Released
Changelog Update: November 2025
November brings enhanced security capabilities and expanded credential query support, with new HAIP profile implementation and improved authorisation mechanisms.
Authorizer
Keystore and Certificate Management: Introduced dedicated keystore functionality with private key derivation and key resolution, enabling secure key management across different operational contexts.
Certificate Chain Support: Authorisation request JWTs now include full certificate chains, providing enhanced trust verification for relying parties validating authorisation requests.
HAIP Profile Support: Authorisation requests can now be created based on High Assurance Interoperability Profile (HAIP) definitions, ensuring compliance with high-assurance credential presentation requirements.
x509_hash Client Identifier: Added support for x509_hash as a client identifier prefix, allowing client identification based on certificate hash values for improved security in certificate-based authentication flows.
Authorisation URI Schema Improvements: Refactored authorisation endpoint URI schema to support profile-based defaults whilst maintaining flexibility for custom implementations.
Response Mode Validation: Authorisation responses now enforce strict response_mode matching, preventing mismatched response delivery methods between requests and responses.
Streamlined Authorisation Requests: Removed the non-standard client_id_schema parameter from authorisation requests, aligning with OpenID4VP specifications.
Validator
DCQL Trusted Authorities: Digital Credential Query Language (DCQL) now supports Authority Key Identifier (AKI) for specifying trusted credential issuers, giving you more precise control over which credential authorities to trust during validation.
Enhanced API Documentation: Updated OpenAPI specifications include detailed descriptions of validation processes, supported formats (DIF Presentation Exchange, DCQL, mDL Device Requests), and comprehensive error response documentation.
Verifier
Enhanced API Documentation: Updated OpenAPI specifications provide clearer descriptions of verification processes and detailed error responses across all status codes, making integration easier for developers.