Affinidi Vault

Identity that lives with the user.

A user-owned digital wallet: people store their DIDs and Verifiable Credentials on-device and present them with consent — so your app holds no private keys and stores zero PII.

Where it fits

The holder layer of the Affinidi Trust Network.

Elements Services issues and verifies credentials; Affinidi Vault is where those credentials live — with the user, under their control.

Identity lives with the user

DIDs and Verifiable Credentials are stored on the user’s device — not in your backend. Users bring their identity to your app.

No private keys in your backend

Users prove and present credentials without your service ever holding their private keys. Less to secure, less to breach.

Consent on every share

Every disclosure is explicit and user-approved, with selective disclosure so users share only what is asked for.

Core capabilities

What Affinidi Vault gives you.

A user-owned wallet plus the standards and SDKs to embed it anywhere.

Affinidi Vault

A user-owned wallet for web and mobile that keeps credentials on-device and enables granular, consent-driven sharing.

  • User-owned
  • On-device
  • Web & mobile

Affinidi SSI

Self-sovereign identity primitives — DIDs and W3C Verifiable Credentials — so users control their own identity data.

  • W3C DIDs
  • Verifiable Credentials
  • Self-sovereign

DCQL

Digital Credentials Query Language — request specific credentials from the wallet with selective disclosure.

  • DCQL
  • Selective disclosure
  • Standardised

Affinidi TDK — Vault

Embed Vault capabilities directly into your own app, including a Dart package for Flutter.

  • Embeddable
  • Dart / Flutter
  • SDK
How it works

How Vault stores, organises and proves identity.

Your application talks to the wallet; the wallet holds credentials on-device and presents them with consent; the verifier checks them cryptographically.

How teams use it

One Vault, different value for every team.

The same user-owned wallet is a reusable identity primitive for product teams and a liability-reducer for platform teams.

For auth, issuance & verification teams

A reusable holder layer for onboarding, credential claim and presentation — build the flow once and reuse it everywhere.

  • Passwordless, wallet-based authentication
  • Deliver issued credentials straight to the user
  • Request and verify presentations with consent

For platform & enterprise teams

Keep credential data with users, not in central stores — reducing breach liability and simplifying compliance.

  • No private keys or PII in your backend
  • Selective disclosure by default
  • Open standards keep users portable
For developers

Two ways to ship with Affinidi Vault.

Point users to the ready-made wallet app, or embed Vault directly into your own product.

Use the web & mobile app

Point users to the Affinidi Vault app for instant onboarding — no build required to start issuing and verifying.

Open Affinidi Vault →

Build with the SDK

Embed Vault capabilities into your own app with the Affinidi TDK, including a Dart package for Flutter.

Explore the TDK →
Explore the suite

Part of Affinidi Elements.

Vault pairs with the credential engine and encrypted messaging to close the full trust loop.

Elements Services Available now

Issue, verify, request and manage Verifiable Credentials.

  • The credential layer for your apps
  • Issuance, Login, Verification, Iota
  • Build a production credential ecosystem
See product page
Affinidi Messaging Available now

Encrypted, verifiable communication.

  • Built on DIDComm v2.1
  • End-to-end encrypted; mediators cannot read
  • Exchange credentials between any parties
See product page
Get started

Ready to ship user-controlled identity?

Give your users a wallet they own — and take private keys and PII off your books. Talk to us or start building today.

Cookie Preferences

We use cookies to enhance your experience. You can manage your preferences below. For more information, read our Cookie Policy.

Strictly Necessary Always Active

These cookies are essential for core website functions such as security, session integrity, and cookie preference storage. They cannot be disabled.

  • _cf_bm: Distinguishes humans from bots (Cloudflare) · 30m
  • _cfuvid: Ensures secure browsing (Cloudflare) · Session
  • __hs_initial_opt_in: Prevents HubSpot's banner · 7 days
  • _gtm_debug: GTM debug mode (testing only) · Session
Analytics

These cookies help us understand how visitors interact with the site so we can improve content and performance. All data is aggregated and anonymous.

  • _ga, _gid, _gat: Google Analytics · Session – 2 years
  • __hstc, hubspotutk, __hssrc: HubSpot visitor tracking · 13 months
  • __hs_opt_out: HubSpot opt-out preference · 6 months
Marketing & Targeting

These cookies allow us and our partners to serve personalised ads and measure campaign performance.

  • _gcl_au, _gcl_dc: Google Ads conversion tracking · 90 days
  • IDE: Google Display Network personalisation · 1 year
  • _fbp: Meta / Facebook remarketing · 90 days
  • li_gc, _li_fat_id, bcookie: LinkedIn tracking · 1–24 months
  • guest_id, personalization_id: Twitter/X analytics · 2 years