Compliance
Relying party
A relying party is whoever asks an EU Digital Identity Wallet for data and relies on the answer, which in practice means your service. The EU framework makes it a registered role, not an informal one: you register with a national authority, and that registration is what eventually gets you the access certificate a wallet checks before releasing anything.
Also called: relying party, wallet relying party, RP, verifier
At a glance
- Also called
- Wallet-relying party, verifier
- Who it is
- Whoever asks the wallet and acts on the answer, usually the service
- Registered with
- A national registrar, under the EUDI framework
- Proves itself with
- A wallet relying party access certificate (WRPAC)
- Acceptance duty
- Regulated relying parties, December 2027
The role, and who holds it
Three parties appear in every wallet interaction. An issuer vouches for an attribute and signs a credential. A holder keeps it on their device and decides what to release. A relying party asks a question and acts on the answer. If you run the shop, the platform or the gambling site, you are the relying party, and the duties attach to you rather than to your vendor.
That last point is the one worth being careful about. Buying a hosted verification service does not move the role; it moves the plumbing. Whether it also moves the registration obligation is genuinely unsettled and may differ by member state, which is a question for counsel rather than a vendor.
Registration is not paperwork for its own sake
The point of registering relying parties is that a wallet can show its user who is asking and what they are entitled to ask for. Without it, "the user consented" means very little, because the user cannot tell a legitimate request from a convincing one.
This is why the technical and the legal sides meet at the access certificate: registration produces a certificate, the wallet checks the certificate, and only then does the consent screen name you. Without one, a production wallet refuses before the user is asked anything at all.
What it means for a timeline
Member states must make the wallet available under Regulation (EU) 2024/1183, and relying parties in regulated sectors must accept it by December 2027. Between now and then the constraint is not usually your integration, which is stable, but the ecosystem around it: registers opening, certificates issuing, wallets shipping.
The practical consequence is that integration work does not need to wait. Build against a sandbox, and go live as the rollout lands, because the code is the same either way.
Check one yourself
Reading about it only gets you so far. These are free validators in Tessio Labs, no signup, and nothing you paste is stored.
Why it matters
The role sits with you, not with your verification vendor. When you write your compliance position, write it as the relying party, because that's how the regulation reads it.
If a vendor can't tell you who holds the registration and the access certificate in their model, that's the question to keep asking, since it determines whether a production wallet will complete a check at all.
Frequently asked
Is the relying party the same as the verifier?
In practice the words are used interchangeably. "Verifier" tends to mean the software that checks the cryptography, and "relying party" the legal entity that asks and acts. They are often not the same organisation, which is exactly why the distinction is worth keeping.
Do I register if I use a hosted verification service?
Technically the access certificate binds to the host that sends the request, which with a hosted service is your provider. Whether the regulation also expects you to be registered in your own right is unsettled and may vary by member state. Ask your counsel rather than your vendor.
What can a relying party ask for?
Only what its registration covers, which is the point of registering. A wallet is meant to show the user what you're entitled to request, so over-asking is visible rather than silent.
Primary sources
This is a plain language explanation, not legal advice. Specifications and dates in this area move, so check anything you are going to rely on against the primary sources.
Keep reading
Age verification API
Or skip the theory and build against it
Tessio proves someone is over 18 from their EU Digital Identity Wallet and stores no personal data. Access is invite only while we onboard design partners. Tell us what you're building.