Multipaz 0.101.0 Released
Written by David Zeuthen, Multipaz project leader.
Following right on our steady 6-to-8 week release cadence, we are thrilled to announce that Multipaz 0.101.0 was officially released late last week on September 10, 2026!
August was an absolute whirlwind of activity for the digital identity community and the Multipaz team. Between deep-dive standards work, community discussions, and rapid feature development, our team was on the ground participating in two major international ISO interoperability events in Bangkok and Geneva. The real-world testing, cross-vendor collaborations, and direct feedback from these events fed straight into making Multipaz 0.101.0 one of our most exciting and battle-tested releases to date.
You can find the full release notes and changelog on GitHub:
As always, all release artifacts are available directly on Maven Central.
Because our changelog is extensive, we’ve hand-picked some of the most exciting highlights from this release to explore below!
1. Summer of Interop: Bangkok and Geneva
Nothing tests code quite like putting dozens of wallet implementers, reader vendors, trust authorities, and government delegations in the same room to see if everyone's software actually talks to each other. This August, we had the privilege of participating in two flagship ISO test events:
Bangkok: Global Digital ID & Verifiable Credential Summit 2026
In late August, we joined international delegates in Thailand for the Bangkok 2026 Summit (August 20–21, 2026), organized by Taskforce 7 and the World Bank Group in collaboration with ETDA.
Hosted alongside ASEAN partners and ISO/IEC SC17 WG10, the event brought together teams from all over the world to demonstrate cross-border digital identity scenarios using ISO/IEC 18013-5 mdocs, ISO/IEC 18013-7, and SD-JWT VCs.
The energy was electric, and you can see the highlights for yourself! Head over to the Taskforce 7 Bangkok Summit page to watch the event highlight video—Multipaz project leader David Zeuthen is featured in that video sharing remarks on why interop testing is so exciting. On that page, you can also find his presentation on Multipaz Open Source Wallet SDK, Ecosystem & Standards.

Geneva: ISO Photo ID and mdoc Interoperability Test Event
Just ten days later, we reconvened in Switzerland for the Geneva 2026 Interop Event (August 30–31, 2026). This event, hosted by IATA and organized by Aptitude, focused intensely on interoperability for Photo IDs, mobile driving licenses (mDLs), and mdoc verification across diverse hardware, operating systems, and reader stacks.
This test event was co-located with the Global Digital Collaboration Conference 2026 (GDC 2026), where Multipaz was actively represented. We took part in several insightful panel discussions covering Photo ID standards, credential revocation, and real-world wallet deployment experiences. We also teamed up with Open Mobile Hub to co-present Your Identity Wallet, Now For AI Agents, exploring how digital credential wallets intersect with autonomous AI agent workflows. Special thanks to the FIDO Alliance for co-organizing this session!
Testing our implementations against a wide battery of independent verifiers and readers gave us tremendous confidence in our protocol implementations—and provided invaluable real-world data that directly shaped the features in 0.101.0!
2. NFC CCE (aka NFCv2) Double-Tap Presentment
In our 0.100.0 release blog post, we introduced NFC Concurrent Channel Engagement (CCE) (previously known as NFCv2) in ISO/IEC 18013-5 Second Edition and showed how it streamlines BLE connection handover to complete an in-person presentment in ~400 milliseconds.
However, in many real-world environments—such as transit gates, retail terminals, point-of-sale systems, or external USB CCID desktop readers—the entire transaction takes place exclusively over NFC without switching to BLE. In such a setup, one might wonder what happens when the requested credential requires explicit user consent and biometric authentication (like Face Unlock or fingerprint)?
Asking the user to hold their phone motionless against an NFC reader terminal while reading a consent dialog and scanning their biometric is awkward, slow, and prone to NFC connection drops ("tears").
To solve this, we contributed recommendations to ISO/IEC 18013-5 Second Edition advising that mdoc readers should gracefully handle disconnections during presentment: if a reader doesn't receive an immediate response on the initial tap, it should instantly revert to a state asking the user to tap again. This simple yet powerful reader behavior enables wallets to implement intuitive "double-tap" presentment—which we are thrilled to support out of the box in Multipaz 0.101.0!
Here is how the double-tap flow works seamlessly in Multipaz:
- First Tap (Request & Inspect): The user taps their phone against the reader. In a fraction of a second, the reader sends its
DeviceRequestover NFC and waits patiently for the response as the user pulls their phone away. - Review & Authenticate: The user pulls their phone back comfortably to inspect what information is being requested. In Multipaz 0.101.0, we factored
mdocPresentment()into three discrete steps: obtaining consent, authenticating the user, and generating the response. The wallet UI prompts for biometric/passcode authentication, and Multipaz pre-unlocks the required keys usingSecureArea.unlockKey()andPreloadedKeyUnlockDataProvider. Notably, this works seamlessly with both platform-based biometric prompts and application-provided knowledge-factor prompts, including combinations of both. - Second Tap (Instant Delivery): Once authenticated, the wallet displays "Hold to reader to share". The user taps the phone against the reader a second time. Multipaz re-engages over NFC, verifies that the reader's request matches the one the user approved (
DeviceRequest.isStructurallyEquivalent()), updates the session transcript, signs the response with the pre-unlocked key, and delivers the response instantly!
Check out this fantastic video demonstrating NFC CCE double-tap presentment in action:
This turns what used to be a clunky, error-prone tap-and-hold interaction into a natural, fluid "tap to see the request, tap again to approve" experience that feels effortless.
