Supported protocols
This page lists every standard and feature EUDIPLO implements, grouped by area, with a link to the guide that explains how to use it. EUDIPLO implements only the protocols of the EUDI Wallet ecosystem, so it stays interoperable with the reference wallets and uses one trust model.
Legend: โ supported ยท โ ๏ธ partial or experimental (see note) ยท โ not supported
Specificationsโ
| Specification | Role in EUDIPLO |
|---|---|
| OpenID for Verifiable Credential Issuance 1.0 (OID4VCI) | Issuance to wallets |
| OpenID for Verifiable Presentations 1.0 (OID4VP) | Presentation requests and verification |
| SD-JWT-based Verifiable Credentials (SD-JWT VC) | Credential format dc+sd-jwt |
| ISO/IEC 18013-5 (mdoc) | Credential format mso_mdoc |
| ISO/IEC 18013-7 Annex C | mdoc presentation over the Digital Credentials API |
| Token Status List | Revocation and suspension |
| OAuth 2.0 PAR (RFC 9126), PKCE (RFC 7636), DPoP (RFC 9449) | Authorization servers hosted by EUDIPLO |
| OAuth 2.0 Attestation-Based Client Authentication | Wallet attestation |
| ETSI TS 119 602 List of Trusted Entities (LoTE) | Trust lists |
| OpenID Federation 1.0 | Federation-based trust (partial) |
OID4VCI (issuance)โ
| Feature | Status | Notes | Guide |
|---|---|---|---|
| Pre-authorized code flow | โ | Optional tx_code; the code is locked after too many wrong attempts | Credential offers |
| Authorization code flow | โ | Built-in, external, chained and OID4VP-based authorization servers | Authorization servers |
| Pushed authorization requests (PAR) | โ | Required by every authorization server EUDIPLO hosts; wallet-initiated requests without issuer_state are accepted | Authorization servers |
| PKCE | โ | S256 only, for every authorization code | Authorization servers |
| Refresh tokens | โ | On by default for hosted authorization servers, 30-day lifetime | Authorization servers |
| DPoP | โ | Proofs verified per RFC 9449 (signature, htm/htu, freshness, single-use jti, ath, key binding) | Authorization servers |
| Chained authorization server | โ | EUDIPLO issues the tokens and delegates user login to an upstream OpenID Connect provider | Authorization servers |
| OID4VP-based authorization server | โ | The wallet authorizes issuance by presenting a credential | Authorization servers |
| Interactive authorization endpoint | โ ๏ธ | Experimental; behavior may change | Interactive authorization |
| Nonce endpoint | โ | POST /issuers/{tenant}/vci/nonce; nonces are single use | Issuance under the hood |
| Batch issuance | โ | Enabled when batchSize is greater than 1; one credential per holder key | Issuance configuration |
| Deferred issuance | โ | Your backend completes or fails the transaction later | Deferred issuance |
| Notification endpoint | โ | Can be disabled per tenant | Notifications |
| Credential request and response encryption | โ | Offered in the issuer metadata; can be made mandatory per tenant | Issuance configuration |
| Signed issuer metadata | โ | Returned for Accept: application/jwt, signed with the tenant's access certificate | Issuance configuration |
| Wallet attestation | โ | OAuth-Client-Attestation headers at PAR and token endpoints of hosted authorization servers | Wallet and key attestation |
| Key attestation | โ | attestation proof type, or a key_attestation header in jwt proofs | Wallet and key attestation |
OID4VP (presentation)โ
| Feature | Status | Notes | Guide |
|---|---|---|---|
| Signed request object by reference | โ | request_uri with GET or POST | Presentation requests |
direct_post.jwt response mode | โ | Responses are always encrypted; plain direct_post is not accepted | Presentation requests |
| DCQL | โ | Including credential_sets, claim_sets, values, multiple and trusted_authorities | DCQL |
| Session separation and response code (ยง13.3) | โ | Wallet-facing identifier separate from the session ID; one-time response_code on same-device redirects | Sessions |
| Client identifier prefixes | โ | x509_hash (default) and x509_san_dns; other prefixes are not supported | Presentation requests |
| Transaction data | โ | Hashes checked in the SD-JWT VC key binding JWT; TS12 types (urn:eudi:sca:*) are validated | Transaction data |
| Registration certificate in the request | โ | Sent as verifier_info | Registration certificates |
| Digital Credentials API | โ | dc_api.jwt response mode with expected_origins | Presentation requests |
| ISO 18013-7 Annex C | โ | org-iso-mdoc over the Digital Credentials API; ignores redirectUri, transaction_data and clientIdScheme | Presentation requests |
| Status check of presented credentials | โ | statusCheckMode: strict (default), best_effort or disabled | Configure verification |
Credential formatsโ
| Format | Issue | Verify | Notes | Guide |
|---|---|---|---|---|
SD-JWT VC (dc+sd-jwt) | โ | โ | Issuer trust signaled with an x5c header (default) or OpenID Federation (sdJwtTrustFormat) | Credential configuration |
mdoc (mso_mdoc) | โ | โ | Over OID4VCI, OID4VP and ISO 18013-7 Annex C | Credential configuration |
| mdoc proximity (BLE, NFC) | โ | โ | No device engagement or offline presentation flows | |
| W3C VCDM formats | โ | โ | jwt_vc_json, ldp_vc and similar are not supported |
Statusโ
| Feature | Status | Notes | Guide |
|---|---|---|---|
| Token Status List (publish) | โ | Served as JWT or CWT depending on the Accept header; status values 1 = revoked, 2 = suspended | Revocation |
| Status list aggregation | โ | Enabled by default (STATUS_ENABLE_AGGREGATION) | Revocation |
| Token Status List (verify) | โ | Checked for presented credentials according to statusCheckMode | Configure verification |
| CRL or OCSP for presented certificates | โ | Credential revocation relies on status lists |
Trustโ
| Feature | Status | Notes | Guide |
|---|---|---|---|
| LoTE trust lists | โ | Host signed lists per tenant and consume external ones; ETSI TS 119 612 XML lists are not loaded | Trust lists |
| OpenID Federation | โ ๏ธ | Entity configurations are fetched and authority_hints followed, but statements are not yet verified cryptographically | OpenID Federation |
| Access certificates | โ | X.509 certificate of the access key chain signs requests and signed metadata and determines the client_id | Keys and certificates |
| Registration certificates | โ | For verifiers (verifier_info) and issuers (issuer_info), issued by a registrar | Registration certificates |
| Credential reuse policy | โ | credentialReusePolicy published in the credential metadata | Credential configuration |
| Embedded disclosure policy | โ | embeddedDisclosurePolicy: none, allowList, rootOfTrust or attestationBased | Credential configuration |
Conformanceโ
EUDIPLO is tested against the OpenID Foundation conformance suite for OID4VCI and OID4VP. To run the suite yourself, see Testing. Results with individual wallets are recorded in Wallet compatibility.