sd-jwt-dotnet
Health Warn
- License — License: Apache-2.0
- Description — Repository has a description
- Active repo — Last push 0 days ago
- Low visibility — Only 5 GitHub stars
Code Fail
- rm -rf — Recursive force deletion command in .github/workflows/ci-validation.yml
Permissions Pass
- Permissions — No dangerous permissions requested
No AI report is available for this listing yet.
Selective Disclosure for JWTs (SD-JWT) .Net implement
SD-JWT .NET Ecosystem
Standards-first .NET infrastructure for Selective Disclosure JSON Web Tokens (SD-JWTs), verifiable credentials, wallet interoperability, and delegated agent trust.
This project provides reusable building blocks for issuers, verifiers, wallet frameworks, enterprise APIs, and agentic systems. It is not a standalone consumer wallet. Instead, it provides the protocol, cryptographic, policy, and reference infrastructure that digital identity and trust systems can build on.
For package maturity classifications, see MATURITY.md. See also What SD-JWT .NET Is - and Is Not and Standards and Maturity Status.
What This Project Is
- A standards-first .NET implementation of SD-JWT and related credential protocols.
- A reusable library ecosystem for issuers, verifiers, wallet frameworks, and enterprise APIs.
- A reference infrastructure layer for wallet and EUDIW-style interoperability.
- A preview experimentation space for Agent Trust and delegated tool-call governance.
What This Project Is Not
- Not a standalone consumer wallet application.
- Not an identity provider.
- Not a certification authority.
- Not a finished standard for AI-agent authorization.
Choose Your Path
I need core SD-JWT
Use SdJwt.Net for RFC 9901 issuance, disclosure, presentation, key binding, and verification.
I am building issuers, verifiers, or wallet infrastructure
Use SdJwt.Net.Vc, SdJwt.Net.Oid4Vci, SdJwt.Net.Oid4Vp, SdJwt.Net.Mdoc, SdJwt.Net.HAIP, and related packages.
I am securing AI agents or enterprise tool calls
Use the preview SdJwt.Net.AgentTrust.* packages for scoped capability tokens, policy enforcement, MCP/API governance, telemetry, and delegation chains.
Quick Start
# Core SD-JWT functionality
dotnet add package SdJwt.Net
# Verifiable Credentials
dotnet add package SdJwt.Net.Vc
# Try the samples
git clone https://github.com/openwallet-foundation-labs/sd-jwt-dotnet.git
cd sd-jwt-dotnet/samples/SdJwt.Net.Samples
dotnet run
Package Ecosystem
Maturity Legend
| Status | Meaning |
|---|---|
| Stable | Suitable for production use, subject to semantic versioning. |
| Spec-Tracking | Tracks an active draft or evolving specification. APIs may change as the specification changes. |
| Profile | Implements or supports a constrained profile over one or more base specifications. |
| Reference | Reference infrastructure or integration pattern, not a standalone product. |
| Preview | Experimental or early-access package. APIs and claims may change. |
Core
| Package | Release | Specification | Status |
|---|---|---|---|
| SdJwt.Net | NuGet (MinVer) | RFC 9901 | Stable |
Credential Formats, Status & Assurance Profiles
| Package | Release | Specification | Status |
|---|---|---|---|
| SdJwt.Net.Vc | NuGet (MinVer) | draft-ietf-oauth-sd-jwt-vc-16 | Spec-Tracking |
| SdJwt.Net.StatusList | NuGet (MinVer) | draft-ietf-oauth-status-list-20 | Spec-Tracking |
| SdJwt.Net.VcDm | NuGet (MinVer) | W3C VCDM 2.0 | Stable |
| SdJwt.Net.HAIP | NuGet (MinVer) | HAIP 1.0 | Profile |
OpenID Identity Protocols
| Package | Release | Specification | Status |
|---|---|---|---|
| SdJwt.Net.Oid4Vci | NuGet (MinVer) | OpenID4VCI 1.0 | Stable |
| SdJwt.Net.Oid4Vp | NuGet (MinVer) | OpenID4VP 1.0 | Stable |
| SdJwt.Net.SiopV2 | NuGet (MinVer) | SIOPv2 draft-13 | Spec-Tracking |
Protocol & Interoperability
| Package | Release | Specification | Status |
|---|---|---|---|
