Skip to content

Roadmap

What is built, what is waiting, and what comes next.

This page lists capabilities, not tasks.

Nobody is running this in production. No customers, no pilots, no live deployments, and nothing below should be read as evidence of any. The battery passport obligation begins on 18 February 2027, and we would rather be correct when it arrives than early and wrong.

There are no dates on anything unbuilt. Timing depends on EU acts, standards votes and registry access, none of which we control. We commit to the status, not to a quarter we would only be guessing.

Status

Where each capability stands today.

Available now

In the software today and exercised by its tests. Available is not the same as in use: nobody runs this in production yet.

Your node, your keys

  • Runs on your own infrastructure

    One self-contained node on servers you choose. Build our setup tool once, and it sets up and starts the node. Self-hosting for your own compliance is free.

  • Signed with your own key

    Every passport is signed on your servers, with a key that never leaves them, under an identity on a web domain you control. The key can be rotated without invalidating anything it already signed.

  • Releases that list their contents

    Each release's container images carry a list of the components inside them and a record of how they were built, so you can check what you are running. The images are not public yet.

Getting data in

  • Spreadsheets in, passports out

    Import your product data with a trial run first. The node reports what is wrong row by row instead of rejecting the whole file.

    • CSV
    • Excel
  • Checked before anything is signed

    A product group's rules run before signing, alongside warnings for values that look implausible. A new signed version of a group's rules can be installed on a running node without a restart.

    • Blocking checks
    • Advisory warnings
    • Updates without a restart
  • Does it need a passport?

    Ask the node whether a product group needs a passport, from when, and under which acts. Every date says whether it comes from the text of the law or from a reading of it.

Reading a passport

  • Scan to read

    The code on the product opens its public passport. No login and no fee.

  • The code, generated for you

    The node generates each passport's QR code as an image, pointing to its public page.

  • Each reader sees what they are entitled to

    Repairers, recyclers and authorities see more than the public, field by field, proven by a credential they hold rather than a setting they choose.

    • Public
    • Legitimate interest
    • Authorities

    How visibility works

  • Export for industrial systems

    Passports can also be served in the Asset Administration Shell format used by Industry 4.0 systems. The field meanings use Odal's own identifiers for now, so a receiving system still has to map them.

A record for the product's whole life

  • Changes without losing history

    Correct a passport, replace it with a newer one, suspend it or retire it. Every earlier version stays readable, a code already printed on a product still works after its passport is replaced, and every change is written to a tamper-evident trail.

    • Correct
    • Replace
    • Suspend
    • Retire
  • Passports keep working when the rules change

    A new version of a product group's schema never breaks the passports issued under an older one. They keep resolving exactly as they were issued.

  • A handover between companies

    Responsibility moves from one company to another on the record: the outgoing company signs the handover and the node signs its acceptance. Either side can decline or withdraw before it completes.

  • A second life, on the record

    When a product is repurposed or remanufactured, its new passport links back to the passport, or passports, it came from, and says which of those happened.

  • Products made of products

    A passport can point to the passports of its components, and the whole chain is verified in one check.

  • A recorded end of life

    The end of a product's life is recorded on its passport, including the handover to a waste operator.

    Follow the whole lifecycle

Proof that stands on its own

  • A proof file anyone can check offline

    The passport, its signatures and its full history in one signed file. It verifies without a network connection and without trusting us.

    Check a proof file in your browser

  • Readable when your server is not

    A signed, pre-rendered copy of each public page can be kept outside the node, so a scan still works while the node is down.

  • A tamper-evident change log

    Every change to a passport is logged. The log cannot be edited or deleted through the node, and each entry is chained to the one before it, so an entry altered behind the node's back shows.

Running it day to day

  • One tool to run it all

    Set up, onboard, import, publish, issue credentials and check status from a single tool.

    • Command line
    • Interactive console
  • Your systems stay informed

    Passport events are sent to your own systems, signed so a receiver can tell a real delivery from a replayed one.

  • Scan counts you own

    How often each passport was opened, counted on your own node. Nothing is recorded about the person who scanned.

  • Company details, recorded once

    Your sites and company identifiers live on the node and are stamped onto every new passport.

  • The unsold-goods disclosure

    Record what was discarded, why and where it went, line by line, ready for the yearly disclosure.

  • Clear about its own state

    The node reports which of the services it relies on are fully working and which are still stand-ins, so it is clear what is not finished yet.

  • Safe by default

    A node will not start with the sample admin login or key-store passphrase from its own setup files, or with an empty passphrase. One set up for production also will not start while a service it relies on, such as sealing or rule checking, is only a stand-in. Overrides exist for development, and they are logged as warnings.

Built, waiting on a legal step

Finished and tested. What holds these back is a legal step, not engineering: a qualified seal needs a qualified certificate, which is issued only to a legal person such as a registered company, and registering passports needs the operator's legal identity.

  • Qualified electronic seals

    Sealing works end to end today with the node's own certificate, and every seal says plainly that it is not qualified. A qualified seal, which the law presumes intact and from its stated origin, needs a qualified certificate issued to the company that seals.

  • Registration in the EU registry

    Registering passports needs the operator's legal identity. Our connection to the registry will be finished against its official interface.

In progress

Being built now. Nothing here is claimed as working.

  • More ways to identify a product

    Every identifier scheme the European standard allows, not only a barcode number, so a company without a GS1 membership can issue passports. The open library supports them, and the node accepts them from its next release.

