-
Notifications
You must be signed in to change notification settings - Fork 0
Home
A dependency-light, HSM-friendly Verifiable Credentials core for Python:
sign and verify W3C VCs in the three mainstream proof formats — VC-JWT,
SD-JWT VC, and Data Integrity — resolve issuer keys, check status-list
revocation, and verify wallet presentations (VP-JWT, OpenID4VP 1.0, HAIP),
fail-closed by default. Published on PyPI as
openvc-core; the import package is
openvc.
pip install openvc-core- This wiki is the manual: task-oriented guides with runnable code. Start with Getting Started.
- The API reference is generated from the docstrings — every module, class, and function.
-
examples/are ten self-contained offline scripts, executed by CI on every push.
Every python block in this wiki is also executed by CI (tests/test_docs_blocks.py),
so the snippets you read here are guaranteed to run against the current release.
| Guide | Covers |
|---|---|
| Getting Started | install, extras, your first issue + verify |
| VC-JWT | the JOSE suite: sign / verify / peek, the algorithm allow-list |
| SD-JWT VC | selective disclosure, Key Binding, Type Metadata |
| Data Integrity | the five cryptosuites, JCS without pyld, ecdsa-sd-2023
|
| Presentations & OpenID4VP | VP-JWT, vp_token + DCQL, HAIP encrypted responses |
| Resolving issuer keys |
did:key / did:jwk / did:web, well-known, caching |
| Status lists | revocation — check and issue, both encodings |
| Trust anchors | X.509 x5c, EU Trusted Lists, the EBSI plugin |
| Async verification |
verify_credential_async for asyncio servers |
| Keys & HSM backends | the SigningKey protocol, KMS / Vault / PKCS#11 |
| Security model | assets, trust boundaries, attacker capabilities → controls |
| Versioning & deprecation | the SemVer contract and what "stable" covers |
src/openvc/ core — knows nothing about EBSI or badges
verify.py verify_credential / verify_many: the one-call pipeline
aio.py verify_credential_async / verify_many_async
openid4vp.py verify_vp_token: stateless OpenID4VP 1.0 verifier
jwe.py decrypt_compact: JWE ECDH-ES decrypt (HAIP responses)
mdoc.py ISO 18013-5 mso_mdoc verification (experimental)
cose.py / cbor.py hand-rolled COSE_Sign1/Mac0 + bounded CBOR (mdoc, no deps)
proof/ the proof suites (vc_jwt, sd_jwt, vp_jwt, data_integrity,
di_ecdsa_rdfc, di_jcs, ecdsa_sd) + shared error taxonomy
did/ did:key, did:jwk, did:web, did:webvh resolvers + registry
keys.py Ed25519 / P-256 / P-384 + ML-DSA (RFC 9964) SigningKey backends
fetch.py SSRF- and DNS-rebinding-safe https fetch
resolvers.py blessed SSRF-guarded status / schema / type-metadata resolvers
cache.py opt-in TTL caching for DID resolution
jwt_vc_issuer.py issuer keys via /.well-known/jwt-vc-issuer
x5c.py X.509 x5c chain trust + SAN issuer binding
rp_cert.py EUDI relying-party access certificates (WRPAC, ETSI TS 119 411-8)
rp_registration.py EUDI relying-party registration certificates (WRPRC, ETSI TS 119 475)
trustlist/ EU Trusted Lists (LOTL → TL) → X.509 anchors
status/ W3C Bitstring + IETF Token Status List (check + issue)
schema.py credentialSchema validation (opt-in)
type_metadata.py SD-JWT VC Type Metadata
multibase.py base58btc multibase + multicodec varint
errors.py OpenvcError — the root of every error family
observability.py opt-in logging + injectable span hook
src/openvc_ebsi/ optional EBSI plugin (read-only); depends on openvc only
Dependency rule: openvc imports nothing upward; openvc_ebsi depends on
openvc, never the reverse.
openvc is the generic VC machinery a badge issuer, an EBSI verifier, or a
EUDI wallet backend builds on. It is intentionally not an Open Badges
library, a wallet, or a node operator; EBSI support is read-only
(onboarding/writing via JSON-RPC + OID4VP is out of scope).
Changelog · Roadmap · Contributing · Security policy · Design decisions (ADRs)
📖 Published automatically from the wiki/ directory of the main repository — edits made directly on the wiki are overwritten by the next sync. To change a page, open a PR against wiki/. Every python block on these pages is executed by CI. · API reference · LGPL-3.0-or-later
Start
Proof formats
Verifying in practice
- Presentations & OpenID4VP
- Resolving issuer keys
- Relying-party certificates
- Credential schemas
- Status lists
- Trust anchors: EU TL & EBSI
- Async verification
Walkthroughs
Operating
Reference