| SdJwt.Net.OidFederation | NuGet (MinVer) | OpenID Federation 1.0 | Stable |
| SdJwt.Net.PresentationExchange | NuGet (MinVer) | DIF PEX v2.1.1 | Stable |
ISO Credential Formats
| Package | Release | Specification | Status |
|---|---|---|---|
| SdJwt.Net.Mdoc | NuGet (MinVer) | ISO 18013-5 mDL | Stable |
Reference Infrastructure
| Package | Release | Purpose | Status |
|---|---|---|---|
| SdJwt.Net.Wallet | NuGet (MinVer) | Holder-side reference infrastructure for credential storage, key abstraction, format plugins, and issuance/presentation orchestration | Reference |
| SdJwt.Net.Eudiw | NuGet (MinVer) | EUDIW / ARF reference helpers for PID-style credentials, trust metadata, relying-party models, and regional validation patterns | Reference |
Reference packages are intended for samples, interoperability testing, architecture guidance, and framework builders. They are not standalone wallet products or compliance-certified implementations.
Agent Trust Kits
Preview implementations of emerging patterns for Agent Trust and bounded delegation. They are designed for early adopters and researchers exploring scoped SD-JWT capability tokens, key binding, selective disclosure, policy, telemetry, and enterprise tool-call governance.
| Package | Release | Specification / Design Source | Status |
|---|---|---|---|
| SdJwt.Net.AgentTrust.Core | NuGet (MinVer) | Capability SD-JWT profile (project proposal) | Preview |
| SdJwt.Net.AgentTrust.Policy | NuGet (MinVer) | Rule-based policy and delegation model | Preview |
| SdJwt.Net.AgentTrust.AspNetCore | NuGet (MinVer) | ASP.NET Core middleware integration | Preview |
| SdJwt.Net.AgentTrust.Maf | NuGet (MinVer) | MAF/MCP middleware and adapter integration | Preview |
| SdJwt.Net.AgentTrust.OpenTelemetry | NuGet (MinVer) | Agent trust metrics and telemetry | Preview |
| SdJwt.Net.AgentTrust.Policy.Opa | NuGet (MinVer) | OPA external policy engine integration | Preview |
| SdJwt.Net.AgentTrust.Mcp | NuGet (MinVer) | MCP trust interceptor and guard | Preview |
| SdJwt.Net.AgentTrust.A2A | NuGet (MinVer) | Agent-to-agent delegation chains | Preview |
Key Features
Enterprise Security
- RFC 9901 Implementation: Implements SD-JWT issuance, disclosure, presentation, key binding, and verification flows.
- HAIP Profile Support: Provides helpers and validation patterns for high-assurance SD-JWT VC deployments.
- Algorithm Enforcement: Blocks weak algorithms (MD5, SHA-1), enforces SHA-2 family
- Defensive Verification: Includes validation for weak algorithms, replay-sensitive inputs, signature integrity, key binding, and verifier-side checks.
- Secretless Deployment Patterns: Documentation covers integration with Azure Key Vault, managed identity, workload identity, and HSM-backed key custody.
- Verify-First Design: All tokens and claims are cryptographically verified before use
High Performance
- Multi-Target: .NET 8, .NET 9, .NET 10, and .NET Standard 2.1 where package dependencies allow
- Platform-Aware Crypto: Uses SHA256.HashData() on .NET 6+ where available
- Batch Throughput: Designed for high-volume issuance and verification
- Low Allocation: Reduced allocations for high-volume scenarios
Standards-Aligned
- IETF Standards and Drafts: RFC 9901, SD-JWT VC draft-16, and Token Status List draft-20
- OpenID Foundation: OpenID4VCI, OpenID4VP, Federation, HAIP
- W3C: Verifiable Credentials data model compatibility
- DIF: Presentation Exchange v2.1.1
- ISO: ISO 18013-5 mdoc support
Developer Experience
- Samples: Console tutorials organized by skill level and use case
- Fluent APIs: Chainable builder interfaces
- Documentation: Guides, deep dives, and security reference
- Tested: 2,500+ xUnit tests across the implemented packages
Ecosystem Architecture
The SD-JWT .NET Ecosystem can be understood as five adoption layers. For the detailed package dependency model, see Ecosystem Architecture.
