Credential issuance with unknown (i.e. not pre-registered) wallets
Nobody has claimed this yet.
- Dominant language
- No language data
- Stars
- 125
- Forks
- 41
- PR merge metrics
- No merged PRs in 30d
Description
Is there anything being planned for supporting the issuance of credentials to wallets that don't have a pre-registered OAuth Client on the issuer's AS?
Q1: I presume that in open and low assurance environments, a wallet should not need to be pre-registered on all the issuers an user may use, right?
For OpenID4VP, we have the client_id_scheme concept (https://openid.net/specs/openid-4-verifiable-presentations-1_0.html#client_metadata_management), which allows for alternative ways of dealing with OAuth clients (Verifiers in the VP case), other than pre-registered.
However, no similar mechanism is available on VCI.
Q2: Is the use of Dynamic Client Registration (RFC 7591) the only way to deal with wallets that are pre-registered on the issuer's AS?
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reading the OpenID4VCI issue discussion, then review the linked OpenID4VP client_metadata_management section and RFC 7591. The issue is resolved when the project has a decided, documented mechanism for issuing credentials to wallets without pre-registered OAuth clients, including whether Dynamic Client Registration is required.
Written by the indexing model from the issue text.
Assessment
- Domain
- authentication, authorization, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100