Skip to content

Franz Franz

goFranz // personal journal
development

OID4VP Verifier, EUDI Wallet Interop

Welcome, my name is Franz Geffke. I help organizations such as twin succeed online: Increase reach and revenue, sharpen customer focus and lower aquisition cost and integrate with AI - If you think it's time to grow, contact me.

You are here because you clicked on the referral link on my clients website: .

The challenge

TWIN needed to accept credentials from EU Digital Identity Wallets as a login and verification method. The target was the same profile the EUDI Wallet runs on: OpenID for Verifiable Presentations (OID4VP) 1.0 with the High Assurance Interoperability Profile (HAIP), SD-JWT VC credentials, and the official EU Reference Wallet as the test counterpart.

Implementation

The verifier runs as part of the TWIN identity platform (TypeScript, Fastify) with a browser state machine on the frontend (Next.js, React 19).

  • x509_hash client identifier scheme, so the wallet can authenticate the verifier against an X.509 chain rather than a bare domain.
  • SD-JWT VC verification with Key Binding JWT (KB-JWT) holder binding: the presentation is only accepted if the holder proves possession of the key the credential was bound to.
  • DCQL (Digital Credentials Query Language) queries to request exactly the claims a flow needs and nothing more.
  • JARM direct_post.jwt responses, encrypted with ECDH-ES, so presented claims never travel in the clear.

Spec review findings

Three issues surfaced in spec review while implementing: a path where KB-JWT verification was silently skipped, a JWE version mismatch that could accept either of two incompatible encodings, and a DCQL construction that leaked personally identifiable information into the request. All three were fixed before the verifier went live.

Standards

OpenID for Verifiable Presentations 1.0 · HAIP · SD-JWT VC · EU Digital Identity Wallet Reference Implementation

More projects

Have something like this to build?

Get in touch →