Raidiam Agent trust showcase

Demonstration. HM Passport Office, NZ Department of Internal Affairs, DVLA and NZTA names are used for illustration. This demonstrator is not affiliated with them, and they did not issue these credentials.

Advanced demonstrator

One agent. Many issuers. Each scheme resolved at run time.

Federation tells each relying party whom to trust. Credentials carry what they prove. OAuth gives the agent only the access that the evidence earns.

How it works today

A payment scheme admits accredited members under its own rules. This page treats each scheme as a federation of those members.

Raidiam helped design the trust infrastructure of UK Open Banking.1 UK Open Banking has 249 third party providers and 90 account providers.2 Raidiam Connect powers the directory and trust framework of Open Finance Brasil, which had 740 participating financial institutions by 2026.3 Open Finance Brasil processed 30 billion API calls in January 2026.4 In Australia, Raidiam's trust framework underpins a national digital identity exchange in which banks verify identity for over 10 million customers.56 ConnectID is an initiative of Australian Payments Plus, and the Australian Government accredits it as an identity exchange.7 In New Zealand, Confirmation of Payee covers 23 financial institutions.8 Raidiam designed and delivered the first Open Banking trust framework in the UK,9 and its infrastructure powers schemes in Brazil, Australia and New Zealand.101112

Banks already carry identity in several countries. Swedish BankID checks identity at the bank.13 Danish MitID is one digital ID for online banking and for public services.14 The Finnish Trust Network lets a service get electronic identification through a broker, without a contract with each identification provider.15

The card networks already register agents. Visa provisions agent specific payment tokens.16 Visa also gives the merchant a signal that the agent is a Visa trusted agent.17 Mastercard registers and verifies agents before they can transact on its network.18 Mastercard Verifiable Intent uses selective disclosure as defined in RFC 9901, the format that this demonstrator also builds on.1920

Each of these registries answers one question for its own members: can this agent act here? OpenID Federation lets a scheme publish that answer, so that any relying party can resolve it at run time without a bilateral integration.21 A card network that published its agent registry as a federation root would give this result to any relying party that accepts that root. The scheme keeps its own rules, its own members and its own accreditation process. Federation changes how a relying party reads the result, not which party decides it. This demonstrator shows what that gives an agent that holds credentials from many issuers at the same time.

Some designs give one provider three roles: the issuer of the agent identity, the trust anchor and the payment custodian. That design is simpler to start, and it puts the trust decisions for all three roles with that provider. This demonstrator keeps the three roles separate. Each issuer is accredited by its own scheme. Each relying party trusts each issuer through that scheme.

The federation map

Each scheme is its own root. The map shows each root, the members that the root lists, and the roots that each relying party used for each credential. No line connects two parties directly. Each trust decision on this page resolves a chain to a root.

live read 26 September 2026, 09:17 UTC.

  • Wallet scheme (demonstration)

    https://aw-roots.agents.showcase.raidiam.io/wallet-scheme

    Entity configuration self signature: valid

    Members this root lists:

    • https://aw-provider.agents.showcase.raidiam.io
  • UK passport scheme (demonstration)

    https://aw-roots.agents.showcase.raidiam.io/uk-passport-scheme

    Entity configuration self signature: valid

    Members this root lists:

    • HM Passport Office (demonstration) https://aw-hmpo.agents.showcase.raidiam.io
    • Fernwing Airways https://aw-travel.agents.showcase.raidiam.io/airline
    • Hotel Kestrelmoor https://aw-travel.agents.showcase.raidiam.io/hotel
  • NZ passport scheme (demonstration)

    https://aw-roots.agents.showcase.raidiam.io/nz-passport-scheme

    Entity configuration self signature: valid

    Members this root lists:

    • NZ Department of Internal Affairs (demonstration) https://aw-dia.agents.showcase.raidiam.io
    • Fernwing Airways https://aw-travel.agents.showcase.raidiam.io/airline
    • Hotel Kestrelmoor https://aw-travel.agents.showcase.raidiam.io/hotel
  • UK driving licence scheme (demonstration)

    https://aw-roots.agents.showcase.raidiam.io/uk-licence

    Entity configuration self signature: valid

    Members this root lists:

    • DVLA (demonstration) https://aw-dvla.agents.showcase.raidiam.io
    • Hotel Kestrelmoor https://aw-travel.agents.showcase.raidiam.io/hotel
    • Brightlane Payments https://aw-travel.agents.showcase.raidiam.io/psp
  • NZ driving licence scheme (demonstration)

    https://aw-roots.agents.showcase.raidiam.io/nz-licence

    Entity configuration self signature: valid

    Members this root lists:

    • NZ Transport Agency (demonstration) https://aw-nzta.agents.showcase.raidiam.io
    • Hotel Kestrelmoor https://aw-travel.agents.showcase.raidiam.io/hotel
    • Brightlane Payments https://aw-travel.agents.showcase.raidiam.io/psp
  • Stanmoor Open Banking

    https://aw-roots.agents.showcase.raidiam.io/open-banking

    Entity configuration self signature: valid

    Members this root lists:

