Verifying using EUDI wallet (v2)
Stable / GA
This is the current stable version of this step type.
Verifies users using their European Digital Identity Wallet
Used when businesses want fast and highly trusted verification based on government‑issued digital identity. Users can securely share verified personal information from their EU Digital Identity Wallet, enabling smooth onboarding with strong, authoritative identity assurance.
Key features
- OID4VP and mdoc Protocols: Implements OpenID for Verifiable Presentations and mdoc protocols.
- Credential request: Requests and verifies EUDI wallet credentials from the user's European Digital Identity Wallet.
- Dynamic output configuration: Output data blocks are dynamically determined based on the
requestedCredentialsconfiguration. - Credential to data block mapping: Maps credential claims to data blocks for seamless flow integration.
- No input required: Does not require any input data block from the flow context.
- Multiple credential support: Can request multiple credentials in a single verification session.
- Provider selection: Optionally specify a verifier provider (e.g., LISSI).
Configuration
| Option | Type | Required | Default | Description |
|---|---|---|---|---|
provider | string | No | — | The verifier provider to use. Supported value: LISSI. Defaults to the platform default when omitted. Accepted values: LISSI. |
requestedCredentials | object[] | Yes | — | A mandatory array that specifies the credentials requested from the user's wallet. Minimum 1 credential required. |
requestedCredentials[].type | string | Yes | — | The URI identifying the type of credential requested (e.g. eu.europa.ec.eudi.pid.1). |
requestedCredentials[].format | string | Yes | — | The credential format to request (e.g. mso_mdoc, vc+sd-jwt). |
requestedCredentials[].datablocks | string[] | Yes | — | An array that maps the expected claims from this credential to known data blocks (e.g., BasicIdentity, ExtendedIdentity). The corresponding data block will be generated and added to the flow context upon success. Can be an empty array. Accepted values: basicIdentity, extendedIdentity, documentData, documentImages, documentVerification, pepAndSanctionsResults, outcomeStatus, comparisonResults, userReference, biometricSamples, authenticatorCredential, deviceSignals, authenticationResult, documentsToSign, signedDocumentsPackage, presentationResult, digitalSignals, deviceInfo, deviceContext, deviceRiskAssessment, amlScreeningResults, eIDMethodSelection, verification, userContact, fundingSource, residentialAddress. |
enableRetry | boolean | No | false | When true, adds a retry output route that can be used to handle user cancellations. |
Example configuration
{
"requestedCredentials": [
{
"type": "https://example.bmi.bund.de/credential/pid/1.0",
"format": "dc+sd-jwt",
"datablocks": ["BasicIdentity"]
}
]
}
Input data blocks
This step does not consume any input data blocks.
Routes
| Route | Description |
|---|---|
verified | Successful wallet presentation. The user has authenticated with their EUDI wallet and consented to sharing the requested credentials through a verifiable or mdoc presentation. |
not_verified | The presentation attempt failed. The credential presented is not valid, the presentation does not satisfy the query, or the user declined (when enableRetry is false). |
retry | Available only when enableRetry is true. User cancelled or declined to share credentials, or the session expired, and can choose to retry. |
Output data blocks
The EUDI wallet v2 step produces different outputs depending on the presentation result. The output data blocks are dynamically determined based on the requestedCredentials configuration.
| Route | Data blocks produced |
|---|---|
verified | Verificationplus every data block configured in requestedCredentials[].datablocks |
not_verified | Verification |
retry | VerificationAvailable only when enableRetry is true. |
Example payloads
Verification — verified
{
"status": "verified",
"terminationReason": null,
"methods": [
{
"type": "verifiablePresentation",
"presentedCredentials": [
{
"credentialType": "https://example.bmi.bund.de/credential/pid/1.0",
"credentialFormat": "dc+sd-jwt",
"issuer": "https://issuer.example.bmi.bund.de",
"presentedClaimNames": [
"given_name",
"family_name",
"birth_date"
]
}
],
"evidence": []
}
],
"provider": null,
"trustFramework": null,
"assuranceLevel": null,
"verifiedAt": "2026-02-10T14:00:01.000Z",
"verificationProcessId": "txn-eudi-abc123"
}
BasicIdentity — verified
{
"givenName": "Jean",
"familyName": "Dupont",
"name": "Jean Dupont",
"birthDate": "1985-03-22",
"birthPlace": "Paris"
}
ExtendedIdentity — verified
{
"portrait": {
"$ref": "vault",
"$id": "020ff369-43d8-4b8a-94e7-6814c0bdc35a"
},
"nationality": "FRA",
"personalAdministrativeNumber": null,
"familyNameBirth": "Dupont",
"givenNameBirth": "Jean",
"sex": 1,
"emailAddress": null,
"mobilePhoneNumber": null,
"residentAddress": "24 RUE DANTON 35700 RENNES FRANCE",
"residentStreet": "RUE DANTON",
"residentHouseNumber": "24",
"residentHouseName": null,
"residentCountry": "FR",
"residentState": "Bretagne",
"residentCity": "RENNES",
"residentPostalCode": "35700"
}
Verification — not_verified
{
"status": "rejected",
"terminationReason": {
"code": "presentation_verification_failed",
"message": "The credential presented did not satisfy the requested query."
},
"methods": [],
"provider": null,
"trustFramework": null,
"assuranceLevel": null,
"verifiedAt": "2026-02-10T14:02:35.000Z",
"verificationProcessId": "txn-eudi-def456"
}