W3C

Verifiable Credentials Working Group Telco

30 September 2026

Attendees

Present
Brent Zundel, Dave Longley, Dmitri Zagidulin, Elaine Wooton, Sebastian Schmittner, Hiroyuki Sano, Henrique Xavier, Ivan Herman, Jennie Meier, Joe Andrieu, Kayode Ezike, Lucy (Qixue) Yang, Manu Sporny, Michael Shea, Phillip Long, Phil Archer, Ted Thibodeau Jr., Will Abramson
Regrets
-
Chair
Brent Zundel
Scribe
Wesley Smith, Dave Longley

Meeting minutes

Brent Zundel: Anyone who would like to introduce themselves?

Lucy (Qixue) Yang: Hi, it's Lucy - this is my first time here. Thanks to the W3C team for approving my Invited Expert status.
… My name is Lucy Yang - I've been in the digital credential space for around 8 years.
… I'm interested in identity credentials and trade credentials, and all of my work with clients leverages W3C VCs. I provide field tested experience and feedback as someone who works across many different use cases.

Brent Zundel: Please queue if you have a task force update.

Manu Sporny: On the status of threat model publication, we were able to successfully publish the VCDM threat model and get Echidna set up. We've sent out instructions to other editors to prepare their specs.
… Recognized Entities, Data Integrity, VCALM are in place or on their way. Please get a static snapshot ready to go by this Friday.
… We plan to publish on Oct. 8th.

Joe Andrieu: The confidence method work is proceeding - we do not yet have a threat model. At next weeks meeting we hope to lock some threat modeling work down to have a threat model by TPAC.

Ivan Herman: A practicality: Friday afternoon my time (France) I will be AFK over the weekend. Please have anything needed on my desk by Friday morning my time.

Wesley Smith: Things are good in the barcodes, Data Integrity, Bitstring status list, forgery defense. We're on track for TPAC, with various initiatives, etc.

Brent Zundel: Also note that the blog post related to VC Barcodes has been upgraded to a press release by the W3C comms team. If you are interested in that process please reach out.

Manu Sporny: Thank you folks for getting work unblocked by approving Greg Bernstein's editor status on the BBS spec at CRFG.

CID Open issues and PRs

<Brent Zundel> https://github.com/w3c/cid/pulls

Brent Zundel: Here is a list of PRs for CID. I think that 168 has been open for a while - it is a PR that will be in scope for the DID working group when they take over the CID spec.
… The other PR is #178.

Phil Archer: I'm curious - I'm also cognizant that Michael offered to help edit the CID spec. We are now moving this to another group - do we have to close all these issues and resolve the PRs, or do the people taking it over inherit them?

Ivan Herman: formally, the repository will be transferred to that group with the related issues - nothing will be lost. The question is more if we want to make textual changes to the document right now.
… Per charter, we can do only editorial changes, and we are not supposed to make any major changes. If we wanted to make a major change we have to reopen the whole thing from scratch.
… I don't know how far along the DID charter is right now, when it will be reviewed, and when it is realistic to expect that group to be up and running.

Michael Shea: with this transfer, does it mean that I'll no longer be considered editor?

Brent Zundel: Officially, the DID WG would need to name you as an editor in that group of this document. I'd be happy to reach out to the chairs.

Michael Shea: I'm not in the DID WG

Brent Zundel: do you want to continue

Michael Shea: mostly editorial changes, I'd be happy to continue, do I need to join another call

Brent Zundel: If you were to continue helping with this document you would need to join another call

Manu Sporny: To respond to Ivan Herman about the DID WG charter, my understanding is that PA was going to put the charter up for a vote before TPAC, so in theory we are 2-3 months away from a transfer happening. I don't think we need to process all the issues and PRs before the transfer.

<Michael Shea> As a note, I will not be offended if someone in the DID WG takes over editorial responsibilities.

<Michael Shea> Happy to do so.

Will Abramson: I talked to PA on Tuesday and he said the same thing, he wants to get it out for a vote ASAP. Michael Shea, we would love to have your continued help, but it would mean attending some DID WG calls, so we can discuss that more. There are some changes we would like to see in the DID WG.

w3c/cid#178

Brent Zundel: PR 178 removes the canonical mapping as we discussed.
… It's a simple PR with a couple of approvals. If you would like to review it you are welcome to - it is the removal of 5 lines, and will be merged soon.

