From OpenID to the EU wallet: the road to user-controlled ID
OpenID promised to put users in charge of their identity in 2005. The EU Digital Identity Wallet is the state-backed attempt, built on OpenID4VP and OpenID4VCI.
HistoryPublished
In 2005 a developer built a way to log in to blogs without creating yet another account. In 2026 every EU member state is due to offer its citizens a digital identity wallet. The two have more in common than the shared word ‘identity’ suggests. This page follows the thread from one to the other.
The promise of 2005
The original OpenID idea was radical in its simplicity: you own an identifier, and you can prove it to any website, using whichever provider you trust. There was no central registry and no single company in charge. By 2007 the OpenID Authentication 2.0 specification was finished, and in 2008 a European community set out to promote it. Everything that followed is on the OpenID timeline.
The reality was less free. In practice a handful of providers issued most OpenIDs, each login went through a provider that could see where you signed in, and the identity was only as good as your account. OpenID could show that you controlled an account, not that you were a particular person. Why OpenID 2.0 faded lists the reasons it did not take off, and From OpenID to OpenID Connect describes the successor that powers social login today.
A different model: issuer, holder, verifier
The EU wallet starts from a different triangle. In the OpenID model there are three parties: the user, the provider and the website. In the wallet model there are also three, but the roles differ.
| OpenID 2.0 and OpenID Connect | EU Digital Identity Wallet | |
|---|---|---|
| Who holds the data | The provider’s account | The user’s wallet app |
| What the website receives | Proof of login, plus profile data the provider releases | Only the attributes the user chooses to present |
| Does the issuer see each use? | Yes, the provider takes part in every login | By design no, the issuer is not contacted when you present a credential |
| Backing | Private companies, no legal assurance level | Law: Regulation (EU) 2024/1183, with defined assurance levels |
| Main protocols | OpenID 2.0, then OpenID Connect | OpenID4VCI, OpenID4VP, ISO mdoc, SD-JWT |
The wallet’s credentials are issued once, by an authority or a trusted organisation, and then live on the device. When a service asks for proof of age, you can share ‘over 18’ without sharing a birth date, a technique known as selective disclosure. How well this protects against tracking depends on implementation, a subject covered in EUDI wallet privacy.
The protocols that connect the two
The most direct link is in the standards. The OpenID Foundation, which maintains OpenID Connect, also published the protocols that carry credentials in and out of wallets. OpenID for Verifiable Presentations 1.0, OpenID4VP, became a final specification on 9 July 2025. OpenID for Verifiable Credential Issuance 1.0, OpenID4VCI, followed on 16 September 2025. Both extend OAuth 2.0, the same base on which OpenID Connect is built, and support several credential formats, including the mobile documents of ISO 18013-5 and SD-JWT.
The EU’s technical rulebook for the wallet builds on these specifications. So the family tree is real: the 2005 idea of a user-chosen login became a login layer on OAuth, and the same OAuth groundwork now carries verified attributes. The OpenID Foundation publishes the full texts at openid.net.
The state of play in October 2026
Under Regulation (EU) 2024/1183, in force since 20 May 2024, every member state must make at least one wallet available by around the end of 2026. Acceptance duties for banks and very large online platforms follow about a year later, in December 2027. The status is uneven. Several countries run pilots or early apps, but certification of wallets lags in places. Our rollout timeline tracks it country by country. The official text is on EUR-Lex.
Where the old problems return
OpenID’s three big weaknesses are still on the table.
- Adoption by relying parties. A wallet is useless if few services ask for it. OpenID had this problem with no way to force acceptance. The EU answers with a legal duty for regulated services.
- Usability. OpenID asked for a typed URL. The wallet must make presenting a credential feel as easy as tapping a payment card. If it does not, people will fall back on passwords.
- Phishing. A fake site that asks for credentials is the wallet’s version of the fake OpenID provider page. The design answers with verifier registration and cryptographic checks, but users and services still have to behave correctly.
There is also a new problem: who is allowed to ask for what. A wallet lets users refuse unnecessary requests, but only if the interface shows clearly who is asking and why. The questions are developed in Five lessons from OpenID for the EU wallet.
What changes for ordinary users
For most people the difference will show up in small moments rather than in protocols. Opening a bank account, proving you are over 18 or confirming a registered address could become a matter of approving a request on your phone, instead of uploading a scan of an ID card or creating yet another account. The promise is less data handed over and fewer copies of your documents stored in places you cannot see. The risk is the one OpenID knew: if the experience is clumsy or services ask for too much, the habit will not form. That is why the details of the interface matter as much as the cryptography.
What to take away
OpenID was an attempt to give users control of their identity without a state or a platform in the middle. The EU wallet is an attempt to do it with a state vouching for the credentials. Neither is perfect. If you want to know how to use the new system, start with the EU Digital Identity Wallet.
Specification dates are from the OpenID Foundation and the legal dates from EUR-Lex; status as of October 2026.
More in History
Clavid 2008: Switzerland's first OpenID identity provider
Clavid, a Swiss OpenID provider, added smart cards, YubiKey, fingerprints and client certificates in 2008. What it built, why it mattered and what became of it.
Facebook Connect vs OpenID: how social login won
Facebook Connect arrived in 2008 as OpenID was gaining support. Why a single branded button beat an open standard, and what social login costs users today.
From Microsoft Passport to passkeys: 25 years of SSO
From Microsoft Passport and the Liberty Alliance to OpenID, social login, FIDO2 and passkeys: how the dream of one safe login for everything changed form.
Google and Windows Live ID open up to OpenID, October 2008
In late October 2008 Microsoft previewed an OpenID provider for Windows Live ID and Google announced limited provider support. What each did and did not offer.
Google, IBM, Microsoft, Yahoo join the OpenID Foundation
On 7 February 2008 Google, IBM, Microsoft, VeriSign and Yahoo became corporate board members of the OpenID Foundation. What it meant and how to read the data.
Jabber.org and OpenID in 2008: XMPP meets web login
In March 2008 the Jabber.org website began accepting OpenID logins. What that meant for open instant messaging, and what became of Jabber.org since.