W3C

VCWG Recognized Entities

14 July 2026

Attendees

Present
benjamin_young, benjamin_young's_presentation, Dave Longley, elaine_wooton, kayode_ezike, phil_archer, Phillip Long, Steve Capell, ted_thibodeau_jr, todd_snyder
Regrets
-
Chair
-
Scribe
transcriber

Meeting minutes

VC Recognized Entities Call Start

Benjamin_Young: Sorry for the wait y'all if you're stuck in a lobby or something. Okay, I think we will start.

Benjamin_Young: This is the VC recognized entities call and I believe we will go through a few semi-active PRs and see if we have time left for issues. I do need to drop towards the end of the hour. I'm happy to hand off hearing, but I am a little concerned that if I leave, everyone's going to get dunked. not certain of that though, because I think I can leave people on the call. would anyone like to hear assuming the technology is still around after I bail?

PR Review Process

Benjamin_Young: All right, we'll just see how things go once we get to that point. I'm going to share the poll requests and I'll try and drop links in chat for those who'd prefer to look at their own screen. looks like Chayasan is not online at the moment, so we're not going to do the digest SRI one.

Use Case Additions for Education and Vital Records

Benjamin_Young: This one has had some recent activity. from last week. Dave has approved Mono is not here. We can't see the diff. Look at this, I guess. Dave, you've approved this. Do you want to give a quick recap?

Dave Longley: Yeah, this is just adding a couple of into the use cases one for the education space, one for vital records. I think it's pretty non-controversial.

Dave Longley: non-normative. just helpful to have there. We can always edit this or change remove as needed. So it looked good to

Benjamin_Young: Yeah, it looks fine.

<Benjamin_Young> Pull requests · w3c/vc-recognized-entities · GitHub

Benjamin_Young: Anybody need an extra second to skin this? hearing no objections. gonna go ahead and rebase and merge it. I think the only complaint is about the CI failure, which I think is just that's the preview generator. There's nothing in the PR I saw that would cause that. So, we're going to assume the PR bot is got other issues.

Credential-Based Discovery PR

Benjamin_Young: Rebasing and merging That transcript should show up. Okay, I'm just going to keep working up from the bottom. Mono again adding a section on credentialbased discovery. So it looks like you plus one to this and so did Steve. You guys have any more you want to say about this?

Steve Capell: Looks pretty also uncontroversial.

<Benjamin_Young> Add &quot;display information&quot; and &quot;credential type&quot; use cases. by msporny · Pull Request #93 · w3c/vc-recognized-entities · GitHub

Steve Capell: The next one's a little trickier.

Benjamin_Young: All right.

Phillip Long: Yeah, it was straightforward.

Phillip Long: I thought nothing.

Benjamin_Young: I will go ahead and merge this one. probably be saying subtopic on that. I don't know. All right. What were you saying, Phil? …

<Benjamin_Young> Add section on credential-based discovery. by msporny · Pull Request #94 · w3c/vc-recognized-entities · GitHub

Phillip Long: I hadn't clicked mute yet.

Benjamin_Young: No worries.

Benjamin_Young: So this one, Steve, I think you were saying was slightly more debatable.

Add section on identifier-based discovery by msporny · Pull Request #99 · w3c/vc-recognized-entities · GitHub

Identifier-Based Discovery Discussion

Steve Capell: This is the one where I briefly questioned the need for a VP without honestly a lot of justification other than sort of feeling that it's the wrong place for a VP. But then the owners of the who is spec interjected fairly strongly I thought saying no no no we insist and I thought okay maybe it doesn't matter that much and then I noticed that Bill Archer who's also not on this call made a comment to the effect as seems unnecessarily complicated. So, this one feels a bit unresolved and in thinking about it, I have to admit I still don't have a good rationale to object to a VP, and I started thinking about it in terms of what is it likely to mean for implementers?

Steve Capell: what's and not just implementers as in software platforms but the kind of the operationalization of it. So I'm imagining for example small tomedium business using some accounting software doesn't know what a did or a VC or a VP is and his software is configured to allow issuing of invoices as VCs and also understands that the government in that jurisdiction is issuing recognized entity credentials for businesses.

