A web and CLI wallet for testing EUDI issuers and verifiers. It also decodes credentials, proxies wallet traffic for debugging and generates DCQL queries from credentials.
Try it online: a shared public demo of the wallet and decoder runs at https://eudi-test.dev.
- Wallet: test issuance and presentation from the CLI or browser. Store state in files, memory or Postgres (wallet).
- Proxy: inspect live OID4VP and OID4VCI traffic (proxy).
- Decoder: inspect credentials, requests, offers and trust lists in the CLI or browser (decode, serve).
- Validation: check signatures, expiry and status, with optional trust lists (validate).
- QR scanning: read credentials and requests from an image or your screen (decode).
- DCQL: generate a query from a credential (dcql).
eudi-dev is a wallet for testing your issuer or verifier. The table compares it with other EUDI tools.
| Tool | What it tests | Runs locally | Scriptable |
|---|---|---|---|
| eudi-dev | your issuer or verifier | yes | CLI and HTTP API |
| Animo OpenID4VC Playground | your wallet | self-hostable | no, web UI |
| EUDIPLO Playground | your wallet | self-hostable | no, web UI |
| EUDI reference issuer and verifier | your wallet | issuer only | no, web UI |
| EUDI Web Wallet Tester | your issuer, OID4VCI only | yes | no, web UI |
| EUDI reference wallet (Android, iOS) | your issuer or verifier | on a device | no |
| Procivis One trial apps | your issuer or wallet | on a device | no |
| Multipaz | your wallet or issuer, and proximity | SDK, apps, hosted issuer and verifier | no |
| polaris-oid4vp | your wallet: OpenID4VP 1.0 + HAIP, SD-JWT VC, direct_post.jwt |
yes, pip install |
CLI, a verdict line per presentation |
| Paradym debuggers | one credential, decoded | no | no |
| SDKs: walt.id, Sphereon, Credo, Procivis One | whatever you build | yes | as you write it |
When to use something else:
- To certify your own implementation, use the OpenID Foundation certification program.
- To test a wallet, point it at one of the hosted issuer or verifier services above.
- To ship a product, use an SDK. The Go packages in this repository are internal (
internal/). - For proximity flows (BLE, NFC), use Multipaz. eudi-dev implements OID4VP over HTTP.
- To read a single credential, use a hosted decoder.
Never use real credentials (see SECURITY.md).
brew install dominikschlosser/tap/eudi-devInstalls the eudi command with shell completion.
Download the latest binary for your platform from Releases.
go install github.com/dominikschlosser/eudi-dev/v2@latestThis installs the binary as eudi-dev (Go uses the module name). The documentation uses eudi. Link it for the shorter name: ln -s "$(go env GOPATH)/bin/eudi-dev" "$(go env GOPATH)/bin/eudi".
The v2 module path is github.com/dominikschlosser/eudi-dev/v2. The /v2 suffix is required for v2 releases. Earlier v2 tags (up to v2.4.2) have an incorrect module path. Install them from release binaries or build them from source.
git clone https://github.com/dominikschlosser/eudi-dev.git
cd eudi-dev
go build -o eudi .docker pull ghcr.io/dominikschlosser/eudi-dev:latest
docker run -p 8085:8085 -p 8086:8086 ghcr.io/dominikschlosser/eudi-devThe default CMD starts a headless wallet server with preloaded PID credentials. State is kept in memory, so the container needs no volume.
→ Full Docker & verifier testing guide → OIDF conformance status, runbook, and results → Examples
testcontainers-eudi starts the wallet in Docker for Java integration tests. Its Java client issues credentials, accepts credential offers and submits presentations.
eudi [--json] [--no-color] [-v] <command> [flags] [input]
Input is a file path, URL, raw credential string, or stdin.
