DIDComm (Decentralised Identifier Communication) is a secure, private messaging protocol built on top of the W3C Decentralised Identifiers specification, enabling peer-to-peer, end-to-end encrypted communication between parties whose identities are anchored to DIDs. The protocol specifies how messages are packaged, signed, and encrypted using keys derived from DID documents, without reliance on any central server or directory. DIDComm messages are transport-agnostic, operating over HTTP, Bluetooth, NFC, or any delivery mechanism, making the protocol suitable for both online and offline identity interactions. It forms the communication backbone of the self-sovereign identity ecosystem.

Content

  • DIDComm emerged from the Hyperledger Aries project and was formalised by the Decentralised Identity Foundation’s DIDComm working group, producing the DIDComm Messaging v2 specification. The core insight is that if two parties each possess a DID with published key material, they need no external infrastructure to establish a secure communication channel—keys are the identity, and the channel is derived from them. This eliminates dependencies on TLS certificate authorities, OAuth providers, or any other trusted third party for the communication layer.
  • The message format uses JOSE (JSON Object Signing and Encryption) standards—specifically JWM (JSON Web Messages)—for envelope construction. A sender encrypts and optionally signs the message payload using the recipient’s public key found via DID resolution, producing an opaque encrypted envelope. Only the holder of the corresponding private key can decrypt it, and the DID-based signature proves authorship without revealing the sender’s real-world identity unless explicitly disclosed.
  • DIDComm supports three message types that enable sophisticated interaction patterns: plaintext messages (for discovery and capability negotiation), signed messages (for non-repudiation), and encrypted messages (for confidential exchange). Higher-level protocols—called ‘DIDComm protocols’—layer on top of these primitives to implement specific workflows: credential issuance (Aries RFC 0453), credential presentation (RFC 0454), and out-of-band invitation (RFC 0434). This separation of transport from application logic mirrors TCP/IP’s layered architecture.
  • The practical significance of DIDComm extends beyond identity into agent-to-agent communication in AI and IoT contexts. Autonomous software agents equipped with DIDs can negotiate, authenticate, and exchange verifiable data without human intermediation, potentially underpinning machine-to-machine credentialing in robotics, supply chain, and agentic AI systems. Its integration with Verifiable Credentials makes it a foundational component of portable, privacy-preserving digital trust infrastructure.