    • Northbank https://aw-northbank.agents.showcase.raidiam.io
    • Fernwing Airways https://aw-travel.agents.showcase.raidiam.io/airline
    • Brightlane Payments https://aw-travel.agents.showcase.raidiam.io/psp
    • Hotel Kestrelmoor https://aw-travel.agents.showcase.raidiam.io/hotel
  • Calder Card Network

    https://aw-roots.agents.showcase.raidiam.io/card-scheme

    Entity configuration self signature: valid

    Members this root lists:

    • Kowhai Bank https://aw-kowhai.agents.showcase.raidiam.io
    • Fernwing Airways https://aw-travel.agents.showcase.raidiam.io/airline
    • Brightlane Payments https://aw-travel.agents.showcase.raidiam.io/psp
    • Hotel Kestrelmoor https://aw-travel.agents.showcase.raidiam.io/hotel
The roots each relying party used, from its own result log
Relying partyRoots used
Fernwing AirwaysCalder Card Network, NZ passport scheme (demonstration), Stanmoor Open Banking, UK passport scheme (demonstration)
Hotel KestrelmoorCalder Card Network, NZ driving licence scheme (demonstration), Stanmoor Open Banking, UK driving licence scheme (demonstration), UK passport scheme (demonstration)
Brightlane PaymentsCalder Card Network, Stanmoor Open Banking, UK driving licence scheme (demonstration)

Superiors outside the scheme roots, as each entity configuration publishes them:

  • https://aw-provider.agents.showcase.raidiam.io names https://authority.directory.showcase.raidiam.io/authority/845f7286-3c74-4d91-9354-af110dbd33c8

Choose the traveller and the instrument

Two travellers use one agent. They are on different schemes. Amelia Hart pays through an open banking scheme. Tane Wiremu pays through a card scheme. One payment service provider, Brightlane Payments, is accredited under both schemes.

Select a traveller and an instrument type. The buttons below run the real flows against the deployed services. The service holds the operator credential. Your browser does not send or receive it.

Traveller
Instrument type

Each run prints each real request and each real answer here, with the named fields only. After a run, reload the page to read the new state from the services.

Fill the agent wallet

The traveller signs in at each issuer and asks it to issue to the agent. The agent runs OpenID for Verifiable Credential Issuance.22 The agent proves its key with an attestation from its Wallet Provider. The issuer resolves that Wallet Provider through the wallet scheme and checks its accreditation. Then the issuer binds the credential to the agent key.

The timeline shows each credential that the agent holds, from the time it arrived to the time it expires. Passports and licences last for years. The task mandate lasts for the trip. The agent holds both kinds at the same time.

live read 26 September 2026, 09:17 UTC.

The bar length is the lifetime of the credential on a log scale. A bar in the graphic colour is the newest unexpired credential of its type, which the agent presents. A grey bar is an earlier or expired one, which the agent keeps.

  1. Payment instrument for Amelia Hart from Northbank. Received 26 September 2026, 08:59 UTC. Expires 26 September 2026, 10:59 UTC (2 hours). Newest of its type.
  2. Task mandate for Amelia Hart from Northbank. Received 26 September 2026, 08:59 UTC. Expires 26 October 2026, 23:59 UTC (31 days). Newest of its type.
  3. Payment instrument for Amelia Hart from Northbank. Received 26 September 2026, 07:23 UTC. Expires 23 November 2026, 23:59 UTC (59 days). Earlier copy.
  4. Task mandate for Amelia Hart from Northbank. Received 26 September 2026, 07:23 UTC. Expires 26 October 2026, 23:59 UTC (31 days). Earlier copy.
  5. Payment instrument for Amelia Hart from Northbank. Received 26 September 2026, 05:24 UTC. Expires 23 November 2026, 23:59 UTC (59 days). Earlier copy.
  6. Task mandate for Amelia Hart from Northbank. Received 26 September 2026, 05:24 UTC. Expires 26 October 2026, 23:59 UTC (31 days). Earlier copy.
  7. UK passport for Amelia Hart from HM Passport Office (demonstration). Received 26 September 2026, 02:43 UTC. Expires 1 June 2033, 23:59 UTC (7 years). Newest of its type.
  8. Payment instrument for Amelia Hart from Northbank. Received 26 September 2026, 02:36 UTC. Expires 23 November 2026, 23:59 UTC (59 days). Earlier copy.
  9. Task mandate for Amelia Hart from Northbank. Received 26 September 2026, 02:36 UTC. Expires 26 October 2026, 23:59 UTC (31 days). Earlier copy.
  10. Driving licence for Amelia Hart from DVLA (demonstration). Received 26 September 2026, 02:36 UTC. Expires 25 September 2031, 02:36 UTC (5 years). Newest of its type.
  11. UK passport for Amelia Hart from HM Passport Office (demonstration). Received 26 September 2026, 02:36 UTC. Expires 1 June 2033, 23:59 UTC (7 years). Earlier copy.
  12. Payment instrument for Tane Wiremu from Kowhai Bank. Received 26 September 2026, 05:24 UTC. Expires 23 November 2026, 23:59 UTC (59 days). Newest of its type.
  13. Task mandate for Tane Wiremu from Kowhai Bank. Received 26 September 2026, 05:24 UTC. Expires 26 October 2026, 23:59 UTC (31 days). Newest of its type.
  14. Payment instrument for Tane Wiremu from Kowhai Bank. Received 26 September 2026, 02:36 UTC. Expires 23 November 2026, 23:59 UTC (59 days). Earlier copy.
  15. Task mandate for Tane Wiremu from Kowhai Bank. Received 26 September 2026, 02:36 UTC. Expires 26 October 2026, 23:59 UTC (31 days). Earlier copy.
  16. Driving licence for Tane Wiremu from NZ Transport Agency (demonstration). Received 26 September 2026, 02:36 UTC. Expires 25 September 2031, 02:36 UTC (5 years). Newest of its type.
  17. NZ passport for Tane Wiremu from NZ Department of Internal Affairs (demonstration). Received 26 September 2026, 02:36 UTC. Expires 18 November 2031, 23:59 UTC (5 years). Newest of its type.
Engineer notes

