Get started
European Digital Identity Wallet

Identity, verified
straight from the wallet.

Valitel is an API-first verifier for the EU Digital Identity Wallet — a relying party as a service. Create a verification with one API call, hand the wallet a QR code, and receive cryptographically verified claims.

OpenID4VP 1.0HAIP ISO/IEC 18013-5SD-JWT VCDCQL
api.valitel.eucurl
# one call from your backend
curl https://api.valitel.eu/v1/verifications \
  -H "authorization: Bearer $VALITEL_API_KEY" \
  -H "content-type: application/json" \
  -d '{ "template": "age_over_18" }'

{ "id": "vrf_G3mgaU2NnqZU-vNBd_jFAw",
  "status": "pending",
  "wallet_uri": "openid4vp://?client_id=…" }

# delivered to your webhook once the wallet answers
X-Valitel-Signature: t=1786724470,v1=e79142f7…

{ "type": "verification.completed",
  "verification": {
    "status": "completed",
    "claims": { "age_over_18": true } } }

How it works

From API call to verified claims

Your backend never touches credential formats, trust lists or wallet protocols. It makes one request, and receives verified claims.

01

Create a verification

One POST from your backend, with a preset template or your own DCQL query. You get back a session id and a wallet URI.

02

The wallet presents

Show the wallet URI as a QR code or deep link — or let the drop-in widget do it. The holder approves the request in their wallet.

03

Valitel verifies

Issuer signatures, trust chains, holder binding and replay protection are checked on every presentation. Issuer certificates are screened against their revocation lists, and every check lands in the result.

04

You receive claims

A signed webhook delivers the verified claims to your backend. Prefer pulling? Poll the API or watch the live log.

The platform

Everything a relying party needs

The verification flow is the headline, but the work of operating one — keys, webhooks, people, audit — is the part you keep living with. It is all here.

Verification templates

Age checks and basic identity ship as presets; write your own DCQL query when a preset is not what you need.

Scoped API keys

Keys are scoped to what they may do and carry their environment in the prefix. Only a SHA-256 hash is stored — a key is shown once, then it is yours alone.

Signed webhooks

Every delivery is HMAC-signed over its exact bytes, timestamped against replay, with dual-secret rotation and a 24-hour overlap.

Drop-in widget

A single script mounts the button, the QR modal and the status polling. Every class is namespaced, so it never fights your page.

Live log and audit trail

Watch verifications land in real time and export the audit trail as CSV. Even an operator viewing claims is itself recorded.

Organisations and roles

Owners, admins and members, invited by link. One account can belong to several organisations and switch between them.

For venues

A free staff app for the till

The Valitel staff app for iOS and Android is free for Valitel customers. Put it on a tablet or phone at the counter, pair it with a code from your back office, and run age checks without building a till client of your own.

  • Paired, never logged inThe till claims a one-time pairing code and holds its own short-lived device credential — never an API key — which you can revoke on its own.
  • One button, one answerStaff press Start age check, the customer scans the QR code with their EU Digital Identity Wallet, and the till shows the decision — never the customer's details.
  • Nothing left behindThe result clears itself from the screen, the app stores nothing about the customer, and it carries no analytics.
  • Counted like any checkChecks a till runs count toward your organisation's daily verification quota, like every other verification.

Get the app

  • iOS · App Store Coming soon
  • Android · Google Play Coming soon

Building your own till?

POS vendors and businesses that want the same pairing and age check inside their own till software will be able to get a licensed integration kit (for JavaScript and TypeScript tills; other platforms use the Devices API) after signing in to Valitel; see integration kits for what it will include. Until then, the Devices API documents the pairing and token calls the staff app makes.

Integration kits

Ready-made integration packages for a fast start Coming soon

Not released yet. When they are, the packages will be free of charge for Valitel customers under licence, downloadable after signing in once an organisation owner or admin has accepted the licence. That covers the software only; implementation services are not included. Until then, the public docs cover the same API calls: the quickstart, the verifications API reference and, for tills, the Devices API.

Enterprise backends

SDKs for Node.js, .NET and Python, with automatic retries planned for each, plus serverless templates: Node.js for AWS Lambda, Azure Functions and Google Cloud Run functions, Python for AWS Lambda, and .NET for Azure Functions. Each template pairs a start-verification handler with a webhook handler that reads the raw body, and reads its secrets from your cloud's own secret store.

POS and till software

A till integration kit for JavaScript and TypeScript tills — device pairing, safe token refresh, QR display and the pass/fail decision — with a POS integration guide. Tills on another platform can call the REST Devices API directly: it is documented today, and the POS integration guide will cover it too.

No code: the staff app

No integration project at all: once it is in the app stores, the free staff app runs checks from a counter tablet or phone. About the staff app

Standards

Built on the European specification stack

Valitel implements the protocol stack the European Digital Identity framework actually names, end to end.

OpenID4VP 1.0

The final presentation protocol, with DCQL credential queries and signed request objects per RFC 9101.

HAIP 1.0

The OpenID4VC High Assurance Interoperability Profile — the profile referenced by Commission Implementing Regulation (EU) 2026/1731.

ISO/IEC 18013-5 mdoc

Mobile documents verified end to end: issuer signature, data-integrity digests and device binding to the holder.

IETF SD-JWT VC

Selective disclosure by design: the wallet reveals the claims a request names, and undisclosed attributes never leave it.

Start verifying

Create an organisation, mint a test key and run your first verification — the presets are ready before your first request.