دع الأشخاص يسجلون الدخول باستخدام الهوية التي يمتلكونها بالفعل.
MitID، BankID، itsme، UAE PASS، gov.br، محفظة EUDI. يسجل المستخدم الدخول باستخدام هويته الرقمية الحكومية أو البنكية، وتعيد المحفظة سمات موقعة ومتحقق منها. قريبًا، مع كل محفظة وبلد موجودين بالفعل في الكتالوج.
EUDI Wallet30 دولة من الاتحاد الأوروبي والمنطقة الاقتصادية الأوروبية · The user's own member state; the issuer differs per country+26قريبًا
التوفر يأتي من كتالوج طرق الإنتاج، وليس من هذه الصفحة. تضيء المحفظة هنا لحظة قبولها داخل سير عملك. لا يوجد تاريخ إطلاق موعود.
قريبًا
اثنان وعشرون محفظة. أربع وثلاثون دولة.
كل محفظة في الكتالوج مدرجة بعلامتها الرسمية، والدول التي تعمل فيها، والجهة المصدرة لها. لا يوجد أي منها مباشر في الإنتاج بعد: مفتاح الإطلاق مغلق، لذا يظهر كل منها كـ 'قريبًا' ولا يمكن تفعيله في سير العمل حتى يتم تشغيله.
كيف يعمل
من تسجيل الدخول بالمحفظة إلى مستخدم موثق في أربع خطوات.
الخطوة 01 / 04
01
أنشئ سير العمل
حدد المحافظ التي تقبلها في كل بلد بمجرد أن تصبح متاحة. اختر ما إذا كان تسجيل الدخول الملغى أو الفاشل يعود إلى التقاط المستندات أو يتم رفضه. لا يتطلب أي كود.
الدمج
ادمج بشكل أصلي مع SDK الخاص بنا للويب، iOS، Android، React Native، أو Flutter. أعد التوجيه إلى صفحة مستضافة. أو ببساطة أرسل لمستخدمك رابطًا — عبر البريد الإلكتروني، الرسائل القصيرة، واتساب، أي مكان.
يمر المستخدم بالتدفق
يعرض Didit المحافظ التي تقبلها لذلك البلد بعلاماتها التجارية الحقيقية، ويسلمها إلى المحفظة التي يختارها المستخدم، وينتظر عودة التأكيد الموقع.
تتلقى النتائج
تحافظ الـ webhooks الموقعة في الوقت الفعلي على مزامنة قاعدة بياناتك لحظة الموافقة على المستخدم، أو رفضه، أو إرساله للمراجعة. استعلم من الـ API عند الطلب. أو افتح لوحة التحكم واقرأ السمات الموقعة.
مصمم للمطورين · مصمم لمكافحة الاحتيال · مفتوح التصميم
ست قدرات. قائمة قبول واحدة لكل دولة.
المحفظة هي إحدى طرق التحقق من الهوية، وتتبع نفس عقد النتائج الخاص بالتقاط المستندات. ما يتغير هو الإثبات: توقيع من الجهة المصدرة بدلاً من صورة.
تحمل كل محفظة علامتها الرسمية، وجهة إصدارها، والدول التي تعمل فيها، ومستوى ضمانها. جميع المحافظ الاثنتين والعشرين موجودة في نفس الكتالوج الذي تقرأه لوحة التحكم الخاصة بك، ومميزة حتى تاريخ إطلاقها، لكي لا تعد القائمة بأكثر مما تستطيع.
كتالوج المحافظ
مباشرة من كتالوج الطرق
22
في الكتالوج
34
الدول المغطاة
10
eIDAS عالي
MitIDقريباً
BankIDقريباً
BankIDقريباً
Vippsقريباً
Buypass IDقريباً
02 · قائمة القبول
اختر ما تقبله. المستخدم يختار.
المحافظ هي قائمة قبول، وليست تصنيفًا. لا توجد أي أدوات للتحكم في الترتيب، لأن الترتيب سيكون مجرد تخمين حول شخص لم تقابله بعد. النرويج تدرج أربع محافظ؛ يختار المستخدم واحدة.
