Lass Leute sich mit ihrer vorhandenen ID anmelden.
Verifiziere Personen mit einer elektronischen Identität (eID), die sie bereits nutzen. Akzeptiere Smart-ID, Mobile-ID, Finnish Trust Network und MitID über einen einzigen Workflow, bei Bedarf mit Dokumenten-Fallback.
EUDI Wallet30 EU- und EWR-Länder · The user's own member state; the issuer differs per country+26Bald
Die Status unterscheiden die Produktionsverfügbarkeit von Integrationstests. Die Länderabdeckung beschreibt die konfigurierte Wallet-Route, nicht eine abgeschlossene Live-Identitätsprüfung in jedem Land. Es wird kein Startdatum versprochen.
Integrationsstatus
Digitale ID-Wallets. Klarer Rollout-Status.
Smart-ID, Mobile-ID, Finnish Trust Network und MitID sind verfügbar. Wähle akzeptierte Wallets nach Land aus und lass Nutzer sich mit einer berechtigten Identität authentifizieren, die sie bereits besitzen. Andere gelistete Integrationen sind noch in Vorbereitung.
So funktioniert's
Vom Wallet-Login zum verifizierten Nutzer in vier Schritten.
Schritt 01 / 04
01
Workflow erstellen
Wähle in der Konsole die für jedes Land in deiner Umgebung verfügbaren Wallets aus. Lege fest, ob ein abgebrochener oder fehlgeschlagener Login auf die Dokumentenerfassung zurückfällt oder abgelehnt wird.
Integrieren
Bette nativ mit unseren Web-, iOS-, Android-, React Native- oder Flutter-SDKs ein. Leite auf eine gehostete Seite weiter. Oder sende deinem Nutzer einfach einen Link – per E-Mail, SMS, WhatsApp, überall.
Nutzer durchläuft den Flow
Für Smart-ID gib den persönlichen Code ein. Für Mobile-ID gib den persönlichen Code und die Telefonnummer ein. Vergleiche den von Didit angezeigten Code mit dem Code auf deinem Telefon und bestätige dann auf deinem Gerät. Deine PIN bleibt auf deinem Telefon.
Du erhältst die Ergebnisse
Echtzeit-signierte Webhooks halten deine Datenbank synchron, sobald ein Nutzer genehmigt, abgelehnt oder zur Überprüfung gesendet wird. Frage die API bei Bedarf ab. Oder öffne die Konsole und lies die signierten Attribute.
Für Entwickler gemacht · Gegen Betrug gebaut · Offen im Design
Sechs Funktionen. Eine Akzeptanzliste pro Land.
Ein Wallet ist eine Methode innerhalb der ID-Verifizierung, mit demselben Ergebnisvertrag wie die Dokumentenerfassung. Was sich ändert, ist der Nachweis: eine Signatur des Ausstellers anstelle eines Fotos.
Akzeptiere die Wallets, die ein Land wirklich nutzt.
Sieh dir jedes Wallet, die Länderabdeckung, die ausstellende Behörde und die Verfügbarkeit auf einen Blick an. Smart-ID, Mobile-ID, Finnish Trust Network und MitID sind verfügbar; geplante Integrationen sind deutlich als „Demnächst verfügbar“ gekennzeichnet.
Wallet-Katalog
Direkt aus dem Methoden-Katalog
23
Im Katalog
35
Abgedeckte Länder
10
eIDAS hoch
MitIDLive
BankIDLive
BankIDBald
VippsBald
Buypass IDBald
02 · Akzeptanzliste
Wähle, was du akzeptierst. Der Nutzer entscheidet.
Wähle aus, welche verfügbaren Wallets du pro Land in deinem Workflow akzeptieren möchtest. Der Nutzer wählt aus dieser Menge. Ein als „coming soon“ gelistetes Wallet kann erst aktiviert werden, wenn der Katalog in deiner Umgebung es als verfügbar kennzeichnet.
Akzeptanzliste für Norwegen
Keine Sortieroptionen
BankIDBald
VippsBald
Buypass IDBald
EUDI WalletBald
Anklicken ist die gesamte Konfiguration. Der Nutzer wählt aus, was du akzeptierst, und die Reihenfolge auf dem Bildschirm hat keine Bedeutung. Jedes Wallet behält seinen Katalogstatus, bis es live geht.
