eIDAS 2.0 · live

Sign in with EU Wallet

Scan the QR with your EU Wallet on another device, or tap the button to open a wallet installed on this one.

Same OID4VP 1.0 request via QR or button. Signed ES256 JAR, one-tap consent, given_name + family_name shared.

Open EU Wallet on this device

Initialising presentation request…

Open Aloaha Web Wallet (new tab) Sign in with passkey Use username and password instead
What is this and how does it work?

Open this page on the device that holds your European Digital Identity Wallet — the EU Reference Wallet with a government-issued PID from dev.issuer.eudiw.dev, or any OID4VP-compatible holder carrying an SD-JWT PID under the current PID Rulebook. The CodeB Verifier mints a fresh OID4VP 1.0 presentation request signed with ES256, bound to the verifier via the wallet‑preferred x509_hash Client Identifier Prefix (HAIP 1.0 x509_san_dns available as fallback) — your wallet validates it, prompts you for consent, and shares given_name + family_name. First-time visitors are auto-provisioned as guest users; returning visitors resume their existing account by the identity in the PID.

Why the wallet path is stronger than document-upload or video‑ID flows: OpenID4VP wallets are cryptographic and hardware‑bound, and where the credential is a government-issued EUDI PID it is also government‑rooted. By contrast, video‑ID checks are increasingly spoofable in 2026 with generative AI (face‑swap and voice‑clone deepfakes on a webcam feed), and document uploads can’t prove the document belongs to the person submitting it. The wallet sidesteps both problems.

No wallet installed? The Aloaha Web Wallet button above opens a browser-based holder in a new tab and receives the same presentation request. Your session on this page updates automatically when the wallet completes. First-time visitors: how to sign in with the Web Wallet · what the wallet is.

Live OID4VP 1.0 + HAIP 1.0 Verifier flow. Every page load mints a fresh signed JAR with an ephemeral P‑256 response‑encryption keypair. Both the request side and the wallet response handler are in production. Signed authorization requests use JAR with x509_hash verifier identification; response handling accepts encrypted direct_post.jwt (HAIP Final default) and plain direct_post for OpenID4VP legacy wallets.
Age verification demo · HAIP implementation notes · EU Wallet feature overview · Free training (dial 1844) · Deutsch