قائمة القبول للنرويج
لا توجد ضوابط ترتيب في أي مكان
BankIDقريباً
Vippsقريباً
Buypass IDقريباً
EUDI Walletقريباً
التأشير هو كل الإعدادات. يختار المستخدم مما تقبله، ولا يحمل الترتيب على الشاشة أي معنى. تحتفظ كل محفظة بحالة الكتالوج الخاصة بها حتى تصبح متاحة.
03 · التسليم
سلّم إلى المحفظة، وعدّ متحققًا منه.
تدير Didit عملية التسليم، وشاشة الانتظار، والعودة. إذا لم يكن لدى المستخدم محفظة، أو ألغى العملية، أو فشل تسجيل الدخول، يحدد مفتاح واحد ما إذا كان سيعود إلى التقاط المستندات أو سيتم رفضه.
التسليم
ما يراه المستخدم النهائي
1اختر محفظة من المحافظ التي تقبلها
2سجل الدخول داخل المحفظة
3عد بسمات موقّعة
لا توجد محفظة، تم الإلغاء، أو فشلوثيقة
04 · السمات الموقعة
اقرأ السمات التي وقعها المصدر.
الاسم، تاريخ الميلاد، والمعرف الوطني الذي تعرضه المحفظة، بالإضافة إلى التأكيد الموقع نفسه. ألغِ تحديد أي سمة اختيارية لا تريد تخزينها ولن يتم كتابتها في الجلسة أبدًا.
السمات الموقعة
MitID · Danish Agency for Digital Government
Full nameدائمًا
Date of birthدائمًا
CPR alias (pseudonymised)دائمًا
Level of assurance reachedدائمًا
Signed assertionدائمًا
توقيع الجهة المصدرةصالح
05 · الضمان
حقق أعلى مستويات الضمان الثلاثة.
يمنحك المستند ضمانًا مستنديًا. يمنحك البحث في السجل مطابقة بيانات. تمنحك المحفظة ضمانًا تشفيريًا، لأن المصدر وقع على السمات وتتحقق Didit من هذا التوقيع.
مستويات الضمان
واجهات الإدارة فقط
مستنديالتقاط المستندات
مطابقة البياناتالبحث في السجل
تشفيريتسجيل الدخول بالمحفظة
لا يرى المستخدمون النهائيون أبدًا تسمية ضمان أو اسم مصدر أو سعر. يرى المراجعون لديك كل هذه الثلاثة.
06 · التغطية
34 دولة في الكتالوج.
تغطي محفظة EUDI وحدها ثلاثين دولة من دول الاتحاد الأوروبي والمنطقة الاقتصادية الأوروبية بمجرد إطلاقها، وتضيف المحافظ الوطنية البرازيل وأوكرانيا والإمارات العربية المتحدة والمملكة المتحدة. لا شيء في هذه الصفحة يتغير حتى يشير الكتالوج إلى أن المحفظة جاهزة، لذا فإن ادعاء التغطية الخاص بك وادعاءنا يظلان متطابقين.
الانتشار في الكتالوج
الدول التي لديها محفظة واحدة على الأقل
34
الدول
30
مغطاة بواسطة محفظة EUDI
التغطية تتبع الكتالوج دولة تلو الأخرى. وجود علم هنا يعني أن المحفظة مدرجة لتلك الدولة، وليس أنها تعمل حاليًا.
الدمج
استدعاء واحد. نتيجة موقعة واحدة تعود.
أنشئ الجلسة، أرسل المستخدم إليها، وتحقق من الـ webhook الموقّع عند وصول النتيجة. تعود المحفظة التي سجل بها المستخدم في النتيجة.
