Glossary
Plain-language definitions of the terms Credenco uses across its products and content, from credential formats and protocols to the roles that issue, hold, and verify them.
Related reading: The EUDI Wallet for HR and recruitment
In depth:Verifiable credentials explainedTS11 explainedDCQL explainedOpenID4VCI issuance explainedEuropean Business Wallet explainedRelying party explainedAll explainers
A
- ARF
- Architecture and Reference Framework: the European Commission’s technical specification of the EUDI Wallet ecosystem, fixing the roles, credential formats, protocols and trust infrastructure that eIDAS 2.0 only describes in law. Know More
- Attestation Provider
- The collective term for a QEAA Provider, PuB-EAA Provider and non-qualified EAA Provider: the three roles the ARF defines for issuing attribute credentials. Know More
- Authentic Source
- A repository or system, run by a public sector body or private entity, that holds and provides attributes and is considered the primary, authoritative record for them. Know More
C
- Credential Issuance Platform
- The software an issuer uses to turn source data into verifiable credentials and deliver them to a wallet, typically over OpenID4VCI. Distinct from the Issuer role, which describes the party rather than the platform. Know More
- Credential Offer
- The OpenID4VCI message, usually behind a QR code or link, with which an issuer starts issuance: it names the issuer, says which credentials are on offer, and tells the wallet how it may collect them. Know More
- Credential Verification API
- The service interface a relying party calls to request and validate a presentation, covering signature checks, the trust chain, status and revocation, and the returned claims. Distinct from the Verifier role, which describes the party rather than the API. Know More
D
- DCQL
- Digital Credentials Query Language: the JSON format a relying party uses inside an OpenID4VP presentation request to describe exactly which credentials and claims it needs, so any compliant wallet can parse the request without a bespoke integration. Know More
- DID
- Decentralized Identifier: a globally unique identifier that does not depend on a central registry. DIDs let issuers, holders, and verifiers reference each other and resolve public keys without a central authority. Know More
- did:web
- A DID method that anchors a DID document on a regular HTTPS domain (e.g. did:web:example.com), using existing web PKI instead of a blockchain or ledger. Know More
- did:webvh
- DID Web with Verifiable History: a successor to did:web that adds a tamper-evident, verifiable history log of every DID document version, plus key pre-rotation and witnesses, so a DID document can't be silently rewritten. Know More
- Digital Credentials API
- The W3C browser API that lets a website request a credential from a wallet on the same device, through the operating system, instead of through a QR code or a custom deep link. It carries an OpenID4VP or ISO/IEC 18013-7 exchange rather than replacing one. Know More
- Digital Identity Wallet
- The general category of app that lets a holder store credentials and attributes and choose exactly what to share with a relying party; the EUDI Wallet is the EU’s specific, regulated implementation of it. Know More
- Digital Product Passport
- A structured, machine-readable record that follows a product through its lifecycle, giving customers, businesses and authorities standardised access to its sustainability, durability and material data. Required under ESPR for product groups covered by a delegated act. Know More
E
- EAA
- Electronic Attestation of Attributes: any electronic attestation certifying attributes about a person or organisation, issued by any provider. A QEAA is its qualified, higher-assurance variant. Know More
- EBSI
- European Blockchain Services Infrastructure: an EU network that anchors cross-border trust for verifiable credentials, such as which issuers and schemas are recognised, used by several EUDI Wallet pilots as their trust registry. Know More
- EBWOID
- European Business Wallet Owner Identification Data: the attestation that identifies the organisation a European Business Wallet belongs to, carrying a cross-border unique identifier, the official legal name from the authentic register, the issuing authority and a trust anchor a verifier can check it against. Know More
- eIDAS 2.0
- The revised European regulation on electronic identification and trust services. It mandates the EUDI Wallet and establishes the legal framework for verifiable credentials to carry legal validity across the European Union. Know More
- ESPR
