EUDI WALLET
Accept EUDI Wallet Credentials In The Flow You Already Run
Shufti verifies EUDI Wallet presentations over OpenID4VP and returns the decision through the API you already call. The same integration covers everyone who arrives without one, across all 27 EU Member States.
EUDI Ready, Without A Second Onboarding Stack
Wallet Verification Runs Inside Your Existing Flow
Shufti validates the presentation, checks the issuer trust chain and credential status, and applies your risk rules. It lands as a configuration change, not a second integration.
Ready In All 27 Member States, As Each Wallet Goes Live
As each Member State brings its wallet into production, Shufti accepts it through the same integration, so wallet support is never a per-country project. Customers who arrive without one are verified in the same flow, on the national eID and document routes their Member State already runs.
Two Regulatory Clocks, One Evidence Trail
Wallet acceptance and AMLR due diligence are examined from the same customer file. Shufti records the route taken and the attributes released, so a reviewer opens the same evidence either way.
EXPLORE THE STACK
One Platform, Every Route Your Customers Arrive On
Verify a wallet presentation like any other check
Presentations arrive over OpenID4VP in SD-JWT VC and ISO/IEC 18013-5 mdoc. Shufti validates the issuer trust chain and credential status, then applies your risk rules to the result.
-
Wallet Presentation
Shufti issues an OpenID4VP presentation request, receives the credential the customer releases from their wallet, validates it, and returns an accept, decline or refer decision.
-
Credential Formats
Presentation uses OpenID4VP, the protocol defined for the ecosystem in ARF v3.0.0. Supported credential formats are SD-JWT VC and ISO/IEC 18013-5 mdoc, covering Person Identification Data and attestations of attributes.
-
Issuer and Trust Chain
A credential is only as good as the chain behind it. Shufti verifies the issuer signature against the trust anchor, checks credential status for revocation, and confirms holder binding, so a valid-looking presentation from a compromised or withdrawn credential does not pass unchallenged.
-
Selective Disclosure
The wallet releases only the attributes you asked for, and under CIR (EU) 2025/848 you may only ask for what you declared. Shufti requests your declared attribute set and no more, which reduces the personal data you hold and keeps the request consistent with your registration.
-
Wallet Fallback Routing
The wallet is offered where it is available, and a customer without one continues on document, NFC, biometric or eID verification. Configured in Journey Builder, so acceptance never becomes a second funnel.
Notified eID schemes and documents, in the same flow
Long before the wallet, national eID schemes carried Europe's high-assurance onboarding, and they keep running alongside it. Shufti verifies against the notified national eID schemes Member States already run, plus documents, NFC chips and biometrics.
-
Authenticate government-issued documents with in-house technology. Recursive OCR handles non-Latin scripts; forensic checks assess tampering, template match and data consistency.
-
Read the cryptographic chip in ePassports and national IDs. PACE and Active Authentication confirm the chip is genuine and unmodified.
-
Passive liveness detection and 1:1 face matching against the document portrait. It matters on the wallet route too: a valid credential proves the credential, not the person holding the device.
-
Match identity against government and bureau records through the notified national eID schemes Member States run, with no document upload. They pre-date the wallet and keep carrying real volume alongside it.
-
Cross-reference the address a customer gives you against authoritative databases or proof-of-address documents, and return a normalised, reviewable result rather than raw user input.
The Obligations That Outlast The Integration
Acceptance brings registration and record-keeping duties that sit outside the API. Shufti captures what a reviewer will ask for.
-
Audit Trail and Retention
Every check, decision and reviewer action is recorded against the customer, including the route used and the attributes requested and released.
-
Intended-Use Declaration
Registration requires declaring which attributes you will request, and asking for more than you declared breaches that declared intended use. Shufti requests your declared set, so the attribute policy is enforced in the flow rather than left to each integration.
-
AMLR (EU) 2024/1624 recognises eIDAS electronic identification means at substantial or high assurance for remote onboarding. Risk assessment and record-keeping obligations remain. A verified wallet presentation is evidence within the file, not a replacement for the file.
-
Automated accept and decline paths run without a reviewer; referred cases queue with the evidence already attached. Distinguishing the automated decision from the human one is what makes the file defensible later.
One Integration For All 27 Member States
Wallets arrive state by state. Shufti accepts each one as it reaches production and verifies the customers who do not yet hold one, so nothing about your integration changes as the EU rollout completes.
-
Member State Readiness
One integration covers all 27 Member States. As each state brings its wallet into production Shufti accepts it, and customers who do not hold one are verified on the national eID, document, NFC or biometric route instead.
-
National eID Schemes
Member States were running notified national eID schemes long before the wallet, and those schemes keep carrying substantial onboarding volume alongside it. Shufti verifies against them in the same flow as a wallet presentation.
-
Where a signature needs eIDAS Article 25 handwritten-equivalent effect, Shufti supplies the identity proofing and orchestration and the qualified certificate is issued by our EU Trusted List QTSP partner, Evrotrust. Shufti is not itself a QTSP. This is a separate capability from wallet verification and does not make Shufti an issuer of wallet credentials or qualified attestations.
-
Deployment and Residency
Cloud, on-premise and hybrid deployment with EU data residency available. Wallet-sourced attributes are high-sensitivity personal data, so residency and retention scope should be settled in contracting rather than assumed.
A Solution Built Around Your Team's Role
Accept wallet presentations, route everyone else through eID and documents, and evidence both from one file. Built for the compliance, product, fraud and engineering demands wallet acceptance actually creates.
Compliance Officer
Evidence wallet acceptance and AMLR due diligence from one file, with the route taken and the attributes released recorded against every customer.
Product Manager
Add wallet acceptance without building a second onboarding funnel. Customers without a wallet continue on the route they use today, inside the same journey.
