Ship digital identity wallet solutions fast and with ease.
Launch your own ID wallet or build Wallet-as-a-Service platforms.
- Self-managed - Host on-prem or in your cloud
- Standards-based - OID4VC, W3C/SD-JWT VC, mDL
- Compliant with ID regulations and trust frameworks
Who it's for
Outcomes trusted across industries
+59K devs, businesses and governments already rely on our infrastructure.
Why so many teams use our stack?
- Go to market fast and stay compliant with a build-apps/buy-infra model.
- Ship production-grade wallets without re-implementing standards (OID4VCI/VP, ISO/IEC 18013, W3C VC, SD-JWT VC, …)
- Manage digital custodial or non-custodial wallets for consumers and organizations, including key management, credential storage and presentation.
- Open, modular architecture maximises flexibility, prevents lock-in and minimises development or compliance risks.
Industries using our solution
Public Sector
Citizen IDs · digital service access
Banking / Finance
Reusable KYC · income checks for loans
Commerce
Customer proofs · fast checkout
Insurance
ePolicies · instant claims · verified risk data
Edu / Work
Digital diplomas · micro credentials
Tech / Telco
eSIM activation · service login · account recovery
Travel / Mobility
Easy check-ins · eTickets · travel creds
Property / Housing
Tenant checks · eLeases · income proofs
Legal / Notary
POA · notarized deeds · formation docs
ENABLE OR RESELL
Build Wallet-as-a-Service platforms or on-prem solutions for any industry
Launch scalable multi-tenant ID wallet solutions for B2B, B2G and B2B2C.
- Ship managed ID wallet platforms, credential marketplaces or partner ecosystems.
- Ship self-managed solutions that your customers can deploy in their cloud or on-prem.
- Embeddable APIs and SDKs ensure a seamless integration of ID wallet capabilities into products and services.
BUILD WALLETS
All you need to launch ID wallets for any use case.
White label wallets
Launch identity wallets fast with our open source progressive web app and UI.
Embedded wallets
Extend your existing applications with all identity capabilities you need.
Mobile wallets
Build mobile apps (iOS, Android) with our multi-platform libraries and SDKs.
Wallet highlights
Core capabilities
Exchange Protocols
OID4VCI/VP, ISO/IEC 18013-7 for mDL.
Credential formats and types
SD-JWT VC, W3C VC 1.1 / 2.0, ISO/IEC 18013-5 mDL/mDoc. Custom attribute structures, types and schemas.
Keys and KMS
Create and protect holder keys (ed25519, secp256k1, secp256r1, RSA) in the wallet DB or via external KMS such as AWS, Azure, Hashicorp, OCI, ...
DIDs and identifiers
Create and resolve DIDs like did:key, did:web and did:jwk and bind them to wallet keys and credentials.
Credential storage & lifecycle
Persist credentials in the wallet database, track status with StatusList2021 / Bitstring Status Lists and perform expiration / revocation checks before sharing.
Authentication and access
Authenticate holders via username/password, external IdPs (OIDC via Keycloak) or other strategies, and manage sessions through the Wallet API.
Wallet models
Support consumer and organizational wallets with flexible user↔wallet mappings—from one-user-one-wallet apps to shared multi-wallet setups.
ID Ecosystems
Wallets aligned with new ID regulations and trust frameworks like eIDAS2, EBSI, DISTF, ...
Apps, SDKs and UX
Launch white-label PWAs, integrate mobile SDKs (Android/iOS) or call the Wallet API directly to embed custodial or non-custodial wallets into your apps.
product editions
Open Source vs Enterprise
The Community Stack
The leading open source decentralized identity and wallet infrastructure used by thousands of devs and organizations.
The Enterprise Stack
Reliable, scalable, compliant and enterprise-grade solution that builds on and extends our “open core”.
