[Openid-dcp] DCP WG call notes - EU (2026-07-30)
Paul Bastian
paul.bastian at posteo.de
Thu Jul 30 16:04:08 UTC 2026
Hi all, here are the notes from today's call:
Attendees: Paul Bastian, Kristina Yasuda, Gareth Oliver, Frederik
Krogsdal Jacobsen, Christian Bormann, George Fletcher, Lukasz Jaromin,
Martjin, Oliver Terbu, Paul Grassi, Valentine Mazurov, Hicham Lozi,
David Zeuthen, Rajvardhan Deshmkh, Michael Jones
- Server-to-Server was adopted by the working group
- merge PR next Tueday in the call
- Paul circulates the idea from IETF to extract IAE from OpenID4VCI into
a separate stand-alone IETF OAuth draft
- this enables usage of native client authentication for usecases
other than Credential issuer, i.e. do a VP presentation to an AS to get
an access token
- should be compatible with what we do in IAE
- support from Frederik, Christian, Gareth
- Paul to circulate a mail to OAuth/DCP mailing list
- OpenID4VP close to 1.1
- question whether to cut an Implementers Draft or go straight to publish
- Paul asks whether we have implementation feedback from HPKE encryption
- Gareth will investigate whether they have implementation ready
- OpenID conformance tests are approved
- news will go out next week
- pre-GDC working group call 31rd August 10am-2:30pm
- please arrive early and attend
- OpenID4VP PRs:
- Add security guidance for platform-specific Origins and DC API. - #761
- this states security assumptions about the equivalent of app-based
platform APIs (compared to DC API for browser)
- Helen took a look, it matches Android implementation, but did not
approve
- Martjin to review whether it is reasonable, but there is no such
iOS API yet
- Add text on untrusted input to 1.0 - #759
- discussions what the SHOULD means - these is a non-exhaustive list
of examples
- merged
- duplicate claims entry - #750
- 3 approvals, blocked by Joseph from an older state of this PR
- Clarify an empty object in a VP Token cannot be used to signify an
error response - #745
- Joseph proposed to link to privacy consideration for not sending
errors before user consent
- Oliver applied the changes, seems ready for merge
- OpenID4VCI:
- add redirect_uri to Credential Offer - #759
- Paul presents the latest status, all comments solved
- reviews needed
- update IA HTTP response codes for consistency with FPA draft-4 - #781
- merging
- Remove any terminating / from the Credential Issuer Identifier when
forming the Credential Issuer Metadata URL - #775
- should we add language that Credential Issuer Identifier SHOULD not
have a terminating slash in the first place
- no objections, Paul adds text
- reviews needed
- Use expected URL instead of expected origins for IAE flow - #695
- Micha doubts that we need expected origins in the first place,
because presentation are audience restricted already
- Gareth to leave a comment in the thread why he thinks it makes sense
Best regards,
Paul
More information about the Openid-specs-digital-credentials-protocols
mailing list