The passport, the task mandate and the payment instrument are SD-JWT VC credentials. SD-JWT VC is an IETF OAuth working group document, submitted to the IESG for publication, with an intended status of Proposed Standard.2324 It is one of the formats that the EUDI Wallet Architecture and Reference Framework says can be used in the EUDI Wallet ecosystem.25 The licences are mdoc credentials in the mso_mdoc format.

Each credential is bound to the agent instance key: cnf.jwk for SD-JWT VC, and the device key in the mobile security object for an mdoc.

The agent authenticates to each issuer with a wallet attestation, following OAuth attestation based client authentication, an IETF OAuth working group specification.26 HAIP 1.0 requires OAuth2 client authentication at the PAR and Token endpoints.27 HAIP 1.0 recommends that ecosystems adopt the Wallet Attestation of OpenID4VCI Appendix E.28 That Wallet Attestation follows the IETF Client Attestation JWT.29 This page makes no claim that the attestation in this demonstration conforms to HAIP.

The key attestation states a key storage level as a fixed value in this demonstration. It is not evidence of certified hardware. The passport carries the traveller's profile claims with no document verification evidence.

Run the trip

For each relying party, the page shows the request, what the agent disclosed, the chain that the relying party resolved, the root it used, and the result. Each relying party sends one request by OpenID for Verifiable Presentations with a DCQL query.30

The airline accepts a UK passport or an NZ passport, together with the task mandate, in one request. Both travellers satisfy it, with credentials from different issuers on different schemes, and no setup between the airline and any issuer. The airline confirms that both credentials are bound to the same agent key, and that the mandate names the passport holder.

The payment service provider asks for the payment instrument and a billing address. It resolves the issuing bank through the open banking scheme or the card scheme. Then it asks the bank to authorise the payment. The bank checks that the agent approved exactly this amount, currency and payee, and it enforces the limit of the instrument.

live read 26 September 2026, 09:17 UTC.

Agent key thumbprint WWhDzCm9BvPefYFLp_9-SeAD6rKGtS_z4F-hI2jHpIs. Every credential in every accepted result below is bound to this key.

Fernwing Airways

The latest result for each traveller, of 6 in the log.

Amelia Hart: passenger data and booking authority for FW101.

Accepted. 26 September 2026, 07:23 UTC

CredentialIssuerRoot usedDisclosed
uk_passportHM Passport Office (demonstration)UK passport scheme (demonstration)given_name, family_name, date_of_birth, document_number, nationality, issuing_state, sex, date_of_expiry
mandateNorthbankStanmoor Open Bankingprincipal, authorization_details
10 checks, 10 passed
  • Passed: [uk_passport] issuer resolves under an accepted root: https://aw-hmpo.agents.showcase.raidiam.io chains to https://aw-roots.agents.showcase.raidiam.io/uk-passport-scheme and holds its accredited-passport-issuer mark
  • Passed: [uk_passport] issuer signature, Key Binding JWT and requested claims: signed by https://aw-hmpo.agents.showcase.raidiam.io (root https://aw-roots.agents.showcase.raidiam.io/uk-passport-scheme), bound to the holder key, nonce and audience match
  • Passed: [uk_passport] no over disclosure: disclosed only given_name, family_name, date_of_birth, document_number, nationality, issuing_state, sex, date_of_expiry
  • Passed: [mandate] issuer resolves under an accepted root: https://aw-northbank.agents.showcase.raidiam.io chains to https://aw-roots.agents.showcase.raidiam.io/open-banking and holds its account-provider mark
  • Passed: [mandate] issuer signature, Key Binding JWT and requested claims: signed by https://aw-northbank.agents.showcase.raidiam.io (root https://aw-roots.agents.showcase.raidiam.io/open-banking), bound to the holder key, nonce and audience match
  • Passed: [mandate] no over disclosure: disclosed only principal, authorization_details
  • Passed: credential sets: uk_passport, mandate
  • Passed: same holder key: both bound to WWhDzCm9BvPefYFLp_9-SeAD6rKGtS_z4F-hI2jHpIs
  • Passed: mandate subject matches the passport holder: mandate for Amelia Hart, passport of Amelia Hart
  • Passed: mandate permits this booking: book_flight from 2026-10-10 to 2026-10-24, flight on 2026-10-10

Tane Wiremu: passenger data and booking authority for FW102.

