Release v2.0.0
SimpulseID Credentials v2.0.0
Credential and identity framework for the ENVITED-X Data Space, operated by ASCS e.V. at identity.ascs.digital. Built as a domain layer on harbour-credentials v1.0.0.
This is the first production release implementing EVES-008 (SimpulseID Credential and Identity Framework) and EVES-009 (Evidence-Based Consent Using Verifiable Presentations).
Credential Types
Five W3C Verifiable Credential types for identity and membership management, all issued by ASCS e.V. as the ENVITED-X trust anchor:
| Credential | Purpose | Subject |
|---|---|---|
| ParticipantCredential | Organization identity (Gaia-X LegalPerson) | `did:ethr` of the organization |
| AdministratorCredential | Elevated-permission natural person | `did:ethr` of the person |
| UserCredential | Standard natural person | `did:ethr` of the person |
| AscsBaseMembershipCredential | ASCS e.V. base membership | `urn:uuid:` (relationship, not entity) |
| AscsEnvitedMembershipCredential | ENVITED research cluster membership | `urn:uuid:` (relationship, not entity) |
Identity Model
- did:ethr on Base (ERC-1056) with P-256 `JsonWebKey` verification methods
- Signer DIDs (participants, users): self-sovereign with local signing keys
- Resource DIDs (programs, services): externally controlled via DID Core `controller` property
- Program metadata served via `ProgramMetadataService` DID service endpoints
- JSON-LD contexts resolved via `w3id.org` persistent identifiers with content negotiation
Schema-First Pipeline
Single source of truth in LinkML:
```
linkml/simpulseid-core.yaml --> make generate --> artifacts/simpulseid-core/
├── simpulseid-core.owl.ttl
├── simpulseid-core.shacl.ttl
└── simpulseid-core.context.jsonld
```
- 5 credential types, 5 subject types, 6 program metadata types
- SimpulseIdLegalForm enum: 21 values across DE/US/UK jurisdictions
- Closed SHACL shapes (`sh:closed true`) reject unexpected properties
- Gaia-X alignment via harbour-credentials import chain
EVES-009 Evidence Protocol
Evidence VPs use the `HARBOUR_DELEGATE` challenge format from harbour-credentials:
- Action type: `credential.issue` (consent to credential issuance)
- Challenge: ` HARBOUR_DELEGATE <SHA-256(TransactionData)>`
- Binding via OID4VP KB-JWT `transaction_data_hashes` for wallet interoperability
- SD-JWT VCs recommended for selective disclosure (GDPR compliance)
Testing
- 30 mutation-based SHACL tests (MinCount, ClosedConstraint, InConstraint, DID mutations, program metadata)
- 30+ structural integrity assertions (Gaia-X composition, DID key linkage, IRI resolution, type pollution regression)
- Evidence VP signing/verification across all 5 credential types
- Enum constraint tests (21 legalForm values, `sh:in` enforcement)
- Full credential lifecycle story (`make story`): generate, sign, verify, validate
CI/CD
- 6-job GitHub Actions pipeline: lint, markdown, generate-validate, test-python, test-ts, story
- Cross-platform matrix: ubuntu/macos/windows x Python 3.12/3.13
- Automated dependency updates via dependabot (pip + GitHub Actions)
- Release changelog via git-cliff (`cliff.toml`)
- w3id artifact publishing to GitHub Pages on release
w3id.org Resolution
| Accept Header | URL | Resolves To |
|---|---|---|
| `application/ld+json` | `w3id.org/ascs-ev/simpulse-id/core/v1/` | JSON-LD context |
| `text/turtle` | `w3id.org/ascs-ev/simpulse-id/core/v1/` | OWL ontology |
| Browser | `w3id.org/ascs-ev/simpulse-id/core/v1/` | Documentation |
Installation
```bash
git clone --recurse-submodules https://github.com/ASCS-eV/simpulse-id-credentials.git
cd simpulse-id-credentials
make setup
make check # generate + validate
make test # full test suite
make story # end-to-end lifecycle
```
Documentation
- Specifications (EVES-008, EVES-009, external standards)
- Credential Types
- Credential Relationships
- Harbour Integration
- Examples
Dependencies
- harbour-credentials v1.0.0 — Cryptographic signing library (by Haven)
- ontology-management-base v0.1.6 — SHACL validation pipeline