Skip to content

SD-JWT VC revocation via IETF Token Status List (gated: RFC + openvc-core + demand) #245

Description

@luisgf

Horizon: mid-long (gated) · Effort: L · 2026-07-17 roadmap analysis (round 3)

SD-JWT VC badges are deliberately irrevocable today: issuance rejects a credentialStatus (#226) because no interoperable revocation mechanism existed for the JOSE track. The mechanism now has a name — IETF OAuth Token Status List, at draft-21 (2026-06-21, expires 2026-12-23) — but it is not finished, and our delegate does not speak it.

Explicit gates — build only when all hold:

  • Token Status List is published as a Standards-Track RFC
  • openvc-core implements it (as of 1.20.2 / 2026-07-16 it does not — its status-list support is W3C Bitstring, which our LDP/JWT-VC tracks already use; delegation is the established pattern for this track, no native build)
  • named demand, or HAIP/EUDI requiring status for the credential types we issue

Until then the #226 policy (reject at issuance + document the boundary) remains correct. Re-evaluation point: the December EUDI checkpoint (cross-referenced from that issue); if the gates are still open there, this moves to the quarterly radar (#173).

Metadata

Metadata

Assignees

No one assigned

    Labels

    roadmapRoadmap item (2026-07 full-code analysis)roadmap-r3Round 3 (2026-07-17): post-v4 / standards-calendar analysis

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions