E-Wallet

A digital wallet for electronic documents — Wallet Building Block for the GovStack initiative

#GovTech Case Study2026
E-Wallet

E-Wallet

AMEDIA turns the experience of a country that scaled digital documents to tens of millions of users into a product another state can run as its own: a working starting point instead of development from scratch, vendor independence through open standards, and alignment with international expectations.

01 — OVERVIEW

A digital wallet for electronic documents, run by a state as its own

E-Wallet is a native Android and iOS application that lets a person receive a digital document from a trusted issuer, store it locally on their own device, and present it to a verifier — online or offline — disclosing only the attributes a particular check requires.

The product is built on the open-source code and design system of the Diia mobile app, adapted to GovStack's architectural requirements, security standards and UI/UX guidance, and aligned with the EUDI Wallet model. It ships as a brand-neutral open-source solution, ready to be adapted to any country's national context.

What the product is worth

Documents live on their own phone, not in someone else's database. They can be presented without an internet connection, and show exactly what is actually being asked for: age without a date of birth, a driving entitlement without a home address. Nobody keeps a log of who checked you and when.

From day one the state owns a product rather than commissioning development: the most expensive and most dangerous stage — a year of building a wallet from scratch — is already behind it. The code, design system, documentation and test-confirmed scenarios can be read, audited and carried forward in-house.

FOR THE PERSONFOR THE STATE

From day one the state owns a product rather than commissioning development: the most expensive and most dangerous stage — a year of building a wallet from scratch — is already behind it. The code, design system, documentation and test-confirmed scenarios can be read, audited and carried forward in-house.

What E-Wallet changes

The first connection is an integration. Every one after it is configuration: a new document is described by a data schema, a visual template and validation rules. An agency that joins the programme a year later goes to production in weeks, with no separate budget cycle and no separate store release.

One application serves every agency and every document type: a new agency connects through configuration. The platform pays for itself not on the first document but on a portfolio.

FROM PROJECT TO CONFIGURATIONTHE STATE GETS A PLATFORM, NOT A SERVICE

One application serves every agency and every document type: a new agency connects through configuration. The platform pays for itself not on the first document but on a portfolio.

Five things the product changes

The nature of the risk changes

Instead of «will we build a digital wallet at all», the state answers «how fast can we roll it out». An existential project risk turns into a manageable deployment risk, with a predictable timeline and budget.

Control stays with the state

Keys, the trust registry, the issuer catalogue and verification policies all stay on the state's side. The supplier neither owns the ecosystem nor becomes a point of failure.

Trust without an online registry

Verification rests on the issuer's cryptographic signature, not on a registry being reachable at the moment of the check. A document verifies offline: at a border crossing, in transport, during a blackout, during a DDoS attack on government resources.

The state stops over-disclosing

Selective disclosure proves a fact without showing the document: age of majority without a date of birth, a driving entitlement without a home address. There is no central log of who checked whom and when — and therefore no asset that can be leaked or turned into a surveillance tool.

Open standards define the ecosystem

Every exchange is built on open specifications alone — OpenID4VCI and OpenID4VP, ISO/IEC 18013-5, SD-JWT VC and mso_mdoc, on a course towards eIDAS 2.0. Any issuer or verifier supporting the same specifications connects without a separate integration project, the country's documents can be accepted beyond its borders, and changing supplier does not cost the replacement of the whole ecosystem.

02 — WHO IT'S FOR

Five roles in the digital document ecosystem

The primary audience is governments introducing or modernising digital documents. The product accounts for the needs of every participant in the ecosystem:

Governments and ministries

A ready reference wallet that can serve as the basis of a national solution, with no need to build a mobile app from scratch.

Document issuers

A client side that works correctly with a standard OpenID4VCI issuer, including deferred and multi-document issuance.

Verifiers

Predictable wallet behaviour during remote and proximity checks, with selective disclosure and trust verification.

Document holders

A simple, clear interface based on proven Diia experience, and full control over what is shared and with whom.

Integrators and vendors

A modular codebase with a single integration boundary for the cryptographic engine and documentation for deployment.

03 — THE PROBLEM IT SOLVES

Digital identity is missing a trustworthy wallet on the user's side

Without one, privacy, data control and international interoperability aren't possible: citizens are forced to share more personal data than necessary, and governments have to build verification services from scratch. The product removes five concrete barriers:

Cost and time to entry

Building a digital wallet from scratch takes years and a significant budget. E-Wallet provides a working open-source starting point.

