Frequently asked questions
General
The aim of the EUDI Wallet ecosystem is to establish a Europe-wide interoperable digital infrastructure that enables people in the EU to securely store digital credentials and use them across borders. The wallet is designed to strengthen digital sovereignty by allowing users to decide for themselves which data they share. At the same time, it creates a European, independent infrastructure that meets the highest data protection and security standards. Through common standards, it enables seamless use in public administration, business and everyday life, thereby forming a central foundation for a modern and efficient digital society.
The EUDI Wallet is the digital wallet for all EU citizens and residents. It enables the secure storage and use of identity documents and certificates such as ID cards driver's license, university diplomas or the Deutschlandticket directly on a smartphone. EUDI Wallets are based on uniform technical standards but are provided independently by each EU Member State. They are used in compliance with the highest security and data protection standards, as well as European and national regulations, and are free of charge and voluntary for users. Under the amended eIDAS Regulation, EUDI Wallets will in the future have the following core functions:
- Secure identification at a high level of trust
- Storing and using digital credentials
- Electronic signing (using so-called qualified electronic signatures (QES))
- Login using pseudonyms
- Confirmation of payments
In Germany, the initial focus is on implementing the ID and proof functions (points 1 and 2).
eIDAS stands for electronic Identification, Authentication, and Trust Services. The original eIDAS Regulation has been in effect since 2014 and was the first to establish rules governing how digital identities and signatures function within the EU. eIDAS 2.0 builds upon this framework. The most important difference: digital identity is no longer intended to function solely for individual government services, but rather to be widely usable in everyday life, including with private providers and across national borders. A key new feature is the introduction of the EUDI Wallet. It enables users to digitally store their identity and credentials and share them selectively. At the same time, requirements for security, data protection, and Europe-wide interoperability are being specified in greater detail.
Germany is developing a state EUDI Wallet, which is due to be launched as an app in early 2027. Initially, it will offer the ability to manage and use digital credentials, both online and in person. In addition to the ID function (derived from the electronic identity card or residence permit), the first supported credentials are expected to be the digital driver's license, the social security card and the pension card. Further documents will follow gradually – the number and variety of these documents depend on the participation of future issuers in the EUDI ecosystem. In addition to public bodies, private companies, associations and other organizations can become issuers. If your organization wishes to issue digital documents in the future, you can find further information in the Ecosystem Knowledge Center.
The official German “EUDI Wallet Sandbox” has been available since December 2025. The sandbox is a state test environment in which organizations can test their use cases and integrations with the state EUDI Wallet, using test data only. The sandbox is the gateway to the national and European EUDI ecosystem. Currently, the wallet’s identification function is supported by Person Identification Data (often abbreviated as “PID”) generated via the electronic identity card and residence permit (eAT). Further forms of identification will be supported in the near future.
The development of the government EUDI Wallet is taking place in stages, accompanied by IT architecture work, pilot projects and the SPRIND prototyping process. In addition to the government solution, non-governmental EUDI Wallet providers will also have the opportunity in the future to have their products certified as EUDI Wallets. All activities of the German EUDI Wallet project are documented publicly and transparently via OpenCoDE, the open-source platform for digital sovereignty in Germany.
The German government has decided to provide a state EUDI Wallet, which will be introduced gradually from 2027. The Federal Ministry for Digital Transformation and Government Modernization (BMDS) is responsible for the project’s technical implementation. This is being carried out as part of the state EUDI Wallet project, which is being implemented by the Federal Agency for Leap Innovation (SPRIND) in collaboration with other project partners.
The rollout of the first version of the state wallet is planned for early 2027.
No, use is voluntary and free of charge.
To use the EUDI Wallet, you generally only need a smartphone and the installed app. However, if you wish to use the official identification function, a one-time verification of your identity is required. For this purpose, you can use a German national ID card, or an electronic residence permit, provided that the respective online ID function is activated.
To use the national EUDI Wallet, a smartphone running the iOS (Apple) or Android (Google) operating system is required.
The EUDI Wallet can currently not be offered as a browser-based service, as it must meet the highest security requirements and access the security functions of smartphones directly (e.g. Secure Enclave/StrongBox). One of the teams tested this in our innovation competition "EUDI Wallet Prototypes." In doing so, we found that this is not yet technically possible. It requires further browser extensions that are still in the standardization process. As a project, we continue to work on this topic.
The EUDI Wallet will offer a secure and privacy-friendly alternative to many current apps and physical documents. Ultimately, the choice to use the wallet instead of existing cards or apps – and the extent to which it is adopted – is entirely up to you and the participating organizations.
The national EUDI Wallet does not need an account/login. Users can use the wallet without creating any account/login. Independently of this, the App Store and Google Play Store require an account for the user to install any application. We are aware that some users prefer alternative distribution methods. These are being looked into. Any such approach must meet the required security standards and must not compromise the integrity of the EUDI Wallet.
Yes, the EUDI Wallet can be used throughout Europe and works across borders.
