OpenID Foundation completes conformance programme for widely adopted digital identity standards

Published August 7, 2026
  • Governments, wallet providers, issuers, verifiers, and vendors now have a proven, free path to declare their verifiable credentials implementations ready. 
  • Early movers who self-certify now will carry greater weight with ecosystem partners, regulators and customers. 

San Ramon, CA, 07 August 2026 – The OpenID Foundation has completed the conformance test suites for OpenID for Verifiable Presentations (OpenID4VP) and OpenID for Verifiable Credential Issuance (OpenID4VCI) protocols when used with the High Assurance Interoperability Profile (HAIP), and they are now open for self-certification. 

OpenID4VP and OpenID4VCI are the world's most widely adopted specifications for digital identity wallets, having been selected by more than 30 jurisdictions, including the United Kingdom, Switzerland, India, and the member states of the European Union through the EU Digital Identity Wallet programme. Until now, they have been able to implement the specifications, but could not assert publicly through an independent third party that an implementation of OpenID4VCI or OpenID4VP complied with the High Assurance Interoperability Profile. 

The completion of the conformance programme means that governments, wallet providers, issuers, verifiers, and technology vendors implementing the specifications can now formally demonstrate through a common, publicly recognized mechanism, that their digital identity systems conform to global standards and can work together as intended. This will carry real weight with ecosystem partners, regulators and customers.

Gail Hodges, Executive Director for the OpenID Foundation, said: “For the first time, we are moving towards a world in which people are able to prove who they are digitally online without revealing more than they need to. Until now, there has been no independent way for governments, regulators or ecosystem partners to verify that different implementations of OpenID for Verifiable Presentations and OpenID for Verifiable Credential Issuance would actually work together or meet the security requirements built into these specifications. This conformance program changes that. Verifiable credentials can now be built, tested, and deployed with confidence.

"This is also a firm foundation from which individual jurisdictions can build and tailor their own conformance requirements to meet their specific needs. We are calling on every implementer of OpenID4VP, OpenID4VCI, and HAIP to self-certify now and be among the first publicly recognized for meeting this global standard."

Putting people in control of their own data

The OpenID4VC family of specifications enable the issuance and presentation of digital credentials while giving individuals greater control over the information they share. 

Someone proving they are over 18 can confirm that fact without revealing their full date of birth, home address or any other personal information. Credentials are signed by their issuer and can be presented in ways that minimise unnecessary disclosure of personal data. Equally, organizations issuing credentials do not gain visibility into where or how those credentials are subsequently used, helping preserve user privacy.

These capabilities have led governments and industry to adopt OpenID4VC as the basis for national and sector-specific digital identity programmes. With conformance testing now complete, implementers have a common mechanism for verifying that their systems conform to the specifications before deployment.

Conformance testing and self-certification

Conformance testing enables organizations to determine whether they have implemented the specifications correctly. The tests produce detailed reports identifying which requirements have been met and where further work may be required. They can be run free of charge using OpenID Foundation-hosted infrastructure or on an organisation's own systems.

Once an implementation has successfully completed the conformance tests, organizations can apply for OpenID Foundation self-certification. Following review, the Foundation publishes the results, providing governments, ecosystem partners and customers with public evidence that an implementation conforms to the relevant specification.

Self-certification is available for the implementation roles defined within each specification. Under OpenID4VP, organizations can certify as a wallet or verifier/relying party. Under OpenID4VCI, certification is available for issuers and wallet providers, with dedicated test profiles for each role.

Both test suites were validated through multiple rounds of real-world interoperability testing - achieving pass rates of over 90% for OpenID4VP and 87% for OpenID4VCI - before the OpenID Foundation’s Digital Credentials Protocols Working Group confirmed the tests as ready in July 2026.

Early movers will set the benchmark

The programme follows the certification model established for OpenID Connect and the FAPI security profile, both already embedded in digital identity and open banking ecosystems worldwide. In Brazil, certification against OpenID Foundation specifications began as a voluntary programme before becoming a regulatory requirement. It is now a mandated condition of participation in the country's open banking ecosystem.

