1 August 2026 5 min read

HIN Platform Renewal 2026: Access Gateway, Client, and Deadlines Through September 14

Firewall approval by August 14, Access Gateway version 4 from August 17, SAML endpoints, hardware tokens, and HIN Client by September 14. The mail gateway is not affected and will be replaced separately.

In 2026, HIN is renewing its identity and access platform. The first deadline is August 14, 2026, followed by the major transition on September 14, 2026.

The HIN Access Gateway (AGW), HIN Client, and authentication methods are affected. The HIN mail gateway is not affected. It will also be replaced, but as part of a separate initiative with its own schedule.

The deadlines

DateActionAffects
08/14/2026Firewall approval for idp.id.hin.ch (185.154.38.46, 193.168.215.45)AGW operators
08/17/2026Automatic installation of AGW version 4AGW operators
From mid-AugustManual installation of HIN Client 4.0 recommendedAll Client users
09/14/2026SAML endpoints migratedFederations, EPR connections
09/14/2026Hardware tokens and test identities expireToken users, integrations
09/14/2026Reconfigure the Authenticator AppApp users
09/14/2026Forced update to HIN Client 4.0All Client users

Access Gateway is not a mail gateway

Both have Gateway in their name and are regularly confused. The Access Gateway controls access to HIN-protected applications and does not affect email traffic. The mail gateway sits in the mail flow and encrypts messages.

Access Gateway: firewall and version 4

By August 14, the AGW must be able to reach idp.id.hin.ch. This is a firewall change, not a setting in the gateway, and is therefore often the responsibility of the network administrator rather than the gateway administrator.

Starting August 17, version 4 will be installed automatically. Requirements: AGW version 3.1.50 or later and Kerberos enabled as the authentication method. Connecting to Active Directory requires an LDAP account with read permissions.

Those who do not meet the requirements will not be updated, and experience shows that this often only becomes apparent when no one can log in anymore. It is therefore better to check the version now than in September.

SAML: new endpoints, fewer attributes

Föderationsdienst
  broker.hin.ch/realms/HINBroker/protocol/saml/descriptor

EPD-Zugang
  idp.id.hin.ch/auth/realms/hinid/protocol/saml/descriptor

The change will alter attribute formats and bindings. The attribute set will be reduced to GLN, name, date of birth, and gender.

This is where integrations fail. Any application that uses additional attributes for roles or tenant separation will no longer receive them after September 14. The issue will not appear as a login error, but as missing permissions in the target system.

Test identities expire on the same date, so anyone wishing to test the transition in an integration environment should do so beforehand.

Organizations operating a federation almost always also operate their own mail infrastructure. For these organizations, the platform renewal falls in the same year as the replacement of the mail gateway with «Stargate»: technically independent, but competing for the same people and maintenance windows.

Tokens, app, and HIN Client 4.0

Hardware tokens will no longer be issued and will expire on September 14. Alternatives: HIN Client, SMS code, or Authenticator App. The app itself remains valid until September 14 and must then be reconfigured through the self-service portal.

The HIN Client will be automatically updated to version 4.0 no later than September 14; manual installation is available from mid-August via download.hin.ch. Login will now take place through the browser.

The critical point is the system requirements: Version 4.0 requires Windows 11 or macOS 14. Older devices must be updated or replaced beforehand. For some practices, the deadline is therefore not a software task, but a procurement task. Those who realize this only in September will face delivery times and reinstallation of their practice software.

Five questions to assess your situation

  1. Which AGW version is running, and is Kerberos enabled?
  2. Does the firewall allow outbound access to idp.id.hin.ch?
  3. How many workstations are still running Windows 10 or macOS 13 and earlier?
  4. How many hardware tokens are in use, and what will affected users switch to?
  5. Does any application use HIN attributes that will be removed in the future?

The answers to 3 and 5 determine the effort required. The rest can be completed in a few hours and is documented by HIN.

The second initiative: «Stargate»

Independently of this, HIN is replacing the mail gateway with the new HIN Gateway, internally known as project «Stargate», technically a data mesh approach with end-to-end encryption and decentralized key management. This is not an appliance replacement, but an architectural change.

The effort is therefore on an entirely different level. The platform renewal primarily requires meeting deadlines for a firewall rule, a software version, and device replacements, while Stargate puts the production mail flow itself up for review: the established rule set, key material, handling of recipients without a HIN identity, and the question of what to fall back on if something does not work as expected. Since migration takes place in booked four-hour windows and HIN recommends one month of preparation, such an appointment leaves no room for unresolved issues.

Sources

  1. HIN platform renewal: These technical adjustments are required for HIN members

    deadlines in August and September, SAML endpoints, reduced attribute set, firewall approvals.

    https://www.hin.ch/de/blog/2026/technische-anpassungen.cfm
  2. The new HIN Client is here: what changes for HIN members

    version 4.0, operating system requirements, browser-based login.

    https://www.hin.ch/de/blog/2026/neuer-hin-client.cfm
  3. HIN Gateway: Secure communication within the HIN Community

    replacement of the mail gateway, architecture, operating models, migration in booked time windows.

    https://www.hin.ch/de/services/hin-mail/hin-gateway.cfm
  4. Configuring the HIN Access Gateway
  5. Connecting Active Directory

    Kerberos and the LDAP account with read permissions.

    https://cdn.hin.ch/agw/manual/DE/5-anbindung-active-directory.html
  6. HIN AG: «From mail gateway to data mesh»

    background on «Stargate», decentralized nodes, schedule.

    https://www.hin.ch/de/blog/2025/vom-mailgateway-zum-data-mesh.cfm

Comments

Comments are loaded from GitHub / Giscus.