W3C

Verifiable Credentials Working Group Telco

05 August 2026

Attendees

Present
Brent Zundel, Denken Chen, Dave Longley, Dmitri Zagidulin, Elaine Wooton, Hiroyuki Sano, Ivan Herman, Jennie Meier, Kayode Ezike, Manu Sporny, Michael Shea, Olvis Enrique Gil Ríos, Phillip Long, Phil Archer, Saad Bin Shams, Ted Thibodeau Jr., Wesley Smith
Regrets
-
Chair
Brent Zundel
Scribe
Elaine Wooton

Meeting minutes

@Brent Zundelz covers admin and agenda

<Brent Zundel> Tracker Doc: https://docs.google.com/spreadsheets/d/1OM-UsLnOZKywcy1eSGZsi_laCHBIy5wmQFOer0a7kYI/edit?pli=1&gid=67467047#gid=67467047

Manu Sporny: reviews need to proceed with horizontal review - we are behind schedule

Dmitri Zagidulin: asked to review PR1629

Task Force Updates

<Michael Shea> michaelshea+

Wesley Smith: progress on barcode spec, threat models is good

<Denken Chen> w3c/vc-confidence-method#30

<Denken Chen> https://w3c.github.io/vc-confidence-method/#assurance-levels

Denken Chen: issue whether to quote ISO or other policies

<Ivan Herman> qq

Brent Zundel: guidance from council is to avoid it unless necessary - just because there's a cost doesn't mean others can't obtain it

Ivan Herman: is there a public text? answer is yes

Kayode Ezike: VCALM - threat model merged / new test suite repo just merged in yesterday - over last month, worked to classify issues - will proceed with focusing on issues that are blockers for candidate rec

<Manu Sporny> w3c/vc-data-model#1638

<Phil Archer> I found the W3C Council Report on the Formal Objection to the use of Normative References to ISO/IEC 18013-7 Annex C in the Digital Credentials API specification which is at https://www.w3.org/2026/06/council-digital-credentials-report.html

Manu Sporny: re vc data model - there's now a threat model - please review. Will speak to status list and some post quantum stuff. There's also a data integrity threat model that is hoped will work for other related specs. Large number of threats will layer on top of that base. The threat models have broken the preview mode. working with Ivan Herman to fix it.

<Brent Zundel> FO Council Report related to referencing ISO specs: https://www.w3.org/2026/06/council-digital-credentials-report.html

Dmitri Zagidulin: render method - have compressed road map to get to horizontal review - consensus on 3 categories - asks group for feedback about meeting frequency which is currently every other week - proposes each week to get to review

<Manu Sporny> Yes, let's please meet every week for Render Method -- we need more time on spec to get it to horizontal review.

Olvis Enrique Gil Ríos: regarding deliverables tracker - suggests new item - verifiable credential for payment rails

group agrees every week is available for render method - Dmitri Zagidulin can update calendar

<Manu Sporny> We really need to move the render method forward faster, would prefer not to delay until after August.

<Dave Longley> +1

@Ivan Herman: perhaps wait until September to change render method meeting frequency / group agrees weekly is needed sooner

Placing the new terms in vocabularies and context files

Brent Zundel: next topic new terms in vocabulary

<Ivan Herman> See: https://github.com/w3c/vc-wg/blob/main/vocabs/newvocabularies.md

Ivan Herman: number of TFs need update of context file - render method (already exists as a class), also confidence method Bitstring is here because there may be a new version due to barcode TF work. Current situation is that bitstring status list has its own vocabulary.

<Manu Sporny> Agree with Ivan Herman's proposal for render, confidence, bitstring... possibly disagree with forgery defense (should probably go in status), recognized entities (should probably go in VCDM), don't have a strong opinion about barcodes, but Wes might.

Ivan Herman: for forgery defence - follow the same model

<Dave Longley> forgery defense could also potentially go into the security vocab

<Manu Sporny> agree ^

<Dave Longley> we've previously offered individual contexts and a "batteries included" context, i think we should probably keep doing that

@Ivan Herman: for recognized entities - should have separate context file not just build on VC / same with barcodes

Ivan Herman: other option is to fold into the rest of the VCDM - need to discuss and make a decision

@Ivan Herman: once decision is made, then can set up framing and then repository

Brent Zundel: reviews Manu Sporny's IRC comments regarding Ivan Herman's proposal

Dave Longley: previously had individual contexts - useful for those who need them / not related to vocabularies - need to continue that conversation

Brent Zundel: I will trust the experts on this

Phil Archer: checking in re longley - can have the individual contexts PLUS an overarching one?

Dave Longley: yes

@Ivan Herman: I am not sure about this because of messaging -

Dave Longley: agree with Ivan Herman on this piece - if creating specific credentials of different types - that's a new context / using components of existing spec is not

group - discussions will continue

DigestSRI - w3c/vc-data-model#1629

Dave Longley: believe we cannot use a copy of something that's in another spec without processing rules applying

Dmitri Zagidulin: goal for the PR was "now what?" - have reasoning for deprecating digest SRI / Manu Sporny and shigeya prior conversation - no consensus and Shigeya's concerns are not addressed.

Brent Zundel: if not resolved by TPAC - seek consensus there / doesn't feel urgent

<Dave Longley> hopefully a "this is deprecated and language that says other specs shouldn't use it, but it won't be removed, it will still be in the next context, etc." is a good compromise

Ivan Herman: Brent Zundel is now the master of the process - which doesn't have the term "deprecate" as such, right? This is more like we have it - if you use it, has to be this way - but don't use it.

Dave Longley: idea is to keep it in the next version of the context - keep it around but with clearer guidance

<Ivan Herman> re deprecation see another spec: https://www.w3.org/TR/epub-34/#sec-obs-deprecated

TPAC

Brent Zundel: please register for TPAC / WG meetings thursday and Friday with Friday shorter / Will be a Tuesday joint session with payments and DC API - all invited

<Brent Zundel> https://www.w3.org/news-events/tpac/2026/registration/

Brent Zundel: planning to talk about CR and about CR / if there are other topics, let Brent know

Request to amend short URL for confidence method

<Denken Chen> https://www.w3.org/2026/03/vc-wg-charter.html#confidence

Dave Longley: maybe expand confidence method to include assurance levels - then does the name need to change / need to discuss in task force but there was no meeting last week

<Denken Chen> +1 to have more discussion in the task force

Ivan Herman: WG must have formal resolution to change short name / then need review as if it is an actual new working draft. Used to be a bigger pain to publish, but forgot it thanks to echidna. But now still needs to be done Manu Spornyally - requires actions by Ivan and the working group and editors. Extra work.

Ivan Herman: the title can be changed - it's the short name that's an issue

Brent Zundel: new VC overview doc - please review / confidence method TF - come back with decision

<Dave Longley> +1 to phil, i feel similarly.

Phil Archer: confidence is too broad

AOB

<Ivan Herman> new version of overview

Michael Shea: mike jones is listed as an owner for the CID repo / if not involved anymore, what needs to happen

Brent Zundel: I will change it

<Olvis Enrique Gil Ríos> Thank you so much!

Brent Zundel: good work

Thanks all!

Minutes Manu Spornyally created (not a transcript), formatted by scribe.perl version 244 (Thu Feb 27 01:23:09 2025 UTC).