22C/ VC Issuance with OpenID Connect (using Credential Manifest?) Part 2

From IIW

VC Issuance with OpenID Connect (using Credential Manifest?) Part 2

Thursday 22C

Convener: Torsten Lodderstedt, Kristina Yasuda

Notes-taker(s)

Tags for the session - technology discussed/ideas considered:

SSI, OIDC, Issuance

Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps

We discussed this hackMD https://hackmd.io/0k1e45a9Ru-cizD7Gp86ig?view

Two problems:

  • Binding of the assertions to the Client/End-user that requested it

    • → defining a new `proof` parameter that client can pass to the Token Endpoint or Credential Endpoint (newly defined endpoint) to request binding of the returned credential to a cryptographic material in the `proof`. To accommodate various kind of proofs.

  • A mechanism to request certain types of credentials.

    • → Claims parameter with DIF Presentation Exchange

Design advice to design credential req-res first

Suggestion to use `response_type` - id_token