VerySafe Talk to us

OpenID Certified EUDI Verifier

Check an EU digital ID in seconds. Keep the answer, not the data.

One API call asks a question. The person approves it in their EU wallet. You get a verdict you can act on, checked against the EU trusted list, and nothing you didn't ask for.

A live check

POSTYour server → VerySafe

POST /v1/verifications
Authorization: Bearer <api-key>

{ "credentialType": "eu_pid",
  "claims": ["age_equal_or_over.18"] }

201 CreatedVerySafe → your server

{ "id": "0f6c1a2e…",
  "status": "pending",
  "credentialType": "eu_pid",
  "requestedClaims": ["age_equal_or_over.18"],
  "authorizationRequestUri": "openid4vp://?client_id=…",
  "pollUrl": "/v1/verifications/0f6c1a2e…" }

GETWaiting for the wallet

GET /v1/verifications/0f6c1a2e…

{ "status": "pending" }

200 OKVerdict

{ "id": "0f6c1a2e…",
  "status": "verified",
  "result": {
    "claims": { "age_equal_or_over": { "18": true } } } }

200 OKVerdict

{ "id": "0f6c1a2e…",
  "status": "failed",
  "result": {
    "failureReason": "Example PID Provider is explicitly
      distrusted on the EU PID Providers list." } }

Verified

Over 18?Yes

  • Provider on the EU trusted list
  • Not withdrawn, not revoked
  • Bound to this request

Refused

Provider withdrawn from the EU trusted list

  • Nothing was stored
Scenario
  • OpenID CertifiedOID4VP 1.0 + HAIP 1.0 verifier, SD-JWT VC and mdoc
  • Hosted in the EUGoogle Cloud, Belgium (europe-west1)
  • Verdicts, not dataDisclosed attributes deleted within the hour
  • Fail closedNo silent yes. Every refusal has a reason.

How a check works

Three steps. No copy of the person's document lands on your systems.

  1. Ask

    Your application makes one call saying what it needs, for example over 18, and gets a QR code or link to show.

  2. Approve

    The person scans it with their EU wallet and shares only what you asked for.

  3. Get the answer

    Verified, or a plain reason why not: unapproved provider, withdrawn, revoked, expired, or a copy.

What you can ask for

Two EU credentials today. Request only the facts you need; everything you do not name stays on the phone.

  • EU personal ID

    PID · SD-JWT VC

    Name, date of birth, nationality, address and document details.

    • Over 16
    • Over 18
    • Over 21
    • Over 65
    • Age in years
    • Nationality
    • Address
    • Document expiry
  • Mobile driving licence

    mDL · ISO/IEC 18013-5 mdoc

    Name, portrait, driving privileges, issuing country and expiry.

    • Over 18
    • Driving privileges
    • Portrait
    • Issuing country
    • Expiry date
    • Document number
  • Any screen

    Cross-device · same device

    On a computer, show a QR code. On a phone, a link opens the wallet, and the person returns to your page after approving.

Why teams choose VerySafe

  • Ask only what you need

    Prove someone is an adult without learning their birthday.

  • Integrate in an afternoon

    Two endpoints. The wallet exchange, signatures, trust lists and revocation happen in the service.

  • Built for AI agents

    An MCP tool returns verdicts only, so personal data never enters a model's context.

  • Verification on its own

    Buy verification without issuance. No platform lock-in.

  • An audit record without personal data

    Every verdict is kept: outcome, reason, issuer and which facts were proven. Never the values.

  • Run it in your own cloud

    A self-hosted edition of the same service, in early access, for teams whose data must stay on their own infrastructure.

MCP

Your AI assistant can check an ID without seeing it

The MCP server gives agents a tool that starts checks and reads verdicts. It never returns attribute values, which answers the first question every compliance team asks.

Read about the MCP tools

tools/call · check_verification
POST /v1/mcp

{ "jsonrpc": "2.0", "id": 1, "method": "tools/call",
  "params": { "name": "check_verification",
    "arguments": { "session_id": "0f6c1a2e…" } } }

→ { "session_id": "0f6c1a2e…",
    "verdict": "verified",
    "credential_type": "eu_pid",
    "disclosed_claim_names": ["age_equal_or_over.18"] }

Hosted by us, or run by you

The same service and the same verdicts. Choose who operates it.

  • VerySafe Cloud

    We run it for you.

    • Google Cloud, Belgium (europe-west1)
    • Start with an API key, no infrastructure
    • We follow changes to EU trusted lists and standards
    • Alerts the moment an EU trusted list is unreachable
  • Self-hosted Early access

    You run it in your own data centre or cloud account. Available on request while in early access.

    • Docker Compose, or a Helm chart for Kubernetes
    • Personal data never leaves your infrastructure
    • Licence checked locally; nothing calls home
    • Monthly usage report with counts only

Where it fits

  • Age checks for shops and online services
  • Opening an account (KYC)
  • Account recovery and step-up security
  • Marketplaces and gig platforms
  • Hiring, right-to-work and tenant checks
  • SIM registration
  • Driving-licence checks
  • AI assistants acting for a person

The dates you are working to

  • End of 2026Every EU member state offers its citizens a digital identity wallet.
  • 1 Jan 2027Public-sector online services that use electronic identification must accept it.
  • 24 Dec 2027Banks, telecoms, transport, health and other regulated sectors that require strong authentication must accept it, as must very large online platforms.

Pricing that starts free

Build and test for free. Pay per completed check when you go live.

  • Sandbox

    Free

    Test environment, the full API and enough checks to build and demo.

  • Pay per check

    Per check

    One flat price per completed check, however you connect.

  • Volume

    Monthly

    A predictable bundle with priority support and an uptime commitment.

  • Self-hosted

    Annual

    A yearly licence for your own infrastructure. Early access, on request.

Talk to us about volume

Be ready before your deadline

Design partners get free checks until launch and a working integration in weeks.

Talk to us