W3C DID (Decentralised Identifier) is a W3C Recommendation standard (published July 2022) that defines a new type of globally unique, persistent, and cryptographically verifiable identifier that does not require a centralised registration authority. A DID resolves to a DID Document — a JSON-LD data structure containing public keys, authentication mechanisms, and service endpoints — enabling the DID subject to prove control and establish secure communication without depending on a third-party identity provider. DIDs are the foundational primitive for self-sovereign identity systems.
Content
- The conceptual origins of DIDs lie in the self-sovereign identity (SSI) movement, initiated by Christopher Allen’s 2016 essay “The Path to Self-Sovereign Identity” and the early work of the Rebooting the Web of Trust community. The W3C Credentials Community Group formalised the DID syntax and data model, leading to a W3C Working Group that published the DID Core specification as a W3C Recommendation in July 2022 — despite a notable objection from Google, Mozilla, and Apple who expressed concern about proliferation of DID methods and insufficient standardisation of resolution.
- Technically, a DID is a URI string of the form
did:<method>:<method-specific-identifier>, such asdid:example:123456789abcdefghi. The DID method defines how to create, resolve, update, and deactivate DIDs for a particular verifiable data registry. Resolution retrieves the DID Document — a JSON-LD object containing:verificationMethod(public keys),authentication(methods authorised for authentication proofs),assertionMethod(for credential issuance),keyAgreement(for encrypted communication), andservice(endpoints for protocol interaction). DID controllers update documents by proving control of existing keys. - W3C DID is significant because it replaces the dependence on centralised identity authorities (certificate authorities, email providers, social network platforms) with a verifiable, portable identifier that a subject controls independently. This has profound implications for credential portability (users own their qualifications and licences), privacy (selective disclosure without issuer tracking), and resilience (identity not lost when a service provider disappears). In enterprise contexts, DIDs enable inter-organisational trust without federation agreements.
- In 2024-2025, the EU Digital Identity Wallet (EUDI Wallet) specified under eIDAS2 mandates W3C DID-compatible identifiers for EU citizens, representing the largest government deployment of the standard globally. The W3C DID Working Group published DID Resolution v1.0 and DID Methods Registry updates. OpenID4VCI and OpenID4VP protocols — which bind DID-based key material to credential issuance and presentation — have achieved wide implementation across wallet vendors. The
did:webmethod is seeing particular enterprise adoption as a low-friction entry point, whiledid:jwkanddid:keyserve ephemeral credential use cases.