VerySafe Talk to us

OpenID Certified EUDI Verifier

The VerySafe EUDI Verifier

A hosted service that checks a credential presented from an EU digital identity wallet and returns a verdict, with the issuer's trust decided against the EU trusted list. Your application asks for a proof, the person approves it on their phone, and you get an answer you can act on, without holding the data behind it.

OpenID Certified

VerySafe EUDI Verifier 1.0.0

OID4VP-1.0-FINAL + HAIP-1.0-FINAL · 11 Sep 2026

View the register entry

OpenID Certified™ by LimogiAI Solutions Inc to the OID4VP-1.0-FINAL+HAIP-1.0-FINAL Verifier profiles of the OpenID for Verifiable Presentations protocol.

How a check works

Three steps. No copy of the person's document lands on your systems.

  1. Ask

    Your application makes one call saying what it needs, for example over 18, and gets a QR code or link to show.

  2. Approve

    The person scans it with their EU wallet and shares only what you asked for.

  3. Get the answer

    Verified, or a plain reason why not: unapproved provider, withdrawn, revoked, expired, or a copy.

What we check for you

Four questions, answered every time. If a check cannot complete, the answer is no, never a silent yes.

  • Is the ID real?

    It must come from a provider on the EU's own list of approved issuers, the same list the wallets trust. The signing certificate is walked to a trust anchor on that list.

  • Is the provider still approved?

    A withdrawn or suspended provider's IDs are refused, and you are told that is why.

  • Has the ID been revoked?

    Both the credential's own status and the issuing certificate's revocation are checked, every time.

  • Is the real owner presenting it?

    The proof is bound to this exact request, so a copy captured once cannot be replayed later or on another site. The holder's device proves it took part.

What you can ask for

Two EU credentials today. Request only the facts you need; everything you do not name stays on the phone.

  • EU personal ID

    PID · SD-JWT VC

    Name, date of birth, nationality, address and document details.

    • Over 16
    • Over 18
    • Over 21
    • Over 65
    • Age in years
    • Nationality
    • Address
    • Document expiry
  • Mobile driving licence

    mDL · ISO/IEC 18013-5 mdoc

    Name, portrait, driving privileges, issuing country and expiry.

    • Over 18
    • Driving privileges
    • Portrait
    • Issuing country
    • Expiry date
    • Document number
  • Any screen

    Cross-device · same device

    On a computer, show a QR code. On a phone, a link opens the wallet, and the person returns to your page after approving.

Three ways to connect

  • The API

    One call to start a check, one to read the verdict. Your application never handles the wallet exchange itself. A key per integration, rate-limited per key.

  • AI assistants

    A Model Context Protocol server, so an assistant can request a check and read the result as a tool. It returns verdicts and never attribute values.

  • An embeddable widget

    A snippet a website drops in to request a proof and receive a token its backend redeems. On the roadmap, not yet built; we will say here when it is.

In code

One call to start a check, one to read the verdict. The host is the one you are given with your key; the key is per integration.

Start a check that asks one question
POST /v1/verifications
Authorization: Bearer <api-key>

{ "credentialType": "eu_pid",
  "claims": ["age_equal_or_over.18"] }
201: show the person the link, or a QR code of it
{
  "id": "0f6c1a2e-7d3b-4c9a-9e1f-2b8d5a4c7e10",
  "status": "pending",
  "credentialType": "eu_pid",
  "requestedClaims": ["age_equal_or_over.18"],
  "authorizationRequestUri": "openid4vp://?client_id=…&request_uri=…",
  "pollUrl": "/v1/verifications/0f6c1a2e-7d3b-4c9a-9e1f-2b8d5a4c7e10"
}
Poll the check: a verdict you can act on
{
  "id": "0f6c1a2e-7d3b-4c9a-9e1f-2b8d5a4c7e10",
  "status": "verified",
  "createdAt": "2026-09-26T09:14:05.000Z",
  "result": {
    "verifiedAt": 1790414061000,
    "claims": { "age_equal_or_over": { "18": true } }
  }
}
…or a plain reason why not
{
  "id": "0f6c1a2e-7d3b-4c9a-9e1f-2b8d5a4c7e10",
  "status": "failed",
  "createdAt": "2026-09-26T09:14:05.000Z",
  "result": {
    "verifiedAt": 1790414061000,
    "failureReason": "Example PID Provider is explicitly distrusted on the EU PID Providers list."
  }
}

Proven, not asserted

The runs behind this page, with the plan identifiers that make them checkable, and the things they do not amount to.

What has actually been shown Last green 11 Sep 2026

Conformance suite
OpenID Foundation conformance suite 5.2.4 — OpenID4VP 1.0 Final + HAIP 1.0, verifier role
Runs
  • Verifier, SD-JWT VC, direct_post.jwt — plan wQGWIJYAtNw28
  • Verifier, ISO 18013-5 mdoc, direct_post.jwt — plan eBLNITGnSIih9
Tested by software we did not write
A European Commission EUDI reference wallet completes the full exchange against the deployed service.
Certification
Certified: see the register entry

What this does not mean

  • Trust is anchored in the European Commission's TEST hierarchy, so a verdict is not eIDAS assurance. That changes when a member state publishes a production trusted list to point at.
  • OpenID Foundation certification is a statement about protocol conformance, self-declared and published by the Foundation. It is not an EU or eIDAS approval, and no EU body has recognised it.
  • It is not wired into the CRMS console: a CRMS tenant's EU verification does not run through this service yet. See the eu-eidas profile on the proof page for what CRMS itself can prove.

Pricing that starts free

Build and test for free. Pay per completed check when you go live.

  • Sandbox

    Free

    Test environment, the full API and enough checks to build and demo.

  • Pay per check

    Per check

    One flat price per completed check, however you connect.

  • Volume

    Monthly

    A predictable bundle with priority support and an uptime commitment.

  • Self-hosted

    Annual

    A yearly licence for your own infrastructure. Early access, on request.

Talk to us about volume

Questions we are asked first

Is a verdict legally valid under eIDAS?

Not yet, and we say so. Trust today is anchored in the European Commission's test hierarchy, so a verdict proves the cryptography and the trust chain against test data. That changes when a member state publishes a production trusted list to point at, and the Trust page will say when it has.

Are you certified?

Yes, by the OpenID Foundation: VerySafe EUDI Verifier 1.0.0 is certified to the OID4VP 1.0 + HAIP 1.0 verifier profiles, for SD-JWT VC and ISO mdoc, since 11 Sep 2026, and the Foundation's register lists it. That is a statement about protocol conformance. It is not an EU or eIDAS approval; relying parties are registered under eIDAS, not certified.

Where does the person's data go?

To the service, for as long as the check takes, and then it is deleted within the hour. Your application receives a verdict and the reasons; if you asked for a claim and the person agreed, you receive that claim and nothing else. The service runs in Google Cloud in Belgium (europe-west1).

Which wallets does it work with?

The exchange follows the EU's own protocol profile, and the wallet we test against is the European Commission's reference wallet. We do not say every wallet: one named counterpart is a stronger claim than a general one, and it is the one we can show.

What does it cost?

Four shapes, no price list yet: a free sandbox, pay per check, volume plans, and an annual licence for the self-hosted edition, which is in early access. The numbers come from the first customer conversations, and design partners get free checks until launch.

Do I have to build the wallet exchange myself?

No. Your application makes one call to start a check and one to read the verdict. The exchange with the wallet (the signed request, the encrypted response, the trust-list and revocation checks) happens in the service.

Be ready before your deadline

Design partners get free checks until launch and a working integration in weeks.

Talk to us