الصق الكتلة أدناه في Claude Code، Cursor، Codex، Devin، Aider، أو Replit Agent. املأ العنصر النائب my_stack بإطار العمل واللغة وحالة الاستخدام الخاصة بك. يقوم الوكيل بتوفير Didit، ويقبل المحافظ لكل بلد، ويربط الـ webhook، ويطلق المنتج.
didit-integration-prompt.md
# Didit digital ID wallets — integrate in 5 minutes
You are adding digital ID wallet sign-in to my_stack. The user signs in with a
government or bank digital identity and the wallet returns signed attributes.
Every URL, header, and enum value below is canonical — do not paraphrase or
"improve" them.
## 1. Provision an account
- Sign up: https://business.didit.me (no credit card required).
- Grab the API key for your application from the console.
## 2. Read the methods catalog first
Wallet availability is server-driven per country. Never hard-code a wallet list.
The catalog is not a public REST endpoint. Read it one of two ways:
- Business Console (signed in): your application -> ID Verification ->
Countries tab. https://docs.didit.me/console/id-verification-methods
- Didit MCP server tool didit_workflow_get_id_verification_methods_catalog,
authenticated with the same x-api-key; pass country (ISO 3166-1 alpha-3)
to narrow it to one country. https://docs.didit.me/integration/mcp/tools
- Public mirror of the coverage table (no auth, read-only):
https://docs.didit.me/core-technology/id-verification/verification-methods#coverage
The catalog gives you, per wallet id: the display name, the countries it
covers, the issuing authority, the level of assurance, the availability state,
and the attributes it returns. As of this prompt every wallet is coming soon:
the launch switch is off in production, so the catalog will not let you accept
one yet. Build against the catalog and re-read it; do not hard-code a date.
## 3. Create a workflow with the ID Verification (OCR) feature
POST https://verification.didit.me/v3/workflows/
-H "x-api-key: <your-api-key>"
-H "Content-Type: application/json"
The ID Verification feature's enum value is OCR (UPPERCASE — strict enum;
there is no ID_VERIFICATION alias and the API rejects it). Wallets are its
wallet method, accepted per country under config.methods on that same
feature entry, in the same request. Keys are ISO 3166-1 alpha-3.
{
"workflow_label": "Wallet onboarding",
"features": [
{
"feature": "OCR",
"config": {
"methods": {
"DNK": {
"document": { "enabled": true },
"wallet": {
"enabled": true,
"providers": ["mitid"],
"on_failure": "fallback_to_document"
}
},
"NOR": {
"document": { "enabled": true },
"wallet": {
"enabled": true,
"providers": ["bankid_no", "vipps"],
"on_failure": "fallback_to_document"
}
}
}
}
}
]
}
Response: the workflow uuid — use it as workflow_id in step 4.
Rules that the API enforces:
- providers is an accept-list, not a ranking. Order carries no meaning and
the end user picks
- on_failure is either fallback_to_document or decline. It covers all three
cases: no wallet, cancelled, sign-in failed
- a wallet id the catalog does not mark available for that country is
rejected, and the rejection fails the whole save — including any lookup
configuration next to it. While every wallet is coming soon, keep
wallet.enabled false (or omit the wallet block) so the save succeeds
- unknown wallet ids already saved on a workflow are preserved untouched, so
a config written by a newer console version is never silently dropped
- a country with no method enabled is rejected at publish time
## 4. Create a session
POST https://verification.didit.me/v3/session/
-H "x-api-key: <your-api-key>"
-H "Content-Type: application/json"
-d '{ "workflow_id": "<id from step 3>", "vendor_data": "<your user id>" }'
Response: 201 with url (the hosted verification link), session_token and
session_id. Redirect the user to url, or open it in the SDK. The field is
named url — there is no session_url and no verification_url. Didit
shows the accepted wallets for the user's country with their brand marks,
hands off to the wallet, and waits for the signed assertion to come back.
