MSD Authority Hub Explore the full ecosystem

MSD Credential Infrastructure

M Wallet

MSDMIDTerminalEvidence

M Wallet is the physical trust layer of the Meridian identity institution: MID credentials, holder confirmation and governed recovery made visible in a device people can hold and inspect.

M Tap serves everyday credential access; M Folio serves high-assurance review. Both carry a recognised identity relationship, never act alone, and recover through verified identity.

01Identity anchored 02Holder confirmed 03Evidence reviewable 04Governed recovery

Review posture: an MSD credential-custody branch, not an identity issuer, financial service or standalone chain product.

M Tap screenless NFC credential card
M TapScreenless NFC credential card
M Folio credential confirmation terminal
M FolioVisible confirmation terminal
Institutional review path: start with the trust architecture, then review the two device forms and their boundaries.
Start with the architecture →
2forms
0secret phrases
EAL6+target secure element
Visibleholder confirmation
M Tap screenless NFC credential card
M TapScreenless NFC credential card
M Folio credential confirmation terminal
M FolioVisible confirmation terminal
POSITIONMSD → MID → Terminal → Evidence
MANDATECredential custody · holder confirmation
FORMSM Tap · M Folio
REVIEWVisible confirmation · governed recovery
BOUNDARYCarries identity · never issues it
Role in MSD

Credential custody for the identity layer.

M Wallet is the hardware custody and holder-confirmation branch of the Meridian Special District ecosystem. It sits after MID / MCID issuance, beside Meridian One service access, and before evidence, revocation and recovery review.

MSD framework Defines the mandate

Institutional authority, issuance perimeter and adoption boundaries stay with the MSD framework and accredited parties.

MID / MCID Recognises the holder

The device carries an already recognised identity relationship. It does not create identity or replace the issuer.

M Wallet Holds and confirms

Credentials, protected requests and recovery actions become visible enough for the holder and reviewer to inspect.

Verify / Chain Keeps evidence reviewable

Provisioning, revocation and recovery can leave proof surfaces without exposing source identity material.

Architecture · hardware trust terminal

Digital authority should be
visible, held, and recoverable.

Meridian Special District is an institution for the digital age; Meridian One opens its services to people and organisations. M Wallet gives that recognised identity a physical form: a device that carries credentials, shows what matters, and requires the holder's confirmation before protected requests proceed.

Most digital access still asks people to trust invisible interfaces, scattered credentials and mistakes that are hard to reverse. That is not enough for a civic identity system. A person or institution should be able to see what is being confirmed, know which credential is involved, and recover through recognised identity if hardware is lost.

Meridian's answer is to place the most sensitive layer in a physical device: not as a speculative product, but as a calm piece of public-grade infrastructure. A good trust terminal should serve residents, executive holders and institutional reviewers with the same clarity.

01 · Institution Identity is recognised first

An MID is issued by authorised institutions; the device only carries that relationship.

02 · Credential Authority is split before it is held

Sensitive authority is not kept at one point; the device carries one protected share.

03 · Terminal Requests are reviewed before confirmation

Credential, requester and intent must appear where the holder can inspect them.

04 · Recovery Lose the device, not the relationship

Loss, damage or replacement returns through verified identity.

No-text layered institutional model showing M Wallet issuance authority, verified identity, bound terminal and review evidence layers
Institutional architecture visual · authority, verified identity, bound terminal and review evidence expressed as one no-text trust model.
Read from top to bottom Authority does not begin in the device. It descends from a recognised institution, passes through verified identity, binds to hardware, and remains reviewable after loss or replacement.
  1. Institution

    Issuance authority stays with accredited parties.

  2. Identity

    The holder is verified before credentials reach hardware.

  3. Terminal

    The device carries and confirms; it does not issue.

  4. Evidence

    Provisioning, revocation and recovery remain reviewable.

Difficulty

Invisible authority creates avoidable risk

When a person cannot see the credential, the requesting party or the action, confirmation becomes ceremony rather than control.

Turn

Bind authority to recognised identity

Split authority, keep one protected share on the device, require the holder's confirmation, and recover through verified identity.

Boundary

Carry, do not issue

Identity is issued by accredited authorities. M Wallet only carries, presents, confirms and recovers within that recognised structure.

Outcome

Credential · confirmation · recovery

One device becomes the visible surface for trusted access, high-value authorisation and institutional review.

How it works

Five steps, from recognised identity to reviewable recovery.

The operating path is deliberately plain: identity first, terminal second, confirmation third, evidence and recovery always within a governed boundary.

01Establish identity

MID / MCID is issued or recognised by authorised institutions before hardware is provisioned.

02Bind terminal

The holder, credential state, device identity and recovery path are matched as a controlled event.

03Review request

The holder sees the credential, requester and intent on the terminal or paired interface.

04Confirm or decline

Protected actions proceed only after holder confirmation. The terminal cannot act alone.

