DLBR / GATEWAY CONTROL

Outside declared use: a 403 response before session creation

The relying party configures an attribute set for each intended use. Before creating a wallet session, the Gateway checks the requested claims against that configuration. In the covered case, is_over_18 is allowed and adding birth_date is refused.

Redacted API response

POST /v1/sessions returns HTTP 403:

{
  "error": "ERR_CLAIM_OUTSIDE_INTENDED_USE",
  "message": "The requested claim is not declared for the selected intended use"
}

The request is rejected before a session or QR code is created. The corresponding Gateway test confirms that an in-scope is_over_18 request can create a session (201), while a request that also asks for birth_date returns 403 without session_id or qr_code_url.

What this check covers

Configured intended useRequested attributesGateway result
is_over_18is_over_18201; session may be created
is_over_18is_over_18, birth_date403; no session or QR code

This is an application-level check against the relying party's Gateway configuration. It is not a lookup in a Member State register, validation of an access certificate, or proof that a relying party is registered or compliant. Commission Implementing Regulation (EU) 2025/848 sets out rules for registering relying parties; this demonstration does not perform that registration. Read the regulation on EUR-Lex.

Sandbox evidence

The matrix records wallet runs, separately from the Gateway behavior above. “Not run” means we have no observed wallet response to report.

CountryWallet / environmentResultWallet errorDate
GermanySPRIND sandboxNot run——
NetherlandsNo public sandbox identifiedNot tested——
SwedenDIGG test platform not open to usNot tested——

Last wallet run: none. No wallet-level interoperability result is claimed.

Data handling context

Selected claims are held in verification-session storage for up to 30 seconds for result delivery. Account and audit records are stored in Cloudflare D1; active verification-session state is stored separately in Cloudflare Durable Objects. DLBR does not claim that all EUDI data is processed or stored only in the EU. The controller is DALIBOR GOGIC PR DLBR, Serbia. EU storage does not register the company as a relying party.

Home
DLBR EIDDeclared useBlog© 2026 DLBR