W3C

Verifiable Credentials Working Group Telco

22 July 2026

Attendees

Present
Benjamin Young, Carolynn Bernier, Dmitri Zagidulin, Eric Scouten, Grace Rachmany, Hiroyuki Sano, Ivan Herman, Jennie Meier, Joe Andrieu, Kevin Dean, Kayode Ezike, Manu Sporny, Michael Shea, Michael Linck, Parth Bhatt, Phillip Long, Phil Archer, Saad Bin Shams, Scott Jones, Ted Thibodeau Jr., Wesley Smith
Regrets
Brent Zundel
Chair
Phil Archer
Scribe
Manu Sporny, Dmitri Zagidulin

Meeting minutes

<Michael Shea> brb

Phil Archer: We have three guests with us today, thankful for their time. Scott Jones, Eric Scouten, and Grace Rachmany, from CAWG.

Phil Archer: We're going to hear about C2PA as well. There are some issues we need to cover after that, Brent is at IETF.

Phil Archer: We will look at VCDM issues, and overview document, and open issue for group to look at.

Phil Archer: Do we have any new members of the group that haven't introduced themselves yet?

Saad Bin Shams: Hi Saad from Siemens AG, recently joined the group, our interest is in Digital Product Passport, should be able to contribute soon.

Phil Archer: Is this your first WG group?

Saad Bin Shams: I've participated in IETF, fairly used to participating in IETF.

Phil Archer: Ok, please join IRC, queue there, welcome to the group!

Phil Archer: Anyone else on the call for the first time today?

Michiko Koriyama: Michiko Koriyama from Keio, working with Shigeya-san.

Phil Archer: We will get to usual meeting work, but we have a presentation today from our guests.

CAWG and C2PA

Scott Jones: Thank you for the opportunity to present, today we're going to talk a bit about C2PA and CAWG ecosystem... building identity into the content provenance ecosystem. We will have an ask about coordination about advancing VCs in this marketplace.

Scott Jones: My nameis Scott Perry, play multiple roles -- VCs and provenance, Co-Chair of steering committee of Trust over IP, co-chair of creator assertions WG, and I have colleagues Grace Rachmany and Eric Scouten with me today.

Grace Rachmany Rachmany: I'm Grace, Executive Director of DIF, mostly a figurehead, I go around to places like IETF where I am today. I love content, and that's why the Creator Assertions Working Group is great!

Scott Jones: The CAWG started out in C2PA and there was a motion to note individual attribution in C2PA spec, they moved it over to DIF with Adobe's support as well as ToIP that houses the CAWG, Grace Rachmany has helped us make sure that effort got under way at DIF.

Eric Scouten Scouten: Hi Eric Scouten, I lead team at Adobe that builds open source and internal implementations of C2PA and CAWG ecosystem, I also co-chair Creator Assertions WG.

Eric Scouten Scouten: Who are we and how does all this fit together? Why are we here and what are we hoping to accomplish with W3C WGs.

Eric Scouten Scouten: We want to enable content creators to attach tamper evident digital nutrition label to the content they produce, how did they create the work, did they use AI tools, who am I, what do I want you to know about the context of the digital media?

Eric Scouten Scouten: We use various cryptographic techniques to determine whether or not the material is original or has been modified... what do hardware and software tool vendors say about content, and what do individuals say about it?

Eric Scouten Scouten: There are three Cs that work togheter: C2PA (What and how), CAWS (Who), and Advocacy and Education.

Eric Scouten Scouten: CAWG defines things that people and orgs to say about content -- how can you use digital credentials to express things about digital content.

Eric Scouten Scouten: contentauthenticity.org is a bunch of companies that feel like content provenance is important for society.

Eric Scouten Scouten: How does this translate to tech used -- taking accountability. Hardware/software tools are the "C2PA claim generator". Individual or organization involved in creating the content is the CAWG named actor (mostly aligns w/ credential community's use of credentialSubject) -- who was operating the camera/microphone?