To inform the public, public relations strategies tailored to specific target groups are currently being developed and further expanded. The involvement of key communicators plays an important role in effectively conveying information to different target groups. In addition, information is provided via official websites, digital information services and social media channels. We are in the midst of this information process for the public and would therefore welcome your input, for example if you would like to invite us to events or have ideas for formats, resources, etc.
The EUDI Wallet represents a major step toward greater digital sovereignty. It enables users to store and use credentials in a self‑determined manner, based on European requirements for data protection, security, non‑discriminatory access, and interoperability. This reduces dependence on individual platform providers and strengthens the sovereign use of digital identities across Europe.
The EU is deliberately pursuing a division-of-labor approach. With the “Architecture and Reference Framework”, the European Commission defines uniform technical, security-related and organizational standards that ensure interoperability and a common level of trust across Europe. However, the actual implementation of these requirements lies with the Member States. The reason for this is that identity infrastructures are closely linked to national sovereign tasks, existing registers, administrative processes and legal frameworks.
Key Features of the EUDI Wallet
The EUDI Wallet is the digital wallet for all EU citizens and residents. It enables the secure storage and use of identity documents and certificates such as ID cards, driver's licenses, university diplomas or the Deutschlandticket directly on a smartphone. EUDI Wallets are based on uniform technical standards but are provided independently by each EU Member State. They are used in compliance with the highest security and data protection standards, as well as European and national regulations, and are free of charge and voluntary for users.
Under the amended eIDAS Regulation, EUDI Wallets will in the future have the following core functions:
- Secure identification at a high level of trust
- Storing and using digital credentials
- Electronic signing (using so-called qualified electronic signatures (QES))
- Login using pseudonyms
- Confirmation of payments
In Germany, the initial focus is on implementing the ID and proof functions (points 1 and 2).
The Ecosystem Knowledge Center provides initial collections of use cases for Relying Parties, for example in the field of mobility or for the implementation of discounts (e.g. through wallet-based verification of student ID cards, volunteer cards, etc.) as well as for identification in digital and analog spaces (e.g. for access control to corporate resources).
The introduction of the state EUDI Wallet will take place in stages. In the first phase, which will be available as a smartphone app from early 2027, the basic core functions will be provided. These include, in particular, the digital ID function and the use of various digital credentials, such as the digital driver's license. Further functionalities, such as signatures and additional certificates (e.g. health cards, educational certificates), payment authorization or pseudonymization, will be rolled out gradually following the launch from 2027.
The wallet will be a secure and privacy-friendly alternative to many existing apps and physical documents. The extent to which it is used and the extent to which it replaces previously used apps and cards is up to users and organizations.
The EUDI Wallet simplifies the retrieval and verification of, among other things, identity details, qualifications and entitlement to benefits, as digital evidence is available in a machine-readable format and enables the end-to-end digitization of processes. At the same time, users are always involved in the processes carried out via the wallet through their active consent to data sharing. There are no checks on the stored documents that run automatically in the background without user intervention.
The wallet is designed to ensure that users retain full control over the sharing of their personal data at all times. It is not possible to transfer information from the EUDI Wallet without the explicit consent of the individual concerned. Public authorities or other third parties cannot access wallet data without this consent. Furthermore, there are currently no plans to allow users to permanently override their consent for recurring use cases or to grant blanket authorization. Every use of the state EUDI Wallet requires the user’s explicit, situation-specific consent.
No. The Bürger-App is not the same as the EUDI Wallet. Both are separate applications with different functions. While the EUDI Wallet serves as a digital wallet for documents such as ID cards, driver's licenses and certificates, the Bürger-App is intended to act as a central access point to digital administrative services.
The project partners are currently working out the specific details of how the EUDI Wallet and the Bürger-App will interact for users.
No. The age verification app presented by the European Commission is not the same as the EUDI Wallet. They are two separate initiatives with different technical foundations. The European age verification app is a separately developed solution that differs in some respects from the technical standards and architecture of the EUDI Wallet. Some Member States plan to link this app to their national wallet systems. For Germany, there are no plans to integrate this age verification app into the government’s EUDI Wallet. Instead, age verification will be implemented directly via the EUDI Wallet standard technology. This approach is fully eIDAS-compliant and ensures that principles such as technological openness, flexibility and digital sovereignty are upheld.
Users manage their credentials in the EUDI Wallet independently. Data is stored only on the user’s smartphone and is only digitally transferred to third parties after explicit consent by the user in the wallet. Consequently, smartphones are not physically handed over for transmission of data. Depending on the use case, the exact process leading up to active authorization may vary. Generally, the following steps apply:
1. Request to the Wallet Data exchange between wallet users and the Relying Party wishing to receive data from the wallet is initiated, for example, by clicking a button on a website, scanning a QR Code, or via NFC/Bluetooth using the device on which the wallet is installed. A Relying Party is a company or public authority that retrieves specific information about a person via the EUDI Wallet, such as identity data or a digital driver's license. It verifies this information and uses it to provide a service or make a decision. In doing so, it relies on the secure and trustworthy architecture of the wallet.
2. Verification of the Relying Party Before the data is sent, the wallet app validates the identity of the Relying Party. Digital trust lists ensure that the party in question is a registered and trustworthy entity. The app clearly displays exactly who is making the request.