Fragmentation and vendor lock-in

Proprietary solutions aren't interoperable. Here every external interaction is built on open specifications, and the cryptographic engine is replaceable.

Distrust of data sharing

Users often cannot see what is actually being shared. Before every exchange, the list of attributes is shown and can be narrowed by hand.

Dependence on connectivity

Proximity presentation works without internet — critical for checks in the field, in transport and at borders.

Risk of device loss

Data is stored locally only; after three failed sign-in attempts the wallet locks and local data is wiped.

04 — KEY FUNCTIONALITY

The full lifecycle of a digital document

Initialization and access

A 6-digit passcode, optional biometrics (Face ID / Touch ID on iOS, face or fingerprint unlock on Android) with the code as the primary factor; lockout and data wipe after three failed attempts.

Receiving documents

Issuance initiated by the user or the issuer (QR code or deep link), confirmation via transaction code, deferred issuance with Pending status, and multi-document issuance.

Viewing and managing

A document card with key attributes, a full-detail screen, switching and reordering cards, valid / expired / revoked status, and deletion with confirmation.

Presenting data

Remote (verifier QR, OpenID4VP) and proximity (QR device engagement + Bluetooth LE, works offline). Sharing from several documents in one request is supported.

Selective disclosure

A request screen listing the attributes the verifier asks for, the option to deselect any of them, and confirmation by code or biometrics; declining shares nothing.

Transaction log

A chronological list of operations with status, time and counterparty; after a document is deleted, only metadata without personal data remains.

05 — HOW THE PRODUCT WORKS

The issuer issues, the wallet stores, the verifier checks

The product implements the classic triangle of trust. The verifier does not contact the issuer on every check: trust is established through the document's cryptographic signature and certificate validation against configured root trust anchors.

1

Issuance

Issuer metadata discovery · OAuth 2.0 authorization with PAR · key possession proof · receipt of the signed document · storage in secure storage.

2

Deferred issuance

The issuer accepts the request, the document is marked Pending, and the wallet polls the endpoint and activates the document as soon as it becomes available.

3

Remote presentation

Request received · verifier certificates checked · attribute list shown · consent · the signed presentation is sent to the response_uri.

4

Proximity presentation

QR for device engagement · exchange over Bluetooth LE per ISO/IEC 18013-5 · consent · transfer. Works without internet.

5

Revocation and expiry

A background service reconciles statuses against the issuer's lists; invalid documents are flagged and cannot be presented.

Participants in the exchange

Credential Holder

Initiates actions and gives consent; every critical operation requires the passcode or biometrics.

E-Wallet

Requests and receives documents, stores them locally, verifies counterparty trust and builds the verifiable presentation.

Credential Issuer

Signs and issues documents, publishes metadata and status lists for revocation checks.

Credential Verifier

Builds the data request and verifies the signature and integrity of the presentation received.

Trust Registry / Trust Anchor

The source of root certificates against which issuer and verifier are validated.

Wallet Provider

Issues attestation of the wallet instance and its keys during issuance.

06 — AUTOMATION

Background automation instead of artificial intelligence

The product contains no AI components or recommendation mechanics — a deliberate decision for an application handling identity documents. Instead, it implements a set of background automations:

Automatic trust verification

Issuer certificates are checked before a document is received, verifier certificates before any data is shared. On a mismatch, the process stops.

Background status monitoring

A service reconciles documents against the issuer's status lists; expired and revoked documents are flagged automatically and blocked from presentation.

Deferred-issuance polling

The wallet checks document readiness on a schedule and when the user returns to the app's main screen, then activates it and notifies the user.

Matching documents to a request

The wallet determines which stored documents and attributes match the verifier's request and presents a ready list for confirmation.

Automatic data wipe

Three failed sign-in attempts or signing out remove all local documents and transactions with no manual action.

07 — STATISTICS AND SCALE

The scope of what was built

100%success rate across 77+ test scenarios
2platforms: Android 8.0+ and iOS 16.2+
10+technical documents
2document types: PID and mDL
2formats: mso_mdoc and SD-JWT VC
37 / 15+independent modules in the codebase (iOS / Android)
7automated business processes

Market context

24M users of the Diia app — the practice the product's UX is grounded in (Ministry of Digital Transformation, May 2026)

800M people without official proof of identity and ~2.8B without access to digital ID (World Bank, ID4D, 2025)

27 EU member states must offer at least one digital wallet by the end of 2026 (eIDAS 2.0)

20+ countries were applying the GovStack approach and Building Blocks as of the end of 2025

08 — PRODUCT ADVANTAGES

A ready foundation, open standards, privacy by default

Platform and adoption

Alignment with GovStack*

Developed against Level 1 of the Wallet Building Block specification — core wallet functionality plus the key security, privacy and interoperability requirements.