- The Ecodesign for Sustainable Products Regulation: the EU regulation, in force since July 2024, that sets ecodesign requirements for products and establishes the Digital Product Passport as the way to make that information available. Know More
- EUDI Wallet
- The European Digital Identity Wallet required by eIDAS 2.0: each EU member state must provide at least one to natural and legal persons for storing and presenting identity data and attestations, and public sector bodies across the EU must accept it for online identification. Know More
- European Business Wallet
- A cloud-based business identity wallet built for the European market: it lets organisations issue, hold, and verify verifiable credentials for company registration, tax IDs, and certifications, so counterparties across the EU can trust them instantly instead of re-checking documents. Credenco's Business Wallet is an implementation of this concept. Know More
F
H
- HAIP
- High Assurance Interoperability Profile: an OpenID Foundation specification that constrains OpenID4VC for use where a high level of security and privacy is required, such as government-issued identity and the EUDI Wallet. Know More
- Holder
- The person or organisation that receives a verifiable credential, stores it in a wallet, and decides when and with whom to share it. The holder is not necessarily the subject the credential is about. Know More
- Holder Binding
- Tying a credential to a cryptographic key the holder controls, so only the rightful holder can present it and a copied credential is useless. SD-JWT and SD-JWT VC implement it as Key Binding: the wallet signs a Key Binding JWT over a nonce and audience from the verifier. Know More
I
- ISO/IEC 18013-5
- The international standard for a mobile driving licence: how a credential is stored on a phone and presented to a reader in person, offline or online. The format the mDL and mdoc are built on. Know More
K
L
- Large Scale Pilots
- The four consortia that tested the EU Digital Identity Wallet in real use cases between 2023 and 2025: EWC, POTENTIAL, NOBID and DC4EU, bringing together over 350 organisations from 26 member states plus Norway, Iceland and Ukraine under the Digital Europe Programme. Know More
- LEI
- Legal Entity Identifier: a 20-character ISO 17442 code, issued by an accredited Local Operating Unit under GLEIF, that uniquely identifies a legal entity worldwide. Know More
- Level of Assurance
- How much confidence a relying party can place in a claimed identity, based on how the holder was identified and how the credential is protected. eIDAS defines three levels: low, substantial and high; the EUDI Wallet is issued at high. Know More
M
O
- OpenID4VCI
- OpenID for Verifiable Credential Issuance: the protocol a wallet uses to request and receive a credential from an issuer over a standard OAuth2-based flow. Know More
- OpenID4VP
- OpenID for Verifiable Presentations: the protocol a wallet uses to present one or more credentials to a verifier in response to a request, so the verifier can check them without a separate integration per issuer. Know More
- Organization Wallet
- A digital identity wallet held by a legal entity rather than a natural person, letting a company issue, hold, and present verifiable credentials about itself. The European Business Wallet is the specific implementation of this concept for the European market. Know More
P
- PID
- Person Identification Data: the government-issued identity credential at the core of every EUDI Wallet, holding attributes such as name, date of birth and a unique identifier, which other attestations are bound to. Know More
- Presentation Exchange
- The specification a relying party uses to describe which credentials and claims it needs from a holder, so a wallet can automatically match the request against the credentials it holds. Know More
Q
- QEAA
- Qualified Electronic Attestation of Attributes: the qualified variant of an EAA, issued by a qualified trust service provider under eIDAS 2.0, carrying the same legal weight as a notarised paper document. Know More
- QERDS
- Qualified Electronic Registered Delivery Service: an eIDAS trust service for sending and receiving electronic data, backed by an EU-wide legal presumption of who sent it, who received it, when, and that it arrived unaltered. Know More
- QES
- Qualified Electronic Signature: an electronic signature created with a qualified device and certificate, which eIDAS gives the same legal effect as a handwritten signature throughout the EU. Know More
R
- Relying party
- The organisation that requests a verifiable credential from a holder and relies on it to make a decision, such as a bank onboarding a new business or a shop checking a customer is old enough to buy an age-restricted product. Know More
- Revocation
