Platform
Platform
Drop-In Authentication
Passkeys
Phishing-resistant, FIDO2/WebAuthn
Biometric authentication
Face and device-native biometrics
WhatsApp OTP
Global reach, lower cost than SMS
Email OTP
Universal second factor
App push authentication
Native device push notifications
Palm biometrics
Contactless identity verification
KEY FEATURES
No-code rules engine
Step-up auth, risk policies, alerts
User observability
Audit trails, dynamic linking
Risk-based authentication
Adaptive MFA by context
Session management
Persistent sessions across channels
Digital credential verification
Accept and verify digital IDs
Pre-built UI
Fastest deployment path
Passkeys
Deploy phishing-resistant passkeys across web and mobile in days
Solutions
Solutions
USE CASE
Account Takeover Prevention
Stop ATO without adding friction
Go Passwordless
Replace passwords with passkeys
Call Centre Authentication
Verify callers without KBA
SMS Cost Optimisation
Cut OTP costs up to 90%
Existing Apps (Drop-In)
Add auth without re-architecting
Palm biometric payments
Contactless in-store payments
INDUSTRY
Financial Services & Banking
Secure high-value transactions
Healthcare
Authentication for ePHI access
Loyalty Programs
Protect points and member accounts
ROLE
Engineering
Fast integration, flexible SDKs
PricingCustomers
Resources
Resources
LEARN
Blog
Guides
Docs
COMPANY
About Us
Why Authsignal
Partners
Careers
Security
Contact
INTEGRATIONS
Amazon Cognito
Auth0
Azure AD B2C
Custom identity provider
Duende IdentityServer
Keycloak
NextAuth.js
Salesforce
Docs
Start a trial
Book a callLogin
AUS Flag

Authsignal secures millions of passkey transactions out of our hosted Sydney region.

AUS Flag

Authsignal secures millions of passkey transactions out of our hosted Sydney region.

Join us today!
Right icon
Blog
/
Current article
Digital IDs

Digital Identity Credentials Are Going Global. Authsignal Makes Them Drop-in.

⬤
August 5, 2026
Share
Authsignal blog hero for Digital Identity Credentials Are Going Global. Authsignal Makes Them Drop-in.

Digital credentials are rolling out globally. Here's how businesses can be ready to accept and verify them without rebuilding their identity stack.

Digital credentials are no longer theoretical

For years, the concept of a digital driving licence or a digital identity credential has lived mostly in policy papers and pilot programmes. That's changing fast.

Across the United States, more than 20 states currently support mobile driver's licenses, with several more expected by the end of 2026. The EU mandates that all member states offer digital identity wallets by the end of this year under eIDAS 2.0, and service providers will be required to accept digital credentials by 2027. Apple Wallet and Google Wallet already support mobile driving licences and government-issued credentials in multiple jurisdictions. Australia has committed AUD $288 million to expand its national digital ID system. In New Zealand, the Digital Identity Services Trust Framework took effect in July 2025, with digital driving licences, the digital Kiwi Access Card, and Business Director credentials on the near-term horizon.

The infrastructure is being built. What's been missing is a straightforward way for businesses to accept and verify these credentials without a major engineering project.

That's what Authsignal's Digital Credential Verification delivers.

What is a digital credential, and why does it matter?

A digital credential is a cryptographically signed, identity-bound representation of identity claims issued by a trusted authority. Think of it as the digital equivalent of a physical driving licence or passport, except every claim is independently verifiable, the credential is cryptographically bound to its rightful holder, and the holder controls exactly which fields they share.

Three properties make a digital credential meaningfully different from a photo of an ID or a self-asserted claim:

Issuer authenticity. The credential is signed by the issuing authority, and that signature chains back to a recognised root of trust (for example, a government certificate authority). A verifier can confirm the credential was genuinely issued by the claimed authority.

Tamper evidence. The identity claims are hashed and committed to in an issuer-signed structure. Any alteration (changing a name, a date of birth, an address) breaks the hash chain and fails verification.

Holder possession. At presentation time, the wallet produces a fresh cryptographic proof signed by a hardware-bound key on the holder's device. A stolen credential response cannot be replayed. The person presenting the credential must have the device it was issued to.

The holder also controls disclosure: a verifier requests specific claims, and the wallet reveals only those claims. The issuer's cryptographic signature holds even when only a subset of fields is shared. This is selective disclosure, and it's one of the most powerful features of the digital credentials model.

ISO mdoc: the standard behind digital identity credentials

The digital credentials ecosystem has two main format families: ISO mdoc (defined by ISO/IEC 18013-5 and the ISO 23220 series) and W3C Verifiable Credentials (the W3C VC Data Model in its JWT and JSON-LD variants).

