W3C VCDM 2.0 JWT with Bitstring Status List
Step 5 of 5 in Prove the credential status profiles.
Profile. A W3C VCDM 2.0 design with the VCDM 2.0 context and types, bound to jwt_vc_json-ld, and
a Bitstring Status List credential published as application/vc+jwt. It shares the status mechanism
with VCDM 1.1 but not the credential model or the securing-format identifier.
Setup. Create the VCDM 2.0 design, choose signing material and trust policy, create the one-bit Bitstring list and keep its id and public URI.
Offer. The design example binds EmployeeCredentialV20 while the offer example selects
Vcdm20JwtLd. The issuer must advertise credential_configurations_supported[Vcdm20JwtLd] first; do
not reuse the VCDM 1.1 configuration or context.
Checks and status. During OID4VP the verifier evaluates the requested claims, JWT signature, VCDM 2.0 context and types, issuer trust, validity and current Bitstring status, and never downgrades to the VCDM 1.1 interpretation. Reject a revoked or undecodable entry, an invalid proof, a mismatched context, a missing trust attachment or an unavailable status URI.
Full walkthrough: section "W3C VCDM 2.0 JWT-JSON-LD + Bitstring Status List" of the profile walkthroughs.
Next
This completes the journey. Continue with Configure mdoc VICAL and CWT status.