[Openid-dcp] Notes for 03.07.2026 DCP WG Call

Jan Vereecken jan.vereecken at meeco.me
Thu Jul 2 16:01:09 UTC 2026


Hi All,

Please find the meeting minutes of today's meeting below.

Have a great day.

Greetings,
Jan

----

03.07.2026 DCP EU WG Meeting

# Attendees

- Michael Jones
- Christian Bormann
- Kristina Yasuda
- Bjorn Hjelm
- Ashmita Chakraborty
- Jin Wen
- Gilbert
- Jan Vereecken
- Paul Bastian
- Brian Campbell
- Oliver Terbu
- Rajvardhan Deshmukh

# Meeting Notes

## OpenID4VP

Refine processing expected_origins and processing steps
https://github.com/openid/OpenID4VP/pull/719

Discussion on Marcos' comment on what a "trustworthy url" is. There is confusion if quoting a W3C Candidate Recommendation Draft is a good idea.
Ready to merge after Marcos' review.

Normative version inconsistency for SD-JWT VC in 1.0 final
https://github.com/openid/OpenID4VP/pull/726

Kristina to review and incorporate Jan's comment

Add additional text clarifying how to match vct and doctype
https://github.com/openid/OpenID4VP/pull/744

Makes sense to have this in errata, too and also not to limit validation rules to the wallet but also verifier.
Gareth to update PR or provide comments.

Clarify an empty object in a VP Token cannot be used to signify an error response
https://github.com/openid/OpenID4VP/pull/745

Discussion on the language used in the PR. Oliver to review suggestions.

Security considerations on untrusted input
https://github.com/openid/OpenID4VP/pull/748

Mike points out there is no JSON Schema standard at present. Brian is not supportive of using JSON Schema.

Christian requests a review on the language around validation steps.

duplicate claims entry
https://github.com/openid/OpenID4VP/pull/750

Summoning of Daniel Fett requested.

Definition for unsigned DC API request isn't 100% clear
https://github.com/openid/OpenID4VP/issues/634

Removed 1.1 tag as it is still depends on W3C approval (which has not yet been received). Christian said they are looking into it atm.

Unclear whether wallet should follow HTTP redirects
https://github.com/openid/OpenID4VP/issues/680

Christian to raise a PR adding clarification as a security consideration disallowing redirects.

Should we mandate the use field for keys in the JSON Web Key Set in client_metadata
https://github.com/openid/OpenID4VP/issues/642

Discussion in the issue. Christian will raise a PR.

Conclusion

Once the current bath of PRs is approved, OpenID4VP is ready for approval.

Discussion whether issue 680 needs to be resolved in 1.1. Conclusion is yes.




[Meeco]<https://www.meeco.me/>

Jan Vereecken, Chief Product Officer, Meeco
+32 473 93 61 03  |  jan.vereecken at meeco.me<mailto:jan.vereecken at meeco.me>
twitter/x: @janvereecken<https://twitter.com/janvereecken>   |  linkedin: janvereecken<http://www.linkedin.com/in/janvereecken>


Discover Meeco at meeco.me<https://www.meeco.me/> or read our blog, case studies, and industry reports on our Insights<https://www.meeco.me/insights> page.
We are on LinkedIn @meeco_me<https://www.linkedin.com/company/meeco-me/mycompany/> and X @meeco_me<https://twitter.com/meeco_me>

This email is confidential and may contain legally privileged information. If you are not the intended recipient, you must not disclose or use the information contained in it. If you have received this email in error, please notify us immediately by return email and delete the document.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-digital-credentials-protocols/attachments/20260702/66e18144/attachment-0001.htm>


More information about the Openid-specs-digital-credentials-protocols mailing list