Eric Scouten Scouten: C2PA deals w/ GPS data, edit actions taken, AI used, CAWG -- uses x509 cert / COSE signature, conformance program Scott Jones alluding to, certificates used have specific purpose (not TLS certs, not S/MIME, specific to C2PA and vendor's agreement).

Eric Scouten Scouten: In CAWG, credentials that describe people/orgs is much more complex/flexible -- can use multiple types of credentials to attest to work, we do have an x509 system, but instead temporary backed by S/MIME governance program, will probably build our own. Specific grammar of W3C VCs, has platform vendor roll up a sequence of social media signals (Instagram, website, etc. verify those and put them in specific type of VC).

Eric Scouten Scouten: Projects we have in place, make VC integration much more generic, not tied to platform vendor, can bring credential from different markets, also working with GLEIF to bring in VLEIs to attest to organizational identity.

Eric Scouten Scouten: Good jumping off point for VCWG discussion, set context with Scott Jones

Scott Jones: As Eric Scouten alluded to, we launched C2PA conformance program over a year ago, viral adoption, Google is all in, bringing all of their products to C2PA, creating canvases of many groups of digital objects that will be available in marketplace for attribution to be attached to. Seeing in CAWG, rapid adoption by major industires, that want attribution of digital photos in marketplace, and entire creator community in film, music, where money flows based ... on attribution.

<Ted Thibodeau Jr.> Grace Rachmany Rachmany, Eric Scouten Scouten, Scott Jones (and others) -- You may also be interested in the W3C Credible Web Community Group, https://www.w3.org/community/credibility/

Scott Jones: Looking at viral acceptance for more verifiable credentials in aggregate than any other use case in market today -- we want every digital object created having a verifiable credential that VCs can be placed on top of it for attribution. In C2PA conformance ecosystem, it's working well, we have governance, platform canvas... real conversation w/ W3C is around attribution.

<Eric Scouten Scouten> Ted Thibodeau Jr. thank you … taking a note to dig deeper on that group's work.

Scott Jones: C2PA is dealing w/ orgs, we are expanding world where individuals want to make claims, and with advance w/ VCs in markets, expand acceptance of VCs to directly within CAWG spec, use that as attribution as another opportunity for different industries to make a claim against digital object, consent, identification, facilitation of metadata, attached to digital object, creating hooks for trust registries and extended registries to allow that.

Scott Jones: Use tech we are building to build fair use and disclosive information about the use of AI.

Scott Jones: We started up VC Task Force and didn't have the number of people that are in this meeting today -- we want to partner with W3C to advance VC options to be used with digital objects, want to get involved in CAWG and bring VCWG to table, largest use case that I'm familiar with in VCs.

Manu Sporny: this is a fantastic initiative. Scott Jones, Eric Scouten, Grace Rachmany, wonderful to see you again
… this group should do everything we can to support the work you're doing
… let's work with CAWG and C2PA to make sure they find success using this tech
… either create a new Task Force to work on this, or to cycle steal from the main call
… but this is really an important initiative
… as Scott Jones mentioned, and Eric Scouten has been letting us know for years

Scott Jones: thanks Manu Sporny. and yes, we're very interested in organizations to participate in this
… we need lots of orgs that are trying to figure out how to do all this
… especially ones already issuing VCs for identity

Benjamin Young: just to continue -- thanks for coming, and for presenting on this. I've been a fan from the sidelines
… I want to ask about practicalities. I know a TF would be amazing. do you have some technical targets or issues, re what you feel is the main interface points could be?

Eric Scouten: I think there are two pieces we're in flight on, and would benefit from guidance
… one is - we have a draft proposal for how a VC can be correctly bound to a specific piece of content. a review of that work on the W3C side would be greatly helpful
… Scott Jones and I can work with you to work out an individual session, or have you join one of our wg sessions
… the other one is -- how do we establish a marketplace of trust? It's easy for someone to self-issue a VC, but how do you know that you should trust VCs from CA DMV, etc
… understanding that, and providing roots of trust that make the CAWG credential marketplace interoperable is the biggest challenge we face
… a lot of the usecases for VCs so far have been closed ecosystems, but now we're stretching the boundaries
… where consumers are unknown at the time of publication, at a larger scale

