ORBIS.ID Open the walletWallet

For government

Serve citizens without becoming the honeypot.

Public bodies are the most attractive target and the least able to accept the risk. Every credential a state can check instead of store is a record that cannot be leaked, cannot be disclosed by mistake, and cannot be retained past its purpose.

Every promise on this page names an entry in the public capability register, and where an entry is not live the state is printed beside the claim rather than filed away somewhere else.

01

A smaller blast radius, by construction

The record that never existed is the one that cannot be lost. When a citizen proves a fact rather than surrendering a document, the agency completes its check without inheriting a copy to defend.

The check itself needs no account with ORBIS, which means an agency does not create a dependency in order to remove a database.

What is real here

  • Live A holder can prove a single claim — over 18, licensed, employed — without revealing the rest of the credential.
  • Live Anyone can verify an ORBIS credential without registering, paying, or asking permission.

02

Issue once, checked by anyone

A credential issued over open standards can be checked by another agency, by the private sector, or by a citizen's own tooling, without a new integration per relationship.

The library that performs the check is public and installable, and a public vector set lets any party prove its own implementation is correct before it is trusted with anything.

The credential lifecycle in four stagesIssue, hold, prove and revoke, showing what each party learns and does not learn at each stage.1IssueA bank, university or authority seals a statement about youIssuer signs• what is true about you• when it expires• a signature that breaks if altered2HoldIt lands in your wallet — not a company’s serverYou keep it• keys in your device’s secure chip• unlocked by face or fingerprint• works offline3ProveAnswer the question asked — and only thatVerifier checks• seal genuine & unaltered• issuer trusted · not expired• single-use, can’t be replayed4RevokeWithdraw it, and every future check sees thatEither side can end it• issuer withdraws the credential• you revoke a verifier’s access• effective on the next checkWhat never happensThe issuer is never told where you used it. The verifier never gets a copy to keep. No profile is built as a side effect of proving something true.
The credential lifecycle in four stages

What is real here

  • Live Issue credentials over OID4VCI as SD-JWT VC — the same wire any standards-compliant wallet already speaks.
  • Live Anyone can verify an ORBIS credential without registering, paying, or asking permission.
  • Live A zero-dependency library that checks ORBIS credentials in Node or a browser, and performs no network calls of its own.
  • Live Sixteen public test vectors let anyone prove their verifier accepts what it should and refuses what it should not.

03

Eligibility proven, not asserted on a form

A benefit, a licence or an entitlement can be proved cryptographically and disclosed one field at a time, so the assessing officer learns the fact that governs the decision and nothing adjacent to it.

When entitlement ends, the credential is withdrawn and the next check fails — and the issuing agency does not learn where the citizen was using it.

What is real here

  • Live A holder can prove a single claim — over 18, licensed, employed — without revealing the rest of the credential.
  • Live Issue credentials over OID4VCI as SD-JWT VC — the same wire any standards-compliant wallet already speaks.
  • Live A revoked credential stops verifying, without the issuer learning where or when it was checked.

04

What a procurement team can check without asking us

Conformance: a public vector set, answering without a credential, so a buyer can run it rather than read about it.

Independence: an installable verifier that makes no network calls of its own, which is also the exit guarantee — the ability to keep verifying if the relationship ends.

Provenance: the deployment reports the commit it is running. Signed build attestation is the part that is missing, and the register says why rather than omitting the row.

Key custody and change control: signing keys are moving into a hardware-backed vault issuer by issuer, with the current count in the register; key operations are composed by one operator and approved by another, and recorded.

Operations: failures and degraded response times raise an alert. No service-level agreement is offered and no uptime figure is published.

What is real here

  • Live Sixteen public test vectors let anyone prove their verifier accepts what it should and refuses what it should not.
  • Live A zero-dependency library that checks ORBIS credentials in Node or a browser, and performs no network calls of its own.
  • Partial The deployment reports the exact commit it is running so it can be compared against the source. Partial — commit reported; signed attestation unavailable.
  • Partial Issuer signing keys live in Azure Key Vault, and the platform signs by calling the vault rather than holding the key. Partial — two of fifteen issuers today.
  • Live Moving or rotating a signing key is composed by one operator and approved by another, with the whole ceremony recorded.
  • Live Server errors, an unresponsive service and degraded response times raise an alert.

05

Standards, not a vendor format

Credentials are issued over OpenID for Verifiable Credential Issuance as SD-JWT VC — the wire a standards-compliant wallet already speaks — so accepting ORBIS is not a bet on an ORBIS format.

That is a statement about the protocols the platform implements and the vectors that prove it, and nothing more. It is not a claim of conformance certification, and it is not a claim of alignment with any national or Union wallet programme.

What is real here

  • Live Issue credentials over OID4VCI as SD-JWT VC — the same wire any standards-compliant wallet already speaks.
  • Live Sixteen public test vectors let anyone prove their verifier accepts what it should and refuses what it should not.
  • Live A zero-dependency library that checks ORBIS credentials in Node or a browser, and performs no network calls of its own.

06

What this page does not claim

The content master proposed eIDAS 2.0 readiness and interoperability with member-state wallets. The register carries no entry for EUDI alignment or for mdoc and mDL support, and the master's own analysis calls that alignment planned — so it is not claimed here in any form.

Also absent for want of a register entry: offline presentation, multi-language and accessibility commitments, stated hosting and data residency, exportable trust lists, a published incident-disclosure policy, a published audit history, and free core services.

No claim is made about national scale. There is no throughput figure, no citizen count and no deployment reference on this page, because there is nothing sourced and dated to put in one.

Regulatory statements are a design position, not legal advice. No compliance certification is held or claimed.

Straight answers

Questions people actually ask.

Is this an alternative to a national wallet?

It is not positioned as one, and this site makes no claim of alignment or interoperability with any national or Union wallet programme, because the capability register carries no entry for it.

What can we verify about the platform ourselves, before any contact?

The conformance vectors, the published verifier library, and the commit the deployment reports it is running. Each is public, each carries its register entry, and none of them requires an account or a conversation.

Where is the list of what is not finished?

On the capability register, in the same words used internally. It records four states, the evidence method behind each, and the date each was last checked — including the entries that are partial, in build, or not built at all.