proposed joint sandbox · organization + wallet · relying-party trust

Carry an organization decision in a wallet—without calling it a vLEI.

A separate real GLEIF testnet lane proves the verifier can check a Legal-Entity chain. A locally self-minted OOR lane supplies a controlled role key. An installed compatible wallet can prove control of its own PID key, and Aadya binds both proofs into a short-lived SD-JWT attestation the same wallet can receive and present.

Unsolicited reference scenario · not a GLEIF or SPRIND partnership
the trust boundary comes first

Real checks do not make synthetic issuers real.

Actually exercised

  • A separate bundled real-GLEIF testnet Legal-Entity chain
  • KERI/ACDC role-chain validation and same-nonce two-key proof of possession
  • OID4VCI issuance plus audience-bound, one-time OID4VP presentation over browser DC API or direct-post PEX
  • A short-lived Aadya SD-JWT bridge offer redeemable only by the enrolled wallet key
  • X.509 access certificate, signed registration policy, purpose and replay checks

Deliberately local or synthetic

  • The runnable OOR credential and its GLEIF-shaped root
  • The PID issuer, wallet holder, company, and service
  • The registrar CA, access certificate, registration certificate, and revocation set
  • Production governance, KYC, legal effect, and partner trust anchors

Not claimed: QVI qualification, eIDAS conformity, production KYC, legal authority, WRPAC/WRPRC conformance, official walt.id certification or broad product compatibility, SPRIND sandbox integration, or endorsement by any named organization. The wallet carries an Aadya attestation—not the underlying vLEI—and Aadya remains responsible for the organizational decision.

the partner-shaped experiment

Each party owns a different answer.

The scenario becomes an external interoperability result only when the proposed partners replace the local fixtures they own.

GLEIF

Which organization and role?

Supply a test Legal-Entity plus OOR/ECR vLEI issued to a controlled key, the pinned QVI/root/schema/status material, and a revocation or rotation event.

SPRIND / EUDI sandbox

Which wallet and registered purpose?

Supply the German sandbox PID and wallet flow, Relying Party Registrar, test trust-list entry, access/registration certificates, and purpose-consent UX.

Aadya

Do both trust planes agree?

Verify the vLEI evidence, bind the role and wallet keys, enforce purpose, revocation and replay, and produce a minimal signed evidence package.

experimental external-wallet standards path

Issue, bind, issue again, then present.

This path uses the application's real OID4VCI issuer and OID4VP verifier. The interactive page uses the browser Digital Credentials API. A separate reproducible lab runner completed both issue/store/present cycles against a local self-hosted walt.id Wallet API on 20 July 2026, with only the requested disclosures selected.

Local walt.id evidence: python3 scripts/run_portable_trust_waltid_demo.py. This is a local compatibility result—not walt.id certification, endorsement, or proof of SPRIND or German EUDI sandbox integration.

The wallet never receives the KERI/ACDC chain. It receives an Aadya-issued, ten-minute organizational-binding attestation. The bridge offer is locked to the exact wallet key observed during PID enrollment. Opaque signed credential-instance bindings also prevent swapping in a different Aadya-issued PID or bridge; Aadya erases the issuer's synthetic PID source record after issuance.

1 · Receive PIDImport a synthetic local PID through OID4VCI.
2 · Prove wallet keyPresent only age_over_18 over a fresh nonce and pinned origin.
3 · Receive bridgeImport Aadya's short-lived, same-wallet-bound SD-JWT VC.
4 · Present bridgeDisclose the fixed attestation fields once; Aadya verifies them.
Ready.

The 256-bit session capability stays only in this page's memory.

bounded offline runner

Onboard, register, present, then attack it.

The endpoint accepts only this fixed scenario. It never accepts a credential, URL, service action, key, or policy from the browser, and it returns only commitments and verdicts—not raw PID, ACDC/CESR, certificate, JWS, or private-key material.

Ready.
failure is part of the demo

Every trust shortcut must stop disclosure.

The runner evaluates each negative case on an isolated branch and reports whether the wallet released data or any external side effect occurred.

Run the scenario to load the attack matrix.

No request has been sent yet.
the real partner plugfest

Replace one local actor at a time.

  1. GLEIF or a participating QVI issues the test role credential to the controlled holder key.
  2. The German EUDI Wallet Sandbox replaces the local PID holder and registrar artifacts.
  3. Run key rotation and revocation while measuring when onboarding or wallet presentation stops.
  4. Publish the signed evidence package and every rejected vector as interoperability evidence—not accreditation.