What the European Wallet Is, and Why Ours Is Not One Yet

Nothing on this page is legal advice. It describes a framework and our position against it, and any obligation you have is between you and whoever regulates you.

What the framework actually asks for

A wallet in that sense is not an application with a nice name. It is a set of obligations.

Hold credentials the person controls, issued by parties the framework recognises.

Present them selectively, disclosing what a verifier needs and not the rest.

Bind them to the holder, so a stolen credential is inert.

Interoperate, across two accepted credential formats, two presentation protocols and a trust infrastructure spanning member states.

And be certified, by a scheme, against criteria, with the result published by somebody other than the wallet's author.

Where we stand against each, measured

Hold: no. The wallet keeps a catalogue and no credential body, read from the schema, so the first obligation is unmet at the storage layer.

Present selectively: no, which follows from the first. The share button produces an unsigned summary and says so itself.

Bind to the holder: implemented, unused. The mechanism exists in the shared package and this wallet does not call it.

Interoperate: partly. We implement one of the two accepted credential formats and none of the other, measured by search with a control.

Certified: no. No conformance run, no submission, no listing, and no certification of any kind.

And one more gap worth naming: a search for passkey, WebAuthn and FIDO across this wallet returns zero files, while the reference implementations treat platform-authenticator key custody as foundational.

What is already built, because absences alone would misdescribe us

A credential format the framework accepts, issued and verified by our shared package, with selective disclosure and holder binding implemented at that layer.

A presentation protocol implementation on the verification side, which is the half of the exchange a relying party runs.

An identifier method registered in the W3C DID Method Registry, with documents that resolve publicly today.

That is a real starting position and it is not a claim to conformance.

What we will not say

Not that we are aligned, compatible or conformant. Those are words with an owner, and the owner publishes a list.

Not that we hold qualified status of any kind, and not that any part of our stack is certified.

Not that a deadline makes us relevant. A date in a regulation creates obligations for regulated parties, not credibility for whoever mentions it loudest.

For a holder, what this means today

Do not expect a credential from this wallet to work in a European flow. It cannot be presented at all yet, and nothing about the format alone closes that.

Do expect the underlying format to travel, if and when custody and presentation exist here, because the format is one the framework accepts and the artefacts are standard-shaped.

Keep reading

What the European Wallet Is, and Why Ours Is Not One Yet · Solidus