[Openid-dcp] Minutes from July 9th, 2026 DCP WG call

Frederik Krogsdal Jacobsen frederik.krogsdal at idura.eu
Thu Jul 9 16:04:03 UTC 2026


   - Participants: Brent Zundel, Frederik Krogsdal Jacobsen, Valentine
   Mazurov, Helen Qin, Thomas Darimont, Lee Campbell, George Fletcher, Paul
   Grassi, Ryan Galluzzo, Paul Bastian, Oliver Terbu, Bjorn Hjelm, Christian
   Bormann, Rene Leveille, Rajvardhan Deshmukh, Mike Jones, Martijn Haring,
   Hicham Lozi, Akash Shah
   - Events
      - In-person WG meeting before GDC? Probably at least 7 people would
      join.
   - Certification issues
      - https://github.com/openid/OpenID4VP/issues/718
         - Lee: It should not really be necessary to say anything here in
         particular, since it is always the case that you may get fewer data
         elements than requested.
         - Martijn: This is a bit different, since ISO 18130-5 says that
         you MUST return a different claim (e.g. if asked for
age_over_18 and you
         only have age_over_19, you MUST return age_over_19). Given the current
         specs, is this allowed?
         - Christian: The answer is probably no.
         - Martijn: We should at least explicitly say that you should not
         follow the “age over” logic if that is the case.
         - Christian: It would be cleaner to just do a big disjunction of
         the possible claims.
         - Frederik: Doing that kind of looks like over-asking, so we
         should at least clarify what is allowed.
         - Lee: Is this really a certification issue? The big disjunction
         would work.
         - Hicham: The wallet would need to do different things depending
         on which kind of request it is getting.
         - Lee: Yes, but that’s the reality of supporting multiple
         protocols. The quirks in the mdoc presentation queries will
probably not be
         added to the unified protocol either.
         - Christian: From a robustness perspective, it would be better to
         explicitly express this in the query instead of having
special exceptions
         for credential types.
         - Martijn: The certification question is whether it is forbidden
         to respond with the extra claims or not.
         - There was not agreement on whether it should be allowed to
         define custom matching logic for specific credential types
(as is done in
         ISO 18130-5).
      - https://github.com/openid/OpenID4VC-HAIP/issues/364
         - The WG confirmed that the intention was to allow people to
         implement the pre-authorized code flow if they want to.
         - The authorization code flow must be supported by wallets and
         issuers.
      - https://github.com/openid/OpenID4VCI/issues/744
         - Frederik and Paul: This is technically a breaking change, but it
         seems extremely unlikely that it would actually break
anything to fix it.
         Any URL library would already implement the corrected behaviour.
      - OpenID4VP
      - https://github.com/openid/OpenID4VP/issues/755
         - Helen: Request from verifiers is to allow setting a preference
         about whether user verification is done by the wallet in the
VP request.
         - Frederik: Why not just always challenge? This seems to be the
         request.
         - Helen: There are some use cases where you don’t need a
         challenge, e.g. phone number credentials to replace SMS OTP.
         - Frederik: What does the “biometric required” flag actually mean?
         A wallet could say it about wildly different things.
         - Lee: It’s the same as for passkeys; it doesn’t really mean
         anything.
         - Ryan: RPs are asking for more specific authentication types
         already. We will need to deal with this eventually. They want
to both state
         a preference and ask what actually happened.
         - Hicham: This should happen in the issuer stage and has a huge
         impact on accessibility.
         - Ryan: The RP will always set the policy, so even if we don’t
         allow this, they will do it some other way.
         - Brent: VCDM is working on something similar:
         https://www.w3.org/TR/vc-confidence-method/
         - Paul: I understand the motivation, but we previously decided not
         to have wallet attestations in VP, so there is no assurance
anyway. If the
         issuer does not do device binding, presenting the credential
as if it has
         user authentication may make verifiers think the credential
actually is
         user bound when it is not.
         - George: In the US, liability can’t be assigned to the issuer, so
         the verifier will need to set their entire policy by themselves.
         - Frederik: Why could they not just also ask for a credential that
         does have user binding if they want that?
         - Hicham: We don’t have to give the verifiers what they want just
         because they want it, and this is one of the cases where it
is not a good
         idea to let them do anything they want.
      - Conformance test readiness for certification
      - Thomas: Does the WG think that the conformance test suite is
      currently in a good enough state that it can be used for certification?
      - There are currently 33 test completions of the test suite. The
      majority are from near-final test suite versions.
      - Some WG members need to check with their development teams.
      - The WG could not give a final confirmation, but this will keep
      existing as a standing agenda point.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-digital-credentials-protocols/attachments/20260709/542040d7/attachment.htm>


More information about the Openid-specs-digital-credentials-protocols mailing list