[Openid-dcp] Notes for 2026-06-22 meeting
Tim Cappalli
timcappalli at cloudauth.dev
Mon Jun 22 10:56:01 UTC 2026
DCP Hybrid Meeting 22nd of June 2026
- Attendees: Dima, Frederik, Tim Capelli, Christian Bormann, Paul Bastian, Micha Kraus, Markus Kreusch, Linas, Daniel, Gareth Oliver
Notes by Paul
- Tim Cappalli pitching topic about W3C DC-API discussing to sign the request
- let's have a session at DICE
- let's coordinate some DICE sessions
- Joint WG first meeting will take place next Monday 29th 1-4pm UTC
- looking at OpenID4VP remaining PRs/issues first
- https://github.com/openid/OpenID4VP/pull/744
- general impression that this is a good improvement, reviews needed
- there may be similar issues with VCDM, but current contributors don't have sufficient knowledge
- Christian is pitching the follow-up PR after Simone's PR got closed
- short text on parsing untrusted inputs, e.g. DCQL query or other JSON
- participants prefer MUST over SHOULD for the given text
- https://github.com/openid/OpenID4VP/pull/745
- looks like a breaking change, Paul suggests to add it to 1.0 errata
- some suggestions on the vp_token requirements
- looking at OpenID4VCI PRs
- IAE: https://github.com/openid/OpenID4VCI/pull/736
- Christian to send URNs to IANA
- Tim to review
- https://github.com/openid/OpenID4VCI/pull/759
- align origin text ("https scheme") with OpenID4VP, discussions on native app origin
- Gareth worried about "explicit user consent" if e.g. user declines offer, Frederik agrees
- removing the whole text about explicit user consent and instead say "The wallet MAY ask the End-User for consent"
- discussion whether the redirect_uri should contain information about the success or failure of the issuance -> new issue after PR
- redirect_uri's primary use is to redirect back to the issuer, warm_welcome
- review: Frederik, Micha, Gareth
Break
Notes by Tim
- Discussed the diagram showing credential datasets breakdown
- Discussion around Credential identifier vs Credential dataset
- credential dataset is abstract and doesn't really exist operationally
- could have 2 datasets that are the same across two devices
- link is there, but only via Access Token. Should this be extended to RTs?
- QQ: If you don't have an RT and get a different AT, should the credential ID be the same?
- 1.0 Errata: should this be defined for RTs? Small change, but big impact. Definitely do in 1.1
- https://github.com/openid/OpenID4VCI/pull/472
- Required vs Optional in credential dataset version:
- 1.0 wallets should ignore this, should discard old one when receiving new with same credential ID
- Agree on recommended
- Cryptographic vs non-cryptographic claims: existing issue to add clarity: #752
- Open question: May need a Credential Dataset ID? Can remain constant across all instances and issuance sessions.
General notes:
- Wednesday APAC - EU call due to DICE
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-digital-credentials-protocols/attachments/20260622/8ee12be1/attachment.htm>
More information about the Openid-specs-digital-credentials-protocols
mailing list