Verifiable credentials interoperability is the way to scale EU digital identity: that’s what the APTITUDE Large Scale Pilot is designed to solve, that’s what Indicio has already built and deployed.

 

By Kent Iverson

I am currently in Geneva to participate in an interoperability meeting on APTITUDE, one of the Large-Scale Pilots for the European Union Digital Identity Wallet, and the Global Digital Collaboration Conference 2026. For many of us, these meetings are where big ideas about digital identity get put into practice. Wallet providers, government issuers, airlines, document manufacturers, and standards bodies discuss how to set rules so that digital credentials can be trusted and used across international borders.

Bridging identity models with interoperable verifiable credentials

Over the last ten years, digital identity has largely diverged into two paths. One is defined by corporate identity provider platforms, where identity services are bundled into expansive tech ecosystems that offer sophisticated software and seamless device integration, yet remain tied to proprietary roadmaps. The other is the state-driven approach, where national identity schemes, mobile driver’s licenses, and digital travel documents are established under government authority, providing legal certainty and accountability, but which may be limited by the borders of their own jurisdiction.

Both paths deliver value, but the businesses that actually use the credentials are left stuck in the middle. An airline that builds on a platform is dependent on that platform’s roadmap while having to comply with a border agency that mandates different standards. Airlines, airports, hotels, and border authorities are all on the receiving end. They don’t get to choose the credential, the wallet, or the device a traveler arrives with; they simply have to accept whatever the traveler carries, and make the identity check work.

Organizations, public and private, need a way to accept a variety of credentials while keeping control of their systems, their vendor choices, and their data.This is where Indicio fits: we’re the neutral layer that lets credentials work between systems and governments.

That is the problem APTITUDE is designed to solve by bringing many wallets, many credential formats, and many governments into a single interoperability test spanning digital travel credentials, ticketing, vehicle registration, and payments across 11 EU member states. It is the interoperability-and-trust question posed at continental scale. 

This is the question Indicio spends every day answering in production. We are at the APTITUDE meeting because we have already solved it commercially — moving real travelers through real borders — with credentials built to European and global standards. Interoperability still has work to do, but the format question has moved toward a practical answer: several formats coexisting, software that reads them all and presents the right credential for the right purpose or verifier with the person only needing to confirm their consent to share their data.

Interoperability is nearly solved, trust is next

Trust is the harder problem. A well-formed, correctly signed mdoc proves that a credential was signed. It does not, by itself, prove that the signer had the authority to issue that credential for that purpose. Issuer authorization, trust lists, and the way a verifier in one country relies on an authority decision made in another are still open questions. I expect that to be the loudest conversation in the room at Palexpo, and I plan to spend most of my time in it.

Aviation has faced a version of this before. The solution was not for airlines to merge into one airline. They built interlining, so a ticket issued by one carrier could be honored by another and the passenger could keep traveling. Each carrier kept its own systems and commercial identity, and the industry agreed on how to pass value between systems that stayed separate. Credentials need the same kind of arrangement; the work is further along than many people realize.

Where we already run it

We know, because we already run it — and increasingly in the places the industry is racing toward. In agentic AI, we have enabled agents to verify a traveler’s digital travel credential for access to an LLM, and we are working on enabling agents to act with a real person’s delegated authority, so that counterparties can trust it without a prior relationship. In financial services, we are deploying verifiable credentials with authenticated biometrics — similar to digital travel credentials — to onboard account holders, verify account access, meet KYC and AML requirements, and execute payments. 

The same infrastructure runs at the border. Our Aruba deployment, built with SITA, is a live border-control program: travelers arrive and present a credential with their face and a phone, and further border deployments are underway. The context changes — a bank, an airport, an AI agent — but the core requirement does not. An organization has to establish a fact about a person, or about something acting for a person, from a credential someone else issued, while keeping only what it needs. We are already solving real customer problems and moving entire industries forward, and we can do that because we are not wedded to any single technology format.

Built for verifiable credentials interoperability in production

Indicio Proven does this across formats that are in production today — mdoc and mDL under ISO 18013-5 and 18013-7, SD-JWT VC, W3C Verifiable Credentials, AnonCreds, and ICAO DTC-1 and DTC-2, exchanged via OpenID4VCI and OpenID4VP. ISO 18013-7 matters most here, because it moves verification beyond the kiosk tap to remote checks, pre-travel, and online check-in, where carriers can take real cost out of operations. While the market fills with companies comparing wallets and formats, most have never run a system where verification had to hold under pressure. Ours move real people through real borders and real KYC at commercial scale, day after day.

The same shift is now reaching the document manufacturers: the companies that have spent decades producing passports and identity cards for governments. They already hold the issuing relationships and understand the authority model; many now need verification infrastructure that lets those documents work beyond issuance. Several of them will be there too.

I’ll be in Geneva from August 30 through September 3. If you issue credentials, build wallets, run a travel program, or help decide which verifiers you can trust, come find me. Bring the case that has been hard to make work. Those are the ones that matter.

Kent@indicio.tech