Steve Capell: for example. And so the software is probably going to orchestrate some sort of let me create a DID for you and then facilitate some sort of interaction and proof of control of the DID with the authorative Business user is just going to click on intuitive buttons. and we're going to finish up with probably a DID that's hosted on behalf of that business user in the accounting package linked to a recognized entity credential issued by the government register.

Steve Capell: And in that context is it going to be any different in terms of user experience whether it's a VP or a VC DID the software already has the private key because it DID the accounting software this created the DID for the business so it can issue a BP it seems feasible right I suspect we thinking through this kind of operationalization hard word to say of this it also occurred to me that if that's the way it sort of happened for those initially large cohort of users that haven't thought ahead and said no wait a minute I want to control my own did and I'm going to hold it and demand that my accounting

Steve Capell: package, use it rather than create it for me. reality is there could be a lot of differents for the all possibly to the same recognized entity credential. it'd be separate recognized entity credentials, wouldn't it? Because in each case, the authorative register would have to prove control of a different did. So, if I've got, I don't know, four different software packages that do stuff, right?

Steve Capell: whether it's issuing invoices or way bills or whatever it is. and each one is going to attach an authoritative identity but each one creates a did for me because I don't know what a did is the end point is going to be four software packages which I have a Four DIDs representing me in my user account. Four recognized entity credentials all issued by the same register but with a different DID subject. Right. …

Benjamin_Young: So,…

Steve Capell: this is just me sort of musing on how this might actually work. Does anyone have any thoughts or comments on do you think that's realistic? And if so, does it actually matter whether it's a VP or a VC that's in the linked?

Steve Capell: in each of these four did documents and…

Todd_Snyder: And that's it.

Steve Capell: is there any concerns with all this?

Benjamin_Young: we've got these are excellent questions.

Steve Capell: Do we need to mitigate against this sort of thing somehow or do we care? excellent question.

Benjamin_Young: We may need to take them one at a time, but Dave Dave is on the queue and Phil Archer has joined. thank you, Phil, for being up so late. go ahead Dave. Phil were discussing Not sure if you can see the back scroll on the chat or…

Benjamin_Young: I apologize for not being as timely as you were.

Phil_Archer: I'm out walking the dog with Thank you.

Phil_Archer: I joined at the top of the air, but there's no one here, so I tried again later on. So, apologies for being wet.

Benjamin_Young: Go ahead, D.

Dave Longley: So, I don't see any specifically glaring problems with anything you said,…

Steve Capell: work that way.

Dave Longley: Most of what you said could work. And I imagine people might design and build software to have it work that way. But I also wanted to say just in case this hadn't been said out loud before, just because something's wrapped up in a specific data model, first of all, doesn't mean that anyone receiving the VP has to care about the proof on it. they might not care. and second of all, it doesn't even have to have a proof on it.

Dave Longley: The data model supports putting VCs in a wrapper together in a VP just as a wrapper, just as a mechanism by which to deliver things.

Steve Capell: Right. Yeah.

Dave Longley: And so, you can have situations with software where you could elect to just put a VP wrapper around whatever VCs you want without offering anyone any authentication. And if that works in a particular ecosystem, then that's fine. And if it doesn't, then you better make sure to sign the thing. and though you've got choices.

Steve Capell: Yeah. Look, I think I talked myself into thinking it doesn't actually matter VP or VC.

Steve Capell: And it also just made me think about broader issues of proliferation of DIDs and how they're managed. cuz we often think of one did with multiple linked recognized entity credentials from different authorities. you are a authorized registered mana beekeeper and this Australian business, but actually unless a business is proactive or a user is proactive in insisting that they control the likelihood is there'll be a proliferation of DIDs and they're really nothing more than a glue between some account on some software package and some credential issued by register.

Steve Capell: So, you could have four dids all linking to the same entity. And I'm not sure it matters either, And I just thought I'd bring it up and see what people thought. But I think it's probably realistic that it'll go that way, right? Yeah.

Dave Longley: Yeah, I agree. I don't think it matters. It's realistic it'll go that way. And people should not assume that there's only going to be, one did for any given entity out there. But there could be a number of them for any number of reasons. And it should all continue to work architecturally.

Steve Capell: In that case, I don't have any great concerns, but I know Phil also had a bit of me about this,…

Benjamin_Young: Go ahead, Phil.

Steve Capell: so maybe he'd like to say something.

