Digital Identity / EUDI Wallet Architecture

What you will do: Walk five steps: open the EUDI Wallet, get a PID issued, receive a university diploma attestation, present your identity to a bank as relying party, then sign a document with a QTSP.

Worked example: Start Issuance Flow at the PID Issuer to get a P-256-bound mdoc, then Login with Wallet at the bank, Consent & Share family name, given name, degree and age_over_18, and the bank confirms Account Opened.

Runtime and privacy: The cryptographic exercise runs in this browser. Review the site privacy terms before entering sensitive material; use synthetic inputs for learning and evaluation.

Browse all Crypto Lab tools · Learn with Digital ID

For your role

Developer / Engineer
Walk the five steps, EUDI Wallet, PID Issuer, University, Bank (RP) and QTSP (QES): the wallet's Credentials, Hardware Keys and History tabs show what is issued, where the keys live and what each relying party asked for.
Security Architect
The PQC Readiness note on the wallet step says today's credentials use P-256 and P-384 and where PQC is expected in the ARF; the Hardware Keys tab is where an architecture has to place the post-quantum keys.
Researcher / Academic
Follow the OpenID4VCI issuance and the mDoc and QES steps with the History tab open: the log records each exchange, which is the material to compare against the ARF and the standards it cites.

EUDI Wallet Architecture

Step 1: EUDI Wallet

View your credentials and secure keys.

EUDI Wallet

Managed by: María Elena García

PQC Readiness

Current EUDI credentials use classical algorithms (P-256, P-384). Future ARF versions are expected to mandate PQC-safe algorithms (ML-DSA, SLH-DSA) for long-lived credentials to protect against quantum threats. Target: high-risk use cases (which EUDI Wallets qualify as) migrated by the end of 2030, per the NIS Cooperation Group Coordinated Implementation Roadmap (2025) — not ETSI TS 119 182-1, which is the unrelated JAdES JSON-signature format spec.

What is selective disclosure? In EUDI wallets, you control which credential fields you share with each relying party. For example, you can prove "over 18" to a bank without revealing your exact date of birth. You will choose which fields to reveal in Step 4.

No credentials installed yet.

This is an educational simulation of the EUDI Wallet Architecture and Reference Framework (ARF). Cryptographic keys are generated in-browser using WebCrypto/WASM (OpenSSL) and stored in memory.

Try it

Try to issue the University diploma before the PID. What happens?

Next step

Turn it into a plan: Deployment Playbook

This tool practises the Digital ID module, phase 5 (Pilots & Migration); Deployment Playbook produces a deliverable of that phase.