Skip to main content

Verify credentials securely

GOV.UK Wallet implements the ISO/IEC 18013-5 specification for reader authentication. It will operate a Certificate Authority (CA) that will establish a chain of trust to make sure only authorised and registered Digital Verification Services (DVS) can consume and verify credentials.

As an authorised DVS, you will be able to:

  • use your own CA and issue end-entity certificates to trusted clients
  • read and process data from GOV.UK Wallet sandbox and production environments

This page will help you to understand how to:

When GOV.UK Wallet releases reader authentication, you must have valid verifier certificates for GOV.UK Wallet to authenticate your requests for data.

Connect to GOV.UK Wallet’s chain of trust and root certificate

The Government Digital Service (GDS) publishes a root certificate that will be pinned to the GOV.UK Wallet app. The root certificate establishes the chain of trust that authenticates your request for data from a holder’s verifiable credentials. All your verifier certificates must connect to this chain and land on the root.

Operate your own certificate authority

GOV.UK Wallet CA will issue you with an intermediate sub-CA certificate that you can use to operate your own CA. You’ll need to request this certificate by sending a Certificate Signing Request (CSR). Once received, you need to install this certificate into your own X.509 CA so you can issue your own end-entity verifier certificates.

Issue end-entity verifier certificates

You can use your sub-CA certificate to issue end-entity verifier certificates to your apps, devices and trusted clients. Your sub-CA carries a NameConstraints extension which limits you to issuing verifier certificates under your own legal business name. This lets your clients consume and verify credentials in person. In the future, you’ll be able to verify online.

Your issued verifier certificates will form a part of the chain of trust with the root certificate. When a verifier starts the proximity sharing flow, they’ll present their verifier certificate and the chain of certificates will authenticate their request.

It’s your responsibility as a DVS to manage your CA and issue verifier certificates according to industry standards for data security. You should follow the National Cyber Security Centre (NCSC) guidance on managing certificates and developing a public key infrastructure (PKI).

You will only be able to issue certificates one level down from your own. Your intermediate sub-CA certificates will be revoked if you:

  • are removed from the digital identity and attributes trust framework
  • breach the agreed terms with your engagement manager
  • are otherwise compromised
This page was last reviewed on 14 July 2026. It needs to be reviewed again on 14 January 2027 by the page owner #di-mobile-wallet-tech-docs .