Skip to main content

Authentic Source

An Authentic Source is a repository or system, run by a public sector body or private entity, that holds and provides attributes about a person, organisation, or object, and is considered the primary, authoritative record for that attribute.

A national trade register is an Authentic Source for company registration data; a tax authority is an Authentic Source for a VAT number, and a civil registry is an Authentic Source for a person's date of birth or address. An Attestation Provider that issues a credential based on an attribute is not itself the Authentic Source unless it also runs the underlying register: the two roles are often the same organisation, but the ARF keeps them conceptually separate, because a wallet or verifier needs to know which party actually vouches for the data's accuracy at the moment it was recorded. For a KYB or KYC check, going back to the Authentic Source rather than a document the counterparty presents is what removes the need to re-verify data that hasn't changed, since the record itself, not a photocopy or a self-declaration, is the thing being trusted. The EUDI Wallet's PID is a clear example: it is issued from population registers or comparable Authentic Sources designated by each member state, and its accuracy rests on that designation rather than on the wallet provider's own checks. Member states are required to identify and publish which bodies count as Authentic Sources for a given attribute, so an Attestation Provider, a wallet, or a relying party can trace a claim back to where it originates instead of relying on a chain of undocumented assertions. This is also what makes the once-only principle workable in practice: once an Authentic Source has confirmed an attribute, that confirmation can be reused across many attestations and many relying parties, rather than the same fact being collected and checked again by every organisation that needs it.

How is an Authentic Source different from an Attestation Provider?

An Authentic Source is the underlying record, a trade register or a civil registry, that holds the attribute and is treated as its origin. An Attestation Provider is the party that issues a credential based on that record. The two roles are often the same organisation, but the ARF keeps them separate so a wallet can trace an attribute back to where it was actually confirmed.

Back to the glossary