Skip to main content

DID

A DID, or Decentralized Identifier, is a globally unique identifier that does not depend on a central registry. It lets issuers, holders and verifiers reference each other and resolve public keys without a central authority.

A DID resolves to a small document listing the public keys and service endpoints its owner controls, so anyone can verify a signature made with that DID without asking a third party for permission.

Every DID has the same shape: the scheme did, a method name, and an identifier that method knows how to resolve, as in did:web:credenco.com. The method decides where the document lives and who keeps it reachable.

The identifier stays fixed while the keys inside its document can be replaced, so an issuer can rotate a compromised key without reissuing everything it ever signed.

In the EUDI Wallet under eIDAS 2.0, DIDs commonly identify issuers and, in some credential formats, holders, giving every participant an identifier that behaves the same way in every member state. A DID does not vouch for anyone, though: it shows that the same party signed two things, not that the party is a licensed bank. That judgement comes from a Trust Framework or a trusted list on top.

Read the full explanation

This page gives the short definition. Our explainer shows what it means in practice: who is involved, how it works and what changes for your organisation.

DID explained

Who controls a DID?

The organisation or person the DID identifies, called its subject, controls it by holding the private key that matches the public key in the DID document. No registry or central authority can revoke or reassign a DID on its subject's behalf.

Back to the glossary