Ivan Herman: When you say merged, merged into what?
… Did we reopen the recommendation in the first place?

Brent Zundel: I don't believe we have published an ED or FPWD for CID 1.1

Manu Sporny: correct, this will be a merge into the editor's draft.
… The PR looks good to me, I think it's fine to remove the language. It is complicated to try to specify.

Brent Zundel: Closing out this type of PR before the transfer is part of being good stewards of the document.
… Moving to VCDM.

<Brent Zundel> Topic VCDM issues and PRs

<Brent Zundel> https://github.com/w3c/vc-data-model/pulls

<Antony Mott> +present

w3c/vc-data-model#1645

Brent Zundel: There are three open PRs, two of which are on the table for us to look at. Starting with #1645.
… This PR has been open for over a month, with three approvals. It does tinker with some language that was much discussed in a previous iteration of the WG.
… Now is the time to discuss this PR.

Manu Sporny: We are waiting on the resolution of merge conflicts to merge this.

Brent Zundel: This PR will be merged when the merge conflicts are resolved.

Ted Thibodeau Jr.: I will review after the merge conflicts.

Joe Andrieu: There are physical technologies that we cannot recreate in digital form, I think there is a way to edit this language to be less zealous.

Dave Longley: That's some result of the conflict - it's not part of the PR.

Brent Zundel: A rereview from everyone would be worthwhile after the merge conflict resolution.

<Dmitri Zagidulin> yeah, I agree with Joe's point on the existing text.

<Dmitri Zagidulin> (suggestions on alternate phrasing welcome)

w3c/vc-data-model#1652

Brent Zundel: The other pull request is from Ivan Herman, this is the first version of the 2.1 version of the vocabulary.

Ivan Herman: The title makes the PR clear - I started to review the vocab changes due to validFrom and validUntil, I took the opportunity to rework the vocabulary.
… What I did last is use a tool to regenerate the JSON-LD context file, the goal being that in the future, instead of having humans produce JSON-LD contexts, automated tooling can do it.

<Ted Thibodeau Jr.> goodness... +3616 lines across 7 files!

Brent Zundel: One of the difficulties in review this is that there are new files. Would it be possible to generate some sort of diff?

Ivan Herman: I can do that, but the diffs are so big, all the terms in the JSON-LD Context that are not in the vocabulary had to be added to the vocabulary to make the tool work.
… One thing to review is the YAML file. Everything else is generated - review the YAML and the context file.

Brent Zundel: Please comment in the PR providing pointers to what should be reviewed vs what is generated.
… Even just a statement listing changes would be useful.
… Process and intent.
… This PR is in need of review - please review it!
… Those are the PRs. We still have a bit of time to look at issues.

Manu Sporny: I have a general question about the threat model for VCDM. We don't have an issue for this. I feel weird being the only person listed on that document - I suggest we put all of the authors of the VCDM on it, since it inherited the security and privacy considerations of the document.

Brent Zundel: I think this makes sense - do others have thoughts?

<Antony Mott> makes sense !

<Elaine Wooton> Didn’t we do a brainstorm. Maybe people involved in that

Phil Archer: Yes, it is a group effort, unless there is an objection, please add the other names.

<Ted Thibodeau Jr.> suggested issue sort order -- https://github.com/w3c/vc-data-model/issues?q=is%3Aissue+state%3Aopen+sort%3Aupdated-asc

Wesley Smith: If we migrate the authors over should they be added as authors to the threat model, not editors.

Manu Sporny: +1

<Brent Zundel> https://github.com/w3c/vc-data-model/issues

Brent Zundel: There are some open issues for VCDM.
… We are going to look at #1649 for what time we have.
… Instead let's start with #1583.

w3c/vc-data-model#1583

Brent Zundel: This came in, for those who remember, at the tail end of getting the VCDM 2.0 out.

<Ted Thibodeau Jr.> updated list link (bypass class 4) -- https://github.com/w3c/vc-data-model/issues?q=is%3Aissue+state%3Aopen+sort%3Aupdated-asc+-label%3A%22class+4%22

Brent Zundel: We deferred it to future work. Does this still need to be done?

Manu Sporny: I just this past weekend did an editorial refactor of the security and privacy considerations section. In the VCDM we have readded the security and privacy considerations sections and link out to the threat model.

<Joe Andrieu> +1

Manu Sporny: I believe Joe Andrieu, simone, and I think this is the best way to proceed.
… I will reference the commit for this issue and close it, barring objections.

