WMP
WMP, the Wallet Messaging Protocol, is a draft specification that lets wallets, people, AI agents and organisations communicate securely. It turns a one-off credential exchange into an ongoing, secure conversation between the parties involved.
Today a credential exchange is usually a single step: scan a QR code, share the data, done. Everything around it, such as a follow-up question, an extra document or an approval, still goes through email, a portal or a phone call. WMP brings all of that into one secure channel.
Typical uses are an organisation issuing a credential, asking for supporting documents and sending status updates, a request for someone's approval, consent or signature, and a person working with an AI agent, or an agent acting on behalf of an organisation. Because WMP supports OpenID4VCI and OpenID4VP, a credential can be issued or shown in the middle of that conversation.
For organisations this means fewer channels to integrate, less manual follow-up and, with the optional evidence profile, signed proof of who sent, received or accepted what and when. Conversations can be encrypted end to end, so sensitive data does not have to sit in mailboxes or shared portals along the way.
Under the hood, WMP uses JSON-RPC 2.0 messages, the same format the Model Context Protocol uses for AI agents, and optionally MLS for end-to-end encrypted group conversations. It runs over WebSocket, HTTPS or native messaging.
WMP is an independent draft, version 0.1.0 from April 2026. It is not part of the EUDI Wallet ARF and no eIDAS implementing act refers to it, so treat it as a proposal to track rather than a requirement to build against.
Is WMP part of the EUDI Wallet standards?
No. WMP is an independent draft, not a European Commission deliverable: the ARF does not name it and no eIDAS implementing act refers to it. It does carry OpenID4VCI and OpenID4VP flows, which the EUDI Wallet does require, so read it as one proposal for the messaging around those flows.