Skip to content

Go live

  • Domain and HTTPS. The box must be served from a real domain over HTTPS.
  • Keys in the right places. Publishable key on the page, secret key on the server only.
  • Your production origins on the tenant’s allowed list. Send us the exact host names.
  • Production trust. Ask us to switch your tenant from the demo issuer to the real authority’s certificate, and to register your reader certificate if you want the wallet to show your own name.
  • Server-side result check on every step that depends on identity (Quickstart, step 5).
  • Request only what you need. Prefer age_over_21 to a birth date; leave out the portrait unless staff compare faces. See Security and privacy.
  • Copy. fields labels the customer understands; wallet-name and wallet-logo set to the wallet they have.
  • Test on a phone, same device (tap) and cross device (scan from another phone).
  • Watch failed and expired rates: many expired means customers take longer than the request window (ask us to raise it); many failed usually means an untrusted issuer or an old wallet build. See Errors and states.
  • Install the new .tgz when an update arrives; the version is in the file name.

Next: the element reference and the Verify API reference.