| Feature | Community Stack | Enterprise Stack |
|---|---|---|
| Standards | ||
Credential Formats SD-JWT VC (dc+sd-jwt), W3C VC as JWT (jwt_vc_json), ISO/IEC 18013-5 mdoc (mso_mdoc), and ISO/IEC 23220. | ✓ | ✓ |
W3C VC JSON-LD Linked-data credentials using ldp_vc. Current Issuer2, Verifier2, and Wallet2 stacks reject this format. | - | - |
Protocols OID4VCI 1.0 and OID4VP 1.0 with pre-authorized and authorization-code flows; ISO-18013-7 for mDL / mdoc remote flows. Deprecated Wallet v1 still covers earlier drafts. | ✓ | ✓ |
Status Credential Formats TokenStatusList (incl. draft 8), Bitstring Status List v1.0, StatusList2021, RevocationList2020 | ✓ | ✓ |
Digital Credentials API Unified browser API for credential issuance/verification; abstracts OID4VCI/VP & ISO-18013-7 for 1-click web integrations. | ~ | ~ |
Same-device remote flow User stays on one device for issuance or presentation, typically via redirect or in-app handover. | ✓ | ✓ |
Cross-device remote flow QR code or companion-device handover for issuance and remote presentation. | ✓ | ✓ |
Proximity presentation In-person credential share over BLE or NFC, including ISO/IEC 18013-5 proximity flows. | ✓ | ✓ |
Selective disclosure Only requested claims leave the wallet, using SD-JWT disclosures or mdoc namespaces. | ✓ | ✓ |
Signed request object (JAR) Wallet authenticates the verifier from a signed request object before showing consent. | ✓ | ✓ |
Request by reference Wallet fetches the presentation request from request_uri over HTTPS, including GET and POST retrieval. | ✓ | ✓ |
X.509 verifier identity Verifier identity from certificate-bound client identifiers, including x509_hash and x509_san_dns. | ✓ | ✓ |
Posted / encrypted presentation responses Authorization responses posted to response_uri as direct_post or encrypted direct_post.jwt. | ✓ | ✓ |
Pushed Authorization Requests Authorization parameters stay off the front channel via PAR during issuance. | ✓ | ✓ |
PKCE (S256) Public wallet clients bind the authorization code with S256 so it cannot be replayed. | ✓ | ✓ |
DPoP Access tokens are bound to the wallet key during issuance. | ✓ | ✓ |
Wallet / client attestation Issuer can accept only attested wallet software; wallets can send attestation headers. | ✓ | ✓ |
Key attestation Issuer can require hardware-backed or attested holder keys on the credential proof. | R | R |
Signed and unsigned issuer metadata Wallets consume unsigned HTTPS issuer metadata and can verify signed JWT issuer metadata. | ✓ | ✓ |
Encrypted credential request Wallet encrypts the credential request so the issuer receives it as JWE. | - | - |
Encrypted credential response Issuer encrypts the issued credential; the wallet must request and decrypt the JWE. | - | - |
OID4VCI notification endpoint Wallet reports accepted, failed, or deleted credentials to the issuer notification endpoint. | R | R |
Present-to-obtain Holder presents an existing credential before a new one is issued. | - | - |
Nonce endpoint Fresh c_nonce for proofs during OpenID4VCI issuance. | ✓ | ✓ |
| Core Capabilities | ||
Key Management (KMS-agnostic) Use external KMS (AWS, Azure, Hashicorp, Oracle, …), PKCS#11 HSMs, or raw keys for PoCs; supports ed25519, secp256r1/k1, RSA and key rotation. | ✓ | ✓ |
DIDs & Identifiers Supports did:key, did:jwk, did:web (and others) plus x509 certificates; | ✓(DID Web Hosting DIY) | ✓(DID Web Hosting Managed) |
Webhooks / Callbacks Notify or mirror lifecycle events (e.g., issuance, verification) into external systems for orchestration and audit. | ✓ | ✓ |
Wallet-initiated issuance Wallet starts issuance from issuer metadata or a catalog, without first receiving an offer. | R | R |
Scope-based credential request Wallet asks for a credential using the issuer-published scope. | ~ | ~ |
Deferred issuance Issuer returns a transaction id and the wallet polls later for the credential. | ✓ | ✓ |
Batch issuance Several credentials or keys in one credential request. | R | R |
Combined offer or request PID plus mDL, or the same document in two formats, in one offer or presentation request. | ✓ | ✓ |
Automatic holder binding & proof-of-key PoP and holder-binding during issuance/presentation per OID4VCI/VP so issuers/verifiers can trust key control. | ✓ | ✓ |
One-user-one-wallet consumer model Custodial, stateful wallet with built-in user auth. | ✓ | ✓ |
One-user-multi-wallet model Flexible user↔wallet mapping with multi-tenant support (shared or individual wallets). | - | ✓ |
Username/password auth for wallet users Built-in email/password login and session management for wallet users. | ✓ | ✓ |