Proliferation of DIDs

Phil_Archer: Not about that particularly. about I'm just thinking about what you were just saying there, and I can see exactly why one organization might end up with multiple bids from a relying party point of view… Phil Archer:

Steve Capell: Christ.

<Phillip Long> If you're sending a VC across the internet without using a signed wrapper, aka a VP, you have to trust something else or not care if the source was who it claims to be.

Phil_Archer: if you're verifying all this stuff. it is the fact that somebody turns up and says I represent this company and here are the four or multiple different identities for someone who is not wellversed in this technology you might think which one's a real one who looks to me one might be real and three are fake and I know that isn't true it's not true but an ill-informed or… non-expert I should say person relying on this may have a problem with that even though they don't need to. Phil Archer:

Steve Capell: It's a plausible attack vector,…

Steve Capell: isn't it? that I'm not chosen our security model where some software system that is not particularly important or strategic to a business but they use it for something says would you like to I don't know link an authoritative identity to this and the software system facilitates a conversation with the authoritative register DID proves control of that did to the register and now essentially that software system has the power to masquerade is that business,…

Phil_Archer: Yeah. Heat.

Steve Capell: and it might be all legitimate because it's genuinely my accounting package. I log into it every day.

<Dave Longley> ^ that's right and for some use cases, all you care about is the VC itself, and the VP is just a container to provide multiple VCs at once.

Steve Capell: I've used it for 10 years or it could be a thing I downloaded because I wanted to I don't know write an academic article and I mean that this kind of possibility for systems I don't know to spin up a DID when I don't even know…

Phil_Archer: Yeah, it is and…

Steve Capell: what a DID is and then link it to an authoritative register and then reuse it in a different context is an attack vector, isn't it?

Phil_Archer: I think as I say it's an issue the kind of the person through no fault of his or her own I should stress that they're not aware of what's going on and so things that I don't understand. I'm more wary of than things I do understand. And so I think if I'm running a trust register and you're asking me to issue a recognized entity credential to four different identifiers,…

Phil_Archer: I might be someone who would say, "Which one do you want? I can't do four. I can only do one." Or, "This doesn't look right." Or whatever it may be. And just give me your name and I'll put your name in this Excel spreadsheet and we'll call it done.

Steve Capell: Yeah, what you're saying is perhaps the onus to mitigate the attack vector falls on the authoritative register…

Steve Capell: who should know better than the member of the

Steve Capell: register about that attack vector and…

Phil_Archer: Yeah.

Steve Capell: wait a minute this is the second time I've been asked to basically issue a recognized entity credential to a did from the same authenticated user right because in all cases in order for the Australian business register to give me a recognized entity credential link did I have to in our case log with my gov so the register knows is that the same mygov account logged in four times and proved control of four different dids and…

Steve Capell: asked me to issue a recognized entity credential to each one of them. Is that a bigger warning? Is that what advice do we give to authority…

Phil_Archer: Yeah, right.

Steve Capell: because it could also be legitimate? Maybe I know what I'm doing and I deliberately want four different dids for four different interaction context. I don't know. But this is a

Steve Capell: It's very hard for the register to know the difference between a legitimate request for forid recognized or an alien formed user being susceptible to identity theft.

Phil_Archer: And I think here…

Phil_Archer: what we're dancing around particular thing actually is governance models rather than technical details.

Steve Capell:

Phil_Archer: Technically it doesn't matter. There are lots of reasons why you might want one or the other and the spec allows So here it is. You work out how you want to use it. So I think maybe we should probably can this conversation now. But it's that kind of thing that bothers me a little bit but I don't think it's a technical issue. It is a governance issue.

Steve Capell: absolutely. It's a governance issue,…

Benjamin_Young: Yeah.

Steve Capell: so I think it doesn't affect this particular PR. It more affects …

Phil_Archer: No. Yes.

<Dave Longley> there's a process that an entity has to go through in order to receive a VC -- the VC is just a stamp that the process was passed

Steve Capell: what we're right about attack vectors and the security side of things.

<Dave Longley> the crypto has nothing to do with the process/governance directly.

Steve Capell: Okay. Sorry.

<Phillip Long> Hence, it'

Benjamin_Young: So, we do have a queue, so let's keep going.

Benjamin_Young: No, you're good. Todd, go ahead.

<Phillip Long> it is a governance/process issue.

