CH-LOGIN will be gradually replaced by AGOV

From 7 September 2025, AGOV will become the primary authentication method. However, CH-LOGIN will remain functional in many cases.

This page helps you determine whether you are affected by this change. It is important to identify whether your situation corresponds to Case A, Case B or Case C:

Case A – You use CH-LOGIN with SMS-mTAN or an authentication app (Google/Microsoft)

No changes for you as long as you continue to use CH-LOGIN as your authentication method.

Note: However, the user can initiate a migration themselves: Once you use AGOV to access a federal service (excluding cantonal or third-party applications), an automatic migration to AGOV will be triggered. From that point on, only AGOV can be used.

Case B – You use CH-LOGIN with a VASCO token

I already have a working VASCO token

You can continue to use CH-LOGIN without changes as long as you select CH-LOGIN at login. Replacement VASCO tokens are also available.

Note: However, the user may initiate a migration  themselves: Once AGOV is used for a federal service, the migration to AGOV becomes irreversible.


I need to replace my VASCO token

It is still possible to replace the VASCO token. Afterwards, CH-LOGIN can still be used.


I am a new user and do not yet have a VASCO token

From 7 September 2025, no new VASCO tokens will be issued for CH-LOGIN.

Please create an AGOV account online and complete identity verification if required:

The video identification process will be triggered automatically if needed:

Case C – You use the VASCO token outside of CH-LOGIN

No changes in this case. VASCO tokens can continue to be used and issued. “Outside of CH-LOGIN” means either completely outside of eIAM on server A3, or within eIAM as “OTP-LOGIN” but outside CH-LOGIN.