05Recover and verify

Loss, revocation and replacement return through verified identity with evidence available for review.

Two forms · one trust architecture

One made for everyday access.
One made for high-assurance review.

Both share the same foundation: identity-bound authority, a target high-grade secure element, holder review and recovery through verified identity. M Tap lowers the access threshold; M Folio makes credential and confirmation review visible on the device.

Concept-stage note: the hardware specifications on this page, including security level, colour e-ink, battery-free / supercapacitor design and dimensions, are target design values. They remain in development and are subject to final release.

M Wallet device family shown as one institutional credential custody terminal architecture
Terminal family visual · M Tap and M Folio read as two physical forms of one governed credential-custody architecture.
M Tap design study showing front and rear screenless NFC credential card forms
M Tap design study · screenless NFC credential card, front and rear, deliberately quiet for daily trusted access.
M Folio design study showing the front credential display, rear surface, metal frame and side control
M Folio design study · credential display, rear material, metal frame and side control presented as an institutional confirmation device.
M Tap Screenless by design

The card stays quiet and durable; detailed review happens on the paired interface before the holder confirms.

M Folio Review moves onto the device

The larger form gives the credential a visible face, so high-assurance requests can be reviewed where authority is carried.

Shared rule Carry authority, never issue it

Both are custody terminals within the Meridian identity institution: bound, recoverable and unable to act alone.

Entry · screenless

M Tap

A screenless NFC credential card for everyday trusted access. It carries the holder's recognised relationship with Meridian, supports tap-based presentation, and leaves detailed review to the paired interface.

  • Credit-card form · battery-free NFC design
  • Phrase-free recovery by verified identity
  • Tap-based credential presentation
  • Request review through the paired interface
M Tap screenless NFC credential card with Meridian mark
Flagship · colour e-ink

M Folio

A passport-folio-sized trusted confirmation device with a colour e-ink face. The credential remains visible at rest, and protected requests can be reviewed on the device before the holder confirms.

  • Colour e-ink · always-on card-face
  • On-device review: what you see is what you confirm
  • Battery-free design · supercapacitor buffer
  • NFC + one-way verification code (air-gap friendly)
M Folio front design showing Meridian ID credential, verified status and gold metal frame
Foundation · shared by both

Confidence cannot be claimed.
It has to be inspectable.

M Wallet is designed as a reviewable trust surface. Every protected request is tied to a recognised identity, constrained by split authority, and made legible before the holder confirms.

Institutional review table with M Wallet credential custody hardware and secure element materials
Institutional review visual · device, credential, chip and assurance materials arranged on one table, emphasising reviewability rather than marketing.
Authority, split to protect it

Identity-anchored threshold control

Authority is split across the device, operator controls and a recovery path. No party should be able to complete protected requests alone.

Review before you confirm

On-device review · what you see is what you confirm

On M Folio, the secure element drives the review surface itself: credential, requesting party and action appear where the holder can inspect them.

Built to be examined

High-grade secure element target · reviewable build path

The target is for protected material to remain inside the secure chip, with a development path that qualified institutional reviewers can examine.

Battery-free design

Bistable colour e-ink, on even when off

E-ink draws almost no power at rest, allowing the credential face to remain visible for long periods. The target is a battery-free refresh path through NFC harvesting and a supercapacitor.

Air-gap friendly

NFC + one-way verification code

Tap to pass short-range data; higher-assurance review can use a one-way code displayed on the device and scanned by the paired interface.

Recoverable

Lose the device, return by identity

A lost device is not a lost relationship: re-verify the MID holder, provision a replacement, and keep the review trail intact.

Compare · which one

One custody architecture,
two ways to hold it.

The foundation is the same; the practical difference is how much visible review the context requires. M Tap is for everyday credential access. M Folio is for higher-value relationships, executive use and institutional assurance.

Selection principle Choose the smallest review surface that satisfies the institutional risk.

The decision is not about a bigger device being better. It is about whether the holder, operator and reviewer need the request to be visible on the terminal itself.

Routine presentation

M Tap

For daily access, workforce entry and low-friction credential presentation where the paired interface can carry detailed review.

Protected confirmation

M Folio

For executive use, travel, high-value relationships and actions where the credential, requester and intent should appear on the device.

Institutional evaluation

Same controls

Both forms remain inside the same issuance, provisioning, revocation and recovery framework, so procurement can review one control model.

Dimension M Tap · screenless M Folio · colour e-ink
PositioningMinimal credential access · entry formIdentity flagship · high assurance
FormCredit-card · thin, flexibleRigid · passport-holder size
DisplayNone (printed face)Colour e-ink (always-on face)
CommunicationNFCNFC + one-way QR
PowerBattery-free (NFC-harvested)Battery-free + supercapacitor
Request reviewPaired interfaceOn the device
Identity card-facePrinted, fixedColour · personalisable
Secure elementTarget EAL6+Target EAL6+
Primary usersResidents · workforce · daily accessExecutives · travel · institutional review
M Tap · daily access

Screenless NFC credential card

For residents, workforce and everyday trusted access. It stays thin, quiet and durable, with detailed review on the paired interface.

