Digital identity infrastructure for the European wallet ecosystem.
Issue, present and verify digital credentials — online and in proximity.
Issue, present and verify digital credentials — online and in proximity.
eIDAS 2.0 is in force. Member states must offer every citizen a wallet, and relying parties in key sectors become obliged to accept it. The organisations that integrate during the window gain a frictionless channel before their competitors are forced to.
Each product runs on open standards and works with third-party implementations — use them together or stand-alone.
Hold and present trusted credentials.
Native iOS and Android EUDI wallet: enrolment, storage and presentation of digital credentials, with hardware-bound keys and user consent on every disclosure.
Verify credentials online or face-to-face.
Credential verification over the internet and in person via QR, NFC and BLE — including fully offline operation with cached trust and status data.
Issue interoperable digital credentials.
OID4VCI issuance platform for PID technology, mDL technology, EAA and enterprise credentials — in mdoc, SD-JWT VC, JWT VC and BBS+ formats.
Build trusted attribute ecosystems.
Issue and verify Electronic Attestations of Attributes. For qualified attestations, ForTrust integrates with the appropriate qualified trust service provider.
Connect services to EUDI Wallets.
Everything a relying party needs to accept wallets: request generation, user consent, verification and clean JSON results — over protocols your team already knows.
Integration guide →Operate the trust layer.
Trusted Lists, VICAL, certificate lifecycle, status lists and revocation — the machinery that decides who is trusted, kept in sync and available offline.
Under Regulation (EU) 2024/1183 and the DSA, accepting the European Wallet becomes a legal requirement across sector after sector from 2026. Every case below carries the full flow, the Commission’s official wording and the obligation date — plus modelled value where industry ranges exist.
EU banks, financial institutions, and e-money issuers must accept the European Wallet for account opening, customer due diligence (KYC), and credit applications. The citizen sees what's requested, confirms, and the bank receives only the ticked attributes — cryptographically signed and offline-verifiable.
“Relying parties, including financial institutions, shall accept the European Digital Identity Wallets for the authentication of natural persons for the purpose of fulfilling the know-your-customer requirements of Directive (EU) 2015/849.”Regulation (EU) 2024/1183, Article 5b
From November 2026, every EU bank, financial institution, e-money issuer, and payment service provider must accept the European Wallet as a valid means of customer identification, alongside physical passports and ID cards. AML / KYC libraries and risk procedures must be updated to read eIDAS 2 electronic attestations.
Reception desks, counters, events — anywhere fast identification is needed without a prior account. The wallet shows an ephemeral QR; the validator scans it with a phone or dedicated reader. Verification is cryptographic, local, under 2 seconds.
“European Digital Identity Wallets shall enable the user to request and obtain, store, select, combine and share, in a manner that is transparent to the user, person identification data and electronic attestations of attributes, including offline.”Regulation (EU) 2024/1183, Article 5a(4)
Every EU Member State public service must accept the European Wallet for authentication and identification by end of 2026 — healthcare, transport, education, local authorities, taxation. Private sectors classed as “critical relying parties” (air and rail transport, telecoms, regulated hospitality) enter scope in 2027.
Online platforms hosting age-restricted content or services must verify age strongly, without asking for an ID card or date of birth. The European Wallet generates a Zero-Knowledge mathematical proof — the site receives only the verdict, no PII.
“Providers of very large online platforms shall put in place appropriate and proportionate measures to ensure a high level of privacy, safety and security of minors on their service. Age verification based on European Digital Identity Wallets is regarded as the preferred, data-minimising mechanism.”DSA — Regulation (EU) 2022/2065, Article 28 + European Commission Guidance, July 2025
From 2026, online platforms hosting age-restricted content or services (gambling, adult content, alcohol delivery, tobacco sales) must implement strong age verification. The European Commission explicitly recommends the European Wallet as the preferred mechanism — no personal data is transferred, only the mathematical verdict. Solutions based on ID-card photos or third-party credit-bureau verifiers do not meet data-minimisation requirements (GDPR Art.5).
Festivals and large events are moving to digital tickets + in-event cashless. The citizen buys the ticket directly into the European Wallet, presents it at the gate via NFC tap (2 seconds, no paper, no e-mail in spam), and pays at stands inside with the same wallet — no cash machines, no plastic wristband. The organiser sees aggregates per event, never the individual participant's identity.
“The European digital identity and the associated electronic attestations may be used to access private services online and offline, including in areas such as event tickets, transport or accommodation, with enhanced privacy through selective disclosure.”Regulation (EU) 2024/1183, recital 14 + Commission Recommendation C(2024) 1432 on the ARF 2.x — proximity flows.
For event organisers, a wallet-held ticket isn't legally mandated yet, but Regulation (EU) 2024/1183 establishes the legal framework for any electronic attestation (including tickets, subscriptions, access passes) to have the same legal value as a paper document. The commercial advantage is immediate: 2-second gate verification (vs. 15-30 seconds for paper-ticket scans), internal cashless with automatic refund, GDPR-by-default compliance (no participant e-mail / phone list to keep), reduced fraud on duplicated tickets.
Gyms, private clubs and subscription venues drop the plastic key card and the dedicated app. The member signs the membership once in their European Wallet, then taps NFC or scans a QR at the reception validator on entry. Membership status (active / suspended / expired) is verified in milliseconds, without transmitting name or ID number — the operator sees only the "access granted" verdict with the membership end date.