Shell completion covers all subcommands, flags, and known values (template names, credential IDs, running wallet instances). Install it for bash, zsh, or fish (detected from $SHELL):
eudi completion install| Command | Purpose |
|---|---|
wallet |
Stateful testing wallet with CLI-driven OID4VP/VCI flows |
issue |
Generate test SD-JWT, JWT, or mdoc credentials for development |
proxy |
Debugging reverse proxy for OID4VP/VCI wallet traffic |
serve |
Web UI for decoding and validating credentials in the browser |
decode |
Detect and inspect credentials, OpenID4VCI/VP requests, and trust lists. Verifies issuer metadata when resolvable |
validate |
Verify signatures, check expiry, and check revocation status |
templates |
Manage credential templates (list, show, save, import, delete) |
dcql |
Generate a DCQL query from a credential's claims |
completion |
Generate or install shell completion (completion install) |
version |
Print version |
A stateful testing wallet with CLI-driven OID4VP/VCI flows, QR scanning, and OS URL scheme registration. State is stored in files by default. --storage selects memory or Postgres.
eudi issue sdjwt --wallet --template pid-sdjwt # Issue a PID into the wallet
eudi wallet serve # Start web UI + OID4VP endpoints
eudi wallet ca-cert --out wallet-ca-cert.pem
eudi wallet tls-cert --out wallet-tls-cert.pem
eudi wallet accept 'openid4vp://authorize?...'
eudi wallet scan --screen # QR scan → auto-dispatch
eudi wallet logs -f # Follow persisted wallet interactionsSecurity: Anyone with network access to the wallet port controls its credentials. Use localhost or an isolated test network and store test data only. The API rejects cross-origin requests. The exception is
/api/dc-api, which verifier pages call from their own origin. It relies on the reported caller origin and the consent dialog. For public hosting, use the--demoprofile (see public demo hosting).
wallet serve hosts the UI and protocol endpoints, including issuer metadata, trust lists and status lists. Use issue ... --wallet --template pid-sdjwt to add a PID. wallet ca-cert and wallet tls-cert export certificates for verifier trust stores. Automated tests can do the same through the HTTP API.
The main commands:
wallet serveto run the walletissue ... --wallet(with--templateor--pid) to preload credentialswallet psto find running wallet serverswallet use <url>to select a remote or containerized walletwallet killto stop a wallet serverwallet trust-listto get the verifier trust list URL or JWTwallet logsto inspect wallet OID4VP/OID4VCI interactionswallet ca-certandwallet tls-certto export certificate materialwallet --mode debug|strictand--preferred-format ...to control runtime behaviorwallet --tls-verify=true|falseto set HTTPS certificate verification and--tls-ca dev-ca.pemto trust a development CAwallet --https-proxy http://proxy:3128(orHTTPS_PROXY) to send requests to issuers and verifiers through a forward proxywallet serve --haipto check verifiers and issuers against HAIP 1.0
--haip adds HAIP 1.0 checks. --mode strict stops the flow on findings, including HAIP findings. --mode debug reports them and continues. See HAIP enforcement.
When a wallet server is running for the selected wallet directory, CLI commands use its API. After wallet use <url>, commands and clicked offer or presentation links go to that target. wallet ps lists local instances and the active remote target.
/api/trustlists lists the trust list profiles. Each entry has a relative path, so it works with Docker port mappings. The web UI shows these URLs above the certificate downloads.
→ Full documentation: subcommands, flags, endpoints, logs, trust lists, storage, URL scheme registration
→ Public demo hosting: run a shared internet-facing demo with --demo (hardened endpoints, periodic reset, imprint page)
→ Flow diagrams: OID4VP / OID4VCI interaction diagrams and parameter checklists
Generate test SD-JWT, JWT, or mdoc credentials for development and testing.
eudi issue sdjwt --pid
eudi issue sdjwt --template employee-card --claims '{"employee_id": "E-42"}'
eudi issue sdjwt --pid --always-disclosed issuing_country,address.country
eudi issue jwt --claims '{"name":"Test","age":30}'
eudi issue mdoc --claims '{"name":"Test"}' --doc-type com.example.test
eudi issue sdjwt | eudi decodeCredential templates hold reusable claim sets (templates list|show|save|import|delete). A template defines the credential type, default claims, and the always disclosed claims. Templates work in the CLI, the HTTP API, and the wallet UI.