- The mechanism an issuer uses to invalidate a credential after it was issued (for example when a qualification expires or a registration is withdrawn), so verifiers checking it afterwards see it as no longer valid. Know More
S
- Same-device vs cross-device flow
- The two ways a wallet and a website reach each other. Same-device means both are on one phone and the site hands over with a deep link or redirect. Cross-device means the site is on a desktop and the wallet scans a QR code, with the answer returning through the backend. Know More
- SD-JWT
- Selective Disclosure JSON Web Token: a credential format that lets a holder reveal only some of the claims inside a signed token while keeping the rest hidden, without invalidating the issuer's signature. Know More
- SD-JWT VC
- The IETF profile that defines how to use SD-JWT to issue and present verifiable credentials, adding a credential type claim, key binding, and issuer metadata rules on top of the underlying selective-disclosure mechanism. The EUDI ARF names it alongside mdoc as a format wallets must support. Know More
- Selective Disclosure
- The ability to share only the specific attributes a verifier needs from a credential, for example proving you are over 18 without revealing your exact birth date. It is a core privacy property of modern credential formats such as SD-JWT. Know More
- Status List
- A compact, signed bitstring an issuer publishes in which every credential it has issued has one index, so a verifier can check whether a credential is still valid without revealing to the issuer which one it looked up. Know More
T
- Trust Anchor
- An authoritative entity, represented by a public key and its associated data, that a relying party accepts as the starting point for verifying a chain of trust. Know More
- Trust Framework
- The set of technical standards, legal rules, and governance agreements that let issuers, holders, and verifiers rely on each other's credentials across organisations and borders, such as the framework eIDAS 2.0 establishes for the EU. Know More
- Trusted List
- The authoritative register a verifier consults to decide whether an issuer is trusted. Each EU member state publishes one under eIDAS 2.0, naming the qualified trust service providers and issuers it authorises. Know More
U
V
- Verifiable Credential
- A tamper-evident digital claim about a person or organisation that can be cryptographically verified without contacting the party that issued it. Verifiable credentials replace paper documents and PDFs with data that a verifier can trust on its own. Know More
- Verifiable Presentation
- The tamper-evident package a holder assembles from one or more verifiable credentials to share with a verifier in response to a specific request, bound to the holder presenting it. Know More
W
- W3C VC
- The World Wide Web Consortium's open data model for verifiable credentials. It defines how claims, issuers, and cryptographic proofs are structured so credentials remain interoperable across different wallets and platforms. Know More
- Wallet as a Service (WaaS)
- A delivery model in which a provider hosts and operates a wallet's issuance, storage, presentation, and underlying security on a buyer's behalf, rather than the buyer building and running that infrastructure itself. Know More
- Wallet Attestation
- A signed data object, issued by a Wallet Provider, that describes the components of a Wallet Unit, its Wallet Instance and its secure key storage, so a PID Provider or Attestation Provider can check them before issuing a credential. It is never shown to Relying Parties. The ARF calls this a Wallet Unit Attestation (WUA). Know More
- Wallet Provider
- The natural or legal person that supplies a Wallet Solution to users under eIDAS 2.0, responsible for its software, security guarantees and compliance obligations. Know More
- Wallet Unit
- The unique configuration a Wallet Provider gives to one Wallet User: the Wallet Instance app together with the secure cryptographic application and device that generate and protect its keys. Know More
- WE BUILD
- A European consortium of over 180 organisations building the infrastructure for an interoperable EU Digital Identity Wallet for businesses, and testing implementations against each other in its Interoperability Test Bed. Know More
- WIA
- A Wallet Instance Attestation is a Wallet Provider-signed proof of a Wallet Instance's integrity and authenticity, presented to PID and Attestation Providers at issuance so they can check the wallet before issuing a credential. Know More
Z
- Zero-Knowledge Proof
- A cryptographic method for proving a statement about a credential is true, such as being over 18, without revealing any of the underlying data the statement is based on. Know More