Skip to main content

E-ID, Wallets, and Verifiable Credentials

Nevis ID acts as verifier and relying party for government and third-party digital identities: a user proves who they are with a credential held in their own wallet, and Nevis ID turns that proof into a sign-in or a new account. Shipped verifier integrations cover the Swiss E-ID (swiyu), the Signicat e-ID and walt.id. Credential issuance, wallet apps, and decentralized identifiers (W3C DID) are delivered by those partners and by the e-ID schemes themselves, not by Nevis ID. Just-in-time account creation and account linking bind a verified e-ID to a Nevis ID account, so an e-ID serves both onboarding and everyday sign-in; bring-your-own-identity through a government e-ID is also covered under Federation and SSO.

Also known as

decentralized identity, verifiable credentials, OID4VC, EUDI wallet, Swiss e-ID (Swiyu), eIDAS, W3C DID, government-eID BYOI.

At a glance

CapabilityDeliveryDetails
Swiss E-ID (swiyu)NativeVerifier integration for the swiyu wallet app: the user scans a verification QR code and presents the credential. The Swiss E-ID is in public beta, and your organization must be registered in the swiyu trust infrastructure (sandbox)
Verifier hostingNativeThe swiyu verifier service runs in the Nevis environment by default; the verifier containers and database can be hosted in your own environment as an alternative
walt.idExample integrationVerifier integration with walt.id, an open source decentralized identity and wallet provider
Credential issuancePartner-deliveredCredentials are issued by the e-ID scheme or the wallet provider. Nevis ID does not issue credentials
Wallet appPartner-deliveredUsers hold credentials in their own wallet, such as swiyu or walt.id. Nevis ID ships no credential wallet; the Nevis Access App is an authenticator, not a wallet
Account binding (BYOI)NativeJust-in-time account creation for a first-time e-ID user, and linking an e-ID to an existing account; see also Federation and SSO
E-ID as a login methodExample integrationE-ID sign-in appears as a button on the login screen and is configurable per deployment
Identity verification through an e-IDExample integrationAn e-ID login can front registration and onboarding; see also Registration, Onboarding, and Identity Verification
eIDAS and EUDI wallet alignmentPartner-deliveredReached through the integrated providers: Signicat conforms to EUDI wallet regulation, walt.id builds on EUDI wallet infrastructure
ProtocolsNativeOpenID Connect and OAuth 2.0 toward the e-ID provider; the Signicat hub additionally offers SAML 2.0 and a REST API
Audit of e-ID loginsNativeE-ID sign-ins are recorded like other authentication events; see Reporting, Analytics, and Audit for retention, export, and SIEM ingestion

Concepts

  • Digital identities (e-ID): what wallet-based digital identity means for a relying party, and the three integrations Nevis ID ships out of the box

How-to Guides

References