メインコンテンツまでスキップ

VC Knots のサポート範囲

下記の表は、OpenID for Verifiable Credential Issuance 1.0 および OpenID for Verifiable Presentations - draft 24 を基準に、このリポジトリの現在の実装範囲を整理したものです。

は該当ロールで実装済み、 は未実装またはエンドツーエンドでは利用できないことを示します。設定に依存する機能は、備考欄に条件を記載しています。

OpenID for Verifiable Credential Issuance 1.0

仕様セクション機能領域仕様上の役割・機能IssuerWallet備考
3.5Issuance FlowPre-Authorized Code Flowv0.6.0 以降
現在の標準フロー。
3.4Issuance FlowAuthorization Code Flowエンドツーエンドでは未対応。
4.1Credential Offercredential_offer(Pre-Authorized Code)v0.6.0 以降
✅ 生成
✅ 解析credential_offer_uri による参照方式は対象外。
3.5Transaction Codetx_codev0.6.0 以降
✅ 発行・検証
✅ 送信Pre-Authorized Code Flow で使用。
A.1Credential Formatjwt_vc_jsonv0.6.0 以降
✅ 発行
✅ 受領
A.3Credential Formatdc+sd-jwt(SD-JWT VC)v0.6.0 以降
✅ 発行
✅ 受領
A.2Credential Formatmso_mdoc
6Token EndpointAccess Token の発行v0.6.0 以降
Pre-Authorized Code に対応。
13.2Client Authenticationprivate_key_jwtv0.6.0 以降
✅ 検証
✅ 送信登録済み OAuth client の Token Endpoint 認証方式。Wallet の既定は匿名(none)で、Wallet 側で private_key_jwt を設定し、かつ Authorization Server Metadata が private_key_jwt と設定した署名アルゴリズムの両方を広告している場合にのみ client assertion を送信します。関連節: 6.1
6.1Client Authentication匿名の Pre-Authorized Token Requestv0.6.0 以降
✅ 条件付き
✅ 送信Authorization Server Metadata の pre-authorized_grant_anonymous_access_supportedtrue の場合のみ。関連節: 12.3
13.2Sender ConstraintDPoPによる送信者制約付き Access Tokenv0.6.0 以降
off / optional / required を設定可能。Token Endpoint と Credential Endpoint に適用。関連節: 6.1, 7.2, 8.2。外部仕様: RFC 9449
8Credential EndpointCredential Request / Responsev0.6.0 以降
8.2Credential ProofJWT Proofv0.6.0 以降
✅ 検証
✅ 生成Credential の鍵所有証明。現在は単一 Proof が対象。
7.2NonceOpenID4VCI c_noncev0.6.0 以降
✅ 発行
✅ 取得・使用POST /nonce の JSON body で返す Credential Proof 用 nonce。
7.2NonceDPoP-Noncev0.6.0 以降
✅ 条件付き
✅ 条件付きDPoPのチャレンジ用レスポンスヘッダー。c_nonce とは別の値。外部仕様: RFC 9449
12.2MetadataCredential Issuer Metadatav0.6.0 以降
✅ 署名なし JSON
✅ 取得署名付き Metadata は未対応。
6.1.1Credential Selectionauthorization_detailsToken Request / Response のエンドツーエンド対応は未実装。
3.3.4Credential Selectioncredential_identifier部分対応Token Response での credential_identifiers 連携が未実装。関連節: 6.2
3.3.2Credential IssuanceBatch Credential Issuance
9Credential IssuanceDeferred Credential Endpoint
10EncryptionCredential Request の暗号化
10EncryptionCredential Response の暗号化
11NotificationNotification Endpoint

OpenID for Verifiable Presentations - draft 24

仕様セクション機能領域仕様上の役割・機能VerifierWallet備考
5Authorization RequestAuthorization Requestv0.6.0 以降
request_uri、URL エンコードされたパラメータ
requestrequest_uri、URL エンコードされたパラメータ
6Credential QueryDCQL
5.4Credential QueryPresentation Exchangev0.6.0 以降
外部仕様: DIF Presentation Exchange
5Authorization Request署名付き Authorization Request(JAR)v0.6.0 以降
Request Objectを使用。外部仕様: RFC 9101
5Authorization Request暗号化された Authorization Request(JAR)外部仕様: RFC 9101
5.6Credential Queryスコープを使用した Authorization Request
5.10.4Client IdentificationClient Identifier Schemev0.6.0 以降
redirect_urix509_san_dns
redirect_urix509_san_dns
5.11Request URIRequest URI Methodv0.6.0 以降
✅ GET
✅ GET、POST
10MetadataWallet Metadata
8.1Authorization ResponseAuthorization Responsev0.6.0 以降
8.5Authorization ResponseAuthorization Error Response
8.3Authorization Response暗号化された Authorization Response
8.2Response ModeResponse Modev0.6.0 以降
direct_post
direct_post
8.4Transaction DataTransaction Datav0.6.0 以降
12Client AuthenticationVerifier Attestation JWT
Appendix ADigital Credentials APIDigital Credential API/DC API
Appendix B.4Credential FormatSD-JWT-VC形式(dc+sd-jwtv0.6.0 以降
Appendix B.4.5Holder BindingSD-JWT VC Key Binding/KB-JWTv0.6.0 以降
Appendix B.1.1Credential Formatjwt_vc_json形式v0.6.0 以降