03 · Die Übergabe
Vergleiche den Code. Bestätige auf deinem Telefon.
Smart-ID verwendet deinen persönlichen Code; Mobile-ID fragt zusätzlich nach deiner Telefonnummer. Didit zeigt einen Vergleichscode an, während du die Anfrage auf deinem Gerät bestätigst. Deine PIN wird niemals bei Didit eingegeben. Abbruch und Fehler folgen deiner Workflow-Fallback-Einstellung.
Die Übergabe
Smart-ID und Mobile-ID Flow
1Gib deinen persönlichen Code ein
2Vergleiche den Code und bestätige auf deinem Telefon
3Rückkehr mit verifizierten Identitätsattributen
Kein Wallet, abgebrochen oder fehlgeschlagenDokument
04 · Signierte Attribute
Lies Attribute, die der Aussteller signiert hat.
Name, Geburtsdatum und die nationale Kennung, die das Wallet preisgibt, plus die signierte Bestätigung selbst. Deaktiviere jedes optionale Attribut, das du nicht speichern möchtest, und es wird niemals in die Session geschrieben.
Signierte Attribute
MitID · Danish Agency for Digital Government
Full nameImmer
Date of birthImmer
CPR alias (pseudonymised)Immer
Level of assurance reachedImmer
Signed assertionImmer
Aussteller-SignaturGültig
05 · Sicherheit
Erreiche die höchste der drei Sicherheitsstufen.
Ein Dokument gibt dir dokumentarische Sicherheit. Ein Registerabgleich gibt dir einen Datenmatch. Ein Wallet gibt dir kryptografische Sicherheit, weil der Aussteller die Attribute signiert hat und Didit diese Signatur prüft.
Assurance-Stufen
Nur für Admin-Oberflächen
DokumentenbasiertDokumentenerfassung
DatenabgleichRegisterabfrage
KryptografischWallet-Login
Endnutzer sehen niemals ein Assurance-Label, einen Quellnamen oder einen Preis. Deine Prüfer sehen alle drei.
06 · Reichweite
Smart-ID und Mobile-ID Länderabdeckung.
Akzeptiere Smart-ID in Estland, Lettland, Litauen und Belgien; Mobile-ID in Estland und Litauen; und Finnish Trust Network in Finnland. Nutzer authentifizieren sich mit einem berechtigten Credential für das ausgewählte Wallet.
Verfügbarkeit im Katalog
Länder mit mindestens einer Wallet
35
Länder
30
Abgedeckt durch die EUDI Wallet
Die Abdeckung folgt dem Katalog Land für Land. Eine Flagge hier bedeutet, dass eine Wallet für dieses Land gelistet ist, nicht dass sie live ist.
Integrieren
Ein Aufruf. Ein signiertes Ergebnis zurück.
Erstelle die Session, leite den Nutzer dorthin und verifiziere den signierten Webhook, wenn das Ergebnis eintrifft. Das Wallet, mit dem sich der Nutzer angemeldet hat, wird im Ergebnis zurückgegeben.
// Your endpoint receives a signed payloadconst crypto = require("node:crypto"); // ESM: import crypto from "node:crypto"// X-Signature-V2 = HMAC over the canonical JSON, never the raw bytes. Match the sender byte for// byte: keys sorted by code point, integers digit for digit, floats in Python's repr.class Num { constructor(src) { this.src = src; } } // a number as written on the wire, not a doubleconst num = (s) => { if (/^-?\d+$/.test(s)) return BigInt(s).toString(); const n = +s; // ints stay exactif (Number.isInteger(n)) return BigInt(n).toString(); const [m, e] = n.toExponential().split("e"); // 27.0 -> 27return +e >= -4 ? String(n) : `${m}e-${String(-e).padStart(2, "0")}`; }; // 1e-05, not 0.00001const byCodePoint = (a, b) => Buffer.compare(Buffer.from(a), Buffer.from(b)); // UTF-8 order = Python'sconst canon = (v) => Array.isArray(v) ? `[${v.map(canon)}]` : v instanceof Num ? num(v.src)
: v && typeof v === "object" ? `{${Object.keys(v).sort(byCodePoint).map((k) => `${JSON.stringify(k)}:${canon(v[k])}`)}}`
: JSON.stringify(v);
// Read the body as text: express.json() would round 1000000000000000129 to a double first.// Register this route ABOVE any global app.use(express.json()): the first parser to run// consumes the stream, and a body it already parsed has lost the digits the signature covers.
