Docs · Get started
Introduction
Valitel is an API-first verifier for the EU Digital Identity Wallet. Your backend makes one HTTP call; Valitel speaks the wallet protocols and hands back verified claims.
What Valitel does
Valitel is a relying party as a service. It creates the OpenID4VP request a wallet answers, serves the signed request object, receives and decrypts the presentation, verifies the issuer signature, the trust chain, the holder binding and the replay protection, and gives you back the claims that were disclosed — over a plain JSON API you can call from any language.
Your backend never handles credential formats, trust lists or wallet protocols. It creates a verification, shows the holder a QR code or deep link, and reads the result.
The verification lifecycle
- Create.
POST /v1/verificationswith a template or your own DCQL query. You get a sessionidand awallet_uri, and the session ispending. - Present. Render
wallet_urias a QR code or a deep link — or let the drop-in widget do it. The holder approves the request in their wallet, and the wallet posts its response to Valitel. - Verify. Valitel checks the presentation: issuer signature, trust chain, certificate revocation, holder binding, and that this session has not already been answered.
- Deliver. The session becomes
completed,failedorexpired. Read the result by polling the API, by receiving a signed webhook, or by redeeming a same-device response code.
Base URL and versioning
All merchant endpoints live under /v1 on a single origin:
https://api.valitel.euRequests and responses are JSON (application/json), with two
deliberate exceptions on the wallet-facing routes, which no merchant calls: the
request object is a compact JWT and the wallet's response is form-encoded.
The machine-readable contract is the API's own OpenAPI 3.1 document, generated from the schemas the API validates against, so it cannot drift from runtime behaviour:
curl -s https://api.valitel.eu/openapi.jsonIf this site and /openapi.json ever disagree, the JSON is right.
Standards
Valitel implements the protocol stack the European Digital Identity framework names, end to end.
| Specification | Where it applies |
|---|---|
| OpenID4VP 1.0 | The presentation protocol, with DCQL credential queries and signed request objects per RFC 9101. |
| HAIP 1.0 | The OpenID4VC High Assurance Interoperability Profile — the profile referenced by Commission Implementing Regulation (EU) 2026/1731. |
| ISO/IEC 18013-5 mdoc | Mobile documents verified end to end: issuer signature, data-integrity digests and device binding to the holder. |
| IETF SD-JWT VC | Selective disclosure: the wallet reveals the claims a request names, and undisclosed attributes never leave it. |