3. Consent to data transfer The user receives an overview of the requested data. The information is only released for transfer after explicit confirmation. Only those data fields that have been requested and approved by the user are transferred. All data requests and transactions (both completed and rejected) are documented and viewable by the user within the wallet.
4. Secure transfer & validation The data is transferred in encrypted form directly from the wallet to the Relying Party. The Relying Party can immediately verify the authenticity of the information cryptographically, as each attribute has been digitally signed by the original issuer. The issuer is not involved in the validation of the data.
Digital Credentials and Digital Identity
“Digital credentials” are digitally signed certificates attesting to a person’s specific characteristics, authorizations or qualifications, which can be processed automatically. A digital signature cryptographically protects a credential against tampering. The recipient of a credential can thus automatically verify whether a certificate is genuine, which is not possible, for example, with photographs of ID documents. Examples of digital credentials include: driver's licenses, vocational or higher education certificates, and e-prescriptions. With digital credentials, users can prove certain attributes (such as name, date of birth, address, authorizations, etc.) securely, in a standardized manner and with legal validity across Europe – both online and in person.
The wallet function itself is free of charge – that is, the storage, presentation and verification of credentials. Issuers may charge fees for issuing certain credentials, as they already do in some cases today – for example, for an admission ticket, a certificate of good conduct, or an official certificate. This is then handled independently of the wallet, for example on the issuer’s website. The costs of developing and introducing the infrastructure underpinning the EUDI ecosystem (such as funds allocated in the federal budget) are borne by the public sector.
Digital documents and the wallet do not automatically replace existing procedures for issuing certificates, references, etc. Rather, it is to be expected that in the future there will increasingly be the option to decide whether one wishes to store and use a document digitally via the wallet and/or in another way.
Digital credentials can generally be managed clearly and flexibly in the EUDI Wallet. However, the options available depend on the type of credential in question. Some certificates are cryptographically bound to the end device. These cannot be moved off-premises or stored separately. If such certificates are deleted, they must be reapplied for from the issuing provider (issuer). Other proofs can, depending on the specific wallet design, be hidden, deactivated or used only when needed, without having to be kept permanently active.
Each wallet belongs to a specific user. The data contained within it is linked to the device and is additionally protected by authentication via PIN, biometrics or similar mechanisms. Therefore, it is not possible to use another device unless one can also bypass this security mechanism.
However: as with many other online age verification mechanisms, it can only be legally pursued, but not technically prevented, that users deliberately share their access to the device with others.
PID (short for Person Identification Data) can currently be generated from the chip data of an identity card or electronic residence permit (eAT) with an active online ID function and transferred to the wallet. The PID is a prerequisite for using the wallet’s ID function and will be legally equivalent to the existing online ID procedure (eID). Unlike the online ID procedure (see next question), adding a PID to the wallet only requires the identity document during the initial setup. After that, the PID is only used via the smartphone.
The technical details and the contents of a sample PID data record can be viewed here.
The online ID function is automatically activated for identity cards applied for since 15 July 2017. You can check whether the eID function of an identity card or eAT is activated using the ID app, for example. To set up the wallet, a PIN must also have been set, or the so-called transport PIN must be available for the initial setting of this PIN. Further information on the online ID function can be found here.
A Qualified Electronic Signature (QES) is a planned core function of the EUDI Wallet, which allows documents to be signed and sealed electronically. It is legally binding in the same way as a handwritten signature and is offered free of charge to individuals.
The implementation of the QES function in the EUDI Wallet will take place in the course of 2027. Various options for implementing the QES in the state EUDI Wallet were presented and discussed during an open consultation session of the state EUDI Wallet project; a final decision is still pending. The recording is available here.
Data Protection and Security
The EUDI Wallet protects sensitive data by storing it exclusively locally and in cryptographically encrypted form on the device. This applies, for example, to Person Identification Data (PID) and the content of certificates. Access to the wallet and its functions is additionally secured by strong authentication (PIN + device lock). When users present their data to a Relying Party, it must be ensured that the Relying Party cannot, in turn, present the data to third-party Relying Parties. To this end, a cryptographic mechanism (‘holder binding’) is used, which ensures that every single use has been authorized by the user within the context of the respective transaction. To achieve the necessary level of security, the keys for this authorization are managed in hardware security modules at the wallet provider’s premises. However, the wallet provider cannot access either the keys themselves or the user data (as this is stored in the wallet), and therefore cannot present any user data to Relying Parties. To prevent user traceability, users remain pseudonymous to the wallet provider. The wallet only passes on data authorized by users. In accordance with the principle of selective disclosure, it is possible via the wallet to present only a specific part of a proof (e.g. ‘over 18 years of age’) without revealing further personal data (such as the exact date of birth). In doing so, the wallet automatically checks with every transaction whether the respective Relying Party is only requesting the information it has previously registered for that specific use case. Any Relying Party wishing to integrate the wallet into their processes must undergo a corresponding registration process involving identification, and in doing so must disclose their use cases as well as which data they intend to request for that specific use case. Before any data is shared, users can see who is requesting their data and for what purpose, and Relying Parties must authenticate themselves to the wallet. This ensures users are always aware of who they are sharing their data with. On this basis, users can also take legal action against Relying Parties should this be necessary. At the same time, the wallet prevents its use from being tracked for profiling purposes. Data is transferred exclusively and directly between the user’s digital wallet and the Relying Party — without passing through servers in the EUDI ecosystem. Issuers of digital credentials are not involved in the sharing of these credentials and receive no information about their use. If the device is lost, the wallet instance can be remotely locked so that no one else can continue to use it.
