OpenID for Verifiable Credential Issuance (OpenID4VCI) is an OpenID Foundation protocol specification that defines a standard API by which an Issuer can deliver W3C Verifiable Credentials to a Holder’s digital wallet using OAuth 2.0 and OpenID Connect as the underlying authorisation and identity layer. The protocol specifies credential offer flows, authorisation code and pre-authorised code grant types, credential endpoint interactions, and metadata discovery, enabling interoperable credential issuance across identity wallet implementations and issuing authority systems. It is designed to complement OpenID4VP (Verifiable Presentations) to form a complete self-sovereign identity exchange ecosystem.
Content
- OpenID4VCI emerged from the OpenID Foundation’s Digital Credentials working group as the digital identity community sought to standardise what had previously been a fragmented landscape of proprietary credential delivery APIs. Earlier SSI systems each defined their own DIDComm-based issuance protocols or vendor-specific REST endpoints, creating interoperability barriers for wallet vendors and issuers alike. The OpenID Foundation, building on its established OAuth 2.0 and OIDC foundations, published the OpenID4VCI draft specification beginning in 2022, with rapid uptake from the eIDAS 2.0 European Digital Identity Wallet framework and the US digital driver’s licence ecosystem.
- The protocol defines two primary issuance flows. In the authorisation code flow, a Holder initiates a request to an Issuer, completes an authentication and consent step via standard OIDC, and receives a credential after the Issuer’s Credential Endpoint processes a signed credential request. In the pre-authorised code flow — suited for in-person or out-of-band initiation — the Issuer provides a credential offer (typically via QR code or deep link) containing a pre-authorised code that the wallet redeems directly without a fresh authentication step. Both flows terminate at a Credential Endpoint that validates the request, generates the credential, and returns it in the format declared by the wallet.
- The specification has become a cornerstone of the European Union’s eIDAS 2.0 regulation implementation, which mandates that member states provide digital identity wallets capable of receiving government-issued credentials. National identity programmes in Germany (EUDI Wallet), France, and Spain are implementing OpenID4VCI as their issuance API. The specification also underlies the Open Wallet Foundation’s wallet interoperability profiles, and major credential issuers including university degree and professional licence authorities are building issuance services conformant to the spec.
- As of 2024-2025, OpenID4VCI is in advanced draft status progressing towards a finalised specification at the OpenID Foundation, with multiple implementations having passed interoperability testing at events like the IETF/OpenID hackathons. Key areas of active development include batch credential issuance for efficiency, deferred issuance flows for credentials that require background verification, and enhanced key attestation bindings to ensure that credentials are cryptographically bound to hardware-backed keys in the holder’s device — a critical property for high-assurance government identity use cases.