Skip to main content

Verifying using EUDI wallet (v1)

Deprecated

This version of this step type has been deprecated. Documentation will not be maintained.
The stable / GA version of this step is [Verifying using EUDI wallet (v1)[(./eudi-wallet-v2)]

Verifies users using their European Digital Identity Wallet​

Used when businesses want fast and highly trusted verification based on government‑issued digital identity. Users can securely share verified personal information from their EU Digital Identity Wallet, enabling smooth onboarding with strong, authoritative identity assurance.


Key features​

  • OID4VP and mdoc Protocols: Implements OpenID for Verifiable Presentations and mdoc protocols.
  • Credential request: Requests and verifies EUDI wallet credentials from the user's European Digital Identity Wallet.
  • Dynamic output configuration: Output data blocks are dynamically determined based on the requestedCredentials configuration.
  • Credential to data block mapping: Maps credential claims to DSL data blocks for seamless flow integration.
  • No input required: Does not require any input data block from the flow context.
  • Multiple credential support: Can request multiple credentials in a single verification session.

Configuration​

OptionTypeRequiredDefaultDescription
providerstringNo—EUDI wallet provider. Accepted value: LISSI. When omitted, the provider is resolved from the Third Party configuration defined at infrastructure level. Accepted values: LISSI.
requestedCredentialsobject[]Yes—A mandatory array that specifies the credentials requested from the user's wallet. Minimum 1 credential required.
requestedCredentials[].typestringYes—The URI identifying the type of credential requested (e.g. eu.europa.ec.eudi.pid.1).
requestedCredentials[].formatstringYes—The credential format to request (e.g. mso_mdoc, vc+sd-jwt).
requestedCredentials[].datablocksstring[]Yes—An array that maps the expected claims from this credential to known data blocks (e.g., BasicIdentity, ExtendedIdentity). The corresponding data block will be generated and added to the flow context upon success. Can be an empty array. Accepted values: basicIdentity, extendedIdentity, documentData, documentImages, documentVerification, pepAndSanctionsResults, outcomeStatus, comparisonResults, userReference, biometricSamples, authenticatorCredential, deviceSignals, authenticationResult, documentsToSign, signedDocumentsPackage, presentationResult, digitalSignals, deviceInfo, deviceContext, deviceRiskAssessment, amlScreeningResults, eIDMethodSelection, verification, userContact, fundingSource, residentialAddress.
enableRetrybooleanNofalseWhen true, adds a retry output route that can be used to handle user cancellations.

Example configuration​

{
"requestedCredentials": [
{
"type": "https://example.bmi.bund.de/credential/pid/1.0",
"format": "dc+sd-jwt",
"datablocks": ["BasicIdentity"]
}
]
}

Input data blocks​

This step does not consume any input data blocks.


Routes​

RouteDescription
verifiedSuccessful wallet presentation. The user has authenticated with their EUDI wallet and consented to sharing the requested credentials through a verifiable or mdoc presentation.
cancelledThe presentation session expired before the user completed the wallet interaction. Only reached when enableRetry is false.
not_verifiedThe presentation attempt failed. The credential presented is not valid, the presentation does not satisfy the query, or the user declined the wallet request (when enableRetry is false).
retryAvailable only when enableRetry is true. User cancelled, declined to share credentials, or the session expired, and can choose to retry.

Output data blocks​

The EUDI wallet step produces different outputs depending on the presentation result. The output data blocks are dynamically determined based on the requestedCredentials configuration.

RouteData blocks produced
verifiedPresentationResult
plus every data block configured in requestedCredentials[].datablocks
cancelledPresentationResult
not_verifiedPresentationResult
retryPresentationResult
Available only when enableRetry is true.

Example payloads​

PresentationResult — success
{
"sessionId": "eudi-sess-7f3a2b1c-4d5e-6f7a-8b9c-0d1e2f3a4b5c",
"result": "success",
"presentedAt": "2026-02-10T14:00:01.000Z",
"presentedCredentials": [
{
"type": "https://example.eudi.ec.europa.eu/pid/1",
"issuer": "https://issuer.eudi.example.eu",
"presentedClaims": [
{
"claimName": "given_name",
"claimValue": "Jean"
},
{
"claimName": "family_name",
"claimValue": "Dupont"
},
{
"claimName": "birth_date",
"claimValue": "1985-03-22"
}
]
}
]
}
BasicIdentity — verified (dynamic, based on requestedCredentials configuration)
{
"givenName": "Jean",
"familyName": "Dupont",
"name": "Jean Dupont",
"birthDate": "1985-03-22",
"birthPlace": null
}
ExtendedIdentity — verified (dynamic, based on requestedCredentials configuration)
{
"portrait": {
"$ref": "vault",
"$id": "020ff369-43d8-4b8a-94e7-6814c0bdc35a"
},
"nationality": "FRA",
"personalAdministrativeNumber": null,
"familyNameBirth": null,
"givenNameBirth": null,
"sex": 1,
"emailAddress": null,
"mobilePhoneNumber": null,
"residentAddress": null,
"residentStreet": null,
"residentHouseNumber": null,
"residentHouseName": null,
"residentCountry": "FR",
"residentState": null,
"residentCity": null,
"residentPostalCode": null
}