app.post("/webhooks/didit", express.text({ type: "application/json" }), (req, res) => {
const exact = JSON.parse(req.body, (k, v, c) => typeof v === "number" ? new Num(c.source) : v); // Node 21+const body = JSON.parse(req.body);
const mac = crypto.createHmac("sha256", SECRET).update(canon(exact), "utf8").digest("hex");
const sig = Buffer.from(String(req.headers["x-signature-v2"] ?? ""));
// Freshness comes from the signed body timestamp; the header alone is unsigned and replayable.const ts = body.timestamp, fresh = String(ts) === req.headers["x-timestamp"]
&& Math.abs(Date.now() / 1000 - ts) <= 300;
if (!fresh || sig.length !== mac.length
|| !crypto.timingSafeEqual(sig, Buffer.from(mac))) return res.sendStatus(401);
const { status, decision } = body;
// One entry per ID Verification node; pick yours by node_id when you run several.const [idv] = decision?.id_verifications ?? [];
// idv.verification_method: "document" | "id_lookup" | "wallet"
res.sendStatus(200);
});
Füge den folgenden Block in Claude Code, Cursor, Codex, Devin, Aider oder Replit Agent ein. Ersetze den Platzhalter `my_stack` durch dein Framework, deine Sprache und deinen Anwendungsfall. Der Agent richtet Didit ein, akzeptiert die Wallets pro Land, verbindet den Webhook und geht live.
didit-integration-prompt.md
# Didit digital ID wallets — integrate in 5 minutes
You are adding digital ID wallet sign-in to my_stack. The user signs in with a
government or bank digital identity and the wallet returns signed attributes.
Every URL, header, and enum value below is canonical — do not paraphrase or
"improve" them.
## 1. Provision an account
- Sign up: https://business.didit.me (no credit card required).
- Grab the API key for your application from the console.
## 2. Read the methods catalog first
Wallet availability is server-driven per country. Never hard-code a wallet list.
The catalog is not a public REST endpoint. Read it one of two ways:
- Business Console (signed in): your application -> ID Verification ->
Countries tab. https://docs.didit.me/console/id-verification-methods
- Didit MCP server tool didit_workflow_get_id_verification_methods_catalog,
authenticated with the same x-api-key; pass country (ISO 3166-1 alpha-3)
to narrow it to one country. https://docs.didit.me/integration/mcp/tools
- Public mirror of the coverage table (no auth, read-only):
https://docs.didit.me/core-technology/id-verification/verification-methods#coverage
The catalog gives you, per wallet id: the display name, the countries it
covers, the issuing authority, the level of assurance, the availability state,
and the attributes it returns. MitID, Smart-ID, Mobile-ID and Finnish Trust
Network are available. Read the Finnish Trust Network integration guide:
https://docs.didit.me/core-technology/id-verification/finnish-trust-network
iDIN and other wallets remain coming soon until the catalog in
your environment marks them available. Re-read it; do not hard-code a date.
## 3. Create a workflow with the ID Verification (OCR) feature
POST https://verification.didit.me/v3/workflows/
-H "x-api-key: <your-api-key>"
-H "Content-Type: application/json"
The ID Verification feature's enum value is OCR (UPPERCASE — strict enum;
there is no ID_VERIFICATION alias and the API rejects it). Wallets are its
wallet method, accepted per country under config.methods on that same
feature entry, in the same request. Keys are ISO 3166-1 alpha-3.
{
"workflow_label": "Wallet onboarding",
"features": [
{
"feature": "OCR",
"config": {
"methods": {
"DNK": {
"document": { "enabled": true },
"wallet": {
"enabled": true,
"providers": ["mitid"],
"on_failure": "fallback_to_document"
}
},
"FIN": {
"document": { "enabled": true },
"wallet": {
"enabled": true,
"providers": ["ftn"],
"on_failure": "fallback_to_document"
}
}
}
}
}
]
}
Response: the workflow uuid — use it as workflow_id in step 4.