Services may only request from a wallet the data previously registered for their specific use case. Relying Parties must first go through a corresponding registration process, and the data they request for their use case is publicly visible. The wallet makes it completely transparent to users which data is being requested. Data is only shared with the user’s consent. Services must ensure that they collect and process data only within the parameters of the GDPR.
Every time the wallet’s identification function is used, the user must authenticate themselves. This is done through possession of the smartphone (possession factor) and the entry of a 6-digit PIN (knowledge factor). These two factors are then used to grant access to a hardware security module on a secure server, which is then used to sign (cryptographically sign) the response to the Relying Party’s request.
There are no plans to make use of the EUDI wallet mandatory for citizens. Although certain bodies are obliged to offer identification via the EUDI Wallet, its use remains voluntary. Furthermore, the wallet has been designed from the outset to preclude centralized state surveillance. Identification and verification processes take place exclusively between the user’s wallet and the relevant Relying Party; the issuer of identity documents is not involved and cannot track these processes. In addition, the principle of consent-based, data-minimal disclosure applies: only the information required in each case is released, without central storage or analysis of usage profiles.
As a general rule: following authorization by the user, the wallet provides only the data registered for a specific use case of a Relying Party, and not complete copies of documents. Whether a copy of the digital credential (including signatures and metadata) is required depends on the legal situation. As a rule, Relying Parties will extract, process and, where necessary, also store data from the credentials. The wallet itself does not create any new storage obligations, but rather helps organizations to process less data. However, existing legal obligations, in particular the GDPR, remain unchanged.
No. To ensure that user interactions remain untraceable, users do not receive a user account from the wallet provider that is linked to identifying data such as an email address or telephone number.
Yes, such a function is planned. This view will be accessible to users within the wallet app and is therefore protected against unauthorized access. The data is stored only locally and not with the wallet provider.
Digital certificates in the EUDI Wallet are cryptographically signed certificates whose authenticity and integrity can be verified by any Relying Party via the EU-wide trust infrastructure using so-called public keys.
Validity is ensured by checking the signature and validity status (e.g. static expiration date and validity) of a certificate during every verification by a Relying Party. Validity can be influenced by the issuer (e.g. revocation), so it is checked against so-called status lists. The issuer is not informed which certificate is being checked. Some certificates, like some paper documents, are valid indefinitely (e.g. diplomas), whilst others may have shorter validity periods.
Use Cases and Scope of Use
The fundamental aim is interoperability within the EU. Furthermore, global usability is also a clear priority for the future.
Yes, the EUDI Wallet can in principle be used by anyone to store and share digital credentials, including people without a German identity card or electronic residence permit (eAT). If you wish to use the wallet for identification purposes, an identity card issued in Germany with an active online ID function (eID) is required (i.e. identity card or electronic residence permit).
Foreign EU citizens can use the German EUDI Wallet even without a German ID card. They can receive, store and present certificates and attributes within it, i.e. use all functions that do not require a German digital ID (PID).
For identification purposes, however, the wallet from their country of origin remains the authoritative source. Only this contains the valid Person Identification Data and serves as a binding identity anchor across the EU.
A further regulation for such wallets is currently being drafted, for which the Federal Ministry for Digital Transformation and Government Modernization (BMDS) is responsible on the part of the German Federal Government. The state EUDI Wallet project focuses on the provision of the EUDI Wallet (for natural persons).
The use of the EUDI Wallet remains voluntary and free of charge for users. The regulatory requirements stipulate that Relying Parties must offer users alternative procedures.
Technical feasibility would be possible with the EUDI Wallet in a data-efficient manner, but such a decision lies with the legislator.
That is conceivable. Guidelines from the European level are still largely pending in this regard.
In accordance with the regulation, EU Member States will either provide the wallet themselves or designate and supervise suitable providers. In Germany, non-governmental providers will also be able to offer and operate EUDI Wallets, but exclusively as notified and regulated wallet providers in compliance with binding technical, security-related and organizational requirements. Independent operation or hosting outside this framework is not possible.
The ePA (Electronic Patient Record) and the EUDI Wallet are two separate applications. The ePA is a centralized health record system: data is stored in record systems within Germany’s telematics infrastructure. Access is logged centrally, and many processes are handled through backend components running in the background. In contrast, the EUDI Wallet is a decentralized credential wallet on a smartphone. Users actively control every data-sharing action, present signed credentials directly to the relying party, and benefit from a system that does not rely on central data storage. Credential issuers are not automatically informed about how or when credentials are used in the wallet. However, it is planned that the EUDI Wallet will be integrated with the Health ID (GesundheitsID) in the future. The Health ID can then be used to access the ePA.
