Protect administration
Password authentication, TOTP for application administrator accounts, session expiry and protected form actions support controlled access.
Security and operations
Give administrators a controlled workspace for access, wallet status and operational visibility—without placing wallet credentials in the backend.
Government and enterprise programs need to know who can administer each organization, how wallet status is handled and which changes have been recorded.
Password authentication, TOTP for application administrator accounts, session expiry and protected form actions support controlled access.
Organization administrators and API keys are restricted to their assigned organization context.
API keys can be limited to specific operational scopes and are stored by digest rather than in clear text.
Wallet instances are linked to attestation status references that can be administered and published.
Audit records capture administrative actions with organization, actor and timestamp context.
Credentials and private keys held in the mobile wallet remain outside backend administration.
A signed Wallet Instance Attestation binds the wallet key to a status reference. The backend records the wallet instance and publishes status for ecosystem checks.
Authorize wallet setup for a member or guest flow.
Issue a signed, key-bound Wallet Instance Attestation.
Track the instance and administer its WIA status.
This website does not claim certification, “zero trust”, a particular hosting model, HSM support, an SLA or absolute security. Deployment controls must be assessed for the customer environment.
Request a security review ↗Bring your administrative roles, integration boundaries and trust policy to a project discussion.