W3C VCDM 1.1 JWT with Bitstring Status List
Step 4 of 5 in Prove the credential status profiles.
Profile. A W3C VCDM 1.1 design with its context and types, bound to jwt_vc_json, and a Bitstring
Status List credential published as application/vc+jwt. The version, context and status
representation stay consistent from design through verification.
Setup. Create the design, choose the issuer DID, JWK or X.509 key, create the Bitstring list with
spec: bitstring_status_list, one bit per status and revocation purpose, and bind the returned list id.
Offer. The design example binds EmployeeCredentialV11 while the offer example selects Vcdm11Jwt;
they are distinct identities. The issuer must already advertise
credential_configurations_supported[Vcdm11Jwt] before the offer selects it through plural
credential_configuration_ids. The design POST alone does not create the issuer configuration.
Checks and status. The verifier checks the JWT signature, issuer trust attachment, VCDM 1.1 context and types, validity, DCQL result and the signed Bitstring list at the credential's URI and index. A revoked bit, wrong list specification, wrong index, missing trust attachment or a VCDM 1.1 and 2.0 mismatch is fail closed. A Bitstring result is only evidenced by a Bitstring list; a StatusList2021 example proves nothing here.
Full walkthrough: section "W3C VCDM 1.1 JWT + Bitstring Status List" of the profile walkthroughs.
Next
Continue with step 5, W3C VCDM 2.0 JWT with Bitstring Status List.