Verify a user with a mobile driver's license (mDL) presented from a phone wallet (such as Apple Wallet, Google Wallet, or a state DMV app like CA DMV Wallet) instead of capturing a photo of a physical ID.
You can offer this in two ways:
- In the Incode Hosted onboarding app, where the wallet option appears automatically on the ID chooser screen after it is enabled in your flow configuration.
- In your own custom web UI, using the Web SDK 2 ID manager to select an available digital-ID method from your own button.
For the full list of supported wallets, schemes, and attributes across regions, see Supported Digital IDs.
How it works
For mDL verification, the user must have their ID saved to their phone wallet. This is called a verifiable digital credential. Verification of a user's digital credential follows the same onboarding session model as the physical id verification:
- Your application creates or opens an Incode onboarding session.
- The user chooses to verify with their digital ID.
- The browser launches the native wallet sheet with
navigator.credentials.get(). - The user selects the credential and consents to share the requested attributes.
- The encrypted wallet response is sent to Incode Server for decryption and verification.
- Verification results are stored on the session and can be retrieved using the standard Incode result APIs.
The user's identity attributes are not returned directly to the web page from the wallet call. The wallet response is encrypted for Incode services and verified attributes are made available through the session's standard OCR data, score, and webhook result surfaces.
Supported Wallets
| Platform | Wallet | Browser | Path |
|---|---|---|---|
| iOS | Apple Wallet | Safari | apple_web |
| iOS | CA DMV Wallet | Safari | apple_web |
| Android | Google Wallet | Chrome | google |
| Android | CA DMV Wallet | Chrome | google |
Incode supports CA DMV Wallet app on both platforms. The CA DMV Wallet app is presented through same path for iOS and Android as Apple and Google wallet
Apple requires approval for every individual client (relying party). Contact your Incode representative before going live with Apple Wallet.
Incode is an approved Google Verifier registrar and handles Google Wallet registration on your behalf. The user must still be on a supported Android Chrome environment with a compatible digital ID in Google Wallet. Contact your Incode representative before going live with Google Wallet.
Option 1: Use the Incode Hosted onboarding app
If you use Incode's hosted or embedded onboarding app, no extra front-end integration is required after the flow is configured.
When the user reaches the ID chooser screen, the app shows a digital ID option alongside the normal document capture options, when all of the following are true:
- Digital IDs are enabled in the flow configuration.
- Apple Wallet or Google Wallet is enabled for the flow.
- The user's device and browser support the wallet method.
- The user has a compatible digital ID in their wallet.
The user taps the wallet option, confirms the wallet presentation in Apple Wallet or Google Wallet, and returns to the onboarding flow after the encrypted response is verified.
If the wallet flow cannot be completed, the user can continue with the regular ID capture fallback path depending on your flow configuration.
Option 2: Use the Web SDK ID manager
Initialize an active Flow session containing the ID Capture module with digital IDs enabled. Resolve its complete configuration before creating the manager:
import { setup } from '@incodetech/core';
import { resolveDashboardModuleConfig } from '@incodetech/core/flow';
import { createIdCaptureManager } from '@incodetech/core/id';
await setup({
apiURL: 'https://demo-api.incodesmile.com',
token: 'YOUR_SESSION_TOKEN',
});
const config = await resolveDashboardModuleConfig({ moduleKey: 'ID' });
const manager = createIdCaptureManager({ config });
const unsubscribe = manager.subscribe((state) => {
if (state.status === 'chooser') {
// Offer a digital-ID button only if availableDocumentTypes includes 'digitalId'.
// Render the other available types as fallback choices.
} else if (state.status === 'deviceWallet') {
// Show progress for requesting/decrypting; wait for the device sheet in presenting.
// In failed, render state.failReason with retry and alternative-method actions.
} else if (state.status === 'finished') {
// This ID step completed. Obtain verified attributes through session results.
} else if (state.status === 'error' || state.status === 'closed') {
// Render the error or leave the verification surface.
}
});
manager.load();
function selectDigitalId() {
const state = manager.getState();
if (state.status === 'chooser' && state.availableDocumentTypes.includes('digitalId')) {
manager.selectDocument('digitalId');
}
}
function retryWallet() {
const state = manager.getState();
if (state.status === 'deviceWallet' && state.phase === 'failed') {
manager.deviceWalletRetry();
}
}
function useAnotherMethod() {
const state = manager.getState();
if (state.status === 'deviceWallet' && state.phase === 'failed') {
manager.deviceWalletUseAnotherMethod();
}
}
function dispose() {
unsubscribe();
manager.stop();
}
Connect selectDigitalId, retryWallet, and useAnotherMethod to user actions. Call dispose when unmounting. Available methods depend on configuration and browser support; selection can use another supported digital-ID route where configured. There is no standalone wallet factory in this integration.
The ID Capture module reference describes wallet phases and failure values. Success reaches finished. Choosing another method returns to the chooser when available, otherwise closed.
Retrieving results
Digital ID results are returned at the end of the Incode onboarding session. Use your existing Incode result retrieval pattern:
- OCR data retrieval for verified identity attributes
- Score or validation result retrieval for decisioning
- Webhooks for session status transitions and downstream automation
The ID manager's finished status is not a replacement for the final session result. Use session results for verification decisions and identity attributes.
Recommended integration patterns
For Incode Hosted onboarding app customers:
- Enable Digital IDs in the flow configuration.
- Let the wallet option appear in the hosted chooser screen.
- Use standard Incode session result and webhook handling after completion.
For Web SDK customers using the built-in ID capture UI:
- Enable Digital IDs in the flow configuration.
- Use the chooser wallet button by default.
- Use the ID manager when you need to own the chooser and its entry points.
For Web SDK customers with fully custom UI:
- Enable Digital IDs in the flow configuration.
- Create your own wallet button.
- Call
selectDocument('digitalId')from the button handler when that option is available. - Subscribe to the ID manager's
deviceWallet,finished,error, andclosedstates. - Fetch final results from the session using standard Incode result APIs.
Error and fallback handling
Wallet presentation can fail when:
- The device or browser does not support Digital Credentials APIs.
- The user does not have a compatible digital ID in their wallet.
- The user cancels the wallet presentation.
- Apple Wallet domain approval is not complete.
- The wallet response cannot be decrypted or verified.
Your application should provide a fallback path, such as retrying wallet verification or continuing with physical ID capture.
Scope notes
- The integration model is flow-based. Requested attributes and enabled wallet methods are configured in Dashboard, not passed ad hoc from the browser.
Related pages
- Supported Digital IDs for the full list of wallets, schemes, and attributes
- ID Capture module configuration for Dashboard setup