UAE PASS
Merged · disabledOAuth + UserInfo profile is implemented and locally regression-tested. User-facing enablement remains gated on a credentialed UAE PASS staging smoke test.
euwallet · global identity & agent management · iOS + Android · verified Rust core
A global identity and agent-management runtime connecting verified people, national and regional identity schemes, enterprise agent identities, and independently delegated authority. EUDI remains the first deeply implemented regulated profile: every system retains its native trust domain, assurance framework, provenance, permissions, and legal meaning.
Global identity layer
Verified people. Governed agents. Independent authority.
Government identity verifies the humans who sponsor, own, and delegate to agents. Microsoft Entra contributes tenant-scoped enterprise identities and native permissions. Mandamus contributes separately delegated authority. Policy combines those independent inputs without turning identity, sponsorship, or a permission into automatic authority.
EUDI remains an exact regulated profile with its own acceptance semantics and conformance evidence. Adding another national identity system does not weaken, reinterpret, or silently generalize the European profile.
OAuth + UserInfo profile is implemented and locally regression-tested. User-facing enablement remains gated on a credentialed UAE PASS staging smoke test.
FAPI 2.0 Login foundation, discovery, PAR, DPoP, protected-token boundary, and native browser transport are implemented. Enablement awaits onboarded RP credentials and a credentialed staging login smoke test; Myinfo remains out of scope.
RP-API 6.0 mTLS boundary, authoritative collect orchestration, animated QR, and iOS universal-link flow pass local tests. Merge and production enablement remain gated on a fully redacted credentialed end-to-end authentication.
Tenant-scoped workforce, blueprint, and agent identity foundations are implemented with explicit sponsors/owners and independent native permission inputs. Enablement awaits a credentialed, fully redacted read-only Microsoft Graph tenant smoke test.
Capability-oriented, not protocol-oriented
authenticate · identify · read attributes · issue & present credentials · retrieve documents · remote & qualified signatures · step-up assurance · discover & verify trust
EUDI-grade assurance is the foundation. Identity and authority remain independent.
Global Identity & Agent Management Runtime
Government and enterprise identity answer who a person or agent is. Sponsorship and ownership establish accountability. Entra permissions and Mandamus delegations remain independent inputs to policy—none silently authorizes an action by itself.
Government identity
Native assurance, provenance, protocols, and legal meaning stay intact.
Human identity
Enterprise identity · Microsoft Entra
Normalized principal
Independent authority
Effective authority
Actions proceed only when identity, organizational permission, human delegation, lifecycle state, and policy agree.
Implementation status: UAE PASS, Singpass, and Entra foundations are merged but user-facing disabled pending credentialed provider smoke tests. BankID is implemented on PR #143 and remains disabled pending merge and a redacted credentialed authentication. EUDI behavior and conformance gates are unchanged.
How a jurisdiction-neutral identity runtime hosts EUDI and other national identity schemes without collapsing their trust or legal semantics.
What the identity runtime does across regulated wallet profiles, national identity systems, and delegated agents.
EUDI-grade engineering beneath a global runtime: machine-checked proofs, explicit threat models, native assurance, and profile-specific conformance.
How quality is measured, and where the evidence behind every claim lives.