New · Hybrid post-quantum verification

Ask a wallet.
Verify the evidence.

Build a policy-bound OpenID4VP request, present from any compatible wallet, and inspect every verifier gate—including atomic ES256 + ML-DSA-65 signature enforcement—before attributes reach your application.

Explore hybrid verification
Request bound Holder proof Formally specified Hybrid post-quantum
Request
Wallet
Verify
Result
Step 02

Shape the request

dc+sd-jwt

Personal Identification Data

Identity attributes with selective disclosure and key binding.

Ask only for what this transaction needs.

2 selected
Holder bindingRequire KB-JWT possession proof
Same-subject policyReject mixed-subject presentations
Experimental capability

Classical assurance. Post-quantum resilience. One decision.

The verifier now supports the frozen euwallet-hybrid-pq-v1 profile. It validates ES256 and ML-DSA-65 over the same domain-separated payload and accepts only when both signatures pass.

Read the implementation notes
ClassicalES256Required
+
Post-quantumML-DSA-65Required
→
Atomic acceptNo downgrade path

Experimental, default-off, and not an EUDI conformity claim.

Evidence, not optimism

A narrow path from wallet to application.

The interface exposes the same security gates as the Rust decision kernel. Mock responses stay visibly marked; production results require a configured cryptographic adapter.

01

Fail closed

No attributes are released without a typed acceptance command.

02

Bound end to end

Client, nonce, transcript, holder key, and disclosure set stay linked.

03

Machine checked

Lean safety theorems and Tamarin protocol lemmas guard the boundary.

04

Quantum resistant

Hybrid ES256 + ML-DSA-65 signatures verified atomically — a hybrid-required policy never falls back to classical.