Verifiable credential
A tamper-evident set of claims signed by an issuer, kept by a holder and checked by a verifier, as defined by the W3C Verifiable Credentials Data Model 2.0.
A verifiable credential is a set of claims about a subject, made by an issuer and secured cryptographically so that anyone can check who issued it and that it has not been altered.
Status. The W3C Verifiable Credentials Data Model v2.0 became a W3C Recommendation on 15 May 2025.
Roles. The data model defines three roles and a supporting registry:
| Role | What it does |
|---|---|
| Issuer | Asserts claims about one or more subjects and issues the credential |
| Holder | Possesses credentials and presents them, often inside a verifiable presentation |
| Verifier | Receives credentials and checks them |
| Verifiable data registry | Mediates identifiers, keys, schemas, revocation registries and other data that verification needs |
The holder is often the subject of the credential, but not always: a parent can hold a credential about a child.
Securing it. The specification recognizes two classes of proof. An enveloping proof wraps the credential, for example using JOSE or COSE. An embedded proof sits inside it, as in Verifiable Credential Data Integrity. The optional credentialStatus property lets an issuer publish whether a credential is suspended or revoked, for example through a Bitstring Status List, which is also a W3C Recommendation.
Where agents come in. A verifiable credential is one way to carry a fact an agent or its principal must prove to a stranger, such as a provider having passed a check or a person holding an account. AP2 builds on the related idea of verifiable digital credentials: its v0.2 mandates are secured as SD-JWTs, and its User Credential model delegates mandates by presenting a credential through OpenID for Verifiable Presentations. The W3C data model is explicit about its limits. It is meant to identify subjects reliably, and it says authorization is not an appropriate use without an accompanying authorization framework.
Neighbouring terms. A decentralized identifier often names the issuer or the subject. Credential revocation covers the status side of the lifecycle.