Ship verifiable credential issuance solutions fast and with ease.

Start to issue digital credentials or build Issuance-as-a-Service platforms.

  • Self-managed - Host on-prem or in your cloud
  • Standards-based - OID4VC, W3C/SD-JWT VC, mDL
  • Compliant with ID regulations and trust frameworks

Who it's for

Outcomes trusted across industries

+59K devs, businesses and governments already rely on our infrastructure.

Why so many teams use our stack?

  • Go to market fast and stay compliant with a build-apps/buy-infra model.
  • Ship production-grade issuance solutions without re-implementing specs (OID4VCI, ISO/IEC 18013, W3C VC, SD-JWT VC, …)
  • Focus on product, not plumbing with ready-made rails for key management, revocation, data sourcing and more
  • Open, modular architecture maximises flexibility, prevents lock-in and minimises development or compliance risks.

Industries using our solution

Public Sector

Citizen IDs · digital service access

Banking / Finance

Reusable KYC · income checks for loans

Commerce

Customer proofs · fast checkout

Insurance

ePolicies · instant claims · verified risk data

Edu / Work

Digital diplomas · micro credentials

Tech / Telco

eSIM activation · service login · account recovery

Travel / Mobility

Easy check-ins · eTickets · travel creds

Property / Housing

Tenant checks · eLeases · income proofs

Legal / Notary

POA · notarized deeds · formation docs

ENABLE OR RESELL

Build ID-as-a-Service platforms or on-prem solutions for any industry

Launch scalable multi-tenant issuance solutions for B2B, B2G and B2B2C.

  • Ship managed issuance platforms, credential marketplaces or partner ecosystems.
  • Ship self-managed solutions that your customers can deploy in their cloud or on-prem.
  • Embeddable APIs and SDKs ensure a seamless integration of issuance capabilities into products and services.

Issuer highlights

Core capabilities

Issuance Protocols

OID4VCI (+ Draft 11/13), ISO/IEC 18013:7 path for mDL.

Credential formats and types

SD-JWT VC, W3C VC 1.1 / 2.0, ISO/IEC 18013:5 mDL/mDoc. Custom attribute structures, types and schemas.

Lifecycle and status

Revocation and suspension: Status lists (e.g. Bitstring Status List, TokenStatusList, ...). Pre-determined validity: Valid-from / expiry dates.

Keys and KMS

Manage keys (e.g. ed25519, secp256r1/k1, RSA) via external KMS (e.g. AWS, Azure, Hashicorp, OCI…).

DIDs and identifiers

DIDs based on various methods (e.g. did:key, did:web, ...) or x509 certificates.

ID Ecosystems

Issuance aligned with new ID regulations and trust frameworks like eIDAS2, EBSI, DISTF, ...

Webhooks and events

Real-time callbacks for offer creation, claim attempts, credential issuance, and failure states.

Data sourcing and functions

Populate claims from your DB/IdP and compute values just-in-time—timestamps, IDs, external lookups.

Credential branding and display

Control wallet rendering, titles, logos, colour palette, attribute labels, and localisation.

product editions

Open Source vs Enterprise

The Community Stack

The leading open source decentralized identity and wallet infrastructure used by thousands of devs and organizations.

Open SourceSelf-Managed

The Enterprise Stack

Reliable, scalable, compliant and enterprise-grade solution that builds on and extends our “open core”.

LicensedSelf-Managed
Feature Community StackEnterprise Stack
Standards

Credential Formats

SD-JWT VC (dc+sd-jwt), W3C VC as JWT (jwt_vc_json), ISO/IEC 18013-5 mdoc (mso_mdoc), and ISO/IEC 23220.

✓
✓

W3C VC JSON-LD

Linked-data credentials using ldp_vc. Current Issuer2, Verifier2, and Wallet2 stacks reject this format.

-
-

Protocols

OID4VCI 1.0 with pre-authorized and authorization-code flows; ISO-18013-7 for mDL / mdoc remote issuance. Deprecated Issuer v1 still covers drafts 11/13.

✓
✓

Status Credential Formats

TokenStatusList (incl. draft 8), Bitstring Status List v1.0, StatusList2021, RevocationList2020

✓
✓

Same-device remote flow

User stays on one device for issuance or presentation, typically via redirect or in-app handover.

✓
✓

Cross-device remote flow

QR code or companion-device handover for issuance and remote presentation.

✓
✓

Pushed Authorization Requests

Authorization parameters stay off the front channel via PAR during issuance.

✓
✓

PKCE (S256)

Public wallet clients bind the authorization code with S256 so it cannot be replayed.

~
~

DPoP

Access tokens are bound to the wallet key during issuance.

✓
✓

Wallet / client attestation

Issuer can accept only attested wallet software; wallets can send attestation headers.

✓
✓

Key attestation

Issuer can require hardware-backed or attested holder keys on the credential proof.

R
R

Signed and unsigned issuer metadata

Wallets consume unsigned HTTPS issuer metadata and can verify signed JWT issuer metadata.

✓
✓

Encrypted credential request

Wallet encrypts the credential request so the issuer receives it as JWE.

✓
✓

Encrypted credential response

Issuer encrypts the issued credential; the wallet must request and decrypt the JWE.