Connection and Integration of the EUDI Wallet
The connection is made via uniform, EU-wide standardized interfaces that enable organizations to securely request, receive and verify wallet credentials. The integration thus functions like a modern, interoperable login/data-sharing system, without technical dependence on individual manufacturers. Organizations can test their integration in advance in the EUDI Wallet Sandbox. For detailed technical information, practical examples and guidelines, we recommend the following point of contact for all questions relating to the state EUDI Wallet ecosystem in Germany, the Ecosystem Knowledge Center.
In Germany, a production-ready test environment is available in the form of the EUDI Wallet Sandbox. It serves as the central gateway to the German EUDI ecosystem and enables organizations to conduct realistic testing – using test data only. Initially, the sandbox supports use cases for secure identification using PID. The state sandbox is necessary to test the technical integration and functionality of the EUDI Wallet with Relying Parties’ systems, ensuring that the solutions work as error-free as possible for users. The sandbox is part of the integration process for Relying Parties and will be available on a permanent basis. Germany is also using prototypes developed as part of an innovation competition organized by SPRIND to test selected aspects of the EUDI Wallet conceptually and technically. In parallel, so-called “large-scale pilots” such as APTITUDE and WE BUILD are running across Europe, in which key use cases and interoperability are being tested.
Relying Parties require testing facilities to test the technical functionality of their systems and the EUDI Wallet. They do this as a preliminary step in the state sandbox before the systems become accessible to end users. The necessary tests are carried out here on a permanent basis without using real data. Furthermore, a ‘closed beta’ is planned as part of the rollout and go-live of the EUDI Wallet. The aim is to test systems and processes under conditions as close to reality as possible with a limited group of end users. The specific details regarding the design of this ‘closed beta’ are currently being worked out.
In principle, every organization – and therefore every public authority – must go through the registration process via sandbox onboarding. However, the specific structure of the registration and onboarding process varies depending on the interaction model of the respective public authority, as several integration options are provided for, particularly within the public administration. On the one hand, a public authority – with the support of a technical service provider where necessary – can integrate the EUDI Wallet directly into its specialist procedures and processes. On the other hand, there is the option of indirect use via existing administrative systems, for example via BundID or in the context of register modernization or via NOOTS. The relevant details regarding the specific implementation are currently being worked out. Further insights into the implementation status can be found in documents from the IT Planning Council dated late November 2025. Specific information on the current registration process can be found here.
Technical Disruptions, Device Loss and Security
In the event of technical problems such as a flat battery, a faulty or unavailable smartphone, the EUDI Wallet cannot be used temporarily as it is linked to the specific device. This does not affect identification using existing physical ID documents, which remains possible at all times. In the current architecture, an internet connection is required to use the secure wallet identification function (PID), as verification is carried out via server-based security mechanisms. In the future, other forms of digital proof should also be presentable without an active internet connection. Appropriate technical solutions are currently under development.
If the smartphone is lost, the credentials stored in the EUDI Wallet remain protected. Access is secured via the PIN assigned by the user for the wallet and the general device lock (i.e. smartphone PIN or biometrics), so that unauthorized persons cannot access the wallet. The lost wallet instance can be revoked in a similar way to a credit card, but unlike a blocked credit card, it is then permanently unusable (it is not possible to restore this instance). To use it on a new device, the wallet must therefore be set up again (i.e. re-downloading the wallet app, re-adding proof of identity). This prevents misuse and ensures that personal data is not disclosed even if the device is lost.
A valid ID document with an active online ID function is required to initialize the wallet’s ID function using a PID. The issued PID is valid for no longer than the associated physical ID document. Upon receiving a new ID document, the PID must also be set up again accordingly.
A blocked wallet can no longer be used, as its revocation status is stored in the infrastructure and every wallet interaction undergoes an authenticity check. Additionally, issuers of proofs can block them based on the status of their respective proofs.
The digital ID card in the EUDI Wallet is personalized and can only be used following strong authentication. Simply possessing the smartphone is not sufficient.
Cloud backups are not possible for Person Identification Data (PID), as the data is tied to the specific device. In the future, there may be a backup option for digital credentials that do not require a cryptographic link to a specific wallet.
Access for All: Support, Accessibility and Protection
The EUDI Wallet will be available for voluntary and free use. The option to use analog proofs will remain available. Furthermore, we are working on information resources for all those interested in using the service.
The EUDI Wallet is being developed in a transparent and user-centered manner to ensure inclusive and broad accessibility. The EUDI Wallet is being implemented in accordance with BITV 2.0 guidelines to ensure accessibility. Since the start of the project, there has been a lively and ongoing dialogue with civil society organizations to incorporate requirements and perspectives into the development process as effectively as possible. Information resources are planned.
In accordance with the principles of “unlinkability” and “unobservability”, the EUDI Wallet specifically prevents profiling and misuse by storing personal data exclusively locally and in encrypted form, and by not allowing central tracking. Individual records and transactions are not technically linked to one another, meaning that no usage profiles can be created, even for migrants or religious minorities. The principle of selective disclosure also applies in the interests of data minimization. With selective disclosure, only the information requested for a specific purpose is released. This makes it possible to provide proof (e.g. “over 18 years of age”) without revealing further personal data (such as place of birth).
