OpenID Certified EUDI Verifier
Check an EU digital ID in seconds. Keep the answer, not the data.
One API call asks a question. The person approves it in their EU wallet. You get a verdict you can act on, checked against the EU trusted list, and nothing you didn't ask for.
A live check
POSTYour server → VerySafe
POST /v1/verifications
Authorization: Bearer <api-key>
{ "credentialType": "eu_pid",
"claims": ["age_equal_or_over.18"] }201 CreatedVerySafe → your server
{ "id": "0f6c1a2e…",
"status": "pending",
"credentialType": "eu_pid",
"requestedClaims": ["age_equal_or_over.18"],
"authorizationRequestUri": "openid4vp://?client_id=…",
"pollUrl": "/v1/verifications/0f6c1a2e…" }GETWaiting for the wallet
GET /v1/verifications/0f6c1a2e…
{ "status": "pending" }200 OKVerdict
{ "id": "0f6c1a2e…",
"status": "verified",
"result": {
"claims": { "age_equal_or_over": { "18": true } } } }200 OKVerdict
{ "id": "0f6c1a2e…",
"status": "failed",
"result": {
"failureReason": "Example PID Provider is explicitly
distrusted on the EU PID Providers list." } }Verified
Over 18?Yes
- Provider on the EU trusted list
- Not withdrawn, not revoked
- Bound to this request
Refused
Provider withdrawn from the EU trusted list
- Nothing was stored
- OpenID CertifiedOID4VP 1.0 + HAIP 1.0 verifier, SD-JWT VC and mdoc
- Hosted in the EUGoogle Cloud, Belgium (europe-west1)
- Verdicts, not dataDisclosed attributes deleted within the hour
- Fail closedNo silent yes. Every refusal has a reason.
How a check works
Three steps. No copy of the person's document lands on your systems.
Ask
Your application makes one call saying what it needs, for example over 18, and gets a QR code or link to show.
Approve
The person scans it with their EU wallet and shares only what you asked for.
Get the answer
Verified, or a plain reason why not: unapproved provider, withdrawn, revoked, expired, or a copy.
What you can ask for
Two EU credentials today. Request only the facts you need; everything you do not name stays on the phone.
-
EU personal ID
PID · SD-JWT VC
Name, date of birth, nationality, address and document details.
- Over 16
- Over 18
- Over 21
- Over 65
- Age in years
- Nationality
- Address
- Document expiry
-
Mobile driving licence
mDL · ISO/IEC 18013-5 mdoc
Name, portrait, driving privileges, issuing country and expiry.
- Over 18
- Driving privileges
- Portrait
- Issuing country
- Expiry date
- Document number
-
Any screen
Cross-device · same device
On a computer, show a QR code. On a phone, a link opens the wallet, and the person returns to your page after approving.
Why teams choose VerySafe
Ask only what you need
Prove someone is an adult without learning their birthday.
Integrate in an afternoon
Two endpoints. The wallet exchange, signatures, trust lists and revocation happen in the service.
Built for AI agents
An MCP tool returns verdicts only, so personal data never enters a model's context.
Verification on its own
Buy verification without issuance. No platform lock-in.
An audit record without personal data
Every verdict is kept: outcome, reason, issuer and which facts were proven. Never the values.
Run it in your own cloud
A self-hosted edition of the same service, in early access, for teams whose data must stay on their own infrastructure.
MCP
Your AI assistant can check an ID without seeing it
The MCP server gives agents a tool that starts checks and reads verdicts. It never returns attribute values, which answers the first question every compliance team asks.
POST /v1/mcp
{ "jsonrpc": "2.0", "id": 1, "method": "tools/call",
"params": { "name": "check_verification",
"arguments": { "session_id": "0f6c1a2e…" } } }
→ { "session_id": "0f6c1a2e…",
"verdict": "verified",
"credential_type": "eu_pid",
"disclosed_claim_names": ["age_equal_or_over.18"] }Hosted by us, or run by you
The same service and the same verdicts. Choose who operates it.
-
VerySafe Cloud
We run it for you.
- Google Cloud, Belgium (europe-west1)
- Start with an API key, no infrastructure
- We follow changes to EU trusted lists and standards
- Alerts the moment an EU trusted list is unreachable
-
Self-hosted Early access
You run it in your own data centre or cloud account. Available on request while in early access.
- Docker Compose, or a Helm chart for Kubernetes
- Personal data never leaves your infrastructure
- Licence checked locally; nothing calls home
- Monthly usage report with counts only
Where it fits
- Age checks for shops and online services
- Opening an account (KYC)
- Account recovery and step-up security
- Marketplaces and gig platforms
- Hiring, right-to-work and tenant checks
- SIM registration
- Driving-licence checks
- AI assistants acting for a person
The dates you are working to
- End of 2026Every EU member state offers its citizens a digital identity wallet.
- 1 Jan 2027Public-sector online services that use electronic identification must accept it.
- 24 Dec 2027Banks, telecoms, transport, health and other regulated sectors that require strong authentication must accept it, as must very large online platforms.
Pricing that starts free
Build and test for free. Pay per completed check when you go live.
Sandbox
Free
Test environment, the full API and enough checks to build and demo.
Pay per check
Per check
One flat price per completed check, however you connect.
Volume
Monthly
A predictable bundle with priority support and an uptime commitment.
Self-hosted
Annual
A yearly licence for your own infrastructure. Early access, on request.
Be ready before your deadline
Design partners get free checks until launch and a working integration in weeks.
Talk to us