Brent Zundel: any objections?
… Manu Sporny, clear to proceed.
… Let's now look briefly at jose-cose

VC-Jose-Cose

<Brent Zundel> https://github.com/w3c/vc-jose-cose/issues

w3c/vc-jose-cose#345

Brent Zundel: There are two issues, one of which is out of scope (as it talks about refactoring the SD-JWT section), so we will look at the other - #345.
… We accidentally left some CR text in the status section of our rec. This is clearly errata and needs to be addressed. Is there anyone who would be willing to raise this PR?

Phil Archer: I'll take care of it.
… Another question that arises from what you were saying - if the other issue is no longer relevant, should we close it?

Brent Zundel: It's not that it's irrelevant, it's that it's not in our charter to address it.

<Ted Thibodeau Jr.> addressed does not always mean closed

Brent Zundel: One of the tasks on my plate is to describe a mapping between a VCDM 2.0 signed as an SD-JWT and an SD-JWT-VC.

Wesley Smith: I have a best practices question related to what Phil asked. In our task force the other day, we were looking at old bitstring status list issues. These are not in our charter to address, I would love guidance on how to proceed with those, left them tagged as future issues but left them alone. They are valuable, but is there something else to be done than tag it with a future tag and let it sit for years?

Brent Zundel: Nope, that's where we're at. I'd love to hear suggestions but that's what we've been doing.

Brent Zundel: People like to look at the ancient issues and do something about them, but we aren't chartered to deal with them, so we just shepherd things forward until a future charter allows.

Brent Zundel: If there are issues that you feel you should close, mark them pending close and inform the broader group.
… Switching to our final topic - what do the task forces need at TPAC?

What does your TF need at TPAC?

<Phil Archer> Skeleton agenda is at

Manu Sporny: Just a question, we hoped to move a handful of specifications into the candidate recommendation phase. Recognized Entities might be ready, although we might not have all required horizontal reviews.
… We don't have a TAG review - should we still attempt to transition? What bar are we trying to hit with all the specs to go into CR?

Phil Archer: We don't know. The hope when we began the current charter was that everything at TPAC was going to go to CR. We all knew that was ambitious. In the skeleton agenda, the skeleton begins with a link to the progress tracker.

<Dmitri Zagidulin> is the goal that all the Task Forces have a session at TPAC? Or only specific ones?

Phil Archer: All I did when I put that skeleton together was to go through the documents that are not in a task force, many of which have open issues and PRs.
… Other than that, trying to avoid bigger collisions with TPAC events.
… The remaining time has been allocated between the task forces.
… There is an hour or so per task force - if you need longer let us know.

Manu Sporny: Based on that feedback, I think if there are issues blocking us from getting into CR for Recognized Entities, those will be on the agenda. If there are no such issues we will request transfer to CR.

Phil Archer: If you are attending remotely, that must and should affect what slot your task force gets.

<Dmitri Zagidulin> (I'm attending remotely)

Joe Andrieu: I wanted to note that on Friday morning I am going to be coopted with SING.

Manu Sporny: Two things to note - we are scheduled in conflict with FedID WG, and there is going to be a meeting on Tuesday about VCs and DC API.
… I don't know if we are lagging or not on horizontal reviews for the minor versions of the spec.
… thoughts if we should be kicking those off?

Ivan Herman: In another WG we had a similar situation, where the core specification has not changed much. We should make this clear to reviewers to expedite things.

Manu Sporny: Does the group want the editors to prepare horizontal review for the minor versions?

<Phil Archer> https://docs.google.com/presentation/d/19vlKzO5nZjsVMVPmuI40jdSGW3kGUtAC1ngW-yQOC6g/edit

Phil Archer: Here are some draft proposals for what to talk about on Thursday given group member's constraints.

<Dmitri Zagidulin> sounds wonderful, thank you so much!

Brent Zundel: Manu Sporny, my take is that we should request reviews and let them know that changes have been minimal.

<Dmitri Zagidulin> @Phil Archer - and just to double-check, Day 1 is Thurs?

Brent Zundel: yes, day 2 is Friday, but there are conflicts on Friday afternoon.

Phil Archer: Yes, we have less F2F time at TPAC than in Brussels.

Minutes Manu Spornyally created (not a transcript), formatted by scribe.perl version 249 (Tue Sep 29 16:09:09 2026 UTC).