openideurope.eu

Verifiable credentials explained: digital proofs you control

Verifiable credentials are digitally signed statements you keep in a wallet and show on demand. Roles, flow, formats, risks and their role in the EU wallet.

StandardsPublished

A verifiable credential is a digital statement about you, signed by someone who is in a position to know, that you keep in a wallet and can show to others. Examples are a driving licence, a university diploma, an employee badge or a simple confirmation that you are over 18. Anyone who receives it can check that it is genuine and unchanged, without contacting the issuer.

What verifiable credentials are for

Paper certificates are checked by looking at a stamp. Online, an ID is usually checked by uploading a photo, which is easy to forge and gives away everything on the card. Verifiable credentials aim to bring the strengths of a paper document, such as being held by the person and carrying an official seal, into a form that works on the internet and respects privacy. The wider picture of identity online is given in what is a digital identity.

The three roles

Role What it does Example
Issuer Creates and digitally signs the credential Passport authority, driving licence agency, university
Holder Keeps the credential in a wallet and decides when to show it You
Verifier Asks for a presentation and checks it A shop, a bank, an airline desk

This is often drawn as a triangle: the issuer gives to the holder, the holder shows to the verifier, and the verifier trusts the issuer’s signature. Verifiers learn which issuers to trust from lists or certificates, for example EU trusted lists for qualified providers.

How it works, step by step

  1. Issuance. The issuer verifies who you are, then creates a credential with attributes (such as name or birth year), signs it, and delivers it to your wallet. For the EU wallet this uses OpenID4VCI.
  2. Binding. The credential is tied to a key stored in your wallet, so that only you can show it.
  3. Storage. The wallet keeps it on your device. The issuer does not need to hold a copy.
  4. Request. A verifier asks for certain attributes.
  5. Presentation. You approve, and the wallet shows the requested attributes, with proof of the issuer’s signature and of your key. With selective disclosure, hidden attributes stay hidden. This step uses OpenID4VP.
  6. Verification. The verifier checks the signature, the validity period and whether the credential has been revoked, for example through a status list.

The formats

“Verifiable credential” is a concept with several concrete formats:

  • W3C Verifiable Credentials Data Model 2.0, a Recommendation since 15 May 2025 (see w3.org/TR/vc-data-model-2.0), uses JSON and can be secured in several ways, including JOSE and SD-JWT.
  • SD-JWT VC, a compact JSON format with selective disclosure, see SD-JWT.
  • ISO mdoc (ISO/IEC 18013-5), a binary format from the mobile driving licence world, see mdoc and ISO 18013-5.

A simplified example of the content, whatever the format:

{
  "issuer": "https://authority.example.gov",
  "credentialSubject": {
    "given_name": "Alex",
    "age_over_18": true
  },
  "validUntil": "2031-10-06T00:00:00Z"
}

The European Digital Identity framework uses different words: it speaks of person identification data (PID) and electronic attestations of attributes, which can be qualified and carry legal weight. Technically these are credentials in the formats above.

Everyday examples

  • Proving you are old enough to buy a ticket or a product without showing your birth date, see EU age verification.
  • Showing a mobile driving licence at a rental desk.
  • Opening a bank account with credentials from your wallet.
  • Sharing a diploma with an employer, who can verify it directly.
  • Proving membership or an employee role at a company entrance.

Security aspects

  • Issuer trust is the anchor. A signature proves who issued the credential, not that the issuer was careful. Trust lists and certification are needed, see levels of assurance.
  • Holder binding. Without it, a copied credential could be reused. Binding to a hardware-protected key is the safeguard.
  • Revocation. Lost or withdrawn credentials must be invalid quickly. Status lists solve that, but must avoid creating a tracking channel.
  • Linkability. If you show the same signature or identifier to many verifiers, they can recognise you. Selective disclosure and per-use proofs reduce this, and the topic is explained in EU wallet privacy.
  • Wallet security. A credential is only as safe as the phone and the wallet app that holds it.
  • Social risks. Credentials make it easy to ask for proof. Without rules, services may demand more than they need.

Status and versions

The W3C Verifiable Credentials Data Model 2.0 reached Recommendation status on 15 May 2025. The protocols that move credentials, OpenID4VCI (final, September 2025) and OpenID4VP (final, July 2025), are OpenID Foundation Final Specifications. Format specifications such as SD-JWT VC are developed in the IETF and ISO, and the EU’s technical framework selects which formats and profiles wallets must support. Check the OpenID specifications page for the current protocol documents.

How it relates to the other standards

Verifiable credentials describe the what. Decentralized identifiers are one optional way to identify issuers and holders, and are not required for every credential. OpenID4VCI and OpenID4VP provide the how of issuing and presenting. In contrast with classic federation such as OpenID Connect, nobody has to be online in the middle when you show a credential.

Role in the EUDI Wallet

The EU Digital Identity Wallet is, at its core, a wallet for verifiable credentials. The Architecture and Reference Framework names ISO mdoc and SD-JWT VC as the main formats. Your national ID data arrives as a PID credential, other documents as attestations, and you show them to public and private services of your choice. The regulation (see eIDAS 2.0 at EUR-Lex) requires that using the wallet is free of charge for natural persons and that selective disclosure is supported.

Frequently asked questions

What is a verifiable credential in plain words?

It is the digital version of a certificate or ID card with a tamper-proof seal. Anyone can check that the seal is genuine and that the content has not been changed, but only the holder can present it.

Is a verifiable credential the same as a blockchain thing?

No. Verifiable credentials do not need a blockchain. Some designs use decentralised identifiers on ledgers, but the EU wallet relies on certificates and trust lists rather than a blockchain.

What is the difference between a credential and a presentation?

The credential is what the issuer signs and hands to the wallet. The presentation is what the wallet shows to a verifier in a given moment, usually a subset of the data plus proof that the holder controls the credential.

Can the issuer see where I use my credential?

Not in a well-designed system: the verifier checks the signature on its own, without calling the issuer. Some designs still check revocation lists, which should be built so that they do not reveal individual use. The EU wallet's privacy goals are discussed in the wallet privacy article.

More in Standards