Institutional authority, issuance perimeter and adoption boundaries stay with the MSD framework and accredited parties.
MSD Credential Infrastructure
M Wallet
MSD→MID→Terminal→Evidence
M Wallet is the physical trust layer of the Meridian identity institution: MID credentials, holder confirmation and governed recovery made visible in a device people can hold and inspect.
M Tap serves everyday credential access; M Folio serves high-assurance review. Both carry a recognised identity relationship, never act alone, and recover through verified identity.
Review posture: an MSD credential-custody branch, not an identity issuer, financial service or standalone chain product.
Digital authority should be
visible, held, and recoverable.
Meridian Special District is an institution for the digital age; Meridian One opens its services to people and organisations. M Wallet gives that recognised identity a physical form: a device that carries credentials, shows what matters, and requires the holder's confirmation before protected requests proceed.
Most digital access still asks people to trust invisible interfaces, scattered credentials and mistakes that are hard to reverse. That is not enough for a civic identity system. A person or institution should be able to see what is being confirmed, know which credential is involved, and recover through recognised identity if hardware is lost.
Meridian's answer is to place the most sensitive layer in a physical device: not as a speculative product, but as a calm piece of public-grade infrastructure. A good trust terminal should serve residents, executive holders and institutional reviewers with the same clarity.
An MID is issued by authorised institutions; the device only carries that relationship.
Sensitive authority is not kept at one point; the device carries one protected share.
Credential, requester and intent must appear where the holder can inspect them.
Loss, damage or replacement returns through verified identity.
- Institution
Issuance authority stays with accredited parties.
- Identity
The holder is verified before credentials reach hardware.
- Terminal
The device carries and confirms; it does not issue.
- Evidence
Provisioning, revocation and recovery remain reviewable.
Invisible authority creates avoidable risk
When a person cannot see the credential, the requesting party or the action, confirmation becomes ceremony rather than control.
Bind authority to recognised identity
Split authority, keep one protected share on the device, require the holder's confirmation, and recover through verified identity.
Carry, do not issue
Identity is issued by accredited authorities. M Wallet only carries, presents, confirms and recovers within that recognised structure.
Credential · confirmation · recovery
One device becomes the visible surface for trusted access, high-value authorisation and institutional review.
Five steps, from recognised identity to reviewable recovery.
The operating path is deliberately plain: identity first, terminal second, confirmation third, evidence and recovery always within a governed boundary.
MID / MCID is issued or recognised by authorised institutions before hardware is provisioned.
The holder, credential state, device identity and recovery path are matched as a controlled event.
The holder sees the credential, requester and intent on the terminal or paired interface.
Protected actions proceed only after holder confirmation. The terminal cannot act alone.
Loss, revocation and replacement return through verified identity with evidence available for review.
One made for everyday access.
One made for high-assurance review.
Both share the same foundation: identity-bound authority, a target high-grade secure element, holder review and recovery through verified identity. M Tap lowers the access threshold; M Folio makes credential and confirmation review visible on the device.
Concept-stage note: the hardware specifications on this page, including security level, colour e-ink, battery-free / supercapacitor design and dimensions, are target design values. They remain in development and are subject to final release.
The card stays quiet and durable; detailed review happens on the paired interface before the holder confirms.
The larger form gives the credential a visible face, so high-assurance requests can be reviewed where authority is carried.
Both are custody terminals within the Meridian identity institution: bound, recoverable and unable to act alone.
M Tap
A screenless NFC credential card for everyday trusted access. It carries the holder's recognised relationship with Meridian, supports tap-based presentation, and leaves detailed review to the paired interface.
- Credit-card form · battery-free NFC design
- Phrase-free recovery by verified identity
- Tap-based credential presentation
- Request review through the paired interface
M Folio
A passport-folio-sized trusted confirmation device with a colour e-ink face. The credential remains visible at rest, and protected requests can be reviewed on the device before the holder confirms.
- Colour e-ink · always-on card-face
- On-device review: what you see is what you confirm
- Battery-free design · supercapacitor buffer
- NFC + one-way verification code (air-gap friendly)
Confidence cannot be claimed.
It has to be inspectable.
M Wallet is designed as a reviewable trust surface. Every protected request is tied to a recognised identity, constrained by split authority, and made legible before the holder confirms.
Identity-anchored threshold control
Authority is split across the device, operator controls and a recovery path. No party should be able to complete protected requests alone.
On-device review · what you see is what you confirm
On M Folio, the secure element drives the review surface itself: credential, requesting party and action appear where the holder can inspect them.