“Relying parties using electronic attestations shall only use the attributes that are necessary for the provision of the requested service, and shall not systematically collect or process personal data not strictly necessary for the transaction.”Regulation (EU) 2024/1183, Article 5f
Sports clubs, gyms and subscription venues aren't required by Regulation (EU) 2024/1183 to accept the wallet, but GDPR Art. 5(1)(c) (data minimisation) forbids storing the ID number / date of birth / address of members purely for access control — the check can be made without PII. Replacing the plastic key card with a wallet pass removes the PII register, lowers breach risk and makes GDPR compliance automatic. Commercially: zero card cost (vs. €2-5 per member), zero loyalty-app cost (€15-40k initial development).
Streaming platforms, smart TVs and content services drop the per-device account creation. The user signs the subscription once in the European Wallet; later, opening the app on any TV, tablet or set-top-box, they scan the QR shown on screen and the wallet proves the active subscription through a pairwise pseudonym — without sharing name, e-mail or payment details.
“The European Digital Identity Wallet allows the user to authenticate anonymously or pseudonymously towards relying parties, whenever the service does not strictly require identification of the natural person.”Regulation (EU) 2024/1183, Article 5a
Digital content and streaming providers aren't required by Regulation (EU) 2024/1183 to accept the wallet, but GDPR Art. 5(1)(c) and the upcoming ePrivacy regulation push toward data minimisation and fewer password-based accounts. The concrete advantage: eliminating "create account + verify e-mail + enter card + remember password" — the main onboarding drop-off source (industry measures 25-40% drop per new TV). For smart TVs, set-top-boxes and consoles, the "scan QR with wallet" flow reduces steps from 5-7 to 1 — essential on screens without a keyboard.
ForTrust is built for interoperability, not a closed ecosystem. A digital credential issued by ForTrust infrastructure has been enrolled by an independently developed EUDI wallet — and ForTrust has, in turn, processed and verified presentations coming from an external wallet. In proximity, verification runs device-to-device over BLE and NFC, including where there is no internet at all.
Think of card payments: the payer's bank and the merchant's terminal don't need to be made by the same company for the transaction to work. Digital identity, done right, works the same way.
For a partner this means integration never forces adopting the whole ForTrust stack: use only the issuance, verification, wallet or trust component you need. Tests were performed in a controlled interoperability environment; the identity of third-party providers is not published without their consent, and full production trust / RP authorisation is handled separately.
Official OID4VP 1.0 conformance suite passed in full — including negative security cases and the HAIP profile.
PID issued into the official EU reference wallet and presentations fully verified by its verifier.
Profile aligned with an official national EUDI sandbox; national-rulebook SD-JWT PID read and verified.
Cross-enrolment and cross-reading with independent European wallet and verifier implementations certified against ISO 18013-5.
The full conformance matrix — element by element, with honest status (implemented / rollout / in validation) — is public on dwallet.fortrust.ro. Named interoperability reports are available to partners on request.
Convert more, store less, comply earlier.
Banks, platforms, venues: verified attributes over protocols your team already runs. Lower onboarding cost and drop-off, no document copies on your servers, and art. 5f compliance before it becomes an emergency.
Start with the RP Gateway →Turn attributes you hold into products.
Employers, universities, associations, municipalities: issue employee IDs, student cards, memberships and entitlements that any conformant wallet can hold and any verifier can trust — a new channel to your members, on your brand.
Talk about issuing →White-label the stack, keep the customer.
System integrators and identity providers: deliver EUDI projects on ForTrust technology — hosted, dedicated or fully white-label — with our engineering behind you and your name in front. Partner terms designed so the integrator wins.
Join the partner programme →We know precisely, because we built it.
Your use case, real phones, your data. A working demo your board can hold in hand.
Hosted, dedicated deployment or white-label — with SLAs, audit trails and your compliance team in the loop.
New credential types, new markets, new channels — same platform, same contract.
Prove age_over_18 — or any other age
threshold — without unnecessary disclosure of identity.
Employee ID, membership, role, entitlement and access rights — issued by your organisation, verified anywhere.
Student status, diplomas, professional qualifications and other educational attestations as verifiable EAAs.
Technology for PID, mDL and other official credentials — integrated with the competent authority and its authentic sources.
EUDI identity & attribute verification for regulated onboarding. ForTrust delivers verifiable credentials and attributes to the financial institution or the specialised provider responsible for the KYC/AML process.
LPID, mandates, representation, signatory rights and powers of attorney for organisations.
Join the pilot programme — talk to us.ForTrust is EUDI-ready technology, conformance-tested with the official OpenID Foundation suite and interoperability-tested against the EU reference environment. Formal certification and national accreditations are pursued together with each deployment — we say exactly what is proven, and prove what we say.
No. Every component runs on open standards, so you can use only the issuance, verification, wallet or trust layer you need — and swap any of them for a third-party implementation later.
If your application speaks OpenID Connect, days: redirect to /authorize, receive verified claims as JSON. A full pilot on your use case typically runs in about 30 days.
Yes — face-to-face verification over BLE/NFC per ISO 18013-5 runs with no internet, using cached trust anchors and status lists on the verifier device.
In their wallet, on their device, protected by hardware-bound keys. A relying party receives only the attributes the citizen approves — cryptographically signed, with an audit trail.
Yes — integrators and resellers can deliver the full experience under their own brand, with ForTrust engineering behind them. Ask about the partner programme.
Tell us your sector and the flow you care about — onboarding with PID, age verification, check-in, access control — and we will show it live, on real phones.