External IdP (OIDC) for wallet users Integrate external OIDC IdPs for wallet user login. | ✓ | ✓ |
Local credential storage Custodial credential storage in wallet DB with list/import/delete APIs. | ✓ | ✓ |
Hardware-backed keys Holder keys stay in platform keystore or Secure Enclave on the device. | ✓ | ✓ |
Transaction log Holder can review past issuance and presentation events. | ~ | ~ |
Backup and restore Attestations can be recovered onto the same wallet product. | R | R |
Move to another wallet Attestations can be migrated to a different wallet product. | R | R |
Wallet-to-wallet share Two holders share an attestation in proximity. | - | - |
Request deletion from a relying party Holder can ask a previous verifier to delete received data. | - | - |
Report a suspicious request Holder can report an unlawful presentation request to a data-protection authority. | - | - |
Pseudonyms / passkeys Wallet can authenticate without releasing identity attributes. | - | - |
Zero-knowledge proofs Presentations that do not disclose the underlying attribute. | - | - |
Wallet instance revocation A compromised wallet unit can be withdrawn. | - | - |
| Credential Lifecycle & Status | ||
Credential status validation Check stored credentials for revocation/status (e.g., Bitstring Status List). | ~ | ~ |
| Identifiers & Trust Anchors | ||
Host did:web Documents Serve and auto-update did:web documents directly from the platform. | ✓Only wallet v1 not v2 | ✓ |
DID Document Storage Persist DIDs and DID documents via internal / enterprise DID store. | - | ✓ |
X.509 PKI Issuance Issues IACA root and Document Signer certificates. | ~(DIY) | ✓ |
| Integrations | ||
External KMS Integrate AWS, Azure, Hashicorp, PKCS#11 HSMs; supports ed25519, secp256r1/k1, RSA with rotation. | ✓ | ✓ |
Trust Registries Check parties against configured trust sources such as VICAL or authority key identifiers. | - | - |
QTSPs Qualified signature support via QTSPs. | - | ROn roadmap |
| ID Ecosystems | ||
EMEA alignment Aligned with EU eIDAS2, EBSI and Swiss SWIYU requirements. | ✓ | ✓ |
APAC alignment Aligned with NZ DISTF, Australia, Thailand, Japan, etc. | ✓ | ✓ |
Americas alignment Aligned with US, Canada, Brazil frameworks. | ✓ | ✓ |
Custom ecosystems Adaptable to other/local ID ecosystems. | ✓ | ✓ |
| Deployment | ||
On-Prem / Self-Hosting Self-hosting in your own cloud or data center — no managed SaaS | ✓ | ✓ |
Multi-tenancy setups Isolated wallet configurations for B2B/B2G/B2B2C use cases | - | ✓ |
Clustering / horizontal scaling Run multiple enterprise stack instances behind a load balancer with shared state (sessions, configs, etc.) | - | ✓ |
API Data Persistence Persisted wallet data across service restarts and deployments. | - | ✓ |
| Security | ||
Data Encryption Encrypt sensitive data at rest in the database. | - | ✓ |
Protected APIs (AuthN/Z) Fine-grained protection of APIs with scoped tokens per tenant/service. | - | ✓ |
Roles & permissions (RBAC) Granular roles for orgs/tenants/services following least-privilege principle; Supports importing and mapping roles from an external IdP's. | - | ✓ |
API keys (server-to-server) Scoped M2M API keys for backend/service integrations. | - | ✓ |
| Monitoring & Analytics | ||
Audit logging Recorded logs and events for auditing and compliance. | - | ✓ |
Analytics & metrics Track operations, success/error rates across tenants/services for ops and reporting. | - | ✓ |
| Administration | ||
User accounts (operators/admins) Admin GUI logins with role-based permissions. | - | ✓ |
Admin GUI Configure services, monitor sessions, and manage credential lifecycle operations (e.g. revocation) or verification states. | - | ✓ |
Learn and build
Docs & examples
Wallet API — Getting Started
Spin up the Community Wallet and create your first wallet.
ConceptsCredential formats
Everything you need to know about credential standards like W3C VC, IETF SD-JWT VC or mDL/mdoc ISO 18013-5)
ConceptsExchange Protocols
Everything you need to know about exchange protocols like OID4VCI/VP or ISO 18013-7.
ConceptsHow to Accept W3C Verifiable Credentials via OID4VCI
End-to-end example for accepting a W3C VC via OID4VCI.
GuideHow to Present Digital Credentials via OID4VP
End-to-end example for presenting a credential via OID4VP.
GuideHow to Import and Store W3C Verifiable Credentials
End-to-end example for importing and storing a W3C VC.
GuideGET STARTED
Pick the stack that fits your rollout
Start for free with open-source or go enterprise when you need to scale.
FAQ
Frequently asked questions
Talk to walt.id
Let’s design your wallet solution
Tell us about your wallet goals and we’ll explore the path that fits.