Todd_Snyder: Yeah. No,…

<Dave Longley> yes

Todd_Snyder: I think Phil kind of hit a lot of the same comments I was just thinking about the use case of an individual. You might have cases where you have multiple identities, Maybe a work identity versus a public one. which of us you could have differents. as far as a VC versus VP, I've always looked at a VP as a transport mechanism. So, I think it makes sense to allow VPs. I think there's plenty of use cases for that. and I kind of agree where we're going with this. This sounds like the bigger discussion is really around security and how to verifiers need to make sure the right things happen. verse the document this specific

Dave Longley: Yeah. I think we've all sort of come around to more or less what I typed in the chat here. to summarize, there's some secure process that you've got to go through. that is totally outside of the scope of the specification in order to receive A VC is just a stamp that happens at the end of that process if you've passed so this is all governance process issues. If you don't have a good secure process, then you'll end up get handing out stamps that essentially become useless because you can give them to anybody. So, make sure your process is good, that you only hand them out to who you intend to hand them out to. And that's not in The only thing this spec might say is just that.

Benjamin_Young: So with all that done and…

Dave Longley: Make your process good or your stamps aren't valuable.

Benjamin_Young: in mind, are there any objections to merging this PR? And do we as a followup need an issue about writing do a good job at your other job, the governance piece? does look like there's some merge conflicts.

Benjamin_Young: So, go ahead while I look at what's going on here.

Phillip Long: Yeah, the other place we could make a comment about this is in the threat model that has to be done as well,…

Phillip Long: which is there are possible ways in which this could be misused and one of them is that someone doesn't have the governance process in place. that's strong enough to mitigate this. So I think we have a couple of places we can deal with it but it's not per se as we've come to a general agreement with it's not per se in the spec of this particular Work.

Benjamin_Young: Yeah, that's a good point. if I do this here, GitHub's going to make a merge commit, which annoys some folks. I'm going to just leave a note about this one that group believes it's mergeable, but it will need rebasing. Go ahead, Steve.

Steve Capell: Yeah. Yeah. objection to this merge request. Just on the threat model thing, I suppose something in me says the threat model of someone having a poor governance process and creating a d losing keys or pretending to be someone else exists obviously for every VC in the ecosystem. I just have an inkling that a recognized entity VC has a higher risk associated with it. Because it's not me just creating a deal as a business and misusing it or losing it. It's me being subject to a third party convincing me to interact with an authorative register. You know what I mean?

Steve Capell: there's a higher impact of poor governance specifically with recognized entities and I think that really needs to be called out in the threat model maybe even some advice about how to handle it particularly for the recognized entity issuer so it's the same governance issues that all VCs have…

Steve Capell: but I think worse in the case of recognized entities

Benjamin_Young: David.

Dave Longley: Yeah, it's certainly the case that the blast damage might be wider and…

Dave Longley: one reason for that is you could be a provider that hands out valuable stamps in some cases and worthless stamps in others and that leads to confusion and to use that word, Ed. Build up some trust in some party because they've done a good job with some of their stamps and some of the other stamps aren't so great. And those other stamps that aren't great can issue very many other VCs potentially. maybe. even their own whole subtree of providers that have similar problems. So I do think it is worth calling out that by extending trust to others to issue more VCs can result in wider blast damage.

Benjamin_Young: Do we want issues for any of that or is it good to just revisit this in the context of threat modeling when the time and place arrives? Okay, sounds good. Let's check out another one. Bill, this one looks to be by you. I know you're not at a screen. Adding the GS1 use case by ref to main VC use cases.

Phil_Archer: Yeah, there's an issue 74 that talks about this. and I was reading the recognized entity document the other day. There are a couple of use cases listed. I thought, we don't need to repeat what's in the main use case doc that Joe and Kevin did some years ago. but I wanted to just set up a reference to the GS1 use case in that document. So, couple short paragraphs which I must admit I wrote in a bit of a hurry. which is awful because I think I know Ted's going to clean it up if I make a mess.

Benjamin_Young: I think in this case Dave took a crack at cleaning it up,…

Phil_Archer: It's great. okay.

Benjamin_Young: but so far that's the only feedback.

Phil_Archer: Thank you.

Ted_Thibodeau_Jr: Never count on my fixes.

Phil_Archer: Thank you very much.

Benjamin_Young: What' you say, Network bag.