→ Full documentation: all flags, round-trip examples → Credential templates: template files, management commands, always disclosed claims
Intercept and debug OID4VP/VCI traffic between a wallet and a verifier/issuer with a live web dashboard.
eudi proxy --target http://localhost:8080Wallet <--> Proxy (:9090) <--> Verifier/Issuer (:8080)
|
Live dashboard (:9091)
→ Full documentation: traffic classification, features, flags
Start a local web UI for decoding and validating credentials in the browser.
eudi serve
eudi serve --port 3000
eudi serve credential.txtThe UI runs at http://localhost:8080 by default. Paste a credential to decode it, expand its sections and check its signature. A credential passed on the command line fills the input. --imprint-file adds a legal notice at /imprint.
Warning: The browser sends credentials to the server for decoding. Run it locally, or see public demo hosting for an internet-facing setup.
Auto-detect and decode credentials (SD-JWT, JWT VC, mdoc), OpenID4VCI/VP requests, and ETSI trust lists.
eudi decode credential.txt
eudi decode 'openid4vp://authorize?...'
eudi decode --screen # QR scan from screen→ Full documentation: auto-detection order, format override, QR scanning, flags
Verify signatures, check expiry, and check revocation status.
eudi validate --key issuer-key.pem credential.txt
eudi validate --trust-list trust-list.jwt credential.txt
eudi validate credential.txt→ Full documentation: flags, trust list explanation
Generate a DCQL (Digital Credentials Query Language) query from a credential's claims. Output is always JSON.
eudi dcql credential.txtExample output (SD-JWT):
{
"credentials": [
{
"id": "urn_eudi_pid_1",
"format": "dc+sd-jwt",
"meta": { "vct_values": ["urn:eudi:pid:1"] },
"claims": [
{ "path": ["birth_date"] },
{ "path": ["family_name"] },
{ "path": ["given_name"] }
]
}
]
}| Format | Description |
|---|---|
SD-JWT (dc+sd-jwt) |
Header/payload, disclosures, _sd resolution, key binding JWT. Signature: ES256/384/512, RS256/384/512, PS256/384/512 |
JWT VC (jwt_vc_json) |
Plain JWT Verifiable Credentials (W3C JWT VC format), presented without changes |
mdoc (mso_mdoc) |
CBOR IssuerSigned & DeviceResponse (hex/base64url), COSE_Sign1 issuerAuth, MSO |
| OpenID4VCI / VP | Credential offers, authorization requests, URI schemes (openid-credential-offer://, haip-vci://, eu-eaa-offer://, openid4vp://, haip-vp://, eudi-openid4vp://) |
| ETSI Trust Lists | TS 119 602 trust list JWTs with entity names, identifiers, and service types |
docs/spec-compliance.md lists the compliance status for OID4VP 1.0, OID4VCI 1.0, HAIP 1.0, SD-JWT (RFC 9901) and SD-JWT VC, mdoc (ISO 18013-5), ETSI trust lists, and Token Status List. docs/diagrams/README.md shows the issuer and verifier interactions as diagrams.
eudi-dev v2.3.7 is OpenID Certified™ for the OpenID4VP 1.0 and OpenID4VCI 1.0 wallet profiles with HAIP 1.0, for both SD-JWT VC and mdoc credentials.
| Certification | Certified flows | Date |
|---|---|---|
| OpenID4VP 1.0 + HAIP 1.0 | Presentation using direct_post.jwt |
18 September 2026 |
| OpenID4VCI 1.0 + HAIP 1.0 | Wallet-initiated issuance and issuer-initiated issuance with offers by value or reference | 3 September 2026 |
The official listings link to the certification submissions and test results. This repository has its own conformance results and a runbook. The OpenID Certified mark is a trademark of the OpenID Foundation and is used under its mark usage terms.
| Flag | Description |
|---|---|
--json |
Output as JSON |
--no-color |
Disable colored output |
-v |
Verbose output (x5c chain, device key, digest IDs) |
No EU affiliation: This is an independent open source project. The European Commission and the European Union do not endorse it and it has no affiliation with them. "EUDI" describes the ecosystem the tool targets (European Digital Identity). For official EUDI Wallet resources see the eu-digital-identity-wallet organization.
Apache-2.0