Accepted. 26 September 2026, 05:25 UTC

CredentialIssuerRoot usedDisclosed
nz_passportNZ Department of Internal Affairs (demonstration)NZ passport scheme (demonstration)given_name, family_name, date_of_birth, document_number, nationality, issuing_state, sex, date_of_expiry
mandateKowhai BankCalder Card Networkprincipal, authorization_details
10 checks, 10 passed
  • Passed: [nz_passport] issuer resolves under an accepted root: https://aw-dia.agents.showcase.raidiam.io chains to https://aw-roots.agents.showcase.raidiam.io/nz-passport-scheme and holds its accredited-passport-issuer mark
  • Passed: [nz_passport] issuer signature, Key Binding JWT and requested claims: signed by https://aw-dia.agents.showcase.raidiam.io (root https://aw-roots.agents.showcase.raidiam.io/nz-passport-scheme), bound to the holder key, nonce and audience match
  • Passed: [nz_passport] no over disclosure: disclosed only given_name, family_name, date_of_birth, document_number, nationality, issuing_state, sex, date_of_expiry
  • Passed: [mandate] issuer resolves under an accepted root: https://aw-kowhai.agents.showcase.raidiam.io chains to https://aw-roots.agents.showcase.raidiam.io/card-scheme and holds its card-issuer mark
  • Passed: [mandate] issuer signature, Key Binding JWT and requested claims: signed by https://aw-kowhai.agents.showcase.raidiam.io (root https://aw-roots.agents.showcase.raidiam.io/card-scheme), bound to the holder key, nonce and audience match
  • Passed: [mandate] no over disclosure: disclosed only principal, authorization_details
  • Passed: credential sets: nz_passport, mandate
  • Passed: same holder key: both bound to WWhDzCm9BvPefYFLp_9-SeAD6rKGtS_z4F-hI2jHpIs
  • Passed: mandate subject matches the passport holder: mandate for Tane Wiremu, passport of Tane Wiremu
  • Passed: mandate permits this booking: book_flight from 2026-10-10 to 2026-10-24, flight on 2026-10-10

Hotel Kestrelmoor

The latest result for each traveller, of 5 in the log.

Amelia Hart: guest name, proof of age over 25 and booking authority for KM-DBL.

Accepted. 26 September 2026, 09:01 UTC

The relying party marked this result as over disclosure: date_of_birth. This is run N2.

CredentialIssuerRoot usedDisclosed
passportHM Passport Office (demonstration)UK passport scheme (demonstration)given_name, family_name, date_of_birth
mandateNorthbankStanmoor Open Bankingprincipal_name, authorization_details
12 checks, 12 passed
  • Passed: [passport] issuer resolves under an accepted root: https://aw-hmpo.agents.showcase.raidiam.io chains to https://aw-roots.agents.showcase.raidiam.io/uk-passport-scheme and holds its accredited-passport-issuer mark
  • Passed: [passport] issuer signature, Key Binding JWT and requested claims: signed by https://aw-hmpo.agents.showcase.raidiam.io (root https://aw-roots.agents.showcase.raidiam.io/uk-passport-scheme), bound to the holder key, nonce and audience match
  • Passed: [passport] no over disclosure: disclosed only given_name, family_name, date_of_birth
  • Passed: [mandate] issuer resolves under an accepted root: https://aw-northbank.agents.showcase.raidiam.io chains to https://aw-roots.agents.showcase.raidiam.io/open-banking and holds its account-provider mark
  • Passed: [mandate] issuer signature, Key Binding JWT and requested claims: signed by https://aw-northbank.agents.showcase.raidiam.io (root https://aw-roots.agents.showcase.raidiam.io/open-banking), bound to the holder key, nonce and audience match
  • Passed: [mandate] no over disclosure: disclosed only principal_name, authorization_details
  • Passed: credential sets: passport, mandate
  • Passed: guest is over 25: age 38 on 2026-10-11, computed from the passport date_of_birth
  • Passed: same holder key: both bound to WWhDzCm9BvPefYFLp_9-SeAD6rKGtS_z4F-hI2jHpIs
  • Passed: mandate subject matches the guest: mandate for Amelia Hart, passport of Amelia Hart
  • Passed: mandate grants book_hotel: travel_booking grants book_hotel
  • Passed: stay inside the mandate trip window: trip 2026-10-10 to 2026-10-24, stay 2026-10-11 to 2026-10-13

Tane Wiremu: guest name, proof of age over 25 and booking authority for KM-DBL.