Developer
One REST API and one SDK for wallet presentations, documents, NFC, biometrics and eID. Webhooks return the decision with the released attributes attached.
Fraud Analyst
A valid credential proves the credential, not the person holding the device. Liveness, device and behavioural signals apply to the wallet route as they do to every other.
One Integration Covers Every Verification Mode
Build fully customisable verification flows with seamless backend integration.
- Gain full control by customising verification flows end-to-end.
- Integrate seamlessly with your backend for quick implementation.
- Design flexible verification journeys tailored to your users.
Launch a native verification experience in your mobile app within minutes.
- Launch native verification within minutes on iOS or Android.
- Use ready-made UI with camera, capture, and real-time feedback.
- Customise flows to fit seamlessly into your mobile app.
Run Shufti within your own identical-capability infrastructure for maximum data control and privacy.
- Keep all sensitive information in-house to meet strict governance and data residency requirements.
- Keep sensitive information fully private and secure in-house.
- Deploy in highly regulated sectors without compromising compliance.
Quickly launch identity verification through a secure, customisable web link, no code required. Learn more.
- Start verifying users instantly with a no-code setup.
- Deliver a consistent identity experience via a link or embedded iframe.
- Deploy quickly via a secure link or embedded iframe.
With KYC Journey Builder, create personalised verification journeys without writing a single line of code.
- Customise your journey effortlessly with drag-and-drop functionality.
- Instantly see how your verification flow looks for your users.
- Easily connect with Hosted Verification for a consistent, branded experience.
Validated By Leading Analysts And Certification Bodies

Ranked Top 5 in the DHS RIVR 2025 for identity validation
Read Blog
Ranked Exceptional for age verification by Liminal Index 2026
View Report
Recognised as a Leader in G2 Summer 2026 reports
View Reviews
Differentiated by Gartner on document diversity and country coverage
Read more
Certified at iBeta Level 3 PAD with 0% APCER
Read BlogBUILT FOR YOUR INDUSTRY
Built For Europe's Regulated Sectors
Verify B2B Partners Without Scaling Compliance Risk
Verify B2B partners and corporate customers across jurisdictions with AMLR-ready live registry checks and sub-2-minute Quick KYB decisions. Scale onboarding without scaling compliance risk.
Don’t just take our word for it, hear from our customers
The Confidence Our Clients Share
The future of digital identity is defined by trust, interoperability, and regulatory alignment, so our partnership with Shufti reinforces DevCode Identity’s commitment to supporting our global customers with the most secure, best-in-class, compliant identity verification solutions available today.
Combining our Conversion Driven Compliance Orchestration Platform with Shufti’s global KYC and IDV capabilities allows our customers not only to navigate complex regulatory demands but also to maintain a seamless customer onboarding experience with the highest achievable conversion rates.
We’re proud to continue our partnership with Shufti as we expand into new jurisdictions.
Shufti’s verification technology not only strengthens our compliance framework but also ensures our players enjoy a smooth, secure onboarding experience.
We aim to offer our clients and their traders the very best tools with which to do their jobs, we’re excited to be able to work with Shufti.
They’re a leading company, and we’re looking forward to offering their solutions to our clients through our CRM.
The relationship with Shufti was born out of frustration with an existing provider, so we started our discussion with Shufti.
The response time was excellent, from the start of speaking to sales to getting up and running with the demo.
Frequently Asked Questions
Does Shufti verify EUDI Wallet credentials today?
Yes. Shufti accepts EUDI Wallet presentations over OpenID4VP, validates the issuer trust chain and credential status, and returns an accept, decline or refer decision through the same API as every other Shufti check.
Which credential formats and protocols does Shufti support?
Presentation uses OpenID4VP, the protocol defined for the ecosystem in the Architecture and Reference Framework v3.0.0. Supported credential formats are SD-JWT VC and ISO/IEC 18013-5 mdoc, covering Person Identification Data and attestations of attributes. Talk to us about the specific attribute sets and Member State schemes in scope for your deployment.
Is Shufti a qualified trust service provider?
No. Shufti is not itself a qualified trust service provider and is not a wallet provider. Shufti supplies the identity verification and orchestration layer. Where a signature needs eIDAS Article 25 handwritten-equivalent legal effect, the qualified certificate is issued by our EU Trusted List QTSP partner, Evrotrust. That partnership covers qualified signing; it does not make Shufti an issuer of wallet credentials or qualified attestations.
What happens to customers who do not have a wallet?
They are verified by document, NFC, biometric or database eIDV, through the same integration and the same decision layer. Wallet rollout is still uneven across the 27 EU Member States, so these routes carry most of your volume for some time yet.
Do we still need AMLR customer due diligence if a customer presents a wallet?
Yes. AMLR (EU) 2024/1624 recognises eIDAS electronic identification means at substantial or high assurance for remote onboarding. Risk assessment, ongoing monitoring and record-keeping obligations remain. A verified wallet presentation is strong evidence within the customer file, not a replacement for the file.
Who is the relying party, us or Shufti?
Under CIR (EU) 2025/848, an intermediary acting on behalf of relying parties is itself deemed a relying party and carries the same obligations, including limits on storing transaction content. Registration is national, so an organisation operating across twelve Member States faces twelve filings. We will confirm the registration model for your deployment during contracting.
Which organisations must accept the wallet?
Regulated sectors and designated Very Large Online Platforms. Each Member State must make at least one wallet available, and relying-party registration rules take effect ahead of the acceptance obligation itself. Micro and small enterprises sit outside it. Talk to us and we will map the sequence against the sectors and Member States you operate in.
Add Wallet Acceptance To The Stack You Already Run
See a wallet presentation verified end to end, alongside the routes that cover everyone else.




















