Glossary · Identity and trust

Decentralized identifier (DID)

A URI such as did:web:example.com that resolves to a DID document of keys and service endpoints, whose controller can prove control (W3C DID 1.0).

A decentralized identifier (DID) is a URI that resolves to a DID document of public keys and service endpoints, and whose controller can prove control of it without permission from a central registry.

Status. Decentralized Identifiers (DIDs) v1.0 has been a W3C Recommendation since 19 July 2022. Version 1.1 was published as a Candidate Recommendation Snapshot on 5 March 2026, so 1.0 is the current Recommendation.

Syntax. A DID has three parts: the did scheme, a method name, and a method-specific identifier, as in the specification’s example did:example:123456789abcdefghi. Each DID method defines how its DIDs are created, resolved, updated and deactivated. A DID resolver takes a DID as input and returns a conforming DID document.

The DID document. It lists verification methods, which are usually public keys, and the relationships each method may be used for, such as authentication or making assertions. It can also list services: endpoints for communicating with the subject or related parties. The DID specification describes rotation, where a controller adds a new verification method and retires the old one, as a defence against key compromise.

did:web. The did:web method, a W3C Credentials Community Group specification, ties a DID to a domain name. did:web:example.com resolves to https://example.com/.well-known/did.json, and a path adds segments, as in did:web:example.com:user:alice. The method trades decentralization for the domain’s existing reputation, much as an A2A Agent Card published at a well-known URI relies on control of its domain.

Relevance to agents. The A2A specification does not use DIDs. It identifies servers by HTTPS URLs validated with TLS certificates and signs Agent Cards with JWS keys that clients fetch by URL or hold in a trusted key store. DIDs appear in the W3C verifiable credentials ecosystem, where they can identify issuers, holders and subjects.

Neighbouring terms. A verifiable credential is the signed claim a DID often anchors. A resolver in agent discovery applies the same “identifier in, endpoint out” pattern.

Sources

  1. W3C Decentralized Identifiers (DIDs) v1.0 (W3C Recommendation, 19 July 2022) (accessed )
  2. W3C Decentralized Identifiers (DIDs) v1.1 (Candidate Recommendation Snapshot, 5 March 2026) (accessed )
  3. did:web Method Specification (W3C Credentials Community Group) (accessed )
  4. W3C Verifiable Credentials Data Model v2.0 (accessed )
  5. A2A Protocol Specification, section 8: Agent Discovery: The Agent Card (accessed )