RFC012 Nuts Organization Credential
Last updated
Last updated
Nuts foundation
W.M. Slakhorst
Request for Comments: 012
Nedap
February 2021
Creating a network with trusted Verified Credentials is victim of the chicken-and-egg-problem. Issuers are not yet convinced they should support VCs until the network is mature enough and nobody is willing to use the network without official credentials/identities. The Nuts organization credential offers a temporary solution. It allows for any DID subject to issue a VC. Trust is established manually by adding the DID to a trusted list of issuers. For development use-cases and as bootstrap for a production network, the Nuts Organization Credential
will add names to DIDs.
This document describes a Nuts standards protocol.
This document is released under the Attribution-ShareAlike 4.0 International (CC BY-SA 4.0) license.
Users that want to interact with another system want to use real-world names when they search for organizations. DIDs do not solve this problem. VCs can add this information (claims) to a DID. This RFC builds upon RFC011.
The credentialSubject
field contains the following:
and has the following requirements:
all fields are required.
all fields are encoded as strings.
id MUST refer to a known Nuts DID as specified by RFC006.
A Nuts Organization Credential is public and MUST be published over the Nuts network. Every DID MAY issue the credential. The VC does not have any other requirements nor does it add requirements to other VCs.
Only proofs from RFC011 are supported.
The Nuts Organization Credential MUST be trusted manually. An implementation can choose to trust each VC individually or trust a certain Issuer. The mechanism for this is up to the implementation.
The Nuts Organization Credential uses the revocation mechanism as stated by RFC011.
The Nuts Organization Credential MAY be used as credential in the Nuts OAuth flow as stated in RFC003. The credential MAY also be used as a way to find the correct DID and its services.
All information in the credential SHOULD be public knowledge. The VC MAY NOT contain private information.
No additional services other than the Nuts network are required.