seven scoped technical lanes · closed public runner
Issue and walk the lab trust chains
Create fresh, purpose-bound Web TLS, eIDAS-profile, mdoc,
wallet, vLEI/EUDI relying-party, and QKD identity artifacts in six local lanes;
separately verify bundled real GLEIF testnet evidence read-only; reject fourteen
boundary attacks; then sign one public evidence manifest. Technical success and
external recognition stay separate.
Real cryptographic checksPrivate and profile-shaped issuers
POST /api/sandbox/trust-chain/run
vLEI + EUDI registrar · bounded public runner
Onboard a company as a wallet relying party
Run a proposed GLEIF and German EUDI Wallet Sandbox scenario:
bind a synthetic PID wallet to a controlled vLEI role, issue local reference access
and registration artifacts, enforce one registered purpose, then reject root, key,
scope, revocation, replay, and signature attacks.
Real cryptographic checksProposed scenario; local partner fixtures
POST /api/sandbox/portable-trust/run
real zero-knowledge · public runner
Unlinkable age verification
Generate and verify a real Groth16/BN254 proof of
age_over_18, then present the same stand-in holder to two relying parties
and compare their different scoped nullifiers. The date of birth is not disclosed.
Live endpointReference-grade setup
POST /verify/age
OID4VCI + OID4VP · public runner
EUDI wallet round-trip
Create a demo credential offer by QR, then initiate a wallet
presentation that asks for an age claim and verifies issuer and holder binding. This
standards path does not by itself claim cross-site unlinkability.
Live endpointsDemo issuer and data
POST /api/v1/oid4vci/offer · POST /api/v1/oid4vp/initiate
holder + action binding · portable runner
Approve one exact network action
Issue a synthetic operator credential to an ephemeral embedded
wallet, bind its presentation to one fixed mock Quality-on-Demand request, and
independently verify the signed receipt. Revocation, altered QoS, and destructive
operations fail closed.
Real cryptographic checksSynthetic identity and network
POST /api/sandbox/operator-wallet/*