Accepted. 26 September 2026, 05:25 UTC

CredentialIssuerRoot usedDisclosed
licenceNZ Transport Agency (demonstration)NZ driving licence scheme (demonstration)family_name, given_name, age_over_25
mandateKowhai BankCalder Card Networkprincipal_name, authorization_details
12 checks, 12 passed
  • Passed: [licence] issuer signature and device signature: org.iso.18013.5.1.mDL, device signature over this request's session transcript
  • Passed: [licence] document signer resolves under an accepted root: https://aw-nzta.agents.showcase.raidiam.io publishes the document signer key, chains to https://aw-roots.agents.showcase.raidiam.io/nz-licence and holds its accredited-mdl-issuer mark
  • Passed: [licence] no over disclosure: disclosed only family_name, given_name, age_over_25
  • Passed: [mandate] issuer resolves under an accepted root: https://aw-kowhai.agents.showcase.raidiam.io chains to https://aw-roots.agents.showcase.raidiam.io/card-scheme and holds its card-issuer mark
  • Passed: [mandate] issuer signature, Key Binding JWT and requested claims: signed by https://aw-kowhai.agents.showcase.raidiam.io (root https://aw-roots.agents.showcase.raidiam.io/card-scheme), bound to the holder key, nonce and audience match
  • Passed: [mandate] no over disclosure: disclosed only principal_name, authorization_details
  • Passed: credential sets: licence, mandate
  • Passed: guest is over 25: licence age_over_25 is true
  • Passed: same holder key: both bound to WWhDzCm9BvPefYFLp_9-SeAD6rKGtS_z4F-hI2jHpIs
  • Passed: mandate subject matches the guest: mandate for Tane Wiremu, licence of Tane Wiremu
  • Passed: mandate grants book_hotel: travel_booking grants book_hotel
  • Passed: stay inside the mandate trip window: trip 2026-10-10 to 2026-10-24, stay 2026-10-11 to 2026-10-13

Brightlane Payments

The latest result for each traveller, of 10 in the log.

Amelia Hart: payment of 540.00 GBP to https://aw-travel.agents.showcase.raidiam.io/hotel.

Accepted. 26 September 2026, 07:23 UTC

CredentialIssuerRoot usedDisclosed
instrumentNorthbankStanmoor Open Bankingtoken_ref, instrument_type, currency
licenceDVLA (demonstration)UK driving licence scheme (demonstration)resident_address, resident_city, resident_postal_code, resident_country
12 checks, 12 passed
  • Passed: [instrument] issuer resolves under an accepted root: https://aw-northbank.agents.showcase.raidiam.io chains to https://aw-roots.agents.showcase.raidiam.io/open-banking and holds its account-provider mark
  • Passed: [instrument] issuer signature, Key Binding JWT and requested claims: signed by https://aw-northbank.agents.showcase.raidiam.io (root https://aw-roots.agents.showcase.raidiam.io/open-banking), bound to the holder key, nonce and audience match
  • Passed: [instrument] no over disclosure: disclosed only token_ref, instrument_type, currency
  • Passed: [licence] issuer signature and device signature: org.iso.18013.5.1.mDL, device signature over this request's session transcript
  • Passed: [licence] document signer resolves under an accepted root: https://aw-dvla.agents.showcase.raidiam.io publishes the document signer key, chains to https://aw-roots.agents.showcase.raidiam.io/uk-licence and holds its accredited-mdl-issuer mark
  • Passed: [licence] no over disclosure: disclosed only resident_address, resident_city, resident_postal_code, resident_country
  • Passed: credential sets: instrument+licence
  • Passed: same holder key: both bound to WWhDzCm9BvPefYFLp_9-SeAD6rKGtS_z4F-hI2jHpIs
  • Passed: billing address present: from the licence issued by https://aw-dvla.agents.showcase.raidiam.io
  • Passed: instrument currency: instrument GBP, payment GBP
  • Passed: instrument limits: the issuing bank holds the limit
  • Passed: issuing bank authorises: Northbank authorised 540.00 GBP

Tane Wiremu: payment of 600.00 NZD to https://aw-travel.agents.showcase.raidiam.io/airline.

Refused: issuing bank authorises: Kowhai Bank refused: the payment exceeds the aggregate limit. 26 September 2026, 05:25 UTC

CredentialIssuerRoot usedDisclosed
instrumentKowhai BankCalder Card Networktoken_ref, instrument_type, currency, billing_address
8 checks, 7 passed
  • Passed: [instrument] issuer resolves under an accepted root: https://aw-kowhai.agents.showcase.raidiam.io chains to https://aw-roots.agents.showcase.raidiam.io/card-scheme and holds its card-issuer mark
  • Passed: [instrument] issuer signature, Key Binding JWT and requested claims: signed by https://aw-kowhai.agents.showcase.raidiam.io (root https://aw-roots.agents.showcase.raidiam.io/card-scheme), bound to the holder key, nonce and audience match
  • Passed: [instrument] no over disclosure: disclosed only token_ref, instrument_type, currency, billing_address
  • Passed: credential sets: instrument
  • Passed: billing address present: from the instrument issued by https://aw-kowhai.agents.showcase.raidiam.io
  • Passed: instrument currency: instrument NZD, payment NZD
  • Passed: instrument limits: the issuing bank holds the limit
  • Failed: issuing bank authorises: Kowhai Bank refused: the payment exceeds the aggregate limit
Engineer notes

The search service checks the wallet attestation of the agent and the wallet scheme mark of its Wallet Provider. It asks for no credential. The buttons on this page do not call search, because only the agent holds the key that signs the attestation.

The bank checks the amount, the currency and the payee that the agent approved, one charge for each approval, and the limit of the instrument. The bank also checks that the mandate grants the purpose that the agent signed, and that the service dates are inside the trip window. The bank does not connect a purpose to a payee. The agent signs only the purpose and the dates of the booking that its operator chose, and it refuses a payment request that names anything else.

The airline checks the trip window and the book_flight permission in the task mandate. The hotel checks the book_hotel permission, and that the stay is inside the trip window. In this demonstration the bank creates the instrument token reference itself. The agent answers each request by direct_post with no person at the wallet.

