eIDAS 2.0 compliant by design

Admitted to the market.Karin arranges it from the wallet.

Hanze Staffing places workers, and from 2027 it may only do so if the NAU has admitted it. Karin de Wit is the one who has to arrange that: a register extract from the KVK, a certificate of conduct from Justis and a tax declaration from the Belastingdienst — three authorities that used to mean scans, e-mail and waiting. This playground puts her Personal ID in your wallet. With it she collects all three into the business wallet, and the NAU answers her application while she waits.

How this works

Three roles, two protocols

Everything on this page follows the European Digital Identity standards. The terminology below is the same you will find in the specifications, so you can map what you see to what you read.

Issuer

The party that states something about you and signs it. Here there are four: the KVK issues the register extract, Justis the certificate of conduct, the Belastingdienst the tax declaration and the NAU the admission itself.

Holder

You. Your credentials live in your wallet on your phone, not in our database. You decide each time whether to share, and what.

Verifier

The party that asks for proof. The NAU is the verifier that matters: it checks that all three attestations are valid, unrevoked and about the same company before it decides. FlexGate then verifies only the NAU's conclusion.

Issuance: OpenID4VCI

You scan a credential offer. Your wallet fetches the credential from the issuer and stores it, cryptographically bound to a key that only your phone holds.

Presentation: OpenID4VP

A verifier sends a query describing what it needs. Your wallet shows you the request, and only what you approve is sent back, signed.

Why the verifier learns less than you might expect

Credentials in SD-JWT VC format support selective disclosure. The NAU does not ask which people Justis screened, and it does not ask for the loonheffingennummer: it asks whether the obligations were met. A paper VOG cannot leave those out; this can.

Next step

Step 1

Use a compatible EUDI wallet

You need a wallet app to receive and share credentials. Any wallet that speaks OpenID4VCI and OpenID4VP can hold them, but it also has to accept credentials from an issuer it does not know yet, and not every wallet does.

Step 2

Issue your test credentials

Scan the QR code with your wallet to receive the Personal ID. The data is fictional: you are receiving Karin's Personal ID, so nothing about you is stored anywhere.

Your credentials

0 / 1

Personal ID (SD-JWT VC)

Issue the Personal ID first: it is what identifies Karin at each of the four portals.

Personal ID (SD-JWT VC)

Karin's name, date of birth, nationality and address. It shows who she is when she signs in at the portals that issue Hanze Staffing's attestations.

Start here

Next step

Step 3

Use the credentials for real

Issuing a credential is only half the story. The KVK, Justis, the Belastingdienst, the NAU and FlexGate are live portals; together they take Hanze Staffing from a registration to an assignment.

Karin gets Hanze Staffing admitted

Admission to the labour-hire market

flexgate.acc.credenco.com

Karin de Wit signs for Hanze Staffing, a company that places workers with other employers. The last time she arranged this it took three authorities, a scanner and a fortnight of waiting. From 1 January 2027 the Wtta closes the market to anyone the NAU has not admitted, and admission means proving who the company is, that its directors were screened and that it meets its tax obligations. In this demo you are Karin: you collect the three proofs into the business wallet, apply once, and register for an assignment with the admission you get back.

What happens next

1

Get Karin's Personal ID

Issue the Personal ID above and store it in the wallet app on your phone. It is what identifies Karin when she signs in; the attestations about Hanze Staffing go into the business wallet.

2

Collect the register extract at the KVK

At mijnkvk.acc.credenco.com Karin collects the company registration (EUCC) into Hanze Staffing's business wallet: the name, the KVK number, the legal form and who may sign for it.

3

Apply for the VOG rechtspersonen at Justis

At justis.acc.credenco.com Karin shares the registration and applies for a certificate of conduct for the company. Justis screens the directors and issues the VOG into the same wallet, stating the purpose: admission to the labour-hire market.

4

Get the tax declaration from the Belastingdienst

At belastingdienst.acc.credenco.com Karin shares the company's identity and receives the Verklaring nakoming fiscale verplichtingen: payroll tax and VAT, assessed over the past year, with no amounts in it.

5

Apply for admission at the NAU

At nau.acc.credenco.com the three attestations go across in one request. The NAU checks signature, origin and validity in seconds, judges the application and issues the admission back into the same wallet.

6

Register for an assignment at FlexGate

FlexGate is the inlener. It asks only for the admission and the register extract: the NAU already weighed the VOG and the tax declaration, and an inlener that asked for them again would be redoing an authority's work.

Issue the Personal ID first

You are missing Personal ID (SD-JWT VC). You can continue, but signing in at the portals will stop when they ask for it.

If something goes wrong

  • "No credentials available" means the attestation being asked for is not in the wallet you are sharing from. The three that matter live in the business wallet, not in the personal one that holds the Personal ID.
  • If an application stops halfway, start again from the portal's home page rather than reloading a page you already scanned into: every attempt gets its own code.