Of course, the ideal situation for the user is handing the connection over to BLE—as showcased in the last presentment in the video—but in some situations this isn't feasible or could be cost-prohibitive. These new provisions enable modern digital credential experiences on existing hardware deployments.
3. In-Browser Multipaz Web Developer Tools
Earlier this summer, we unveiled tools.multipaz.org, and with 0.101.0, the developer tool suite has grown into an indispensable Swiss Army knife for digital credential engineers.
Because Multipaz is built from the ground up on Kotlin Multiplatform (KMP), our cryptographic algorithms, CBOR/COSE encoders, and credential validators compile directly to Kotlin/JS. That means the tools run 100% locally in your browser—ensuring zero Personally Identifiable Information (PII) ever leaves your machine!
Highlights of the tool suite in 0.101.0 include:
- ISO mdoc MSO and IssuerNamespaces Inspector: Parse and inspect Mobile Security Objects (MSO), IssuerSigned structures, and element digests with full certificate chain visualization.
- Concise Diagnostic Notation (CDN) Decoder & Generator: Full support for Concise Diagnostic Notation according to
draft-ietf-cbor-edn-literals, making human-readable CBOR debugging a breeze. - SD-JWT VC Decoder & Payload Viewer: Inspect selective disclosures, key bindings, and decoded claims.
- ISO 18013-7 Annex C / W3C DC API Verifier: Test verifier requests in-browser, complete with the ability to build your own request.
- PKCS#12 and MpzPass Utilities: Decode and inspect
.p12/.pfxcontainers and digitally signed.mpzpasscontainers directly in your browser.
4. Transaction Data Architecture Overhaul
Transaction data (such as transaction amounts, currency codes, merchant names, and terminal IDs) must often be cryptographically bound to the credential presentation. In 0.101.0, we completely overhauled and decoupled transaction data handling across presentation protocols (ISO/IEC 18013-5 and OpenID4VP) and credential formats (ISO mdoc and SD-JWT VC).
This update introduces:
- Strongly typed Kotlin models representing protocol-specific parameters cleanly.
- Element-level device key authorization enforcement in the MSO according to ISO/IEC 18013-5.
- Support for custom user input (such as adding a tip during payment confirmation), scoped directly to credential matching.
- Freshly redesigned transaction consent prompts across both Compose Multiplatform and SwiftUI.
And Much More!
There’s a whole lot more in Multipaz 0.101.0 that we couldn't fit into a single post:
- Multiplatform PKCS#12 (
.p12/.pfx) container encoding/decoding per RFC 7292 across JVM, iOS, and Web Crypto, with passphrase support. - Comprehensive Reader and Issuer Identifiers using Authority Key Identifiers (AKI) across ISO 18013-5 and OpenID4VP. Issuer Identifiers allow verifiers to signal to the wallet that the presented credential must be issued by one of the specified issuers, while reader identifiers (typically provided by the issuer or wallet provider) restrict presentation of a pass to readers that authenticate with one of the specified identifiers. Both help simplify the UX for holders by showing a credential in the consent prompt only if it's eligible for presentment.
- A high-level
RevocationCheckerutility for Token Status Lists with optional caching, useful for building verification user interfaces. - Strict ISO/IEC 18013-5 Second Edition inspection checks in the verifier.
- PII-free default logging, iOS SQLite busy timeout protection, and streamlined XCFramework consumption on Apple platforms.
Check out the full Multipaz 0.101.0 Release Notes on GitHub for all the details!
What’s Next: Full Speed Toward 1.0.0!
With every release, Multipaz grows faster, more capable, and closer to our milestone: Multipaz 1.0.0, targeted for the end of the year!
Looking ahead to Multipaz 0.102.0 (due in about six to eight weeks), we are focusing on several high-impact areas:
- Post-Quantum Cryptography (PQC): Support for ML-DSA and ML-KEM in our cryptographic library wrappers, leveraging proven code already shipping in Android, iOS, Web Crypto, and dedicated cryptography libraries. This will allow us to start prototyping the exciting work already underway in ISO/IEC SC17 WG10 to bring quantum-resistant cryptography to the ISO/IEC 18013 and 23220 series of standards.
- Multiple Matching Documents: Support for
"uniqueDocSetRequired": falsein ISO/IEC 18013-5 Second Edition (and its cousin"multiple": truein OpenID4VP / DCQL). When a relying party setsuniqueDocSetRequiredtofalse, it means they are requesting multiple documents satisfying the request—such as a parent carrying movie tickets or boarding passes for the whole family! Supporting this will bring powerful enhancements to our consent prompts and pre-consent matching engines. - Extension Points for Consent Prompts: The Multipaz library already provides a beautiful, responsive consent prompt for both Compose Multiplatform and native SwiftUI, but we recognize that digital identity presentation is evolving rapidly beyond just displaying a static list of claims. We are designing rich extension points so wallet applications can directly provide custom UI slots and tailored user experiences within the presentment flow. After all, the wallet application is the entity with deep knowledge about the transaction, relying party, issuing authority, and credential, and this knowledge can be used to render a much more opinionated and useful consent prompt than the default UI provided by the SDK.
- OpenID4VCI Conformance & Server-to-Server: Continued focus on conformance testing for our OpenID4VCI implementations across both issuer and wallet stacks. We’re also eager to start prototyping the new OpenID4VCI server-to-server protocol now that the initial draft has landed in the OpenID Foundation repository!
Multipaz is a proud OpenWallet Foundation project and is completely free and open-source. Whether you are building digital wallets, integrating verifiers, or contributing to the codebase, we’d love to have you join our community! We meet every Tuesday—check the OWF community calendar for details.
Until the next release—happy coding!