
What the Foundation Launched
The OpenID Foundation has released conformance test suites for two core digital identity specifications — OpenID for Verifiable Presentations (OpenID4VP) and OpenID for Verifiable Credential Issuance (OpenID4VCI) — and made both available for free self-certification.
Wallet providers, credential issuers, verifiers, government agencies, and technology vendors can now demonstrate that their implementations meet the High Assurance Interoperability Profile (HAIP) through an independent, publicly recognised mechanism rather than self-declaring compliance.
The specifications underpin digital identity programmes in over 30 jurisdictions, including the UK, Switzerland, India, and EU member states through the EU Digital Identity Wallet initiative. Until now, no third-party route existed to verify that implementations would interoperate or satisfy HAIP security requirements.
Scope and Testing Process
Under OpenID4VP, organisations can self-certify either as a wallet or as a verifier (relying party). Under OpenID4VCI, certification covers issuers and wallet providers, with dedicated test profiles for each role.
Both suites underwent multiple rounds of real-world interoperability testing, achieving pass rates above 90% for OpenID4VP and 87% for OpenID4VCI, before the Foundation's Digital Credentials Protocols Working Group approved them as production-ready in July 2026.
Tests can be run at no cost using Foundation-hosted infrastructure or on an organisation's own systems. Once an implementation passes, the Foundation publishes the results publicly.
Until now, there has been no independent way for governments, regulators or ecosystem partners to verify that different implementations of OpenID for Verifiable Presentations and OpenID for Verifiable Credential Issuance would actually work together or meet the security requirements built into these specifications. This conformance programme changes that.
Gail Hodges, executive director of the OpenID Foundation, made that comment in a statement accompanying the launch.
Industry Participation
Several organisations that took part in the interoperability testing programme welcomed the launch, including Google, SpruceID, Authlete, and Meeco, all of which contributed to both specification development and the test infrastructure.
Regulatory Context and Precedent
The programme follows the same model as OpenID Connect and the FAPI security profile, both of which are already embedded in open banking ecosystems worldwide.
Brazil's trajectory is instructive: FAPI certification began as a voluntary programme before becoming a mandated condition of participation in its open banking ecosystem. The same pattern could repeat for digital identity.
The Foundation said it is in active dialogue with the EU Digital Identity Wallet ecosystem and other jurisdictions about how its open-source conformance tools can support local requirements.
Commercial Implications
For organisations building in the identity space, the commercial signal is clear. Regulators in the EU and the UK are already leaning on the OpenID4VC specifications as the technical baseline for high-assurance digital identity.
Where voluntary certification leads, mandatory certification typically follows. Organisations that self-certify early will be listed publicly on the Foundation's website and will be the reference point for ecosystem partners evaluating interoperability.
Those that wait risk being at a disadvantage when a regulator, a government procurement body, or a large relying party makes certification a condition of participation.
The Foundation is calling on all implementers of OpenID4VP, OpenID4VCI, and HAIP to self-certify now.
Source
Original coverage by The Fintech Times.
Use the button below to read the article on the publisher website.
Read on The Fintech TimesRelated to this article