✓
✓

OID4VCI notification endpoint

Wallet reports accepted, failed, or deleted credentials to the issuer notification endpoint.

R
R

Present-to-obtain

Holder presents an existing credential before a new one is issued.

-
-

Nonce endpoint

Fresh c_nonce for proofs during OpenID4VCI issuance.

✓
✓
Core Capabilities

Key Management (KMS-agnostic)

Use external KMS (AWS, Azure, Hashicorp, Oracle, …), PKCS#11 HSMs, or raw keys for PoCs; supports ed25519, secp256r1/k1, RSA and key rotation.

✓
✓

DIDs & Identifiers

Supports did:key, did:jwk, did:web (and others) plus x509 certificates;

✓(DID Web Hosting DIY)
✓(DID Web Hosting Managed)

Webhooks / Callbacks

Notify or mirror lifecycle events (e.g., issuance, verification) into external systems for orchestration and audit.

✓
✓

Credential Templates / Types

Flexible JSON models to define credential data structures as profiles or sign arbitrary JSON payloads.

✓
✓

Credential Issuance Trigger

Issuer-initiated credential offers start the issuance session via QR, deep link, or credential_offer_uri.

✓
✓

Credential Delivery

Generate OID4VCI offers as QR codes or deep links.

✓
✓

User Auth for Issuance

Pre-auth (with optional PIN) or auth-code via external IdP; verified claims can map into credential fields.

✓
✓

Issuance Modes

Single-credential issuance per offer configuration.

✓
✓

Wallet-initiated issuance

Wallet starts issuance from issuer metadata or a catalog, without first receiving an offer.

✓
✓

Scope-based credential request

Wallet asks for a credential using the issuer-published scope.

✓
✓

Deferred issuance

Issuer returns a transaction id and the wallet polls later for the credential.

-
-

Batch issuance

Several credentials or keys in one credential request.

R
R

Combined offer or request

PID plus mDL, or the same document in two formats, in one offer or presentation request.

-
-

Wallet instance revocation

A compromised wallet unit can be withdrawn.

-
-
Credential Lifecycle & Status

Set Revocation & Suspension

Use status fields and status credentials to revoke/suspend credentials.

~(DIY)
✓(Managed)

Set Expiration & Validity Controls

Configure static or dynamically generated validity periods (valid-from / expiry) via data functions.

✓
✓
Identifiers & Trust Anchors

Host did:web Documents

Serve and auto-update did:web documents directly from the platform.

-
✓

DID Document Storage

Persist DIDs and DID documents via internal / enterprise DID store.

-
✓

X.509 PKI Issuance

Issues IACA root and Document Signer certificates.

~(DIY)
✓
Credential Branding

Issuer Metadata

Configure credential-type branding (logo, color, description) for consistent wallet display.

✓
✓

Embedded Display Data

Per-instance visuals for credential variants (e.g. ticket tiers).

✓
✓
Integrations

External KMS

Integrate AWS, Azure, Hashicorp, PKCS#11 HSMs; supports ed25519, secp256r1/k1, RSA with rotation.

✓
✓

QTSPs

Qualified signature support via QTSPs.

-
ROn roadmap
ID Ecosystems

EMEA alignment

Aligned with EU eIDAS2, EBSI and Swiss SWIYU requirements.

✓
✓

APAC alignment

Aligned with NZ DISTF, Australia, Thailand, Japan, etc.

✓
✓

Americas alignment

Aligned with US, Canada, Brazil frameworks.

✓
✓

Custom ecosystems

Adaptable to other/local ID ecosystems.

✓
✓
Deployment

On-Prem / Self-Hosting

Self-hosting in your own cloud or data center — no managed SaaS

✓
✓

Multi-tenancy setups

Isolated issuer configurations for B2B/B2G/B2B2C use cases

-
✓

Clustering / horizontal scaling

Run multiple enterprise stack instances behind a load balancer with shared state (sessions, configs, etc.)

-
✓

API Data Persistence

Persisted issuer data across service restarts and deployments.

-
✓
Security

Data Encryption

Encrypt sensitive data at rest in the database.

-
✓

Protected APIs (AuthN/Z)

Fine-grained protection of APIs with scoped tokens per tenant/service.

-
✓

Roles & permissions (RBAC)

Granular roles for orgs/tenants/services following least-privilege principle; Supports importing and mapping roles from an external IdP's.

-
✓

API keys (server-to-server)

Scoped M2M API keys for backend/service integrations.

-
✓

Session data ejection (PII)

Issuer and verifier session PII is ejected with MongoDB TTL when the session expires, so stored session data is limited to the session lifetime.

-
✓

API Rate Limiting

Configure rate limits on OID4VCI/OID4VP endpoints

-
✓
Monitoring & Analytics

Audit logging

Recorded logs and events for auditing and compliance.

-
✓

Analytics & metrics

Track operations, success/error rates across tenants/services for ops and reporting.

-
✓
Administration

User accounts (operators/admins)

Admin GUI logins with role-based permissions.

-
✓

Admin GUI

Configure services, monitor sessions, and manage credential lifecycle operations (e.g. revocation) or verification states.

-
✓

FAQ

Frequently asked questions

Talk to walt.id

Let’s design your issuance solution

Tell us about your issuance goals and we’ll explore the path that fits.