Terms Of Use

Last update: 10 July 2026

Status: Private Beta

This page explains the terms of use for Internal Access. You must accept these terms to use Internal Access.

These terms apply to users who:

  • use Internal Access to access public sector services (hereafter referred to as ‘service users’)
  • create and manage client applications through Internal Access (hereafter referred to as ‘service managers’)

You must ensure that you have read and understood the sections of these terms which apply to you.

About Internal Access

Internal Access is an authentication service which proves an individual’s identity for the purpose of signing into services in the public sector. Internal Access does not provide authorisation. Any service you sign into through Internal Access assumes the responsibility for authorising which users should have access.

Internal Access is managed by the Department for Science, Innovation and Technology (DSIT), and will be referred to as ‘we’ from now on.

DSIT is the data controller and the data processor for Internal Access. This means DSIT manages how and why personal data is used. You can find out more on the Information Commissioner’s Office website.

Changes to these terms and conditions

We can update these terms, as well as the cookies policy and privacy notice, at any time without notice.

If we change the terms and conditions, we’ll ask you to accept them the next time you use Internal Access.

Terms of use for service users

You will use Internal Access to access public sector services and for no other purpose.

Unless permitted by law or under these terms and conditions, you must:

  • only use public sector email addresses, unless your email is specified within the email exceptions policy section below
  • ensure any associated accounts are protected by multi-factor authentication (MFA)
  • use only your work-managed devices to open emails from Internal Access

You must not use Internal Access:

  • to transmit any material that is insulting or offensive
  • to collect any data or attempt to decipher any transmissions to or from the servers running Internal Access
  • in a way that could damage, disable, overburden, impair or compromise our systems or security
  • in a way that interferes with other users
  • in any unlawful or fraudulent manner or for any unlawful or fraudulent purpose
  • to transmit, send or upload any data that contains viruses, Trojan horses, worms, spyware or any other harmful programs designed to adversely affect the operation of computer software or hardware
  • in connection with any kind of denial of service attack or for any malicious purpose
  • with someone else’s registered details

If you breach any of these terms and conditions, we will stop you from accessing services through Internal Access, take action to enforce these terms and conditions, and will also take other action as appropriate.

If, by doing any of the above acts, you are also committing a criminal offence, we will report it to the relevant law enforcement authorities. We will cooperate with those authorities by disclosing your identity to them.

Terms of use for service managers

Internal Access is currently in Private Beta. This means that we are not currently accepting new service managers, and that there are certain features which may change.

As a service manager, you must check that Internal Access meets your organisation's standards for your application for:

  • processing and storing authentication and session data
  • cyber security
  • data protection

You must complete this review before you begin using the service in a production environment, and at regular intervals while live.

Standards compliance

Internal Access is planned to be fully-compliant with OIDC and OAuth 2.1 specifications. You must ensure that all client applications you manage remain compliant and do not deviate from those specifications set out by Internal Access.

Where the current implementation deviates from these standards, those deviations are subject to deprecation.

Actively-used features will receive at least 2 months' notice before removal. This notice includes:

  • why the feature is being deprecated
  • what the timelines are
  • your responsibility to discontinue the use of affected features
  • alternative options for deprecated features

Unused clients will be closed down after 3 months of inactivity. You will receive notice before they are closed down.

Features with no usage in the past month may be removed on a 2 week timeline. In this case, you will receive notice about any features that have been identified for removal. If the feature remains unused 2 weeks from this notice, it will be removed.

Your responsibilities

As a service manager, you agree to:

  • report any suspected security breach immediately to your designated contact, including suspected compromise of client secrets (see section below), redirect URI tampering, or any unexpected authentication activity
  • only use the service to authenticate users and systems within the scope agreed at onboarding
  • make sure the data you register with the service, including redirect URIs and client configuration, is accurate and kept up to date
  • migrate all deprecations by the communicated deadline so that you do not rely on non-standard or deprecated behaviour
  • never use the service to authenticate users or systems outside your registered scope
  • make sure the data you send to Internal Access complies with applicable data protection legislation

Protecting your client credentials

You must protect your client secret, or confidential key, from unauthorised access or disclosure. This includes:

  • encrypting secrets at rest and in transit
  • never hard-coding secrets in source code or configuration files
  • rotating your secret when someone with access leaves your team, or whenever you suspect it may have been compromised

If you believe your credentials have been compromised, you must contact us immediately by emailing digital-backbone@dsit.gov.uk.

Email exceptions policy

Internal Access only allows access through allowed emails. Authorised emails are those that are on public sector domains, such as gov.uk, nhs.net, or those used by individuals working in the wider public sector.

Exceptions can be allowed in a client by the service manager, but these are limited to:

  • email addresses of individuals working in the public sector that aren't on a public sector domain
  • time-limited access to email addresses of delivery partners working on public sector projects who are working directly with people in the public sector

It is the responsibility of the service manager to ensure that only users with authorised email addresses have access through the allowlist. Service managers also hold the responsibility to ensure that delivery partners with time-limited access are removed as soon as their access is no longer required.

We retain the right to suspend access to any user who does not have an authorised email address, and to suspend the service for any service manager who does not follow these terms.

Our responsibilities

Internal Access allows you to access public sector services, and these services will have have their own terms of use and legal notices. The Internal Access terms of use do not exempt you from any other terms and conditions.

We are not responsible for the services which use Internal Access. We do not have any control over the content on these websites.

We’re not responsible for:

  • the protection of any information you give to these websites
  • any loss or damage that may come from your use of these websites, or any other websites they link to

You agree to release us from any claims or disputes that may come from using these websites.

You should read all terms and conditions, privacy policies and end user licences that relate to these websites before you use them.

Support

For support, contact digital-backbone@dsit.gov.uk.

Support is available Monday to Friday, 9am to 5pm UK time, excluding public holidays. We currently do not offer out-of-hours support.