OID4VP Verifier, EUDI Wallet Interop
Welcome, my name is Franz Geffke. I help organizations such as twin succeed online: Increase reach and revenue, sharpen customer focus and lower aquisition cost and integrate with AI - If you think it's time to grow, contact me.
You are here because you clicked on the referral link on my clients website: .
The challenge
TWIN needed to accept credentials from EU Digital Identity Wallets as a login and verification method. The target was the same profile the EUDI Wallet runs on: OpenID for Verifiable Presentations (OID4VP) 1.0 with the High Assurance Interoperability Profile (HAIP), SD-JWT VC credentials, and the official EU Reference Wallet as the test counterpart.
Implementation
The verifier runs as part of the TWIN identity platform (TypeScript, Fastify) with a browser state machine on the frontend (Next.js, React 19).
x509_hashclient identifier scheme, so the wallet can authenticate the verifier against an X.509 chain rather than a bare domain.- SD-JWT VC verification with Key Binding JWT (KB-JWT) holder binding: the presentation is only accepted if the holder proves possession of the key the credential was bound to.
- DCQL (Digital Credentials Query Language) queries to request exactly the claims a flow needs and nothing more.
- JARM
direct_post.jwtresponses, encrypted with ECDH-ES, so presented claims never travel in the clear.
Spec review findings
Three issues surfaced in spec review while implementing: a path where KB-JWT verification was silently skipped, a JWE version mismatch that could accept either of two incompatible encodings, and a DCQL construction that leaked personally identifiable information into the request. All three were fixed before the verifier went live.
Standards
OpenID for Verifiable Presentations 1.0 · HAIP · SD-JWT VC · EU Digital Identity Wallet Reference Implementation