The minimisation matrix

The rows are the fields that the agent disclosed. The columns are the relying parties. A cell is filled only where the log of that relying party shows that it received the field. The airline receives the passport fields that it asks for and the task mandate. The hotel receives a name, an over 25 flag and the task mandate grant. The payment service provider receives the instrument and a billing address, and no passport field.

This is minimisation: each party receives only what it asks for and is entitled to ask for. This page does not claim unlinkability. Two relying parties that compare their records can still link one traveller.

live read 26 September 2026, 09:17 UTC.

A run that the hotel marks as over disclosure (N2) is shown under the negative runs, not here. The search column comes from the code: search asks for no credential.

Amelia HartFrom Fernwing Airways at 26 September 2026, 07:23 UTC; Hotel Kestrelmoor at 26 September 2026, 07:23 UTC; Brightlane Payments at 26 September 2026, 07:23 UTC
FieldRoutewise (search)from the codeFernwing AirwaysHotel KestrelmoorBrightlane Payments
instrument: currencynot receivednot receivednot receivedreceived
instrument: instrument_typenot receivednot receivednot receivedreceived
instrument: token_refnot receivednot receivednot receivedreceived
licence: age_over_25not receivednot receivedreceivednot received
licence: family_namenot receivednot receivedreceivednot received
licence: given_namenot receivednot receivedreceivednot received
licence: resident_addressnot receivednot receivednot receivedreceived
licence: resident_citynot receivednot receivednot receivedreceived
licence: resident_countrynot receivednot receivednot receivedreceived
licence: resident_postal_codenot receivednot receivednot receivedreceived
mandate: authorization_detailsnot receivedreceivedreceivednot received
mandate: principalnot receivedreceivednot receivednot received
mandate: principal_namenot receivednot receivedreceivednot received
passport: date_of_birthnot receivedreceivednot receivednot received
passport: date_of_expirynot receivedreceivednot receivednot received
passport: document_numbernot receivedreceivednot receivednot received
passport: family_namenot receivedreceivednot receivednot received
passport: given_namenot receivedreceivednot receivednot received
passport: issuing_statenot receivedreceivednot receivednot received
passport: nationalitynot receivedreceivednot receivednot received
passport: sexnot receivedreceivednot receivednot received
Tane WiremuFrom Fernwing Airways at 26 September 2026, 05:25 UTC; Hotel Kestrelmoor at 26 September 2026, 05:25 UTC; Brightlane Payments at 26 September 2026, 05:25 UTC
FieldRoutewise (search)from the codeFernwing AirwaysHotel KestrelmoorBrightlane Payments
instrument: billing_addressnot receivednot receivednot receivedreceived
instrument: currencynot receivednot receivednot receivedreceived
instrument: instrument_typenot receivednot receivednot receivedreceived
instrument: token_refnot receivednot receivednot receivedreceived
licence: age_over_25not receivednot receivedreceivednot received
licence: family_namenot receivednot receivedreceivednot received
licence: given_namenot receivednot receivedreceivednot received
mandate: authorization_detailsnot receivedreceivedreceivednot received
mandate: principalnot receivedreceivednot receivednot received
mandate: principal_namenot receivednot receivedreceivednot received
passport: date_of_birthnot receivedreceivednot receivednot received
passport: date_of_expirynot receivedreceivednot receivednot received
passport: document_numbernot receivedreceivednot receivednot received
passport: family_namenot receivedreceivednot receivednot received
passport: given_namenot receivedreceivednot receivednot received
passport: issuing_statenot receivedreceivednot receivednot received
passport: nationalitynot receivedreceivednot receivednot received
passport: sexnot receivedreceivednot receivednot received

The negative runs

Four runs show where each control sits. In N1, the passport issuer stops an agent whose Wallet Provider has no accreditation, and it records the reason. In N2, the hotel accepts a date of birth as an age check, and it marks this as over disclosure beside the licence path. In N3, the bank stops an upgrade that is more than the remaining limit, and it names both amounts. In N4, the airline stops a presentation signed by a different key.

live read 26 September 2026, 09:17 UTC.

N1, at the token endpoint of the passport issuer

No entry in the refusal log of either passport issuer, and no recording.

N2, at the hotel

Over disclosed with the passport: date_of_birth (26 September 2026, 09:01 UTC).

The licence path disclosed, from the licence and the task mandate: family_name, given_name, age_over_25, principal_name, authorization_details.

N3, at the issuing bank

Kowhai Bank refused: the payment exceeds the aggregate limit. Requested NZD 600.00, permitted NZD 430.00 (26 September 2026, 05:25 UTC).

N4, at the airline

No entry in the log and no recording.

Bank refusal logs
BankReasonTime
Kowhai Bankthe payment exceeds the aggregate limit26 September 2026, 05:25 UTC
Kowhai Bankthe payment exceeds the aggregate limit26 September 2026, 05:15 UTC
Northbankthe payment exceeds the aggregate limit26 September 2026, 05:14 UTC
Engineer notes

N1 is refused at the token endpoint of the issuer. That endpoint answers with a general client authentication failure, so the reason on this page comes from the refusal log of the issuer at GET /refusals/recent. This demonstration runs one agent, and its Wallet Provider is accredited, so N1 shows only when the refusal log or a recording holds an entry.

