Summary
- Switzerland is renaming its existing Public Beta environment as the swiyu Sandbox.
- A dedicated Sandbox Wallet will remain available for issuers and verifiers testing credential services.
- The future production swiyu Wallet will connect only to production infrastructure, creating a clearer boundary around live identity credentials.
Switzerland is putting a harder boundary between experimentation and live digital identity services, separating the wallet used for testing from the software that will eventually connect citizens to its production e-ID infrastructure.
Switzerland’s federal e-ID programme is renaming its existing Public Beta environment as the Sandbox and providing a dedicated swiyu Sandbox Wallet for organisations testing digital credentials. The main swiyu Wallet will be compatible only with production infrastructure once the service goes live.
The change gives prospective credential issuers and verifiers somewhere to continue building and testing integrations without mixing experimental activity with the future live service. The Sandbox Wallet is available for Android as a package distributed through GitHub rather than Google Play, while the iOS version is accessible through a specified App Store link but cannot be found through a normal store search.
Separating test and production systems is conventional engineering practice, but the distinction becomes more consequential when an application carries state-recognised identity credentials. A test wallet needs to tolerate changing interfaces and unfinished integrations; a production wallet has to operate under much tighter assumptions about security, identity assurance, data integrity, and the organisations permitted to trust it.
The wallet is only one part of the identity system
Switzerland’s model extends beyond placing a digital version of a government identity document on a phone. The federal government operates the underlying trust infrastructure and issues the e-ID, while the same framework is intended to support other electronic credentials issued by cantons, municipalities, and private organisations.
That architecture makes the test environment useful well before the national identity service is complete. Public bodies, banks, employers, transport organisations, and other potential participants can build software that issues or verifies credentials against a stable sandbox without gaining access to live identities.
The federal programme describes the underlying infrastructure as decentralised and open source, with privacy and data security designed into the system. Those choices do not remove ordinary delivery risks, because digital identity still depends on mobile software, back-end services, cryptography, identity verification, and operational processes working across organisations with different technology estates.
Switzerland has already extended the timetable for the e-ID itself while further work is carried out on the online issuance process. The Federal Office of Justice said in June that changes were needed in response to AI developments, including stronger measures against malware insertion and improved detection of deepfakes during remote identity checks.
Infrastructure can progress while issuance is hardened
The broader trust infrastructure is still expected to become operational during the first half of 2027. It has already been tested by public and private organisations, and the government intends that other electronic credentials should be able to use it even if the complete e-ID timetable moves again.
That sequencing reduces the risk of treating digital identity as one large launch event. Infrastructure, developer tooling, credential integrations, mobile software, and security controls can mature on separate tracks, while the Sandbox remains available after production systems are locked down.
There is also a governance benefit in making the boundary explicit. Long-running public betas can acquire real users and dependencies until it becomes unclear whether a service is still experimental or has quietly become operational. A separately named Sandbox and wallet make it easier to keep trial credentials, test data, and unfinished integrations away from the production trust environment.
The project remains politically sensitive. Swiss voters approved the legal basis for the state e-ID in a narrow referendum in September 2025, after an earlier private-sector identity model had been rejected, and the programme has continued to emphasise privacy and public control.
AI-enabled impersonation adds another moving security problem because remote identity issuance has to distinguish a genuine applicant from synthetic or manipulated media. That makes the decision to separate experimental integration work from live identity infrastructure less cosmetic than it first appears.
For organisations building services around the Swiss system, development can now continue against a clearly designated test environment while production software is hardened separately. The first half of 2027 remains the next infrastructure milestone, when Switzerland expects the trust layer itself to be operational and capable of supporting credentials beyond the final national e-ID.










