[Openid-dcp] Minutes from July 9th, 2026 DCP WG call
Frederik Krogsdal Jacobsen
frederik.krogsdal at idura.eu
Thu Jul 9 16:04:03 UTC 2026
- Participants: Brent Zundel, Frederik Krogsdal Jacobsen, Valentine
Mazurov, Helen Qin, Thomas Darimont, Lee Campbell, George Fletcher, Paul
Grassi, Ryan Galluzzo, Paul Bastian, Oliver Terbu, Bjorn Hjelm, Christian
Bormann, Rene Leveille, Rajvardhan Deshmukh, Mike Jones, Martijn Haring,
Hicham Lozi, Akash Shah
- Events
- In-person WG meeting before GDC? Probably at least 7 people would
join.
- Certification issues
- https://github.com/openid/OpenID4VP/issues/718
- Lee: It should not really be necessary to say anything here in
particular, since it is always the case that you may get fewer data
elements than requested.
- Martijn: This is a bit different, since ISO 18130-5 says that
you MUST return a different claim (e.g. if asked for
age_over_18 and you
only have age_over_19, you MUST return age_over_19). Given the current
specs, is this allowed?
- Christian: The answer is probably no.
- Martijn: We should at least explicitly say that you should not
follow the “age over” logic if that is the case.
- Christian: It would be cleaner to just do a big disjunction of
the possible claims.
- Frederik: Doing that kind of looks like over-asking, so we
should at least clarify what is allowed.
- Lee: Is this really a certification issue? The big disjunction
would work.
- Hicham: The wallet would need to do different things depending
on which kind of request it is getting.
- Lee: Yes, but that’s the reality of supporting multiple
protocols. The quirks in the mdoc presentation queries will
probably not be
added to the unified protocol either.
- Christian: From a robustness perspective, it would be better to
explicitly express this in the query instead of having
special exceptions
for credential types.
- Martijn: The certification question is whether it is forbidden
to respond with the extra claims or not.
- There was not agreement on whether it should be allowed to
define custom matching logic for specific credential types
(as is done in
ISO 18130-5).
- https://github.com/openid/OpenID4VC-HAIP/issues/364
- The WG confirmed that the intention was to allow people to
implement the pre-authorized code flow if they want to.
- The authorization code flow must be supported by wallets and
issuers.
- https://github.com/openid/OpenID4VCI/issues/744
- Frederik and Paul: This is technically a breaking change, but it
seems extremely unlikely that it would actually break
anything to fix it.
Any URL library would already implement the corrected behaviour.
- OpenID4VP
- https://github.com/openid/OpenID4VP/issues/755
- Helen: Request from verifiers is to allow setting a preference
about whether user verification is done by the wallet in the
VP request.
- Frederik: Why not just always challenge? This seems to be the
request.
- Helen: There are some use cases where you don’t need a
challenge, e.g. phone number credentials to replace SMS OTP.
- Frederik: What does the “biometric required” flag actually mean?
A wallet could say it about wildly different things.
- Lee: It’s the same as for passkeys; it doesn’t really mean
anything.
- Ryan: RPs are asking for more specific authentication types
already. We will need to deal with this eventually. They want
to both state
a preference and ask what actually happened.
- Hicham: This should happen in the issuer stage and has a huge
impact on accessibility.
- Ryan: The RP will always set the policy, so even if we don’t
allow this, they will do it some other way.
- Brent: VCDM is working on something similar:
https://www.w3.org/TR/vc-confidence-method/
- Paul: I understand the motivation, but we previously decided not
to have wallet attestations in VP, so there is no assurance
anyway. If the
issuer does not do device binding, presenting the credential
as if it has
user authentication may make verifiers think the credential
actually is
user bound when it is not.
- George: In the US, liability can’t be assigned to the issuer, so
the verifier will need to set their entire policy by themselves.
- Frederik: Why could they not just also ask for a credential that
does have user binding if they want that?
- Hicham: We don’t have to give the verifiers what they want just
because they want it, and this is one of the cases where it
is not a good
idea to let them do anything they want.
- Conformance test readiness for certification
- Thomas: Does the WG think that the conformance test suite is
currently in a good enough state that it can be used for certification?
- There are currently 33 test completions of the test suite. The
majority are from near-final test suite versions.
- Some WG members need to check with their development teams.
- The WG could not give a final confirmation, but this will keep
existing as a standing agenda point.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-digital-credentials-protocols/attachments/20260709/542040d7/attachment.htm>
More information about the Openid-specs-digital-credentials-protocols
mailing list