Requirements from Samtrafiken

Requirements from Samtrafiken

Common Requirements for the Sale of Public Transport Tickets

Introduction

This is an English version of appendix 1 to the Reseller Agreement – Samtrafiken ACCESS API lokaltrafik.

The purpose is to clarify the requirements placed on resellers (ÅF) when implementing and selling public transport tickets via Samtrafiken. If these requirements are not met, the Regional Public Transport Authority (RKM) has the right to halt ticket sales to the Digital Reseller Platform (DÅFP).


1. Visual Requirements

The following information must be displayed on or in direct connection with the ticket provided to the traveler via the DÅFP:

  • Product name (ticket type)

  • Geographic validity

  • Validity period (when and how long)

  • Passenger category(ies)

  • Number of travelers covered by the ticket

  • RKM’s name

  • RKM’s ticket ID


2. Technical Requirements

The ÅF undertakes to meet the following technical requirements:

  • The ÅF must have implemented the current or at least the previous version of the BoB standard.

  • The ticket must be optically machine-readable and follow the BoB standard when generating the Aztec code.

  • A new Aztec code must be generated at least every 5 seconds.

  • External signature (device signature) must be applied to all tickets.

  • The ticket must be machine-validatable even after key rotations.

  • External signature (Device signature) must be applied to all tickets.

  • Time is fetched from the server’s operating system.


3. Ticket Carriers

Tickets must be distributed via mobile application or website under the following conditions:

  • Digital tickets may only be available on/stored on one device at a time.

  • When switching to another device, RKM’s terms must be followed. These terms are described for each RKM under Information about products available through Samtrafiken ACCESS API lokaltrafik:Information about products available

  • Transfer from paper/PDF ticket to digital ticket is not allowed.


4. Blocked Tickets

If an RKM blocks a ticket, it must also be blocked or removed from the DÅFP.

The customer must be informed that the ticket is blocked and no longer valid, either directly in the ticket view or in another way.


5. Customer Service

Contact details for the ÅF’s customer service must be clearly visible in the customer interface.


6. Security and Key Management

OAuth2 – Private Keys

  • The private key used for authentication against Samtrafiken’s systems must only be accessible to systems and individuals with a legitimate need.

  • The key must not be shared via insecure channels (e.g., email or chat).

  • The ÅF must regularly review and document who has access to the key.

  • Backups must be stored securely and inaccessible to unauthorized persons.

Recommended actions include:

  • Use of a secure Key Management Service (KMS)

  • Strong access controls and multi-factor authentication

  • Logging of key usage for traceability

  • Documented procedures for key rotation when needed

  • Incident handling plan in case of compromised keys

Device Key

  • For tickets in apps, the device key must not be stored in backend systems or written to logs.

  • It must be stored encrypted in the app.

  • When transferring the device key from Samtrafiken’s system to the app, the encryption provided by Samtrafiken must be used, see:
    Samtrafiken Connect Quick Start Guide version 1.8


7. Testing and Version Management

The ÅF must plan for continuous testing and version management, including:

  • Active participation in test cycles before and during major/minor releases from Samtrafiken, RKM, and other related systems.

  • Performing regression tests during version updates.

  • Providing quick feedback and test results.

  • Allocating resources for testing within the agreed timeframe.

  • Following established test protocols and documentation procedures.

  • Reporting errors and participating in retesting according to instructions.

  • Using the established channel to report production issues.


8. Communication and Availability

Communication is crucial for cooperation, and the ÅF shall:

  • Appoint primary and backup contacts for business, technical, and support matters.

  • Be available and responsive during agreed hours.

  • Participate in status meetings and emergency calls when needed.

  • Keep contact details updated in shared documentation.

  • Follow escalation procedures and use agreed communication channels.

  • Provide advance notice for planned deployments or technical maintenance.

  • Be available during critical incidents.


9. Application

This appendix (currently in it’s Swedish version) shall be attached as standard to all ÅF agreements within the scope of Samtrafiken ACCESS API lokaltrafik and applies regardless of which RKM is the contracting party with the ÅF.