  • Carbon and repairability figures in the passport

    The node already checks a battery's declared recycled content against the legal minimums. The carbon and repairability calculators are written and published in the open library, but the node does not run them yet, so no passport carries a computed carbon or repairability figure today.

  • Spreadsheet import for every product group

    Import covers most product groups today. Phones and tablets, and detergents, are still to come.

  • The unsold-goods report, ready to publish

    The records exist today. What is missing is the finished document a company publishes on its own website each year.

  • Show only part of a passport

    A passport can be issued as a digital credential its holder presents in part: they choose which fields to reveal, and the reader can still check those fields were signed. The open library has it; the node does not issue it yet.

  • A live passport you can scan

    A sample passport served by a real node, which anyone can open from this website and scan with a phone.

Planned

Committed to, and not yet being built.

Proven and complete

  • Proven against the standards

    Each standard's own official tests, run against the software, with a plain statement of what passes. Alignment with all eight European standards for digital product passports, including the two on security.

    • Official test suites
    • European passport standards
  • Complete toy and detergent passports

    Everything the toy and detergent regulations ask their passports to carry, which the software covers only in part today, including the local language and a colour image of the product.

    • Toys
    • Detergents

Reading a passport

  • The finished public passport page

    The page a scan opens, in your company's look, in the reader's language, and with product images where the rules ask for them. Today's page is a plain placeholder.

    • Your brand
    • The reader's language
    • Product images

Running it

  • Install without building anything

    Ready-made images and a single install command, so a node runs without being built from source first.

    • Ready-made images
    • One-command install

Building on a node

  • JavaScript and TypeScript packages

    Packages for building on a node in JavaScript and TypeScript, starting with a client for the node's interface. Each is built directly from the node's own interface and the open library, so it always says exactly what the node does. It waits on one decision first: how each node gets its own web address.

  • A dashboard for running your node

    A web dashboard for the day-to-day work of running a node, built on those packages. It talks to your own node straight from your browser, so your data never passes through us. It waits on one decision first: how each node gets its own web address.

Being considered

Options, not promises. Not started, not scheduled, and deliberately without dates.

Trust and identity

  • Keys in hardware you control

    Signing keys held in a hardware security module or your own key service, rather than in an encrypted file on the server.

  • Proof on every scan

    The public passport page checks the signature in the reader's own browser, so a scan shows that the passport was signed by its company and has not changed since.

  • A public checker anyone can run

    Check any passport against the European standards on your own machine, without sending it anywhere.

  • Company identity through the European Business Wallet

    The EU has proposed a wallet that lets a company prove who it is and sign and seal documents. It could give a company's passports their legal identity. It is a proposal, not law yet.

  • Readers identified by the EU Digital Identity Wallet

    Repairers, recyclers and authorities prove who they are with the digital identity wallet every EU country is introducing, instead of a credential issued by the node.

Data in and out

  • Import any spreadsheet as it is

    The node maps your own column names, number formats and material names, so you do not reshape your files to its template first.

  • Supplier data, signed at the source

    Ask a supplier for component data, such as materials or recycled content, with a signed request, and receive a signed answer that goes straight into your passport.

  • The EU's shared vocabulary

    Passport data expressed in the common vocabulary the EU maintains, so every system reads a field the same way.

  • Connected to industrial data spaces

    Passports shared into industrial data spaces such as Catena-X, through the connectors those networks already use, rather than a network of our own.

  • Readable in the UN Transparency Protocol format

    The same signed passport, also offered in the United Nations' format for supply-chain transparency, for trading partners who use it.

Keeping up with the law

  • Rules that keep up with the law

    A watch on the EU acts and standards that tells a node's operator what changed and which of their passports it affects.

  • Ready for the iron and steel passport

    Iron and steel is expected to be the first product group to get a passport under the ecodesign rules. The software models it today and would follow the act as it is adopted.

  • Battery carbon footprint

    Waiting on the EU to publish the calculation method. Guessing would produce a number that looks official and is not.

  • A practice copy of the EU registry

    Somewhere to rehearse registering passports before connecting to the real registry.

Running a node

  • Managed deployments

    A node run for you, for companies that would rather not operate one themselves. It would still be yours alone: one company, one node, nothing shared with anyone else.

  • Update notices for self-hosted nodes

    A signed channel that tells a self-hosted node when a new release is available.

  • Monitoring from your own tools

    A node's health, workload and warnings, in the monitoring and alerting tools your company already runs.

  • A back-up copy held by an independent provider

    A copy of each passport kept by an independent service provider, so it stays available even if the company that issued it, or its server, does not.

Beyond passports

  • Records beyond passports

    The node already keeps one record about a company's year rather than a product: the unsold-goods disclosure. The same kind of record, signed like a passport, could cover other reporting duties.

How items move

What it takes to change status.

An item is available when it is in a released version and a test exercises it through the running system. Code that is written but not released does not count, and neither does a demonstration.

An item is waiting on a legal step when it is built and tested but cannot yet do the thing it exists for, for a legal reason rather than an engineering one.

An item is in progress only while someone is building it. An item is planned when we have committed to it and nobody is building it yet; it carries no date. An item being considered is an option: it carries no date and no promise.

Items can move backwards. Finding out while building something that it needs more groundwork is an ordinary outcome, and we record it here rather than let the item slip without notice.

More detail

Where the technical detail lives.

This page is written for everyone. How each capability works, and how to run it, is in the documentation, and the code itself is public on GitHub.