Ted_Thibodeau_Jr: Never count on my fixes.

Ted_Thibodeau_Jr: There will be a day where I just have too much beer to start and then all butts are off.

Benjamin_Young: Dave, go ahead. sorry, Phil. It sounds like you got cut off.

Phil_Archer: But no, just

Ted_Thibodeau_Jr: He's in the tunnel.

Benjamin_Young: Yeah.

Phil_Archer: A quick thing there,…

Benjamin_Young: Dave, why don't Yeah,…

Phil_Archer: Which I would,…

Benjamin_Young: go ahead.

Phil_Archer: Ious. It certainly isn't normal to anything. So, it's uncontentious. I'm out walking. I would hope it's uncontentious. It's a fairly straightforward thing. it does of course need review by the people, but I would hope it's pretty straightforward. It doesn't add anything normal to or challenge anything that we're saying.

Benjamin_Young: This is the PR we're looking at,…

Benjamin_Young: correct? Okay.

Phil_Archer: This is a PR I did about an hour ago. Yeah. Thanks,

Benjamin_Young: Yep. Yeah, for go ahead, Dave.

Dave Longley: Yeah, I approved this one.

Dave Longley: My only little tweak there was grounding it in credentials. So I don't think it's a use case for this spec to be checking any identifier presented in any way. But if you present an identifier inside of a credential, then we have the means by which to do something to check that. And so all I did was add a little bit of text that says …

Dave Longley: where it previously said if you're presented with such an identifier, it now says in my suggestion if you're presented with such an identifier in a credential. That that and a slight language tweak. because with the word may appeared and we like to use the word might to avoid the normative language

Benjamin_Young: Yeah. Yep.

Benjamin_Young: Sounds And I saw a thumbs up from Phil. So I think we will go ahead and merge this unless there are objections. All right,…

Phil_Archer: Thank Yeah.

Benjamin_Young: that one is done.

Ted_Thibodeau_Jr: It's fine if it already went in, but give me a few hours yet.

Benjamin_Young: It did. Sorry, I don't know if you want to trace the lines that just got merged. and…

Ted_Thibodeau_Jr: I'll figure it out.

Benjamin_Young: I screwed up. I forgot to apply longly suggestion as well.

Ted_Thibodeau_Jr: Jeez.

Benjamin_Young: I I can revert it. Then I'm not even sure. Can I create a new pull request with the crap. Because we talked about it, but then I didn't click the extra button. Can we make this a separate PR? No, we cannot.

Ted_Thibodeau_Jr: The whole repo is blank.

Benjamin_Young: I'm going to click this revert button. I want to see what it does. Yeah, don't start.

Phil_Archer: f*** you.

Benjamin_Young: Yeah, that just pulled out the entire text. So, we don't want to do that. here's what I can do though. We will do it live. United entities index and the line number was 48.

Benjamin_Young: Nope. Nope. My number's changed.

Benjamin_Young: and credential for line 30 might. Okay, that looks like all of what you had.

Benjamin_Young: Okay, putting it on a new branch or request and Okay, sorry about that y' Ended up. All right.

Benjamin_Young: And I left you a note, Ted, so you can add more content, tweaks, etc. If you want, although I think this PR is only gonna have that one line in it, so you could possibly browse around and make changes, I guess. Yeah, you can suggest changes anywhere. Do the whole PR that way if you want. let's see. It is 4:37, so I pretty much need to drop I think that's it in pull requests. that branch is still there. Let me kill that thing. Okay, that's gone.

Benjamin_Young: I can leave you all with an issue to discuss if you would and Dave, maybe you can let me know over Slack if everyone ended up being dropped, but I believe I can sign off. Okay, Steve saying, "Happy to finish early. We did merge a lot of good stuff. Are y'all okay to drop now or do you want another 20-ish minutes? Thumbs up from All right, enjoy the rest of your Tuesday, everybody. Thanks for coming and it's nice and productive. Take care all. Meeting ended after 00:33:28 👋 This editable transcript was computer generated and might contain errors. People can also change the text after it was created.

<Steve Capell> Happy to finish early. Good progress today

This transcription was generated by a large language model (LLM) and might contain errors. When in doubt, check the audio recording. This page was formatted by scribe.perl version 248 (Mon Oct 27 20:04:16 2025 UTC).