Rules that the API enforces:
- providers is an accept-list, not a ranking. Order carries no meaning and
the end user picks
- on_failure is either fallback_to_document or decline. It covers all three
cases: no wallet, cancelled, sign-in failed
- a wallet id the catalog does not mark available for that country is
rejected, and the rejection fails the whole save — including any lookup
configuration next to it. For unavailable wallets, keep wallet.enabled
false (or omit the wallet block) so the save succeeds
- unknown wallet ids already saved on a workflow are preserved untouched, so
a config written by a newer console version is never silently dropped
- a country with no method enabled is rejected at publish time
## 4. Create a session
POST https://verification.didit.me/v3/session/
-H "x-api-key: <your-api-key>"
-H "Content-Type: application/json"
-d '{ "workflow_id": "<id from step 3>", "vendor_data": "<your user id>" }'
Response: 201 with url (the hosted verification link), session_token and
session_id. Redirect the user to url, or open it in the SDK. The field is
named url — there is no session_url and no verification_url. Didit
shows the accepted wallets for the user's country with their brand marks,
hands off to the wallet, and waits for the signed assertion to come back.
## 5. Webhooks
Register a destination (console -> API & Webhooks, or
POST https://verification.didit.me/v3/webhook/destinations/ with
webhook_version "v3" and subscribed_events ["status.updated"]) and store the
secret_shared_key it returns. Verify every delivery:
Header: X-Signature-V2 (NOT X-Signature, NOT X-Signature-Simple)
Algorithm: HMAC-SHA256, hex digest, over the CANONICAL JSON of the payload
— the sender's Python json.dumps(sort_keys=True,
separators=(",", ":"), ensure_ascii=False) after whole-valued
floats become ints. Reproduce those bytes EXACTLY; do NOT
"parse, sort keys, JSON.stringify", which fails in four ways:
numbers come from the wire TEXT, never from parsed doubles
(read the body with express.text, not express.json(),
registered ABOVE any global app.use(express.json()), and
re-emit integers through BigInt(source) — JSON.parse rounds
1000000000000000129); floats use Python's repr (1e-05, not
0.00001; 27.0 becomes 27); keys sort by Unicode CODE POINT as
strings ("10" before "2", U+FF21 before U+1F642, which
JavaScript's default .sort() reverses); and the bytes come
straight from the sorted entries, never from a rebuilt object.
Do NOT hash the raw request bytes — that is the v1
X-Signature algorithm and fails for V2 whenever whitespace or
key order differs from the canonical form.
Freshness: the signed body field timestamp is the dispatch time (Unix
seconds, refreshed on every retry). Reject when
abs(now - timestamp) > 300 seconds, and reject when the
X-Timestamp header does not equal it. The header is not
covered by the signature, so it must never be the only replay
check: a captured delivery replays with just that header
refreshed.
Compare: constant-time (crypto.timingSafeEqual)
Reference handler (Express) — use it as written:
// Your endpoint receives a signed payload
const crypto = require("node:crypto"); // ESM: import crypto from "node:crypto"
// X-Signature-V2 = HMAC over the canonical JSON, never the raw bytes. Match the sender byte for
// byte: keys sorted by code point, integers digit for digit, floats in Python's repr.
class Num { constructor(src) { this.src = src; } } // a number as written on the wire, not a double
const num = (s) => { if (/^-?\d+$/.test(s)) return BigInt(s).toString(); const n = +s; // ints stay exact
if (Number.isInteger(n)) return BigInt(n).toString(); const [m, e] = n.toExponential().split("e"); // 27.0 -> 27
return +e >= -4 ? String(n) : `${m}e-${String(-e).padStart(2, "0")}`; }; // 1e-05, not 0.00001
const byCodePoint = (a, b) => Buffer.compare(Buffer.from(a), Buffer.from(b)); // UTF-8 order = Python's
const canon = (v) => Array.isArray(v) ? `[${v.map(canon)}]` : v instanceof Num ? num(v.src)
: v && typeof v === "object" ? `{${Object.keys(v).sort(byCodePoint).map((k) => `${JSON.stringify(k)}:${canon(v[k])}`)}}`
: JSON.stringify(v);
// Read the body as text: express.json() would round 1000000000000000129 to a double first.