The OpenID Foundation is in active dialogue with the EU Digital Identity Wallet ecosystem and other jurisdictions about how OpenID Foundation open source tests and conformance tools can support their local ecosystem requirements. While self-certification is not yet a universal requirement across all ecosystems, the direction it is heading is clear.

With this in mind, the OpenID Foundation is calling on organizations implementing OpenID4VP and OpenID4VCI to self-certify now. Those who act now will be among the first organizations publicly listed on the OpenID Foundation website, and the ones their ecosystem partners will look to as the benchmark for what conformance looks like in practice.

Implementer voices

The following organizations were among 16 unique entities that participated in the OpenID4VP and OpenID4VCI interoperability testing programme. They have shared their perspectives on the completion of the conformance programme:

Lee Campbell, Android Auth, Identity and Payments Lead, Google, said: “The success of the digital identity ecosystem depends on globally interoperable standards that are widely adopted and implemented correctly. Over the last few years, we have actively contributed to the OpenID4VP, OpenID4VCI, and HAIP specifications, and we are excited to see the OpenID Foundation publish the final editions. We want to support all our app and wallet developers to implement these standards correctly on our platform. With the release of these conformance tests, we now have a proven mechanism to ensure security, interoperability, and consistency across the Android ecosystem.”

Wayne Chang, Founder and CEO, SpruceID, said: "SpruceID is proud to support the OpenID Foundation's standardization efforts, enabling interoperability across issuers, holders, and verifiers. This work directly supports our mission to give users control over their data across the web, ensuring that there are many ways for users to obtain useful verifiable digital credentials and meaningful ways to use them securely, such as applying for state benefits or opening a bank account. Conformance to standards ensures that systems are built in ways that increase user choice, prevent fraud, and protect privacy."

Oriol Canadés, Founder, Fikua, said: "As we build toward the EU Digital Identity Wallet, conformance to OpenID4VP, OpenID4VCI and HAIP is no longer optional; it is the foundation regulators and relying parties will depend on. The OpenID Foundation test suite lets Fikua validate that our issuer, wallet and verifier all speak the same language as the rest of Europe."

Takahiko Kawasaki, Co-Founder of Authlete, said: “As a long-time implementer of and contributor to OpenID standards, Authlete has provided testing infrastructure to support the development of multiple OpenID Foundation conformance test suites, including the HAIP test suite for OpenID4VCI. We believe open standards deliver their full value only when they are implemented correctly and work securely and interoperably in practice. Robust conformance testing gives implementers, regulators and relying parties confidence that different systems will work together as intended. We are proud that our contribution helps strengthen trust across the verifiable credentials ecosystem.”

Jan Vereecken, Chief Product Officer, Meeco, said: "OpenID4VC HAIP is shaping up to be one of the most consequential profiles for high-assurance verifiable digital credentials, not just in Europe but globally. The OpenID Foundation's conformance suite, covering both OpenID4VCI and OpenID4VP across issuer, wallet, and verifier, gives it real teeth. The breadth of coverage, spanning required and optional features, success scenarios and failure scenarios alike, is exactly what the ecosystem needs. At Meeco, we see conformance testing as an essential part of the work, not a checkbox to tick. It is how we give partners and collaborators confidence that our platform is interoperable in practice, not just on paper."

Henry Hang, CTO, Turing Space, said: "Conformance testing is essential to building real-world interoperability — and we are proud to contribute to strengthening the ecosystem, making the world more trustworthy."

ENDS

For more information, please contact:

Notes to editors

About the OpenID Foundation

The OpenID Foundation (OIDF) is a global open standards body committed to building trusted identity ecosystems. Our mission is to lead the global community in identity standards that are secure, interoperable, and privacy respecting. Founded in 2007, we are a community of technical experts. The Foundation's OpenID Connect standard is now used by billions of people across millions of applications. More recently, the FAPI security profile - built on OAuth 2.0 - has become the standard of choice for interoperable Open Banking and Open Data implementations, while OpenID for Verifiable Credentials specifications are underpinning a new generation of digital wallets. Today, the OpenID Foundation's standards are the connective tissue that enable people to assert their identity and access their data at scale, the scale of the internet, enabling "networks of networks" to interoperate globally. Individuals, companies, governments and non-profits are encouraged to join or participate. Find out more at openid.net.




Tagged