Frequently asked questions
The questions we get most often, and the current limitations, plainly stated.
What does Todis actually verify?
That the proof presented by a user's digital identity wallet is genuine (signed by a recognized issuer and still valid), without ever showing you more information than what you asked for.
Do I need to become a qualified trust service provider myself?
No. You remain a simple relying party. That's exactly Todis's role: doing the cryptographic verification on your behalf.
Which wallet formats are supported?
Both main formats of the EUDI Wallet ecosystem: SD-JWT VC (fully automatic
issuer verification through the European registry) and mdoc/ISO 18013-5 (mobile
driving licences, and the France Identité PID). For an mdoc, the issuer is
verified against the trust anchors (IACAs) Todis keeps in a registry, listed by
GET /trust/registries; to have a missing issuer added, write to
integration@todis.eu.
Which countries are covered?
Todis automatically verifies issuers from every EU/EEA member state via the official registry published by the European Commission, updated live, with no action needed on our part. Compatibility for a specific country may vary due to local technical specifics; if a particular country is critical for your use case, contact us and we'll verify it before you go live.
What data do you see about my users?
The proof transits through our servers for the duration of the verification (never stored, never logged, never reused), and we only pass you what you explicitly asked for, thanks to selective disclosure (a visitor can, for example, prove they're of age without revealing their full date of birth).
Can I self-host the service?
Self-hosting is not part of our standard offers. If your organisation has a sovereignty requirement that demands it, let's talk: it is a tailored engagement, not a checkbox.
Do I need to register somewhere to use the service?
Not today. The European framework (eIDAS 2.0) plans that, eventually, the
relying party (Todis, on your behalf) will register with a national
authority, and that infrastructure isn't open yet in member states. It does
not stop you from moving forward, nor even from working today: on 29 August
2026 we verified a production France Identité wallet end to
end, a PID in mdoc form, against the production certificate authority (IACA)
that the Agence Nationale des Titres Sécurisés publishes on the wallet's page
of the France Identité playground, and with our verifier identifier exactly as
it is issued (a client_id in the x509_hash scheme,
which that wallet accepts). What you need is therefore not a permission but
two technical pieces: that trust anchor, and an encrypted response
(encrypted_response), which some national wallets require. We follow the regulatory work closely and will tell you what
changes when it does.
Can my visitors open their wallet without scanning a QR code?
Yes, on our hosted verification page. If the visitor's browser allows it, a button offers to open the wallet installed on their phone directly. Otherwise, the QR code stays on the page and the verification runs as usual.
Just ask for this option when you create the session: there is nothing else to declare or register. When choosing their wallet, the visitor sees the address of our page.
For an age check, this button asks for the European age attestation: a visitor who only holds their digital identity goes through the QR code. The technical details are in the technical reference.
Can I test before I pay?
Yes. A free integration token is available: 50 free requests, no credit card and no deadline, to validate your integration (hosted page, session, direct verification). Need more volume for your testing? Write to integration@todis.eu, we'll get in touch to set up an access that fits.
How does billing work?
Three simple plans, no commitment to get started: see the pricing page.
Got a question that's not here?
contact@todis.eu, we reply quickly.