Technical Requirements
The ÅF undertakes to meet the following technical requirements:
The ÅF must have implemented the current or at least the previous version of the BoB standard.
The ticket must be optically machine-readable and follow the BoB standard when generating the Aztec code.
A new Aztec code must be generated at least every 5 seconds.
External signature (device signature) must be applied to all tickets.
The ticket must be machine-validatable even after key rotations.
External signature (Device signature) must be applied to all tickets.
Time is fetched from the server’s operating system.
3. Ticket Carriers
Tickets must be distributed via mobile application or website under the following conditions:
Digital tickets may only be available on/stored on one device at a time.
When switching to another device, RKM’s terms must be followed. These terms are described for each RKM under Information about products available through Samtrafiken ACCESS API lokaltrafik:Information about products available
Transfer from paper/PDF ticket to digital ticket is not allowed.
4. Blocked Tickets
If an RKM blocks a ticket, it must also be blocked or removed from the DÅFP.
The customer must be informed that the ticket is blocked and no longer valid, either directly in the ticket view or in another way.
5. Customer Service
Contact details for the ÅF’s customer service must be clearly visible in the customer interface.
6. Security and Key Management
OAuth2 – Private Keys
The private key used for authentication against Samtrafiken’s systems must only be accessible to systems and individuals with a legitimate need.
The key must not be shared via insecure channels (e.g., email or chat).
The ÅF must regularly review and document who has access to the key.
Backups must be stored securely and inaccessible to unauthorized persons.
Recommended actions include:
Use of a secure Key Management Service (KMS)
Strong access controls and multi-factor authentication
Logging of key usage for traceability
Documented procedures for key rotation when needed
Incident handling plan in case of compromised keys
Device Key
For tickets in apps, the device key must not be stored in backend systems or written to logs.
It must be stored encrypted in the app.
When transferring the device key from Samtrafiken’s system to the app, the encryption provided by Samtrafiken must be used, see:
Samtrafiken Connect Quick Start Guide version 1.8
7. Testing and Version Management
The ÅF must plan for continuous testing and version management, including:
Active participation in test cycles before and during major/minor releases from Samtrafiken, RKM, and other related systems.
Performing regression tests during version updates.
Providing quick feedback and test results.
Allocating resources for testing within the agreed timeframe.
Following established test protocols and documentation procedures.
Reporting errors and participating in retesting according to instructions.
Using the established channel to report production issues.
8. Communication and Availability
Communication is crucial for cooperation, and the ÅF shall:
Appoint primary and backup contacts for business, technical, and support matters.
Be available and responsive during agreed hours.
Participate in status meetings and emergency calls when needed.
Keep contact details updated in shared documentation.
Follow escalation procedures and use agreed communication channels.
Provide advance notice for planned deployments or technical maintenance.
Be available during critical incidents.
9. Application
This appendix (currently in it’s Swedish version) shall be attached as standard to all ÅF agreements within the scope of Samtrafiken ACCESS API lokaltrafik and applies regardless of which RKM is the contracting party with the ÅF.