did:scid

Identity Protocol

A DID method specification developed by the Trust over IP (ToIP) DID SCID Task Force that enables any Self-Certifying Identifier (SCID) format — including KERI AIDs, did:peer, did:key, and did:plc formats — to be expressed as a W3C-conformant DID. The method is designed to address portability and third-party independence: a SCID binds cryptographically to its controlling keys, requires no registry for verification, and can be stored locally or multi-anchored across locations. Supports both "pure" peer-to-peer SCIDs and web-hosted SCIDs with optional location parameters.

Community

Details

License Open specification (ToIP Confluence wiki; no reference implementation repository separately identified)
Dev Status 🔨 WIP
Dev Status Detail WIP (specification under active development by ToIP DID SCID Task Force; not yet at Final status)
Owner Trust over IP (ToIP) Foundation — DID SCID Task Force; hosted under Linux Foundation; specification available on ToIP Confluence wiki
Country International (ToIP Foundation is Linux Foundation project; global contributor base)
Start Year 2024
Stack Language-agnostic specification; compatible with any SCID format (KERI, did:peer, did:key, did:plc); verification requires only access to DID document and key event history
Funding Foundation (Linux Foundation / Trust over IP Foundation; member-funded)
Last Investigated Jul 1, 2026

Use Case Domains

Identity Protocol Attributes

Origins Self-sovereign identity / DID ecosystem (motivated by need to unify the many SCID formats — KERI AIDs, did:peer, did:key, did:plc — under a single W3C DID method that preserves their shared property: cryptographic binding to keys without registry dependency)
Database N/A (verification requires no database; DID document and key event history carry all necessary information; multi-anchoring to multiple locations optional)
Query Language DID URL resolution (standard W3C DID resolution; location-parameterized variants resolve via HTTPS; pure peer-to-peer variants resolved from local storage)
Data Formats W3C DID Document (JSON-LD); SCID verification metadata (format depends on SCID type: KERI OOBI data, did:peer microledger, etc.)
Mobile Support Library-level (any DID resolver implementation; no dedicated mobile app)
Web Support Yes (web-hosted SCIDs use HTTPS for DID document hosting; pure SCIDs are location-independent)
Native Apps Library-level (embedded in DID resolver implementations; no standalone native app)
Terms Free / Open standard (ToIP specification; no licensing fees)
Funds Unknown (ToIP Foundation member contributions; specific task force budget not disclosed)
Based On W3C DID Core specification; KERI (for KERI-based SCID variants); did:peer, did:key, did:plc (other supported SCID formats); ToIP High Assurance VIDs Specification
Permissions Cryptographic Capabilities (key control determines all permissions; no ACL; delegation via key event history entries)
Authentication & Identity Self-Certifying Identifier (SCID) — identity derived from cryptographic key operations; no third party required for verification; portable across locations via multi-anchoring
Storage Model Local or distributed (pure SCIDs store verification metadata locally per peer; web-hosted SCIDs use HTTPS; multi-anchoring across multiple locations for resilience)
Interoperability W3C DID ecosystem (compatible with any W3C DID consumer); KERI (AIDs expressible as did:scid); did:peer, did:key, did:plc (all expressible as did:scid); ToIP ecosystem
Data Portability Full portability (SCID is not bound to any location or provider; verification metadata portable; key rotation and revocation tracked in key event history)
Governance & Decision Making Foundation-governed (ToIP DID SCID Task Force under Linux Foundation governance; specification evolution via ToIP working group process)
Protocol Maturity / Standardization WIP (ToIP DID SCID Task Force specification; under active development; not yet submitted to W3C DID Methods Registry or other formal body)
Identity Standards W3C DID Core (Decentralized Identifiers 1.0); KERI (Key Event Receipt Infrastructure) for KERI-based variants; ToIP High Assurance VIDs
DID Methods Supported did:scid (defines this method); interoperates with did:peer, did:key, did:plc, KERI AIDs (all expressible as did:scid variants)
Key Management User-controlled (SCID cryptographically bound to controlling keys; key rotation tracked in key event history; pre-rotation supported via KERI-style commitments)
Credential Types N/A (DID method specification; does not define credential types; compatible with W3C VCs issued against did:scid identifiers)
Verification Method Cryptographic signature verification (SCID binding verified against key event history; no external registry or blockchain required; pure function on DID document + key history)
Privacy Features Unlinkability (pairwise DIDs possible; pure peer-to-peer SCID not published to any registry); minimal disclosure (verification metadata portable without revealing usage context)
Authentication Methods Cryptographic signatures (DID-based key control; challenge-response via standard DID authentication flows)
Revocation Mechanism Key event history (key rotation and revocation tracked in cryptographically chained key event log; KERI-style pre-rotation for forward secrecy)
Agent Types Supported Humans (individuals), Organizations, Devices/IoT, Services/APIs, Autonomous agents — any entity that can control cryptographic keys
Wallet/Client Types SDK/Library integration (any DID resolver library); compatible with KERI wallets and standard W3C DID wallets
Recovery Mechanisms Pre-rotation / Key event history (recovery keys committed in advance via KERI-style pre-rotation; M-of-N multisignature revocation possible with KERI variants)
Compliance / Regulations Unknown (specification does not address specific regulatory compliance; compatible with eIDAS and GDPR-aligned DID implementations)
Credential Exchange Protocols Compatible with DIDComm, OIDC4VC, and any protocol supporting W3C DID resolution
Trust Framework Cryptographic verification only (no external trust anchor required; trust established through cryptographic proof of key control; optional multi-anchoring for additional resilience)
Cost Model Free (no blockchain fees; no registry fees; pure cryptographic verification)
Censorship Resistance Fully censorship-resistant (pure SCIDs require no external service; multi-anchoring to diverse locations increases resilience; no central authority controls identifier validity)