The wallet is an application that can support the digitalization of public administration processes. Implementation and design are the responsibility of the authority providing the service. The wallet does not replace advice from a public authority. It will still be possible to contact public authorities in person or in writing (including digitally).
Advice centers can support clients by providing information and training. Concepts and materials are currently being developed to explain how to use the wallet to users. To ensure these resources are accessible and understandable to everyone, the project began consulting different target groups at an early stage and involving them in the development of the EUDI Wallet. The success of such a participatory approach depends on the involvement of a wide range of different stakeholders. We would be delighted if you could get in touch with us if you have any questions or ideas on this matter.
Currently: no. However, we are aware of the importance of this issue and are working on implementing a proxy function in the future (e.g. for legal guardians or parents).
Minors can use the wallet to store and present digital proof of identity. Depending on whether young people aged 16 and over hold an ID document with an activated eID function, they can also use the wallet’s ID function.
Parental representation has not yet been implemented in the EUDI Wallet. The wallet is, in principle, linked to a specific individual. However, the amended eIDAS Regulation provides that Member States may in the future provide evidence of family relationships. The EUDI Wallet will be technically capable of storing and using such evidence, for example regarding parenthood. How this requirement will be implemented in Germany in practice, including the source of the relevant data, is currently being clarified. As regards age verification, the following already applies today: parents cannot provide proof of age for their children from their own wallet. This requires the child’s personal proof of identity or a formalized representation solution to be introduced in the future.
Participation in the EUDI Wallet Ecosystem
Public authorities across the EU must accept the EUDI Wallet whenever a service requires a person's identity to be established (identification). They must also accept the wallet for sign-in and access procedures in which users confirm their previously established identity (authentication), for example when logging in to digital public services.
Private-sector organizations that are legally required to identify their customers, such as banks or mobile network operators, must also accept the EUDI Wallet as proof of identity. One example is opening a bank account in compliance with the Money Laundering Act (GwG).
In addition, a non-discrimination principle applies to certified EUDI Wallets. Relying Parties must accept credentials from any officially recognized EUDI Wallet. This principle applies both to organizations that are legally required to accept EUDI Wallets and to those that voluntarily choose to support wallet-based credential verification.
An organization must register within the EUDI ecosystem and, following successful identification, receives an access and registration certificate for the organization and the use case. This two-stage process takes place via standardized EU interfaces and will in the future be digitally supported by an online website (“EUDI Wallet Hub DE”). The registered organizations and use cases can be viewed in a public overview (known as the transparency register). This means that information on the activities of Relying Parties regarding the retrieval and reading of data from the EUDI Wallet is available to the public.
An organization must register as an issuer within the EUDI ecosystem. In addition to registration steps and technical integration, this also involves the identification of the organization. Following successful registration, issuers are incorporated into the trust infrastructure so that Relying Parties can recognize them as authorized issuers of a specific certificate.
They then issue digital certificates in accordance with the Europe-wide uniform technical standards of the Architecture and Reference Framework (ARF) and the applicable rulebook for the various certificates (e.g. defined data formats, signatures, status lists).
Liability issues are still being clarified in national legislation.
Common Points of Criticism
We take reports of misuse very seriously and use them to implement specific protective measures. The fraud discussed in the past related to the eID card for EU/EEA citizens (“EU citizen card”) and challenges in issuing this specific document via the relevant registration authorities – this document is not supported in the first phase of the EUDI Wallet in Germany. People from other EU Member States should instead use the EUDI Wallet of their country of origin or residence.
We take the criticism seriously. The EUDI Wallet is being developed strictly in accordance with the amended eIDAS Regulation and the European architectural framework, which set out high standards for data protection and security. The architecture is deliberately designed so that no central authority can track the use of the wallet. All data transfers take place exclusively between the user’s wallet and the relevant Relying Party. To this end, the EUDI Wallet relies on signed certificates.
Signed certificates allow the recipient to verify their authenticity and integrity directly, without the involvement of the issuer of the certificate in question – a safeguard against the concern sometimes discussed in public debate under the term "phone-home function", that issuers of certificates could always be automatically involved in or notified of the use of the certificates they have provided whenever a verification of the certificates they have issued takes place. The use of signed data protects privacy (no central tracking), increases robustness (also possible offline in so-called “proximity” scenarios) and creates EU-wide interoperability in accordance with eIDAS 2.0/ARF. The decision-making process regarding signed data versus an authenticated channel can be followed both in the position paper by SPRIND GmbH and on OpenCoDE.
Technical
The implementation of the EUDI Wallet is based on the European eIDAS 2.0 Regulation, the corresponding implementing acts and the EU-wide Architecture and Reference Framework specification (often abbreviated as “ARF”), which define the key technical standards, security mechanisms and interoperability requirements.