See MATURITY.md for the maturity classification of each package.
Reference Patterns
Reference pattern documentation lives under docs/reference-patterns. The repository also includes runnable console examples under samples/SdJwt.Net.Samples.
Architecture Overview
Quick Examples
Basic SD-JWT
using SdJwt.Net.Issuer;
// Create issuer
var issuer = new SdIssuer(signingKey, SecurityAlgorithms.EcdsaSha256);
// Issue with selective disclosure
var credential = issuer.Issue(claims, new SdIssuanceOptions
{
DisclosureStructure = new { email = true, address = new { city = true } }
});
// Holder creates presentation
var holder = new SdJwtHolder(credential.Issuance);
var presentation = holder.CreatePresentation(
disclosure => disclosure.ClaimName == "email");
HAIP-Oriented Verifiable Credentials
using SdJwt.Net.Vc.Issuer;
using SdJwt.Net.HAIP;
// High-assurance issuer policy check
var haipValidator = new HaipCryptoValidator(HaipLevel.Level3_Sovereign, logger);
var keyValidation = haipValidator.ValidateKeyCompliance(signingKey, "ES512");
if (keyValidation.IsCompliant)
{
var vcIssuer = new SdJwtVcIssuer(issuerKey, algorithm);
var credential = vcIssuer.Issue("https://gov.example/national-id", vcPayload, options);
}
Status Management
using SdJwt.Net.StatusList.Issuer;
// Create status list
var statusManager = new StatusListManager(statusKey, algorithm);
var statusValues = new byte[] { 0, 1, 2 }; // valid, invalid, suspended
var statusList = await statusManager.CreateStatusListTokenAsync(
statusListUrl, statusValues, bits: 2);
// Check credential status
var statusVerifier = new StatusListVerifier(httpClient);
var statusResult = await statusVerifier.CheckStatusAsync(statusClaim, keyResolver);
var isValid = statusResult.IsValid;
Preview Agent Trust
var minted = await adapter.MintForToolCallAsync(
toolName: "ledger",
arguments: new Dictionary<string, object> { ["action"] = "Read" },
context: new CapabilityContext
{
CorrelationId = Guid.NewGuid().ToString("N"),
WorkflowId = "wf-ledger-sync"
});
request.Headers.Authorization = $"SdJwt {minted.Token}";
Security, Platform, and Performance
- Security Model - Cryptographic controls, defensive verification, HAIP profile guidance, privacy, and deployment considerations
- Platform Support - Target frameworks, supported platforms, and BenchmarkDotNet performance harness
- Package Maturity - Stable, Spec-Tracking, Profile, Reference, and Preview classifications
Documentation
Getting Started
- Documentation Portal - Main entry point to all documentation
- 15-Minute Quickstart - Tutorial to get up and running quickly
- Ecosystem Architecture - Deep dive into system architecture
- Interactive Samples - Console tutorials and use cases
- Package Documentation - Core package API reference
Standards Implementation
- Verifiable Credentials - SD-JWT VC specification
- Status Lists - Credential lifecycle management
- OpenID4VCI - Credential issuance protocols
- OpenID4VP - Presentation protocols
- SIOPv2 - Subject-signed ID Tokens for combined OpenID4VP responses
- mdoc/mDL - ISO 18013-5 mobile documents
- W3C VCDM - Verifiable Credentials Data Model 2.0 data models
Advanced Features
- OpenID Federation - Trust chain management
- Presentation Exchange - Credential selection
- HAIP Profile Support - High-assurance validation helpers and profile-oriented checks
- Agent Trust Core - Capability token minting and verification
