Skip to main content

Supported protocols

This page lists every standard and feature EUDIPLO implements, grouped by area, with a link to the guide that explains how to use it. EUDIPLO implements only the protocols of the EUDI Wallet ecosystem, so it stays interoperable with the reference wallets and uses one trust model.

Legend: โœ… supported ยท โš ๏ธ partial or experimental (see note) ยท โŒ not supported

Specificationsโ€‹

SpecificationRole in EUDIPLO
OpenID for Verifiable Credential Issuance 1.0 (OID4VCI)Issuance to wallets
OpenID for Verifiable Presentations 1.0 (OID4VP)Presentation requests and verification
SD-JWT-based Verifiable Credentials (SD-JWT VC)Credential format dc+sd-jwt
ISO/IEC 18013-5 (mdoc)Credential format mso_mdoc
ISO/IEC 18013-7 Annex Cmdoc presentation over the Digital Credentials API
Token Status ListRevocation and suspension
OAuth 2.0 PAR (RFC 9126), PKCE (RFC 7636), DPoP (RFC 9449)Authorization servers hosted by EUDIPLO
OAuth 2.0 Attestation-Based Client AuthenticationWallet attestation
ETSI TS 119 602 List of Trusted Entities (LoTE)Trust lists
OpenID Federation 1.0Federation-based trust (partial)

OID4VCI (issuance)โ€‹

FeatureStatusNotesGuide
Pre-authorized code flowโœ…Optional tx_code; the code is locked after too many wrong attemptsCredential offers
Authorization code flowโœ…Built-in, external, chained and OID4VP-based authorization serversAuthorization servers
Pushed authorization requests (PAR)โœ…Required by every authorization server EUDIPLO hosts; wallet-initiated requests without issuer_state are acceptedAuthorization servers
PKCEโœ…S256 only, for every authorization codeAuthorization servers
Refresh tokensโœ…On by default for hosted authorization servers, 30-day lifetimeAuthorization servers
DPoPโœ…Proofs verified per RFC 9449 (signature, htm/htu, freshness, single-use jti, ath, key binding)Authorization servers
Chained authorization serverโœ…EUDIPLO issues the tokens and delegates user login to an upstream OpenID Connect providerAuthorization servers
OID4VP-based authorization serverโœ…The wallet authorizes issuance by presenting a credentialAuthorization servers
Interactive authorization endpointโš ๏ธExperimental; behavior may changeInteractive authorization
Nonce endpointโœ…POST /issuers/{tenant}/vci/nonce; nonces are single useIssuance under the hood
Batch issuanceโœ…Enabled when batchSize is greater than 1; one credential per holder keyIssuance configuration
Deferred issuanceโœ…Your backend completes or fails the transaction laterDeferred issuance
Notification endpointโœ…Can be disabled per tenantNotifications
Credential request and response encryptionโœ…Offered in the issuer metadata; can be made mandatory per tenantIssuance configuration
Signed issuer metadataโœ…Returned for Accept: application/jwt, signed with the tenant's access certificateIssuance configuration
Wallet attestationโœ…OAuth-Client-Attestation headers at PAR and token endpoints of hosted authorization serversWallet and key attestation
Key attestationโœ…attestation proof type, or a key_attestation header in jwt proofsWallet and key attestation

OID4VP (presentation)โ€‹

FeatureStatusNotesGuide
Signed request object by referenceโœ…request_uri with GET or POSTPresentation requests
direct_post.jwt response modeโœ…Responses are always encrypted; plain direct_post is not acceptedPresentation requests
DCQLโœ…Including credential_sets, claim_sets, values, multiple and trusted_authoritiesDCQL
Session separation and response code (ยง13.3)โœ…Wallet-facing identifier separate from the session ID; one-time response_code on same-device redirectsSessions
Client identifier prefixesโœ…x509_hash (default) and x509_san_dns; other prefixes are not supportedPresentation requests
Transaction dataโœ…Hashes checked in the SD-JWT VC key binding JWT; TS12 types (urn:eudi:sca:*) are validatedTransaction data
Registration certificate in the requestโœ…Sent as verifier_infoRegistration certificates
Digital Credentials APIโœ…dc_api.jwt response mode with expected_originsPresentation requests
ISO 18013-7 Annex Cโœ…org-iso-mdoc over the Digital Credentials API; ignores redirectUri, transaction_data and clientIdSchemePresentation requests
Status check of presented credentialsโœ…statusCheckMode: strict (default), best_effort or disabledConfigure verification

Credential formatsโ€‹

FormatIssueVerifyNotesGuide
SD-JWT VC (dc+sd-jwt)โœ…โœ…Issuer trust signaled with an x5c header (default) or OpenID Federation (sdJwtTrustFormat)Credential configuration
mdoc (mso_mdoc)โœ…โœ…Over OID4VCI, OID4VP and ISO 18013-7 Annex CCredential configuration
mdoc proximity (BLE, NFC)โŒโŒNo device engagement or offline presentation flows
W3C VCDM formatsโŒโŒjwt_vc_json, ldp_vc and similar are not supported

Statusโ€‹

FeatureStatusNotesGuide
Token Status List (publish)โœ…Served as JWT or CWT depending on the Accept header; status values 1 = revoked, 2 = suspendedRevocation
Status list aggregationโœ…Enabled by default (STATUS_ENABLE_AGGREGATION)Revocation
Token Status List (verify)โœ…Checked for presented credentials according to statusCheckModeConfigure verification
CRL or OCSP for presented certificatesโŒCredential revocation relies on status lists

Trustโ€‹

FeatureStatusNotesGuide
LoTE trust listsโœ…Host signed lists per tenant and consume external ones; ETSI TS 119 612 XML lists are not loadedTrust lists
OpenID Federationโš ๏ธEntity configurations are fetched and authority_hints followed, but statements are not yet verified cryptographicallyOpenID Federation
Access certificatesโœ…X.509 certificate of the access key chain signs requests and signed metadata and determines the client_idKeys and certificates
Registration certificatesโœ…For verifiers (verifier_info) and issuers (issuer_info), issued by a registrarRegistration certificates
Credential reuse policyโœ…credentialReusePolicy published in the credential metadataCredential configuration
Embedded disclosure policyโœ…embeddedDisclosurePolicy: none, allowList, rootOfTrust or attestationBasedCredential configuration

Conformanceโ€‹

EUDIPLO is tested against the OpenID Foundation conformance suite for OID4VCI and OID4VP. To run the suite yourself, see Testing. Results with individual wallets are recorded in Wallet compatibility.