Identity standards explained
Behind every 'Sign in with…' button and every digital ID wallet there is a small number of open standards. This section explains what each one does, how they fit together, and why the protocols that carry the EU Digital Identity Wallet descend directly from the OpenID work of the late 2000s.
15 pages
In this section
Decentralized identifiers (DIDs): what they are and do
A DID is a W3C identifier you control without a central registry. How DID documents work, how they relate to credentials, and their role in the EUDI Wallet.
FIDO2 and WebAuthn explained: the standards behind passkeys
FIDO2 combines WebAuthn and CTAP to replace passwords with phishing-resistant key pairs. How login works, what WebAuthn Level 3 adds and its EU wallet link.
Identity federation explained: one login, many services
Identity federation lets one trusted provider vouch for you across many services. How it works, the standards it uses, and how the EUDI Wallet changes it.
mdoc and ISO 18013-5: how mobile IDs work
mdoc is the ISO format behind mobile driving licences and one of two EUDI Wallet formats. How ISO 18013-5 and 18013-7 work, and what stays private.
OAuth 2.0 explained: delegated access without passwords
OAuth 2.0 lets an app act for you at another service without your password. How the flow works, the main risks, OAuth 2.1 and where OAuth meets the EU wallet.
OpenID 2.0 explained: the original decentralised login
OpenID 1.x and 2.0 let you log in to websites with a URL you controlled. How discovery, delegation and providers worked, and why OpenID Connect replaced them.
OpenID Connect explained: login on top of OAuth 2.0
OpenID Connect (OIDC) lets an app verify who you are via a provider like Google. Learn the flow, the ID token, the risks and OIDC's place beside the EU wallet.
OpenID vs OAuth: authentication vs authorisation
OAuth decides what an app may access, OpenID Connect proves who signed in. See the differences in a table, a simple analogy and why mixing them up is risky.
OpenID4VCI explained: how credentials get into a wallet
OpenID for Verifiable Credential Issuance (OpenID4VCI) 1.0 brings credentials from issuers into a wallet. Roles, flow, security and its place in the EU wallet.
OpenID4VP explained: how a wallet presents credentials
OpenID for Verifiable Presentations (OpenID4VP) 1.0 is the protocol a wallet uses to show credentials to a service. Flow, roles, security and EU wallet role.
SAML explained: enterprise and university single sign-on
SAML 2.0 lets a company or university login unlock many services via XML assertions. How it works, where it is used, the risks and how it differs from OIDC.
SCIM explained: automatic user provisioning (RFC 7644)
SCIM is the standard that creates, updates and removes user accounts across apps automatically. How RFC 7643 and 7644 work, with examples, risks and its limits.
SD-JWT explained: selective disclosure tokens (RFC 9901)
SD-JWT lets you share only chosen claims from a signed credential, such as your age but not your name. How it works, where the EUDI Wallet uses it, its limits.
Verifiable credentials explained: digital proofs you control
Verifiable credentials are digitally signed statements you keep in a wallet and show on demand. Roles, flow, formats, risks and their role in the EU wallet.
What is a relying party? From OpenID to EUDI Wallet
A relying party is a service that relies on someone else to confirm who you are. How the term evolved from OpenID 2.0 to OpenID Connect and the EUDI Wallet.
Other sections
Digital identity in Europe
eIDAS 2.0, the EU Digital Identity Wallet, levels of assurance and qualified signatures, explained without the legal fog. What changes for citizens and for businesses.
Digital ID by country
How online identification works in every EU and EEA country, Switzerland, the UK and Turkey: the national eID, the wallet status, and how to get it.
Passkeys and login security
Passkeys, two-factor authentication, hardware keys and account recovery, explained step by step. How to make your accounts hard to take over without making them hard to use.
Reviews and comparisons
Independent comparisons of password managers, hardware security keys and authenticator apps, with a close look at where your data is stored and which providers are European.
History of open identity
From OpenID 1.0 and the European OpenID community of 2007 to OpenID Connect and the EU wallet: how the idea of a portable, user-controlled login developed.