High-grade secure element target · reviewable build path
The target is for protected material to remain inside the secure chip, with a development path that qualified institutional reviewers can examine.
Bistable colour e-ink, on even when off
E-ink draws almost no power at rest, allowing the credential face to remain visible for long periods. The target is a battery-free refresh path through NFC harvesting and a supercapacitor.
NFC + one-way verification code
Tap to pass short-range data; higher-assurance review can use a one-way code displayed on the device and scanned by the paired interface.
Lose the device, return by identity
A lost device is not a lost relationship: re-verify the MID holder, provision a replacement, and keep the review trail intact.
One custody architecture,
two ways to hold it.
The foundation is the same; the practical difference is how much visible review the context requires. M Tap is for everyday credential access. M Folio is for higher-value relationships, executive use and institutional assurance.
The decision is not about a bigger device being better. It is about whether the holder, operator and reviewer need the request to be visible on the terminal itself.
M Tap
For daily access, workforce entry and low-friction credential presentation where the paired interface can carry detailed review.
M Folio
For executive use, travel, high-value relationships and actions where the credential, requester and intent should appear on the device.
Same controls
Both forms remain inside the same issuance, provisioning, revocation and recovery framework, so procurement can review one control model.
| Dimension | M Tap · screenless | M Folio · colour e-ink |
|---|---|---|
| Positioning | Minimal credential access · entry form | Identity flagship · high assurance |
| Form | Credit-card · thin, flexible | Rigid · passport-holder size |
| Display | None (printed face) | Colour e-ink (always-on face) |
| Communication | NFC | NFC + one-way QR |
| Power | Battery-free (NFC-harvested) | Battery-free + supercapacitor |
| Request review | Paired interface | On the device |
| Identity card-face | Printed, fixed | Colour · personalisable |
| Secure element | Target EAL6+ | Target EAL6+ |
| Primary users | Residents · workforce · daily access | Executives · travel · institutional review |
Screenless NFC credential card
For residents, workforce and everyday trusted access. It stays thin, quiet and durable, with detailed review on the paired interface.
- Credit-card form
- Battery-free NFC-harvested design target
- Request review through the paired interface
- Recovery through verified identity
Colour e-ink confirmation terminal
For important holders, travel, institutional assurance and higher-value relationships. Credentials and protected requests move onto the device surface.
- Rigid passport-holder form
- Colour e-ink always-on card face
- On-device review before confirmation
- NFC + one-way verification code
Concept stage: the figures above are target specifications, still in development and subject to final release.
What it does,
and where it stops.
A device that carries identity and authority must state its limits plainly. That boundary allows M Wallet to be reviewed as institutional infrastructure, not as a consumer-finance product.
Recognised before issuance
Identity is verified and screened against sanctions lists before an MID is issued. The device draws on that verified status; it never works around it.
Where credentials meet hardware
Device provisioning is treated as a controlled event: the holder, credential status, hardware identity and recovery path must align.
Watched while in use
Unusual authorisation patterns can be flagged, and identity status can be re-screened as lists change. The system starts from recognised identity, not anonymous activity.
For governments, issuers and channel partners, M Wallet can be reviewed through four questions: who may issue, how a credential enters the device, how the holder confirms, and how loss is revoked and recovered.
Where issuance authority stays
MID issuance remains with authorised institutions; the device carries an already-recognised identity relationship.
How provisioning leaves evidence
The holder, credential state, device identity and recovery path form a reviewable provisioning event.
How confirmation is made visible
Protected requests must be clear to the holder before confirmation happens on the device or paired interface.
How loss is handled
Revoke the lost device, re-verify the holder, provision a replacement and preserve the review trail.
If one day
the device is lost.
Recovery is not built around a remembered code. It is built around re-establishing the recognised holder, revoking the lost device, and provisioning a replacement under review.
It is left in a taxi
The terminal is gone, and the credential card with it. The risk is no longer treated as a failure of private memory; it becomes a controlled recovery event.
As on the first day, prove who you are
The holder re-verifies through the Meridian identity process. The system recognises the person and their status, not a remembered code stored somewhere unsafe.
The relationship returns on new hardware
The lost device is revoked, the replacement is provisioned, and the review trail remains intact. The holder returns through identity, not through a memorised secret.
Make trusted authority
something people can hold.
M Wallet is designed as the physical trust layer of the Meridian ecosystem: a credential custody terminal that makes identity, confirmation and recovery visible enough for residents, institutions and government reviewers to examine and trust.
For governments, institutions and channel partners — including sample evaluation, white-label and procurement enquiries — get in touch. The email address and product specifications remain concept-stage placeholders until official release.