N2 is a success, and the over disclosure is the finding. N3 names the bank as the party that refused, with the requested and permitted amounts. N4 fails on the Key Binding JWT signature. N4 needs a second agent with a copy of the credentials of the first agent. This demonstration runs one agent, so N4 runs in the automated tests only.

Other ways to get the same control

This design is one choice among several. The regulator chapter compares six patterns on the same trip, and assesses this one against seven controls.

Compare the six patterns against the seven controls

The thesis

The standards that this demonstrator uses are published, and the page calls a specification final only where the specification says so.312230 The schemes already exist. This demonstrator adds the connection between them: each scheme publishes its membership as a federation, and each relying party resolves it at run time.

Each party keeps the role it has today. The scheme accredits its members. Each issuer vouches for its own facts. The bank enforces the spend. For a scheme, the step is to publish its membership as a federation root, with its rules and its accreditation process unchanged.

Revocation and change of a mandate are out of scope for this demonstration.

Sources

Each claim about the world outside this demonstrator cites a primary source. The quote is taken word for word from the page, on the date shown.

  1. Raidiam was founded in London in 2016 and helped design the trust infrastructure of UK Open Banking. https://www.raidiam.com/about-us. Quote: “Raidiam helped design the UK’s Open Banking trust infrastructure: the world’s first regulated open data ecosystem.”. Read 26 September 2026.
  2. UK Open Banking, whose first trust framework Raidiam built, has 249 third party providers and 90 account providers. https://www.raidiam.com/case-studies. Quote: “UK Open Banking Built the world's first trust framework for Open Banking. The architecture that shaped how regulated data sharing works, globally. 249 TPPs 90 Account providers”. Read 26 September 2026.
  3. By 2026, Open Finance Brasil had 740 participating financial institutions, and Raidiam Connect powers its core directory and trust framework. https://www.raidiam.com/case-studies/open-finance-brasil. Quote: “By 2026, Open Finance Brasil had 740 participating financial institutions, serving around 60 million customers”. Read 26 September 2026.
  4. In January 2026 Open Finance Brasil processed 30 billion API calls in one month. https://www.raidiam.com/case-studies/open-finance-brasil. Quote: “In Jan 2026, the system processed 30 billion API calls in a single month”. Read 26 September 2026.
  5. In Australia, Raidiam's trust framework and infrastructure underpin a national digital identity exchange, in which consumers use their existing mobile banking logins to verify their identity. https://www.raidiam.com/case-studies/enabling-standards-based-digital-identity-ecosystem-in-australia. Quote: “Raidiam's trust framework solution and infrastructure underpin this exchange, enabling consumers to use their existing mobile banking logins to verify their identity for digital transactions.”. Read 26 September 2026.
  6. In that exchange, banks act as trusted parties and verify identity for over 10 million customers. https://www.raidiam.com/case-studies/enabling-standards-based-digital-identity-ecosystem-in-australia. Quote: “banks acting as Trusted Parties and merchants across sectors such as retail, telecommunications, and real estate integrating as Relying Parties, enabling secure digital identity verification for over 10 million customers.”. Read 26 September 2026.
  7. ConnectID is an initiative of Australian Payments Plus, the domestic payments operator, and is accredited by the Australian Government as an identity exchange. https://www.auspayplus.com.au/solutions/connectid. Quote: “ConnectID is accredited as an identity exchange by the Australian Government”. Read 26 September 2026.
  8. In New Zealand, Confirmation of Payee covers 23 financial institutions and more than 95 percent of accounts. https://www.raidiam.com/case-studies. Quote: “23 Financial institutions 95%+ Account coverage”. Read 26 September 2026.
  9. Raidiam designed and delivered the first Open Banking trust framework in the UK. https://www.raidiam.com/about-us. Quote: “designing and delivering the world’s first Trust Framework for Open Banking in the UK”. Read 26 September 2026.
  10. Raidiam's infrastructure powers Open Finance and Open Insurance in Brazil. https://www.raidiam.com/about-us. Quote: “including enabling Open Finance and Open Insurance in Brazil”. Read 26 September 2026.
  11. Raidiam's infrastructure powers the national digital identity scheme that connected Australia's Big Four banks. https://www.raidiam.com/case-studies. Quote: “Raidiam connected Australia's Big Four banks through a national digital identity scheme”. Read 26 September 2026.
  12. Raidiam's infrastructure powers Confirmation of Payee in New Zealand. https://www.raidiam.com/case-studies. Quote: “New Zealand Confirmation of Payee The fastest national CoP deployment on record.”. Read 26 September 2026.
  13. Swedish BankID is a bank issued electronic identity, and the identity check happens at the bank. https://www.bankid.com/en/individuals/about-bankid. Quote: “This step is done in your bank branch, often when you become a customer.”. Read 26 September 2026.
  14. Denmark's MitID is one digital ID for online banking and for public self service solutions. https://www.mitid.dk/en-gb/about-mitid/. Quote: “MitID is a digital ID that can be used for various purposes, including transferring money in online banking or logging into public self-service solutions”. Read 26 September 2026.