Shorter time to market

A state starts from a working application and a full documentation set instead of a blank page.

International interoperability

A document issued on Android is presented on iOS and vice versa — in the same infrastructure, under the same protocols and trust rules.

No vendor lock-in

Open standards on every external interaction; the cryptographic engine is replaceable without rewriting the functional modules.

White-label readiness

Shipped without state symbols; trust anchors and the issuer catalogue are configurable without changing the core logic. One codebase, different countries and brands.

Privacy, transparency and resilience

Privacy by default

Local storage, selective disclosure, and no centralized tracking of user activity.

Unobservability

The issuer never learns to whom or when a document it issued was presented.

Transparency for the user

The transaction log records issuance, presentation and deletion with status, time and counterparty — locally, with no centralized collection.

Works offline

Proximity presentation requires no internet, either on the wallet side or during the check.

Open source

Full transparency of the implementation, and the ability to audit it, extend it and carry it forward in-house.

09 — INTEGRATIONS

Open protocols for digital trust

Every external interaction is built on open specifications aligned with the EUDI Wallet model:

Issuer systems

OpenID4VCI: metadata discovery, OAuth 2.0 authorization (PAR + Authorization Code), key possession proof, receipt of the signed document, deferred-issuance endpoint.

Verifier systems

OpenID4VP for remote checks and ISO/IEC 18013-5 over Bluetooth LE for proximity; verifier identification via x509_san_dns / x509_hash schemes.

Trust infrastructure

X.509 certificate chain validation against a set of root anchors: issuer root certificates and IACA roots for reader authentication.

Revocation checks

IETF OAuth Status List: the wallet retrieves and verifies signed status lists from the issuer's endpoint.

Wallet Provider

REST/JSON endpoints attesting the wallet instance and its key set during issuance.

GovStack ecosystem

Interaction with other Building Blocks through the Information Mediator; the solution is intended for validation in the GovStack demo environment.

EUDI reference infrastructure

The configuration has been verified against public EUDI reference issuers, confirming compatibility with the European model.

10 — TECHNOLOGY STACK

Implementation technologies

ANDROID

Kotlin 2.1.10, Gradle 8.13, AGP 8.11.1, JDK 17, compileSdk 35, minSdk 26; 15+ modules, including a separate wallet_core configured through a JSON issuer catalogue and PEM certificates.

IOS

Swift 5, Xcode 15+, iOS 16 deployment target, Swift Package Manager (around 37 packages), local packages with the WalletEngine target.

PROTOCOLS

OpenID4VCI, OpenID4VP, OAuth 2.0 (PAR, Authorization Code), OpenID Connect, DPoP, ISO/IEC 18013-5, IETF OAuth Status List.

DATA FORMATS

SD-JWT VC, mso_mdoc (CBOR), JOSE / JWT / JWK, REST / JSON.

SECURITY

Keys in the Secure Enclave (iOS) and Android Keystore / StrongBox with no export; local secure storage; the passcode is stored only as a hash; TLS 1.2+ with a preference for 1.3.

COMMUNICATION CHANNELS

HTTPS for remote scenarios, Bluetooth LE and QR codes for proximity.

Foundation and licensing: the open-source code of the Diia mobile app (EUPL-1.2); the result is suitable for publication in a public repository, with no secrets or keys in the code. * Alignment with the GovStack Wallet Building Block specification is a target level declared by the project team based on its own technical audit; the PoC has not undergone independent external certification as of publication.

11 — PROVEN RESULT

Diia GovStack Wallet: Diia's experience as a Building Block

Project result

The experience of the Diia national platform has been carried into an internationally interoperable Wallet Building Block. Within the proof-of-concept, the full lifecycle of working with digital documents was implemented on iOS and Android — National ID (PID) and International Driving License (mDL) in mDoc and SD-JWT VC formats, with remote and proximity presentation.

It is Ukraine's first mobile Building Block developed for the GovStack initiative, and the first genuinely working solution built on Diia's open-source code rather than a demonstration prototype. These are proof-of-concept results, not production-usage figures.

Product access

See the product from the inside