Credential issuance is the process by which an authoritative entity — an issuer — creates, signs, and delivers a structured attestation about a subject’s attributes, qualifications, or identity to that subject or to a designated holder. In the W3C Verifiable Credentials model, issuance involves binding claims to a subject’s decentralised identifier using the issuer’s cryptographic key, producing a tamper-evident credential that the holder can present to verifiers without returning to the issuer. The issuance process encompasses schema selection, claim population, signature generation, and delivery, and may be implemented with varying degrees of issuer privacy, holder binding strength, and revocability.

Content

  • Before verifiable credential frameworks, credential issuance was tightly coupled to verification: a diploma required the university to be contacted; an age assertion required showing a government-issued identity document. The X.509 certificate system, developed in the 1980s for TLS and PKI, introduced cryptographically signed credentials but kept issuance and verification tightly coupled to hierarchical certificate authority chains. The emergence of OpenID Connect and OAuth 2.0 in the 2010s created federated identity patterns, but these still routed verification through the issuer. The W3C Verifiable Credentials specification, reaching Recommendation status in 2019 and its second version in 2023, decoupled issuance from verification by cryptographically binding claims to a holder’s decentralised identifier.
  • The technical issuance process involves the issuer selecting a credential type and conforming schema, populating claim fields with verified attribute values, selecting a signature suite (e.g. Ed25519Signature2020, BBS+, or SD-JWT), signing the credential data structure, and delivering the signed credential to the holder. Selective disclosure schemes such as BBS+ signatures and SD-JWT allow the holder to present only a subset of claims from the issued credential, preserving privacy. Status list mechanisms (revocation lists, status list credentials) allow the issuer to mark credentials as revoked without requiring holder interaction.
  • The significance of credential issuance lies in its role as the entry point to digital trust ecosystems. Governments issuing mobile driving licences (ISO/IEC 18013-5 mDL), universities issuing digital diplomas (Open Badges, Europass), and healthcare providers issuing professional qualifications all participate in credential ecosystems by performing the issuance step. The EU’s eIDAS 2.0 regulation mandates that member states issue identity wallets capable of receiving verifiable credentials from public authorities, representing the largest credential issuance deployment mandate to date.
  • As of 2024–2025, credential issuance standards are converging across multiple specifications: W3C VC Data Model 2.0, OpenID for Verifiable Credential Issuance (OID4VCI), and the IETF SD-JWT VC specification. The OID4VCI protocol has become the de facto issuance transport, enabling wallets to request credentials from issuer endpoints using standard OAuth 2.0 flows. Hardware-bound credentials — where the holder’s private key resides in a secure element — are emerging as a requirement for high-assurance issuance scenarios such as government identity and professional licensing.