  • Credit-card form
  • Battery-free NFC-harvested design target
  • Request review through the paired interface
  • Recovery through verified identity
M Folio · high-assurance review

Colour e-ink confirmation terminal

For important holders, travel, institutional assurance and higher-value relationships. Credentials and protected requests move onto the device surface.

  • Rigid passport-holder form
  • Colour e-ink always-on card face
  • On-device review before confirmation
  • NFC + one-way verification code

Concept stage: the figures above are target specifications, still in development and subject to final release.

THE BOUNDARY · WHAT IT DOES, AND DOES NOT

What it does,
and where it stops.

A device that carries identity and authority must state its limits plainly. That boundary allows M Wallet to be reviewed as institutional infrastructure, not as a consumer-finance product.

Carries MID credentials and holder authority, with selective disclosure and controlled offline presentation.
Confirms protected requests only after the holder can review the credential, requester and intent.
Recovers through the identity institution when a device is lost, damaged or replaced.
Does not issue identity. The right to issue an MID stays with accredited authorities.
Does not act for the holder. The operator cannot complete protected requests on the holder's behalf.
Does not provide financial services. It is a credential custody terminal; it does not operate a venue, hold deposits or offer investment products.
M Wallet terminal in an institutional trust-loop chamber surrounded by six golden evidence gates
Trust-loop visual · issuance, provisioning, confirmation, revocation, recovery and review evidence close around one controlled terminal.
Compliance · before the door

Recognised before issuance

Identity is verified and screened against sanctions lists before an MID is issued. The device draws on that verified status; it never works around it.

Compliance · at provisioning

Where credentials meet hardware

Device provisioning is treated as a controlled event: the holder, credential status, hardware identity and recovery path must align.

Compliance · in use

Watched while in use

Unusual authorisation patterns can be flagged, and identity status can be re-screened as lists change. The system starts from recognised identity, not anonymous activity.

Institutional review pathway The object under review is not the shell of the device. It is the control relationship behind it.

For governments, issuers and channel partners, M Wallet can be reviewed through four questions: who may issue, how a credential enters the device, how the holder confirms, and how loss is revoked and recovered.

01

Where issuance authority stays

MID issuance remains with authorised institutions; the device carries an already-recognised identity relationship.

02

How provisioning leaves evidence

The holder, credential state, device identity and recovery path form a reviewable provisioning event.

03

How confirmation is made visible

Protected requests must be clear to the holder before confirmation happens on the device or paired interface.

04

How loss is handled

Revoke the lost device, re-verify the holder, provision a replacement and preserve the review trail.

Before operation A device should enter the institutional system only when five states stand together.
Known holder

Identity has been verified and can be re-checked.

Bound terminal

Device identity, credential state and recovery path align.

Visible request

Protected requests are reviewed before confirmation.

Revocable relationship

A lost device can expire while the relationship moves to new hardware.

Verifiable record

Key events leave an evidence surface that can be cross-checked.

Recover · the worst day

If one day
the device is lost.

Recovery is not built around a remembered code. It is built around re-establishing the recognised holder, revoking the lost device, and provisioning a replacement under review.

Institutional service desk with M Wallet replacement device and credential recovery materials
Recovery service visual · recovery framed as identity review, device revocation and replacement provisioning, not as a generic support interaction.
The moment

It is left in a taxi

The terminal is gone, and the credential card with it. The risk is no longer treated as a failure of private memory; it becomes a controlled recovery event.

Prove again

As on the first day, prove who you are

The holder re-verifies through the Meridian identity process. The system recognises the person and their status, not a remembered code stored somewhere unsafe.

Return

The relationship returns on new hardware

The lost device is revoked, the replacement is provisioned, and the review trail remains intact. The holder returns through identity, not through a memorised secret.

Lose the device, not the recognised relationship. This is identity-anchored custody in its plainest and most important form.
Start

Make trusted authority
something people can hold.

M Wallet is designed as the physical trust layer of the Meridian ecosystem: a credential custody terminal that makes identity, confirmation and recovery visible enough for residents, institutions and government reviewers to examine and trust.

Identity outlives the device The terminal cannot act alone Recovery preserves the review trail

For governments, institutions and channel partners — including sample evaluation, white-label and procurement enquiries — get in touch. The email address and product specifications remain concept-stage placeholders until official release.

Institutional review chamber with M Wallet terminals, credential card and gold evidence lines connecting issuance, provisioning, confirmation and recovery
Continuity review visual · issuance, provisioning, confirmation and recovery remain visible as one controlled relationship.