[Openid-dcp] DCP WG call notes - EU (2026-07-30)

Paul Bastian paul.bastian at posteo.de
Thu Jul 30 16:04:08 UTC 2026


Hi all, here are the notes from today's call:

Attendees: Paul Bastian, Kristina Yasuda, Gareth Oliver, Frederik 
Krogsdal Jacobsen, Christian Bormann, George Fletcher, Lukasz Jaromin, 
Martjin, Oliver Terbu, Paul Grassi, Valentine Mazurov, Hicham Lozi, 
David Zeuthen, Rajvardhan Deshmkh, Michael Jones

- Server-to-Server was adopted by the working group
   - merge PR next Tueday in the call
- Paul circulates the idea from IETF to extract IAE from OpenID4VCI into 
a separate stand-alone IETF OAuth draft
   - this enables usage of native client authentication for usecases 
other than Credential issuer, i.e. do a VP presentation to an AS to get 
an access token
   - should be compatible with what we do in IAE
   - support from Frederik, Christian, Gareth
   - Paul to circulate a mail to OAuth/DCP mailing list
- OpenID4VP close to 1.1
   - question whether to cut an Implementers Draft or go straight to publish
   - Paul asks whether we have implementation feedback from HPKE encryption
   - Gareth will investigate whether they have implementation ready
- OpenID conformance tests are approved
   - news will go out next week
- pre-GDC working group call 31rd August 10am-2:30pm
   - please arrive early and attend
- OpenID4VP PRs:
- Add security guidance for platform-specific Origins and DC API. - #761
   - this states security assumptions about the equivalent of app-based 
platform APIs (compared to DC API for browser)
   - Helen took a look, it matches Android implementation, but did not 
approve
   - Martjin to review whether it is reasonable, but there is no such 
iOS API yet
- Add text on untrusted input to 1.0 - #759
   - discussions what the SHOULD means - these is a non-exhaustive list 
of examples
   - merged
- duplicate claims entry - #750
   - 3 approvals, blocked by Joseph from an older state of this PR
- Clarify an empty object in a VP Token cannot be used to signify an 
error response - #745
   - Joseph proposed to link to privacy consideration for not sending 
errors before user consent
   - Oliver applied the changes, seems ready for merge
- OpenID4VCI:
- add redirect_uri to Credential Offer - #759
   - Paul presents the latest status, all comments solved
   - reviews needed
- update IA HTTP response codes for consistency with FPA draft-4 - #781
   - merging
- Remove any terminating / from the Credential Issuer Identifier when 
forming the Credential Issuer Metadata URL - #775
   - should we add language that Credential Issuer Identifier SHOULD not 
have a terminating slash in the first place
   - no objections, Paul adds text
   - reviews needed
- Use expected URL instead of expected origins for IAE flow - #695
   - Micha doubts that we need expected origins in the first place, 
because presentation are audience restricted already
   - Gareth to leave a comment in the thread why he thinks it makes sense

Best regards,
Paul



More information about the Openid-specs-digital-credentials-protocols mailing list