The development of the state wallet in Germany took place through a public architecture and consultation process. The Federal Office for Information Security (BSI) supports the implementation through technical specifications, procedures and security requirements. The technical guideline (TR) TR-03189, which is currently being drafted (and is therefore not yet publicly available), specifies how the EUDI Wallet should be designed and which components interact within it. The operating organization’s cybersecurity certification is carried out in accordance with ISO/IEC 27001; in addition, specific technical security requirements apply in accordance with the guidelines of the BSI and the ARF.
Reuse is prevented by holder binding, which is achieved through a cryptographic "proof of possession". Only the wallet possesses the private key with which each presentation is cryptographically confirmed. Furthermore, the audience, nonce and timestamp bind the presentation to a specific request and prevent replay attacks. For SD-JWT, the relevant data structure is defined in Section 4.3 of RFC 9901. Relying Parties will generally enforce this verification.
The EUDI Wallet is not restricted to specific device manufacturers, but still requires the use of a mobile operating system such as iOS or Android. The use of a server-based hardware security module enables high compatibility; a dedicated secure element within the device’s hardware is not necessary. An NFC interface is also required to use the PID. However, this does not result in any additional or special hardware requirements for the device beyond the standard specifications of modern smartphones.
To use the digital ID card within the EUDI Wallet, you need an ID card (national ID card or electronic residence permit) with an activated online ID function. To add the digital ID card to the EUDI Wallet, enter the 6-digit PIN you chose for the online ID. Then hold the ID card against the smartphone’s NFC contact point, and the EUDI Wallet will read the necessary data. After successful verification, a 6-digit PIN is assigned for the digital ID card (PID). The EUDI Wallet is now ready for use. Good to know: there are also digital credentials that can be used without setting up the digital ID card (PID function).
Yes, the source code for the government-issued EUDI Wallet, the Ecosystem Management Portal (EMP), and the PID provider (for issuing PIDs to the EUDI Wallet) will be released as open source, making it available for reuse and analysis by any interested parties, including but not limited to security researchers. The architectural documentation for the EUDI Wallet is already publicly available and is constantly evolved and updated. Furthermore, a security bug bounty program will be established prior to the go-live of the state EUDI Wallet, with the aim of inviting interested individuals to take a critical look at the wallet and its technical architecture and to reward them for identifying bugs.
At launch, the government-run EUDI Wallet will be available on the mainstream mobile operating systems Android and iOS. This ensures that the wallet can be provided to the broadest possible user base via established platforms with proven security mechanisms. At the same time, it is being assessed whether the EUDI Wallet can be operated on alternative operating systems in the future. A prerequisite is that the high security requirements of the amended eIDAS Regulation can be reliably met, particularly with regard to device integrity and security attestations. Supporting alternative operating systems is technically feasible in principle, but must be compatible with these requirements.
Yes. As digital credentials are stored locally on the respective device, they must be set up accordingly on each device. For security reasons, there may be restrictions on the number of devices on which a particular credential can be set up, such as when setting up the PID.
Using the government‑run EUDI Wallet does not require a Google or Apple account, and the wallet is not linked to such an account. An account is only needed to download or update the app via the respective app store. The EUDI Wallet itself operates independently of platform provider user accounts. Its availability and functionality are designed so that they do not depend on individual decisions made by single companies. The underlying security mechanisms are based on open and platform-independent standards. In addition, alternative distribution channels are being considered in the long term to further reduce dependencies.
The EUDI Wallet is legally required to meet the eIDAS Level of Assurance “High” (LoA High). This is achieved through a multi‑layer security architecture that applies strict requirements to both the app and the smartphone. A key element is cryptographic key attestation, which ensures that sensitive keys are generated and used only in a secure device environment. On Android devices, Android Key Attestation is the primary mechanism used to verify device integrity and secure key handling. Additional platform-provided risk signals, such as the Play Integrity API, are currently being evaluated as an optional supplement. A final decision has not yet been made. If no clear security benefit is demonstrated, these mechanisms will not be included in the final EUDI Wallet architecture.
Administrations and municipalities
No. The state wallet is provided centrally. Municipalities only need to organize their processes with regard to documents from the EUDI Wallet.
The EUDI Wallet offers significant efficiency gains for municipalities by automating credential processes and reducing manual verification efforts. Thanks to EU-wide interoperability and the use of existing infrastructures, digital identity services can be seamlessly integrated, significantly accelerating administrative procedures.
The integration of the EUDI Wallet and BundID is intended to facilitate connectivity with public administration. The two solutions complement each other: BundID serves as a central platform for identification, authentication, and the exchange of credentials, connecting users with digital government services, while the EUDI Wallet enables the secure provision of identity data and credentials.
Via direct integration with the specialized procedure:
- The authority can connect its specialized procedure directly to the EUDI Wallet infrastructure.
- To do so, it can use its own interface, a wallet adapter, or a suitable service provider.
- Credentials are generated directly from the specialized procedure in compliance with the eIDAS framework and made available to the EUDI Wallet.
- This approach is particularly suitable for high transaction volumes and fully digital, end-to-end processes without media discontinuities.
Via the BundID mailbox:
- The authority provides the data from its specialized procedure in a structured format.
- A wallet adapter converts the data into eIDAS-compliant formats.
