DLBR / GATEWAY CONTROL
Outside declared use: a 403 response before session creation
The relying party configures an attribute set for each intended use. Before creating a wallet session, the Gateway checks the requested claims against that configuration. In the covered case, is_over_18 is allowed and adding birth_date is refused.
Redacted API response
POST /v1/sessions returns HTTP 403:
{
"error": "ERR_CLAIM_OUTSIDE_INTENDED_USE",
"message": "The requested claim is not declared for the selected intended use"
}The request is rejected before a session or QR code is created. The corresponding Gateway test confirms that an in-scope is_over_18 request can create a session (201), while a request that also asks for birth_date returns 403 without session_id or qr_code_url.
What this check covers
| Configured intended use | Requested attributes | Gateway result |
|---|---|---|
is_over_18 | is_over_18 | 201; session may be created |
is_over_18 | is_over_18, birth_date | 403; no session or QR code |
This is an application-level check against the relying party's Gateway configuration. It is not a lookup in a Member State register, validation of an access certificate, or proof that a relying party is registered or compliant. Commission Implementing Regulation (EU) 2025/848 sets out rules for registering relying parties; this demonstration does not perform that registration. Read the regulation on EUR-Lex.
Sandbox evidence
The matrix records wallet runs, separately from the Gateway behavior above. “Not run” means we have no observed wallet response to report.
| Country | Wallet / environment | Result | Wallet error | Date |
|---|---|---|---|---|
| Germany | SPRIND sandbox | Not run | — | — |
| Netherlands | No public sandbox identified | Not tested | — | — |
| Sweden | DIGG test platform not open to us | Not tested | — | — |
Last wallet run: none. No wallet-level interoperability result is claimed.
Data handling context
Selected claims are held in verification-session storage for up to 30 seconds for result delivery. Account and audit records are stored in Cloudflare D1; active verification-session state is stored separately in Cloudflare Durable Objects. DLBR does not claim that all EUDI data is processed or stored only in the EU. The controller is DALIBOR GOGIC PR DLBR, Serbia. EU storage does not register the company as a relying party.