- Agent Trust Policy - Rule and delegation engine
- Agent Trust ASP.NET Core - Inbound token verification middleware
- Agent Trust MAF - Outbound token propagation for tool calls
- Agent Trust OpenTelemetry - Metrics and telemetry
- Agent Trust OPA - External policy engine via OPA
- Agent Trust MCP - MCP trust interceptor and guard
- Agent Trust A2A - Agent-to-agent delegation chains
- Agent Trust Guide - End-to-end integration walkthrough
- Agent Trust Concepts - Architecture and flow model
- Agent Trust Profile - Preview profile for capability tokens, policy, delegation, and audit
Enterprise Planning
- Enterprise Roadmap - Strategic roadmap with ISO mDL/mdoc, DC API, eIDAS 2.0
Installation
Core Package
dotnet add package SdJwt.Net
Install by Capability
# Core SD-JWT
dotnet add package SdJwt.Net
# Verifiable credentials
dotnet add package SdJwt.Net.Vc
dotnet add package SdJwt.Net.VcDm
dotnet add package SdJwt.Net.StatusList
# OpenID4VC protocols
dotnet add package SdJwt.Net.Oid4Vci
dotnet add package SdJwt.Net.Oid4Vp
dotnet add package SdJwt.Net.SiopV2
# Advanced features
dotnet add package SdJwt.Net.OidFederation
dotnet add package SdJwt.Net.PresentationExchange
dotnet add package SdJwt.Net.HAIP
# ISO credential formats
dotnet add package SdJwt.Net.Mdoc
# Preview: Agent Trust
dotnet add package SdJwt.Net.AgentTrust.Core
dotnet add package SdJwt.Net.AgentTrust.Policy
dotnet add package SdJwt.Net.AgentTrust.AspNetCore
dotnet add package SdJwt.Net.AgentTrust.Maf
dotnet add package SdJwt.Net.AgentTrust.OpenTelemetry
dotnet add package SdJwt.Net.AgentTrust.Policy.Opa
dotnet add package SdJwt.Net.AgentTrust.Mcp
dotnet add package SdJwt.Net.AgentTrust.A2A
# Wallet infrastructure
dotnet add package SdJwt.Net.Wallet
dotnet add package SdJwt.Net.Eudiw
Try the Examples
git clone https://github.com/openwallet-foundation-labs/sd-jwt-dotnet.git
cd sd-jwt-dotnet/samples/SdJwt.Net.Samples
dotnet run
Contributing
We welcome contributions! Please see the CONTRIBUTING.md file for detailed guidelines and instructions.
Community & Support
Getting Help
- Documentation: docs/ - Guides and API reference
- Discussions: GitHub Discussions for community questions
- Issues: GitHub Issues for bug reports
- Security: Report security issues to [email protected] or see SECURITY.md
Community
- Open Wallet Foundation: Part of the OpenWallet Foundation ecosystem
- Standards Alignment: Tracks and implements specifications from IETF OAuth WG, OpenID Foundation, DIF, W3C, ISO, and OWF ecosystems.
License
Licensed under the Apache License 2.0 - see the LICENSE file for details.
This permissive license allows commercial use, modification, distribution, and private use while providing license and copyright notice requirements.
Acknowledgments
This project builds on work from the identity standards community:
- IETF OAuth Working Group - SD-JWT and Status List specifications
- OpenID Foundation - OpenID4VCI, OpenID4VP, Federation, and HAIP standards
- DIF - Presentation Exchange specification
- W3C - Verifiable Credentials data model
- Open Wallet Foundation - Digital identity standards advancement
Special Thanks
- All specification editors and contributors
- Early adopters and feedback providers
- Security researchers and auditors
- The broader .NET and identity communities
Reviews (0)
Sign in to leave a review.
Leave a reviewNo results found