- The BundID mailbox provides a wallet credential (e.g., a certificate of good conduct or a BAföG funding decision).
- Citizens and residents can transfer the credential to their personal wallet via a link or QR code.
Via NOOTS for register-based information:
- The authority can provide register data directly to the EUDI Wallet via NOOTS in a seamless, end-to-end digital process.
- Credentials are generated from connected registers in an EUDI Wallet-compliant format.
- A prerequisite is that the respective register is already connected to NOOTS.
- This approach is particularly suitable for standardized register extracts and information that can be provided from existing registers.
The Federal Ministry for Digital Transformation and Government Modernisation (BMDS) is currently testing various options for administrative integration. This pilot program, conducted in partnership with the City of Dresden and the Free State of Saxony, is scheduled to run through the second quarter of 2026. The ultimate goal of these efforts is to establish a consistent, federally coordinated onboarding model for all municipalities across Germany.
Relying Parties and Use Cases
A Relying Party (RP) is any organization or institution that verifies digital credentials presented by users via their EUDI Wallet. In doing so, the RP relies on the issuing authorities (Issuers) and the underlying trust framework of the ecosystem. This ensures that the data presented is both authentic and valid at the time of verification.
The state EUDI Wallet will be available from 2027. Early integration is recommended. The testing of use cases and participation in the sandbox is a prerequisite for later use in productive operation.
You can test your use case in the EUDI Wallet Sandbox by participating either as a Relying Party or an EAA Provider. The prerequisites are a concrete PID or EAA use case and the technical readiness to participate in testing activities. The project team will support you in refining your use case and preparing the technical integration. Within the test environment, you can then trial the retrieval, issuance, or verification of EUDI Wallet data and digital credentials using test data. Further information on the onboarding process and the broader ecosystem can be found in the Ecosystem Knowledge Center.
Integration options depend heavily on the specific use cases and existing technical procedures. The state EUDI Wallet project provides technical development guidelines for all wallet functions (so-called "Developer Guides”) to make integration into existing systems as straightforward as possible. Integration is the responsibility of the respective providers.
No, its use is voluntary, but it makes life considerably easier for both users and companies thanks to seamless, time-saving and more efficient everyday processes.
Sandbox
The EUDI Wallet Sandbox is Germany's official test environment for the state-issued EUDI Wallet. It enables companies, organizations, and public authorities to test use cases in a secure, production-like environment before they are fully rolled out. The sandbox is open to both public and private organizations and supports compliance with eIDAS 2.0 regulations.
The EUDI Wallet Sandbox is initially open to organizations ready to validate their identification use cases (PID) under realistic conditions using test data. As first movers, these participants help refine the ecosystem by providing valuable feedback while using the sandbox as a collaborative learning platform. Access will be expanded to additional organizations in stages, allowing more participants to prepare for the official public rollout of the national EUDI Wallet. To determine if your organization is ready to join, please consult the Onboarding Guide, plan your specific use cases, and begin your integration preparations.
Yes, the official German EUDI Wallet Sandbox has been available since December 2025. As a central testing and innovation platform, it enables organizations to trial integrations with the government-issued EUDI Wallet using test data only, prior to public rollout. The sandbox currently supports use cases for digital identification based on Person Identification Data (PID), for example using the German identity card or electronic residence permit (eAT), as well as Electronic Attestations of Attributes (EAAs) and other digital credentials. Organizations can define and test their own credential types, both as issuers and as verifiers. Additional credential types and use cases are being added on an ongoing basis.
- Review the onboarding requirements.
- Define your PID use case and submit it for review.
- Complete the onboarding steps, including a kick-off meeting with the project team.
- Use the Sandbox Readiness Checklist to assess your organization’s readiness.
Welcome to the Service Provider Listing The current listing of service providers on this website is an interim solution. From now on, every service provider has the opportunity to register and be listed on the website via the consent form.
Currently listed service providers: Adesso Authada Bundesdruckerei Deutsche Post Ecsec Engity Etonec esatus euro-V GmbH G+D Governikus iGrant.io Js-soft L21s Lissi Materna Information & Communication SE Mobivention msg systems ag Nect PassportReader Patronymus Ping Identity Procivis SET GmbH SVA System Vertrieb Alexander GmbH Truvity Verimi
Marketplace Under Development The full Marketplace concept is still being developed. In the future, the Marketplace will be hosted on the Ecosystem Management Portal and will include additional filter criteria such as technical integration, consulting, legal guidance, compliance support, or implementation experience to help organizations identify service providers that best match their specific needs. The Service Provider Marketplace is going to be part of the German EUDI Wallet Ecosystem. It aims to make relevant service providers more visible and easier to find for relying parties and other organizations seeking support.
No Endorsement or Ranking The listing does not represent a recommendation, certification, ranking, or endorsement of individual service providers. It is intended to provide transparency and support ecosystem development.
Register as a Service Provider Service providers who would like to be listed can register via the consent form.
Contribute to the Development Service providers interested in sharing feedback on the Marketplace concept are welcome to get in touch for an exchange or interview-style conversation. Your input can help shape the next development steps of the Marketplace.