Kevin Dean: hi, Kevin with Legendary Requirements, working on supply side standards for a while
… when I was at GS1 we ran across this from time to time, with content creators who were licensing their characters for merchandise for example
… and the challenge as always is to ensure that a retailer who is selling what appears to be licensed content is sourcing it legitimately

Eric Scouten: yes, that's the usecase, with some wrinkles. the data formats we use from C2PA are immutable
… and the legal agreements that establish the rights to use characters etc, are mutable
… legal agreements change, ownership rights, and so on, change after media is published
… so if walmart comes across a representation of a character 5 years from now, how do they find out what changed in the 5 years

Scott Jones: we're looking at 2 distinct governance models
… one is a specific industry controlling specific metadata.
… the thing we want to solve is -- if an individual is claiming an identity, how do we know who they are. and what's the governance model to give us confidence in it
… there's some aspects in 509 that allow for some of this. I want to see a governance model at scale for VCs too
… maybe at the W3C level

<Benjamin Young> https://w3c.github.io/vc-recognized-entities/

Benjamin Young: Ivan Herman mentioned it already in chat, but I wanted to share about the VC Recognized Entities spec
… which covers exactly the use case you were talking about
… handles self-signed content by a content creator
… like the Patreon artist space
… where currently the artist doesnt have a lot of tools to back up their claims
… so, recognized entities could play towards promoting a way individuals and orgs can support each other's claims

<Eric Scouten Scouten> Benjamin Young thanks – taking a note to read up on RE spec

Phil Archer: thanks Benjamin, i'm delighted this conversation has taken off
… what I did was completely and utterly abuse the system, and Steve Cappell has done the same
… so what Steve and I have both done, is to crowbar our usecases directly into the VC Recognized Entity standard. so, those usecases are really well covered!
… thing like -- a product claims it's organic, is it? and country of origin? etc
… resting on a trust anchor at the base. so, the VC Recognized Entity might be of direct use to you
… wearing my W3C co-chair hat for a moment,
… there's some great opportunities here, and of course some challenges
… noone, including you and all of us, has any time to do any more than we're already doing. hopefully we'll find time
… secondly, like DIF, TOIP we have IP rules
… about contributions and so on.
… what we'd need to do is to take this positivity and turn it into concrete action steps
… a conversation involving Grace Rachmany, and Ivan Herman (team contact representing W3C here), about how we make this happen
… in terms of formal agreement / working together
… anyone else in the group has questions?

Scott Jones: please provide our email addresses

<Eric Scouten Scouten> When you transition to other topics, I'll jump off. Thank you for the opportunity to talk with your group! :-)

Grace Rachmany: just to add, we already have some joint WGs with W3C, so the lawyer part might be easier

Eric Scouten: as Grace Rachmany said, and others, we run under W3C IPR, so, should work
… and welcome anyone as individual members or org collaboration

Phil Archer: as GS1, I'm co-organizing a workshop with W3C (giving me so much schitzophrenia)
… some of the people taking part in that are about Know Your Agent / KY Customer / KY Supplier
… very similar to what you were talking about, Eric Scouten
… not just attaching identity to software, but what its authorization is

Grace Rachmany: we do have a working group specifically on this, the TAWG wg - Trusted AI WG
… and they have a KYA-OS spec

Scott Jones: I am going to be at the GDC week in geneva, and the week before
… hopefully we can have conversatins about it

Phil Archer: I'll be there

Dmitri Zagidulin: can you post a link to CAWG meetings?

Phil Archer: Eric Scouten - is there a stable URL for the slides?

Eric Scouten: will send the slides

Phil Archer: ok, for the group, lets go through some of the regular stuff
… couple of things on the agenda

VCDM 2.1

Phil Archer: I know Manu Sporny isn't here, but Kevin --

<Phil Archer> https://github.com/w3c/vc-data-model/issues

Phil Archer: you very kindly put your hand up to help with this
… what Manu Sporny said briefly before the call was -- these issues have been triaged, and several are looking for PRs. Kevin, would you be willing/able to take a stab at working on those?

