Skip to main content

Digital Credentials API

The Digital Credentials API is the W3C browser API that lets a website request a credential from a wallet on the same device, handing the request to the operating system instead of relying on a QR code or a custom deep link.

A website calls navigator.credentials.get() with a digital credential request that names a presentation protocol and carries that protocol's own request as its payload. The browser passes the request to the operating system, which shows a native picker of the wallets installed on the device, and the wallet the holder chooses returns its protocol response through the same call. The API only carries the exchange: what is asked for, what is disclosed and how the response is verified all stay defined by the protocol inside it. A companion navigator.credentials.create() call does the same for issuance, so a site can hand a credential offer to a wallet the same way.

Before this existed, a presentation on the device the holder was already using meant either a QR code that the phone displaying it could not scan, or a deep link that had to guess which wallet was installed. Routing the request through the operating system removes both problems, because the holder gets one native picker covering every wallet on the device and the site never has to detect or name a wallet itself. The browser also adds the calling origin to the request, so the wallet can show the holder which site is asking and reject a request that was copied from somewhere else, which is what makes the flow resistant to phishing and relay attacks.

The API is deliberately protocol neutral, and two bindings matter in the EUDI Wallet ecosystem: OpenID4VP defines its own profile for the API, and ISO/IEC 18013-7 Annex C binds the same mdoc exchange to it. The EUDI ARF discusses it as the way to improve remote presentation, provided the browser supplies the relying party's origin so a Wallet Unit can work out who is asking, and provided a cross-device flow keeps a proximity check between the two devices. That leaves ISO/IEC 18013-5 device retrieval as the in-person channel rather than something the browser API replaces.

Support is no longer experimental. The API is enabled by default in Chrome on Android and on desktop, and in Safari on recent Apple releases, while Firefox has not enabled it. Browsers still differ in which protocols and credential formats they accept, and desktop support generally works by pairing with a phone that holds the wallet rather than by storing credentials in the browser. Treat it as an enhancement for the browsers and devices that have it, and keep the QR code or redirect flow for the ones that do not.

Technical deep dive

This page explains what the technology does and who it affects. Our developer documentation covers the implementation itself: the messages, the fields and the worked examples an integration team needs.

Read the technical documentation

Does the Digital Credentials API replace OpenID4VP?

No. The API is the delivery channel: it carries a request from a website to a wallet through the operating system and carries the response back. What the request contains and how the response is verified is still defined by a protocol, OpenID4VP for a presentation request or ISO/IEC 18013-7 Annex C for an mdoc exchange. A relying party that already speaks OpenID4VP keeps the same request and the same verification, and gains a better way to deliver it on the device the holder is already using.

Back to the glossary