[Openid-dcp] Notes for 2026-06-22 meeting

Tim Cappalli timcappalli at cloudauth.dev
Mon Jun 22 10:56:01 UTC 2026


DCP Hybrid Meeting 22nd of June 2026

- Attendees: Dima, Frederik, Tim Capelli, Christian Bormann, Paul Bastian, Micha Kraus, Markus Kreusch, Linas, Daniel, Gareth Oliver

Notes by Paul

- Tim Cappalli pitching topic about W3C DC-API discussing to sign the request
  - let's have a session at DICE
- let's coordinate some DICE sessions
- Joint WG first meeting will take place next Monday 29th 1-4pm UTC
- looking at OpenID4VP remaining PRs/issues first
- https://github.com/openid/OpenID4VP/pull/744
  - general impression that this is a good improvement, reviews needed
  - there may be similar issues with VCDM, but current contributors don't have sufficient knowledge
- Christian is pitching  the follow-up PR after Simone's PR got closed
  - short text on parsing untrusted inputs, e.g. DCQL query or other JSON
  - participants prefer MUST over SHOULD for the given text
- https://github.com/openid/OpenID4VP/pull/745
  - looks like a breaking change, Paul suggests to add it to 1.0 errata
  - some suggestions on the vp_token requirements
- looking at OpenID4VCI PRs
  - IAE: https://github.com/openid/OpenID4VCI/pull/736
  - Christian to send URNs to IANA
  - Tim to review
- https://github.com/openid/OpenID4VCI/pull/759
  - align origin text ("https scheme") with OpenID4VP, discussions on native app origin
  - Gareth worried about "explicit user consent" if e.g. user declines offer, Frederik agrees
  - removing the whole text about explicit user consent and instead say "The wallet MAY ask the End-User for consent"
  - discussion whether the redirect_uri should contain information about the success or failure of the issuance -> new issue after PR
  - redirect_uri's primary use is to redirect back to the issuer, warm_welcome
  - review: Frederik, Micha, Gareth

Break
Notes by Tim

- Discussed the diagram showing credential datasets breakdown
  - Discussion around Credential identifier vs Credential dataset
    - credential dataset is abstract and doesn't really exist operationally
    - could have 2 datasets that are the same across two devices
    - link is there, but only via Access Token. Should this be extended to RTs?
    - QQ: If you don't have an RT and get a different AT, should the credential ID be the same?
      - 1.0 Errata: should this be defined for RTs? Small change, but big impact. Definitely do in 1.1
- https://github.com/openid/OpenID4VCI/pull/472
  - Required vs Optional in credential dataset version:
    - 1.0 wallets should ignore this, should discard old one when receiving new with same credential ID
    - Agree on recommended
  - Cryptographic vs non-cryptographic claims: existing issue to add clarity: #752
  - Open question: May need a Credential Dataset ID? Can remain constant across all instances and issuance sessions.

General notes:
- Wednesday APAC - EU call due to DICE

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-digital-credentials-protocols/attachments/20260622/8ee12be1/attachment.htm>


More information about the Openid-specs-digital-credentials-protocols mailing list