## 5. Webhooks
Register a destination (console -> API & Webhooks, or
POST https://verification.didit.me/v3/webhook/destinations/ with
webhook_version "v3" and subscribed_events ["status.updated"]) and store the
secret_shared_key it returns. Verify every delivery:
Header: X-Signature-V2 (NOT X-Signature, NOT X-Signature-Simple)
Algorithm: HMAC-SHA256, hex digest, over the CANONICAL JSON of the payload:
parse the body, sort keys recursively, serialise compact with
Unicode preserved and whole-valued floats as integers. Do NOT
hash the raw request bytes — that is the v1 X-Signature
algorithm and fails for V2 whenever whitespace or key order
differs from the canonical form.
Freshness: the signed body field timestamp is the dispatch time (Unix
seconds, refreshed on every retry). Reject when
abs(now - timestamp) > 300 seconds, and reject when the
X-Timestamp header does not equal it. The header is not
covered by the signature, so it must never be the only replay
check: a captured delivery replays with just that header
refreshed.
Compare: constant-time (crypto.timingSafeEqual)
Reference handler (Express) — use it as written:
const crypto = require("crypto");
// X-Signature-V2 signs canonical JSON: keys sorted as strings, compact,
// Unicode preserved. Emit the sorted entries directly - rebuilding an object
// would reorder integer-like keys ("10", "2"). Never hash req.rawBody.
const canonical = (v) =>
Array.isArray(v) ? "[" + v.map(canonical).join(",") + "]"
: v && typeof v === "object"
? "{" + Object.keys(v).sort()
.map((k) => JSON.stringify(k) + ":" + canonical(v[k])).join(",") + "}"
: JSON.stringify(v);
app.post("/webhooks/didit", express.json(), (req, res) => {
// Freshness: the signed body timestamp (refreshed on retry) must be recent
// and X-Timestamp must agree - the header alone is unsigned and replayable.
const ts = Number(req.body?.timestamp);
if (!ts || String(ts) !== req.headers["x-timestamp"] ||
Math.abs(Date.now() / 1000 - ts) > 300) return res.sendStatus(401);
const expected = crypto.createHmac("sha256", SECRET)
.update(canonical(req.body), "utf8").digest("hex");
const sig = String(req.headers["x-signature-v2"] ?? "");
const valid = sig.length === expected.length &&
crypto.timingSafeEqual(Buffer.from(sig), Buffer.from(expected));
if (!valid) return res.sendStatus(401);
const { status, decision } = req.body;
// One entry per ID Verification node; pick yours by node_id when you run several.
const [idv] = decision?.id_verifications ?? [];
// idv.verification_method: "document" | "id_lookup" | "wallet"
res.sendStatus(200);
});
Body fields you will use: session_id, status, webhook_type, workflow_id,
vendor_data, decision.
Status values: Approved, Declined, In Review, In Progress, Not Started,
Abandoned.
## 6. Reading the result
The decision is the V3 shape: every feature result is a plural array with one
entry per workflow node. ID Verification results live in
decision.id_verifications[] — there is no singular decision.kyc (that is the
V2 shape) and no decision.id_verification. Select your entry by node_id (the
id of your ID Verification node in the workflow graph); with a single ID step,
take index 0. Each entry carries, next to the document fields:
verification_method "document" | "id_lookup" | "wallet"
assurance "documentary" | "data_match" | "cryptographic"
wallet_provider the catalog wallet id the user signed in with; null
on document and id_lookup entries
wallet_verification provider, provider_name, issuing_authority,
issuing_country, credential_type, level_of_assurance
(low | substantial | high), verified_at,
signature_valid, attributes (what the wallet shared),
portrait when the wallet shares one; null otherwise
fallback_from { method, reason, action } when the session fell
back to document capture or was declined; else null
A wallet entry that succeeds is assurance cryptographic — the highest of the
three. Check wallet_verification.signature_valid before you trust attributes.
