Released
Changelog Update: September 2025
We've enhanced our authorization capabilities with DCQL support, improved developer experience with new testing infrastructure, and strengthened our security compliance framework.
Authorizer Service
Features
- DCQL Query Support: Added support for Digital Credential Query Language (DCQL) in the Authorizer Service, enabling more flexible and structured credential requests alongside existing DIF Presentation Exchange support
- Additional Configuration Options: Expanded Authorizer configuration capabilities with new parameters for authorization endpoints and client ID prefix support, providing greater flexibility in deployment scenarios
Improvements
- X509 Certificate Handling: Fixed x509_san_dns prefix handling and clientId generation to properly support DNS name extraction from URLs, ensuring correct certificate-based authentication
- Response Alignment: Aligned authorizer responses with OpenID4VP specifications for better standards compliance to 1.0.0
- CORS Configuration: Fixed CORS handling for resolver paths, improving cross-origin request support
Infrastructure & Testing
Security & Compliance
- Security Compliance Page: Added dedicated security and compliance documentation page with updated ISO9001 certification details
- Terms of Service Updates: Incorporated equality and accessibility clauses into terms of service, demonstrating commitment to inclusive practices
- Log Retention: Implemented automated log lifecycle policies for log storage, improving log management and compliance
Developer Experience
Dashboard Interface
- Tester Components: Replaced diagnostic tabs with new tester components and restructured documentation for improved user experience