  15. The Finnish Trust Network lets a service obtain electronic identification through a broker without a contract with every identification provider. https://www.kyberturvallisuuskeskus.fi/en/our-activities/regulation-and-supervision/electronic-identification. Quote: “The aim of the trust network is to allow electronic services to centrally obtain electronic identification from the identification broker service without having to conclude contracts with all identification means providers.”. Read 26 September 2026.
  16. Visa Intelligent Commerce provisions agent specific payment tokens. https://developer.visa.com/capabilities/visa-intelligent-commerce. Quote: “Provisioning and life cycle management of agent-specific payment tokens that can be used by agents to make secure transactions on behalf of the user”. Read 26 September 2026.
  17. Visa's Trusted Agent Protocol gives the merchant a signal that the agent is a Visa trusted agent. https://developer.visa.com/capabilities/trusted-agent-protocol. Quote: “An indication that the agent is a Visa trusted agent”. Read 26 September 2026.
  18. Mastercard Agent Pay registers and verifies AI agents before they may transact on the Mastercard network. https://www.mastercard.com/global/en/news-and-trends/stories/2025/agentic-commerce-framework.html. Quote: “Mastercard’s Agent Pay Acceptance Framework begins by registering and verifying AI agents before they are permitted to transact on the Mastercard network.”. Read 26 September 2026.
  19. Mastercard's Verifiable Intent, introduced with Google, uses selective disclosure as defined in RFC 9901, the format that SD-JWT VC builds on. https://www.mastercard.com/global/en/news-and-trends/stories/2026/verifiable-intent.html. Quote: “Verifiable Intent uses Selective Disclosure, a privacy control technique”. Read 26 September 2026.
  20. SD-JWT, the selective disclosure format, is RFC 9901 on the IETF standards track. https://datatracker.ietf.org/doc/rfc9901/. Quote: “This is an Internet Standards Track document.”. Read 26 September 2026.
  21. OpenID Federation mediates trust through a third party, for a multilateral federation in which bilateral agreements might not be practical. https://openid.net/specs/openid-federation-1_0.html. Quote: “In a multilateral federation, bilateral agreements might not be practical, in which case, trust can be mediated by a third party. That is the model used in this specification.”. Read 26 September 2026.
  22. OpenID for Verifiable Credential Issuance 1.0 is a final OpenID Foundation specification. https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0.html. Quote: “Status: Final”. Read 26 September 2026.
  23. SD-JWT VC is an IETF OAuth working group document, which the working group has submitted to the IESG for publication. https://datatracker.ietf.org/doc/draft-ietf-oauth-sd-jwt-vc/. Quote: “WG state Submitted to IESG for Publication”. Read 26 September 2026.
  24. The intended IETF status of SD-JWT VC is Proposed Standard. https://datatracker.ietf.org/doc/draft-ietf-oauth-sd-jwt-vc/. Quote: “Intended RFC status Proposed Standard”. Read 26 September 2026.
  25. SD-JWT VC is one of the standardised formats that the EUDI Wallet Architecture and Reference Framework says can be used within the EUDI Wallet ecosystem. https://eu-digital-identity-wallet.github.io/eudi-doc-architecture-and-reference-framework/latest/main/05-data-model-and-data-exchange-protocols/. Quote: “Within the EUDI Wallet ecosystem, the following standardised formats for electronic attestations of attributes can be used”. Read 26 September 2026.
  26. OAuth attestation based client authentication is an IETF OAuth working group specification. https://datatracker.ietf.org/doc/draft-ietf-oauth-attestation-based-client-auth/. Quote: “Discussion of this document takes place on the Web Authorization Protocol Working Group mailing list”. Read 26 September 2026.
  27. HAIP 1.0 requires OAuth2 client authentication at the PAR and Token endpoints. https://openid.net/specs/openid4vc-high-assurance-interoperability-profile-1_0.html. Quote: “Wallets MUST use, and Issuers MUST require, an OAuth2 Client authentication mechanism at OAuth2 Endpoints that support client authentication (such as the PAR and Token Endpoints).”. Read 26 September 2026.
  28. HAIP 1.0 recommends that ecosystems adopt the Wallet Attestation of OpenID4VCI Appendix E. https://openid.net/specs/openid4vc-high-assurance-interoperability-profile-1_0.html. Quote: “Ecosystems that desire wallet-issuer interoperability on the level of Wallet Attestations SHOULD require Wallets to support the authentication mechanism and Wallet Attestation format specified in Appendix E”. Read 26 September 2026.
  29. The Wallet Attestation of OpenID4VCI 1.0 Appendix E follows the IETF Client Attestation JWT. https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0.html. Quote: “The Wallet Attestation format follows Section 5.1”. Read 26 September 2026.
  30. OpenID for Verifiable Presentations 1.0 is a final OpenID Foundation specification. https://openid.net/specs/openid-4-verifiable-presentations-1_0.html. Quote: “Status: Final”. Read 26 September 2026.
  31. OpenID Federation 1.0 is a final OpenID Foundation specification. https://openid.net/specs/openid-federation-1_0.html. Quote: “Status: Final”. Read 26 September 2026.
  32. A New Zealand driver licence shows the holder's address only if the holder chose to have it printed. https://www.nzta.govt.nz/driver-licences/getting-a-licence/your-driver-licence-explained. Quote: “address, if you chose to have that printed on your licence.”. Read 26 September 2026.