Poland opens its EUDI Wallet sandbox: what organisations can test before production
The free sandbox provides a demo mObywatel Europa app and identity verifier. We explain useful test cases, privacy choices and failure modes.
- AUTHOR
- Karol Rapacz / CEO of Breachroad · OSCP · PNPT
- PUBLISHED
- 1 October 2026
- READING TIME
- 9 min read
- TOPIC
- Identity and Access
Companies and public institutions can now test how their services integrate with the European Digital Identity Wallet. Poland’s Ministry of Digital Affairs and Central IT Centre opened the free sandbox on 16 September. It provides a demonstration mObywatel Europa application and a web verifier for test identity data in a controlled environment.
The development matters to banks, insurers, telecommunications providers, transport, education, healthcare, retail and digital services. Organisations can learn before production deployment rather than waiting until the identity method becomes a customer expectation or an interoperability requirement.
Prove the necessary attribute instead of copying a document
The European wallet changes the data-sharing model. Instead of sending a copy of a complete identity document, a person will be able to present selected credentials, such as identity, age or entitlement to drive. Poland is building its wallet within the mObywatel ecosystem under the common European framework introduced by eIDAS 2.0.
For users, this can provide greater control over the information disclosed. A retailer that only needs proof of adulthood does not automatically need a home address and document number. For the organisation, however, this calls for process redesign: it must decide which attribute is genuinely necessary, how to verify it and how long to retain evidence without accumulating unnecessary personal data.
The sandbox is the right place to ask those questions, but access to a test environment will not make the organisational decisions. Technical integration needs to sit alongside purpose limitation, failure handling and customer experience.
What the first sandbox stage provides
Participants receive a demonstration version of mObywatel Europa. In the first stage, they can work primarily with test identity data and verify it through a web-based verifier. The environment is intended to uncover integration and organisational problems without affecting production data or services.
An interested organisation reviews the participation rules and submits the form and supporting documents. Following approval, it receives further instructions and access. This is not an anonymous public playground but a controlled programme involving the institutions developing the Polish implementation.
Join with a specific use case: age assurance without document copying, account opening, SIM registration, access to a healthcare service or verification of driving entitlement. The test should have a business owner and involve privacy, security, engineering and customer support.
Five failure paths worth testing
A first test normally answers whether a valid credential passes. More significant risks appear in less convenient situations:
- the customer declines to share an attribute or offers a different credential;
- a credential has expired, been revoked or cannot be checked;
- the wallet, phone or verifier is temporarily unavailable;
- support asks for excessive data to “complete the process manually”;
- a criminal impersonates the wallet or uses a fraudulent QR code and sign-in page.
The organisation needs a secure alternative route. Wallet downtime must not lead automatically to sending a document photo by ordinary email. Communication matters just as much: users need to understand what they are sharing, with whom and for what purpose.
Minimise data before integrating
A new identity channel is an opportunity to remove old document copies and unnecessary form fields, not merely to add a button to an existing process. Map data required by law, information genuinely needed by the business and fields collected from habit. Then define retention, permissions, event logging and a route for user requests.
The integration itself needs protection: keys and certificates, test environments, trusted-component records, updates and monitoring for unusual activity. A test credential must not open a production account, and sandbox data must not enter reports that are treated as genuine proof of identity.
Teams can base their design on Zero Trust principles and technical GDPR security measures. Cybersecurity training helps customer-facing teams handle impersonation, pressure and unsafe process workarounds.
Source facts and Breachroad conclusions
The Ministry of Digital Affairs announcement confirms the launch date, organisers, free environment, first-stage capabilities, target sectors and application process. It also connects the wallet with mObywatel and eIDAS 2.0.
The failure scenarios, secure alternative-path principles and data-minimisation recommendations are Breachroad conclusions. Production architecture and requirements may continue to evolve alongside European specifications.