Both can encode identity claims and support selective disclosure. They differ in adoption, encoding, and the assurance level that issuers are willing to certify against.

The credentials businesses will encounter first are overwhelmingly mdoc. Mobile driving licences issued by AAMVA member states across the US, several Australian states that already offer mDLs and digital photo IDs with others transitioning or launching, NZ digital driving licences, and the digital Kiwi Access Card all use the mdoc format. Some EU PID credentials will also use mdoc, while others will use the W3C Verifiable Credentials format. Apple Wallet and Google Wallet treat mdoc as first-class. The browser Digital Credentials API on iOS currently accepts only mdoc-encoded credentials.

Authsignal's Digital Credential Verification is built mdoc-first, because that's where the credentials are. The architecture supports any ISO mdoc digital credential, not just government-issued ones, positioning businesses to accept credentials from a broadening ecosystem as it matures.

What Digital Credential Verification does

Digital Credential Verification provides a single integration point for businesses to accept and verify digital credentials. The verification flow works like this:

1. The business requests verification, specifying the fields needed. For example: "confirm this person is over 18" or "verify their name and date of birth." Only the requested fields are included in the presentation.

2. The user presents their credential from their wallet. Digital Credential Verification supports Apple Wallet, Google Wallet, standards-based government wallets including the Govt.nz wallet, and any compatible wallet that implements the relevant presentation protocols. The user sees a consent screen showing exactly which fields will be shared, and only those fields are disclosed.

3. Optionally, biometric holder verification confirms the person presenting the credential is the real holder. Orchestrated through Authsignal's biometric vendor marketplace, the verification performs a live face match between the credential's portrait photo and the user's real-time selfie. iProov's Genuine Presence Assurance technology is the launch provider for this capability.

4. The verification result is returned to the business application. A cryptographically verified result: not a probability score, not a fuzzy match against a document photo, but a deterministic answer backed by the issuing authority's signature and the holder's device-bound proof.

The integration is wallet-agnostic. It works across Apple, Google, government, and third-party wallets. It supports same-device presentation (the user is on their phone, the wallet opens natively) and cross-device presentation (the user is on a desktop, a QR code bridges to the wallet on their phone). Authsignal's pre-built UI provides the fastest deployment path, and the developer-friendly integration drops into existing identity stacks, the same architectural approach Authsignal customers already use for passkeys and adaptive MFA.

Biometric holder verification: the marketplace model

A digital credential proves three things: it was issued by a trusted authority, it hasn't been tampered with, and it was presented from the device it was bound to. But it doesn't prove, on its own, that the person holding the device right now is the person the credential was issued to.

For low-risk interactions (confirming a customer is over 18 to purchase a bottle of wine) the device-binding guarantee may be sufficient. For high-assurance use cases like financial services KYC, account recovery, and high-value transactions, biometric holder verification closes the gap.

Authsignal orchestrates biometric holder verification through its biometric vendor marketplace. The marketplace architecture allows businesses to configure the biometric provider that best fits their requirements, with the platform designed to support multiple best-of-breed vendors. At launch, iProov's Genuine Presence Assurance technology provides the biometric binding layer, performing a real-time face match between the portrait photo embedded in the credential and the user's live selfie. This confirms the credential holder is the real person, blocking stolen devices, shared wallets, and deepfake attacks. Portrait images are processed transiently and are not retained after verification.

This isn't a new partnership. Authsignal and iProov announced their global strategic partnership in June 2025, integrating iProov's Biometric Solution Suite into the Authsignal platform. Digital Credential Verification extends that collaboration into a concrete new capability, with the marketplace model ensuring businesses aren't locked into a single biometric vendor as the ecosystem evolves.

iProov's technology is used by the US Department of Homeland Security, the UK Home Office, the UK National Health Service, the Australian Taxation Office, and GovTech Singapore, among others.

Use cases

Age verification. Digital credentials support fields like age_over_18 as a simple boolean. The verifier sees only the answer, not the customer's date of birth or any other identity information. This is instant, cryptographic age confirmation without exposing full identity, applicable to online alcohol and tobacco purchase, gambling registration, age-gated event ticketing, and any context where a business needs to confirm a customer meets an age threshold. With age assurance regulations accelerating globally (25 US states have now adopted some form of age verification legislation, the UK's Online Safety Act is being enforced, Australia's Social Media Minimum Age requirement is live, and New Zealand is building an age assurance credential for its government-issued digital wallet) the demand for privacy-preserving, cryptographically backed age verification is growing fast.