Field-by-field reference: https://docs.didit.me/reference/data-models#id-verification
## 7. Billing
- published customer prices in USD per completed wallet verification:
- MitID personal: $0.35; production availability: Coming soon
- BankID Sweden: $0.30; production availability: Coming soon
- BankID Norway High: $0.35; production availability: Coming soon
- Vipps Plus: $0.28; production availability: Coming soon
- Buypass ID: Coming soon; production availability: Coming soon
- itsme: Coming soon; production availability: Coming soon
- iDIN full identification: $0.85; production availability: Coming soon
- Finnish Trust Network: $0.30; production availability: Coming soon
- Personalausweis Profile 2: $0.45; production availability: Coming soon
- Freja eID: Coming soon; production availability: Coming soon
- UAE PASS: Coming soon; production availability: Coming soon
- gov.br: Coming soon; production availability: Coming soon
- OneID: Coming soon; production availability: Coming soon
- GOV.UK Wallet: Coming soon; production availability: Coming soon
- Smart-ID: Coming soon; production availability: Coming soon
- Mobile-ID: Coming soon; production availability: Coming soon
- Bank iD: Coming soon; production availability: Coming soon
- MojeID: Coming soon; production availability: Coming soon
- Diia: Coming soon; production availability: Coming soon
- FranceConnect: Coming soon; production availability: Coming soon
- Auðkenni: Coming soon; production availability: Coming soon
- EUDI Wallet: Coming soon; production availability: Coming soon
- an announced price does not enable a wallet; check the live workflow catalog
- wallet checks are outside the document free tier; other checks are billed separately
- full pricing: https://docs.didit.me/core-technology/id-verification/digital-id-wallets#pricing
- document capture bills its own price when the user falls back
## 8. Hard rules — do not change
- base URL for v3 endpoints: verification.didit.me
- auth header: x-api-key (lowercase, hyphenated)
- webhook headers: X-Signature-V2 plus X-Timestamp; canonical JSON, never
raw bytes; freshness from the signed body timestamp
- feature enum: OCR (uppercase) — the ID Verification feature; per-country
methods go under its config.methods
- method keys: document, id_lookup, wallet (lowercase, snake_case)
- wallet ids come from the catalog verbatim, lowercase, snake_case
- country keys: ISO 3166-1 alpha-3, uppercase
- result path: decision.id_verifications[] (array), never decision.kyc
## 9. Verify your integration
- run one session per accepted wallet in sandbox
- assert the id_verifications[] entry for your node has verification_method
wallet and wallet_verification.signature_valid true
- cancel a wallet sign-in and assert your on_failure setting actually fires
- assert your webhook accepts a correctly signed payload with reordered
keys, whitespace and integer-like metadata keys ("10" before "2"), and
rejects a wrong X-Signature-V2, a payload whose signed timestamp is older
than 300 seconds, and that same stale payload with only the X-Timestamp
header refreshed
Docs: https://docs.didit.me/integration/integration-prompt
متوافق حسب التصميم
افتح دولة جديدة بنقرة واحدة. نحن نقوم بالعمل الشاق.
نحن نفتح الشركات التابعة المحلية، ونؤمن التراخيص، ونجري اختبارات الاختراق، ونحصل على الشهادات، ونتوافق مع كل لائحة جديدة. لنشر عمليات التحقق في بلد جديد، ما عليك سوى تفعيل مفتاح. أكثر من 220 دولة تعمل، يتم تدقيقها واختبار اختراقها كل ربع سنة, المزود الوحيد للهوية الذي وصفته حكومة دولة عضو في الاتحاد الأوروبي رسميًا بأنه أكثر أمانًا من التحقق الشخصي.
الأسعار أدناه هي بالدولار الأمريكي لكل عملية تحقق مكتملة من المحفظة. تغطي هذه الأسعار منتج الهوية المذكور؛ ويتم احتساب فحوصات سير العمل الأخرى والوثائق الاحتياطية بشكل منفصل. لا تغطي فحوصات المستندات المجانية الشهرية البالغ عددها 500 محفظة الهوية. السعر المعلن لا يعني أن المحفظة متاحة حاليًا: يتم عرض التوفر بشكل منفصل. الأسعار غير المعلنة هي "قريبًا". محافظ الهوية تتحقق من الأشخاص؛ فحص محافظ العملات المشفرة هو منتج منفصل.