// Register this route ABOVE any global app.use(express.json()): the first parser to run
// consumes the stream, and a body it already parsed has lost the digits the signature covers.
app.post("/webhooks/didit", express.text({ type: "application/json" }), (req, res) => {
const exact = JSON.parse(req.body, (k, v, c) => typeof v === "number" ? new Num(c.source) : v); // Node 21+
const body = JSON.parse(req.body);
const mac = crypto.createHmac("sha256", SECRET).update(canon(exact), "utf8").digest("hex");
const sig = Buffer.from(String(req.headers["x-signature-v2"] ?? ""));
// Freshness comes from the signed body timestamp; the header alone is unsigned and replayable.
const ts = body.timestamp, fresh = String(ts) === req.headers["x-timestamp"]
&& Math.abs(Date.now() / 1000 - ts) <= 300;
if (!fresh || sig.length !== mac.length
|| !crypto.timingSafeEqual(sig, Buffer.from(mac))) return res.sendStatus(401);
const { status, decision } = body;
// One entry per ID Verification node; pick yours by node_id when you run several.
const [idv] = decision?.id_verifications ?? [];
// idv.verification_method: "document" | "id_lookup" | "wallet"
res.sendStatus(200);
});
Body fields you will use: session_id, status, webhook_type, workflow_id,
vendor_data, decision.
Status values: Approved, Declined, In Review, In Progress, Not Started,
Abandoned.
## 6. Reading the result
The decision is the V3 shape: every feature result is a plural array with one
entry per workflow node. ID Verification results live in
decision.id_verifications[] — there is no singular decision.kyc (that is the
V2 shape) and no decision.id_verification. Select your entry by node_id (the
id of your ID Verification node in the workflow graph); with a single ID step,
take index 0. Each entry carries, next to the document fields:
verification_method "document" | "id_lookup" | "wallet"
assurance "documentary" | "data_match" | "cryptographic"
wallet_provider the catalog wallet id the user signed in with; null
on document and id_lookup entries
wallet_verification provider, provider_name, issuing_authority,
issuing_country, credential_type, level_of_assurance
(low | substantial | high), verified_at,
signature_valid, attributes (what the wallet shared),
portrait when the wallet shares one; null otherwise
fallback_from { method, reason, action } when the session fell
back to document capture or was declined; else null
A wallet entry that succeeds is assurance cryptographic — the highest of the
three. Check wallet_verification.signature_valid before you trust attributes.
Field-by-field reference: https://docs.didit.me/reference/data-models#id-verification
## 7. Billing
- published customer prices in USD per completed wallet verification:
- MitID personal: $0.25; production availability: Available
- BankID Sweden: $0.20; production availability: Available
- Finnish Trust Network: $0.25; production availability: Available
- Smart-ID: $0.20; production availability: Available
- Mobile-ID: $0.20; production availability: Available
- BankID Norway High: $0.35; production availability: Coming soon
- Vipps Plus: $0.25; production availability: Coming soon
- Buypass ID: Coming soon; production availability: Coming soon
- itsme: Coming soon; production availability: Coming soon
- iDIN full identification: $0.85; production availability: Coming soon
- Personalausweis Profile 2: $0.45; production availability: Coming soon
- Freja eID: $0.25; production availability: Coming soon
- UAE PASS: Coming soon; production availability: Coming soon
- gov.br: Coming soon; production availability: Coming soon
- OneID: $2.50; production availability: Coming soon
- GOV.UK Wallet: Coming soon; production availability: Coming soon
- Bank iD: Coming soon; production availability: Coming soon
- MojeID: Coming soon; production availability: Coming soon
- Diia: Coming soon; production availability: Coming soon
- FranceConnect: Coming soon; production availability: Coming soon
- Auðkenni: Coming soon; production availability: Coming soon
- ConnectID: Coming soon; production availability: Coming soon
- EUDI Wallet: Coming soon; production availability: Coming soon