KYC and onboarding. A digital credential collapses the traditional KYC checklist (document capture, selfie, liveness check, document verification, fuzzy match) into a single cryptographic verification. The result is faster, deterministic, and higher assurance than heuristic document-detection vendors. Use cases include bank account opening, fintech registration, telco SIM activation, and insurance onboarding.

Consumer financial services step-up. The same credential that onboarded a customer can authenticate them at high-risk touchpoints throughout the relationship. A verified digital driving licence becomes a step-up factor stronger than SMS, stronger than email OTP, and harder to phish than cross-device passkeys. Applicable to high-value transaction approval, new payee additions, and periodic KYC refresh.

Account recovery. A customer who has lost access to their account can prove ownership with their digital credential. No passwords, no SMS codes, no phone support queues. The credential provides a cryptographic proof of identity that is stronger and faster than any legacy recovery flow.

Business verification. Business Director credentials, like those being developed by MBIE in New Zealand, can prove authority to act on behalf of a business. This collapses days of documentation back-and-forth for B2B account onboarding, corporate banking, and regulatory filings into a single verified presentation.

NZ Government Marketplace listing

Authsignal is now listed on the NZ Government Marketplace under the new Digital Identity channel, established under the Digital Identity Services Trust Framework Act 2023. This means NZ government agencies can engage Authsignal as a digital identity service provider through the government's standard procurement channel. The listing covers Authentication Services, Binding Services, Information Services, and Verification Support Services.

The Digital Identity channel represents the NZ Government's recognition that digital identity services are becoming core infrastructure. Being listed alongside this new channel positions Authsignal as a trusted provider in the emerging NZ digital identity ecosystem.

What's next

Justin Soong, Authsignal's Founder and Director of Product, will be speaking on the panel "Enabling Better Customer Experiences: Digital Identity in Action" at the Digital Trust Hui Taumata in Wellington on 11 August 2026. The panel will explore what digital identity unlocks for everyday customer journeys, the practical question that sits behind every credential standard and every trust framework.

If your team is evaluating how to accept digital credentials, we'd welcome the conversation.

Explore Digital Credential Verification →

Book a demo →

Digital Trust Hui Taumata, 11 August 2026, Te Papa Tongarewa, Wellington →

‍

‍

Question icon
Have a question?
Talk to an expert
NewsletterDemo PasskeysView docs
Digital IDs

You might also like

Hong Kong's SFC has told brokers and crypto platforms to drop OTP login
SMS OTP
Passkeys

Hong Kong's SFC has told brokers and crypto platforms to drop OTP login

August 5, 2026
Why Singpass built its own passkey manager instead of using iCloud Keychain
Passkeys
Synced passkeys
Device-bound passkeys

Why Singpass built its own passkey manager instead of using iCloud Keychain

July 11, 2026
The passkey UX patterns that drive adoption in 2026
Passkeys
Passkeys implementation

The passkey UX patterns that drive adoption in 2026

July 2, 2026

Secure your customers’ accounts today with Authsignal

Passkey demoCreate free account
Authsignal Purple Logo

Authsignal is a drop-in authentication and orchestration layer for consumer-facing businesses. Passkeys, adaptive MFA, and omnichannel verification on top of your existing identity stack. Deployed in weeks, not quarters.

AICPA SOCFido Certified
LinkedInTwitter
Platform
Drop-In Authentication
PasskeysBiometric authenticationWhatsApp OTPEmail OTPApp push authenticationPalm biometricsSMS OTPEmail OTPMagic LinksAuthenticator apps (TOTP)
View all auth methods
KEY FEATURES
No-code rules engineUser observabilityRisk-based authenticationSession managementDigital credentials APIPre-built UI
Pricing
Customers
Solutions
USE CASE
Account takeovers (ATO)
Go passwordless
Call center
SMS cost optimization
Existing apps
Palm biometric payments
View all use cases
industry
Financial services
Healthcare
Marketplace
View all use cases
ROLE
Engineering
Docs
Compare
Twilio Verify vs AuthsignalAuth0 vs AuthsignalAWS Cognito vs Authsignal + AWS Cognito
Resources
LEARN
BlogGuidesDocs
COMPANY
About usWhy AuthsignalPartnersCareersSecurityContact
Integrations
Amazon Cognito
Azure AD B2C
Duende IdentityServer
Keycloak
Auth0
NextAuth.js
Custom identity provider
WSO2 Identity Platform
United States
+1 214 974-4877
Australia
+61 387 715 810
New Zealand
+64 275 491 983
© 2026 Authsignal - All Rights Reserved
Terms of servicePrivacy policySecuritySystem statusCookies