Get started

Docs · Get started

Introduction

Valitel is an API-first verifier for the EU Digital Identity Wallet. Your backend makes one HTTP call; Valitel speaks the wallet protocols and hands back verified claims.

What Valitel does

Valitel is a relying party as a service. It creates the OpenID4VP request a wallet answers, serves the signed request object, receives and decrypts the presentation, verifies the issuer signature, the trust chain, the holder binding and the replay protection, and gives you back the claims that were disclosed — over a plain JSON API you can call from any language.

Your backend never handles credential formats, trust lists or wallet protocols. It creates a verification, shows the holder a QR code or deep link, and reads the result.

The verification lifecycle

  1. Create. POST /v1/verifications with a template or your own DCQL query. You get a session id and a wallet_uri, and the session is pending.
  2. Present. Render wallet_uri as a QR code or a deep link — or let the drop-in widget do it. The holder approves the request in their wallet, and the wallet posts its response to Valitel.
  3. Verify. Valitel checks the presentation: issuer signature, trust chain, certificate revocation, holder binding, and that this session has not already been answered.
  4. Deliver. The session becomes completed, failed or expired. Read the result by polling the API, by receiving a signed webhook, or by redeeming a same-device response code.

Base URL and versioning

All merchant endpoints live under /v1 on a single origin:

Base URL
https://api.valitel.eu

Requests and responses are JSON (application/json), with two deliberate exceptions on the wallet-facing routes, which no merchant calls: the request object is a compact JWT and the wallet's response is form-encoded.

The machine-readable contract is the API's own OpenAPI 3.1 document, generated from the schemas the API validates against, so it cannot drift from runtime behaviour:

OpenAPI 3.1
curl -s https://api.valitel.eu/openapi.json

If this site and /openapi.json ever disagree, the JSON is right.

Standards

Valitel implements the protocol stack the European Digital Identity framework names, end to end.

SpecificationWhere it applies
OpenID4VP 1.0The presentation protocol, with DCQL credential queries and signed request objects per RFC 9101.
HAIP 1.0The OpenID4VC High Assurance Interoperability Profile — the profile referenced by Commission Implementing Regulation (EU) 2026/1731.
ISO/IEC 18013-5 mdocMobile documents verified end to end: issuer signature, data-integrity digests and device binding to the holder.
IETF SD-JWT VCSelective disclosure: the wallet reveals the claims a request names, and undisclosed attributes never leave it.

Where to go next