- Estonian ID-card: Coming soon; production availability: Coming soon
- eParaksts: Coming soon; production availability: Coming soon
- an announced price does not enable a wallet; check the live workflow catalog
- wallet checks are outside the document free tier; other checks are billed separately
- full pricing: https://docs.didit.me/core-technology/id-verification/digital-id-wallets#pricing
- document capture bills its own price when the user falls back
## 8. Hard rules — do not change
- base URL for v3 endpoints: verification.didit.me
- auth header: x-api-key (lowercase, hyphenated)
- webhook headers: X-Signature-V2 plus X-Timestamp; canonical JSON, never
raw bytes; freshness from the signed body timestamp
- feature enum: OCR (uppercase) — the ID Verification feature; per-country
methods go under its config.methods
- method keys: document, id_lookup, wallet (lowercase, snake_case)
- wallet ids come from the catalog verbatim, lowercase, snake_case
- country keys: ISO 3166-1 alpha-3, uppercase
- result path: decision.id_verifications[] (array), never decision.kyc
## 9. Verify your integration
- run one session per accepted wallet in sandbox
- assert the id_verifications[] entry for your node has verification_method
wallet and wallet_verification.signature_valid true
- cancel a wallet sign-in and assert your on_failure setting actually fires
- assert your webhook accepts a correctly signed payload with reordered
keys, whitespace and integer-like metadata keys ("10" before "2"), and
rejects a wrong X-Signature-V2, a payload whose signed timestamp is older
than 300 seconds, and that same stale payload with only the X-Timestamp
header refreshed
Docs: https://docs.didit.me/integration/integration-prompt
Compliant by Design
Ein neues Land mit einem Klick erschließen. Wir machen die Arbeit.
Wir gründen lokale Tochtergesellschaften, sichern Lizenzen, führen Penetrationstests durch, erhalten Zertifizierungen und passen uns jeder neuen Regulierung an. Um Verifizierungen in einem neuen Land zu starten, legst du einfach einen Schalter um. Über 220 Länder live, vierteljährlich auditiert und Pen-getestet, der einzige Identitätsanbieter, den eine EU-Mitgliedsregierung offiziell als sicherer als die persönliche Verifizierung eingestuft hat.
Die unten angegebenen Preise sind in USD pro erfolgreich abgeschlossener Wallet-Verifizierung. Sie decken das genannte Identitätsprodukt ab; andere Workflow-Checks und Dokumenten-Fallback werden separat abgerechnet. Die 500 kostenlosen monatlichen Dokumenten-Checks decken keine Wallets ab. Ein angekündigter Preis bedeutet nicht, dass ein Wallet live ist: Die Verfügbarkeit wird separat angezeigt. Verfügbare Wallets ohne veröffentlichten Preis zeigen „Auf Anfrage“ an; geplante Wallets ohne veröffentlichten Preis zeigen „Demnächst verfügbar“ an. Identity Wallets verifizieren Personen; die Überprüfung von Krypto-Wallets ist ein separates Produkt.
„Verfügbar“ bedeutet, dass es in der Produktion aktiviert ist. „Demnächst verfügbar“ bedeutet, dass es noch nicht in der Produktion aktiviert ist, auch wenn Integrationstests bereits begonnen haben. Verfügbare Wallets werden zuerst angezeigt.
ConnectID (Australien) ist für Sandbox-Tests integriert; der Produktionszugang ist noch in Arbeit. Estnische ID-Karte (Estland) und eParaksts (Lettland) sind weiterhin als Integrationen geplant. Für diese Wallets gibt es keine veröffentlichten Preise oder Produktionsstarttermine.
Kostenlos starten. Nach Verbrauch zahlen. Bis zum Enterprise-Level skalieren.
500 kostenlose Verifizierungen jeden Monat, für immer. Danach zahlst du nur, wenn ein Modul läuft. Individuelle Verträge, Datenresidenz und Service Level Agreements (SLAs) für Enterprise-Kunden.
Kostenlos
$0/ Monat · keine Kreditkarte nötig
Zum Entwickeln, Testen und für deine ersten Nutzer.
Alles, was du für den Start brauchst:
500 vollständige KYC-Verifizierungen pro Monat
ID, Liveness, Face Match, Gerät & IP
Über 200 Betrugssignale, Blocklist, Duplikate
Wiederverwendbares KYC im Didit-Netzwerk
Workflow Builder, Case Management, SDKs
KI-SupportKI-Agent in der Konsole, Docs und Community.