- From: wes-smith <notifications@github.com>
- Date: Wed, 12 Aug 2026 08:23:18 -0700
- To: w3ctag/design-reviews <design-reviews@noreply.github.com>
- Cc: Subscribed <subscribed@noreply.github.com>
- Message-ID: <w3ctag/design-reviews/issues/1263@github.com>
wes-smith created an issue (w3ctag/design-reviews#1263) ### Specification https://w3c.github.io/vc-barcodes/ ### Explainer https://w3c.github.io/vc-barcodes/#introduction ### Links - The WG's request for this TAG review: https://www.w3.org/2026/08/12-vcwg-minutes.html#ResolutionSummary - Previous early design review, if any: None - An introduction to the feature, aimed at unfamiliar audiences: https://w3c.github.io/vc-barcodes/#introduction - A description of the problems that end-users were facing before this proposal:https://w3c.github.io/vc-barcodes/#introduction (existing optical barcodes on security critical documents are often unprotected and trivially forged; there is no compact, non-proprietary way to prove authenticity, integrity and status of the printed data) - Alternatives considered: Non-CBOR serializations of Verifiable Credentials were considered, but are incompatibly large with standard barcode size constraints. - Examples of how to use the proposal to solve the end-users' problems: https://w3c.github.io/vc-barcodes/#test-vectors, https://w3c.github.io/vc-barcodes/#introductory-examples - What do the end-users experience with this proposal: a verifier optically scans a barcode with trusted software and learns whether the data is authentic, unmodified, and (optionally) not revoked/suspended. - User research you did to validate the problem and/or design, if any: Feedback and extensive discussion from production deployments (CA DMV) and pilot programs (DHS, US First Responders, US Vital Records) - Test Suite: N/A, will be created when transitioning into CR, expectations will be to follow existing pattern for VC test suites at https://w3c.github.io/vc-data-integrity/implementations/#test-suite-reports resulting in additions to the VC ecosystem conformance dashboard: https://canivc.com/ NOTE: The VCWG has volunteered to follow the new Threat Modelling approach championed by the Security IG, which largely replaces the traditional Security/Privacy Considerations section with a new Threat Model section: https://w3c.github.io/vc-barcodes/#threat-model and a more comprehensive Threat Model document: https://w3c.github.io/vc-barcodes/threat-model/ ### The specification - [x] Follows the [Web Platform Design Principles](https://www.w3.org/TR/design-principles/). - [x] Includes Security and Privacy Considerations sections based on answers to the [Security/Privacy Questionnaire](https://www.w3.org/TR/security-privacy-questionnaire/). ### Where and by whom is the work is being done? - GitHub repo: https://github.com/w3c/vc-barcodes/ - Primary contacts: - Wesley Smith (@wes-smith), Digital Bazaar, Editor/Author - Ivan Herman (@iherman), W3C, Staff Contact - Phil Archer (@philarcher), GS1, VCWG Chair - Organization/project driving the specification: CA DMV, National Association of Convenience Stores, DHS Silicon Valley Innovation Project, Conexxus, US First Responders, US Vital Records - This work is being funded by: CA DMV, National Association of Convenience Stores, DHS Silicon Valley Innovation Project, Conexxus, US First Responders, US Vital Records - Primary standards group developing this feature: W3C Verifiable Credentials Working Group - Incubation and standards groups that have discussed the design: - W3C Credentials Community Group, W3C JSON-LD Community Group, W3C JSON-LD Working Group, US Federal Agencies, Internet Identity Workshop, Rebooting the Web of Trust. ### Feedback so far - Active horizontal reviews: https://github.com/w3c/vc-barcodes/issues/40 - Multi-stakeholder feedback: - See "Incubation and standards groups that have discussed the design" above and the meeting minutes here -- https://w3c.github.io/vc-wg/minutes/#bcdi - Major unresolved issues with or opposition to this specification: No major unresolved issues - Status/issue trackers for implementations: None yet ### You should also know that... We are planning to enter Candidate Recommendation as soon as we have received horizontal reviews and responded to requests for changes. This is one of the reviews that is gating our entrance into Candidate Recommendation. Our goal is to enter Candidate Recommendation during W3C TPAC 2026. <!-- Content below this is maintained by @w3c-tag-bot --> --- Track conversations at https://tag-github-bot.w3.org/gh/w3ctag/design-reviews/1263 -- Reply to this email directly or view it on GitHub: https://github.com/w3ctag/design-reviews/issues/1263 You are receiving this because you are subscribed to this thread. Message ID: <w3ctag/design-reviews/issues/1263@github.com>
Received on Wednesday, 12 August 2026 15:23:22 UTC