Kevin Dean: ok I will take a look

Phil Archer: this is one of the documents that we as the full WG need to take care of
… we need to keep our eye on it as the main group (vs task forces
… next step is to prep it for horizontal review
… so the first thing is to start on it, start correcting the errors, postpone things for the future
… so, thank you, Kevin

Overview doc, rename to 1.0 and start draft of 1.1

Phil Archer: anyone else have comments about VC DM 2.1?
… if not, the next topic..
… Ivan Herman, this is on your doorstep

<Ivan Herman> https://www.w3.org/TR/vc-overview/

Ivan Herman: for those who were not around in the first round of the WG, I added an overview doc in the old days of 1.0
… and is decently used (for example, at W3C), when communicating with other institutions
… so I really think it's an important doc (not just cause I added it)

<Ivan Herman> https://iherman.github.io/vc-overview-1.1/

Ivan Herman: incorporating the input from all the task forces is a large amount of work
… I took a first pass at it
… question is: how do we move forward to officialize the changes?
… we made a mistake back in the day not to give a version to the overview. so any change I'd do in the current doc would be reflected on the overview
… and that wouldn't be good, since there are major changes since 1.1
… so, would be ideal to cut a stable version to the public, so we can have a working version we can continue editing as the WG works

<Ivan Herman> - re-publish the current one titled VC Overview 1.0, with short name vc-overview-1.0

<Ivan Herman> - vc-overview will redirect to vc-overview-1.0

<Ivan Herman> - officially publish VC Overview 1.1 as a Draft Note, with short name vc-overview-1.1 (essentially through a PR to the content above)

<Ivan Herman> - At some point in the future it will become a Note and vc-overview will redirect to vc-overview-1.1

Ivan Herman: I have put together a set of steps I think should be done ^
… (Ivan Herman goes over the steps above)

Phil Archer: any comment on this?

Ivan Herman: i need a lot of review for the 1.1 version
… lots of details there around SD, various methods and classes and so on
… I tried to review all the new docs from the task forces, but there's still a bit of hand-waving, that needs review and help
… the other thing, to avoid any kind of misunderstanding -- there's an Editor, and a list of Authors
… which at the moment is a concat of all the editors that have published before

Phil Archer: ok, I have forked your repo, I currently have 4 PRs and 2 issues

Ivan Herman: good

Phil Archer: yes, it's an important document
… an essential guide

<Phil Archer> Proposed Resolution: We re-publish the existing Overview document unchanged but renamed version 1.0 (/TR/vc-overview-1.0). We will then adopt Ivan Herman's draft as a FPWD of version 1.1 (/TR/vc-overview-1.1)

<Dmitri Zagidulin> +1

<Ivan Herman> +1

<Phil Archer> +1

<Phillip Long> +1

<Hiroyuki Sano> +1

<Kayode Ezike> +1

<Ted Thibodeau Jr.> +1

<Jennie Meier> +1

<Michael Shea> +1

<Saad Bin Shams> +1

<Joe Andrieu> +1

RESOLUTION: We re-publish the existing Overview document unchanged but renamed version 1.0 (/TR/vc-overview-1.0). We will then adopt Ivan Herman's draft as a FPWD of version 1.1 (/TR/vc-overview-1.1)

Phil Archer: so resolved.

Phil Archer: we'll look at issue 12 next time
… anyone have any other comments before we close?
… thanks all!
… next week, I'll chair again (Brent is away)
… I'll be issuing agenda for next week tomorrow though
… for the new members of the group -- do please take a look at the Task Forces

<Michael Shea> thanks phil!

Phil Archer: thanks again all, talk to you all later

Summary of resolutions

  1. We re-publish the existing Overview document unchanged but renamed version 1.0 (/TR/vc-overview-1.0). We will then adopt Ivan Herman's draft as a FPWD of version 1.1 (/TR/vc-overview-1.1)
Minutes Manu Spornyally created (not a transcript), formatted by scribe.perl version 244 (Thu Feb 27 01:23:09 2025 UTC).