

We’re pleased to announce that our OAuth/OpenID backend service, Authlete 3.0, has earned OpenID Certification for its implementation of OpenID for Verifiable Credential Issuance (OpenID4VCI) 1.0 used with OpenID4VC High Assurance Interoperability Profile (HAIP) 1.0, confirming conformance to these specifications. Authlete supports both SD-JWT VC and mdoc/mDL formats.
OpenID4VCI is an open standard for issuing verifiable credentials into digital identity wallets. The specification has been adopted by more than 30 jurisdictions globally, including all European Union member states, the UK, Switzerland, India, and California. HAIP strengthens the security and interoperability of OpenID4VCI implementations for use cases that demand high levels of assurance.
As a longtime expert in OAuth and OpenID Connect (OIDC) implementation, we’ve helped shape the specifications and the conformance tests used to validate them. We provided testing infrastructure to support the development of the HAIP conformance test suite for OpenID4VCI, helping to ensure that other implementers can build to the standard correctly as well.
"This certification gives our customers assurance and confidence that verifiable credentials issued with Authlete 3.0 are interoperable and secure," said Takahiko Kawasaki, Co-Founder and Representative Director of Authlete. "We strive to enable our customers to correctly implement open standard specifications, and we're proud to have contributed to the development of the test suites. We'll continue to support new specifications in a timely manner as the ecosystem evolves."
A Verifiable Credential (VC) is issued by a Credential Issuer. VCs are tamper-evident digital credentials whose Issuer can be cryptographically verified. Compared to paper documents or physical cards, VCs offer stronger security, allow third-party verification of authenticity, and are highly portable. Additionally, VC Holders can selectively disclose only the information they choose to share. Since Holders do not need to carry physical credentials, VCs offer greater flexibility and convenience.
OpenID for Verifiable Credential Issuance (OpenID4VCI) is a standard specification for issuing Verifiable Credentials (VCs). By adopting this specification, organizations can issue VCs in various formats, such as SD-JWT VC and mdoc/mDL, while leveraging the security and flexibility of OAuth 2.0. The final version of OpenID4VCI 1.0 was officially approved in September 2025. For more details on this specification, please refer to our developer documentation.
The High Assurance Interoperability Profile (HAIP) is a specification that ensures interoperability among VC Issuers, Wallets, and Verifiers of credentials, particularly for use cases that demand high levels of security and privacy. This specification expects VCs in SD-JWT VC and mdoc formats to be used. Additionally, HAIP requires that implementations of the OpenID4VCI specification meet the key requirements defined by the FAPI 2.0 Security Profile.
VC use cases span a wide range from government-issued identity documents such as passports and driver's licenses to reusable Know Your Business (KYB)/Know Your Customer (KYC) credentials used by financial institutions for account opening, to diplomas issued by higher education institutions. By leveraging OpenID4VCI-compliant VCs, public sector, financial, and educational institutions can drive credential digitization, streamline credential issuance and management, and improve end-user convenience.
The European Union has adopted OpenID4VCI for the European Digital Identity Wallet (EUDI Wallet), slated for rollout by the end of 2026. The EUDI Wallet is not a single mobile application, but a framework under which EU member states will approve one or more compliant wallet apps. These wallets will enable EU citizens, residents, and businesses to verify their identity and share verifiable credentials both online and in person when accessing public and private services. The framework is designed to ensure interoperability across all member states, enabling secure, cross-border identity verification.
In Japan, Authlete's OpenID4VCI implementation was used in a pilot project conducted by DENTSU SOKEN INC. as part of Japan’s Trusted Web Use Case Demonstration Project. The project validated a new framework for promoting trust-based transactions based on KYB/KYC. The Japanese government has also been conducting use-case trials to help ensure interoperability of digital identity between Japan and other countries and regions. As part of this effort, it has also carried out a pilot project with the EU.
Service providers can use Authlete 3.0's APIs to quickly build OpenID4VCI- and HAIP-compliant VC issuance infrastructure. Settings such as credential offer duration and transaction duration can be configured through the management console. We’ve supported OpenID4VCI since 2023, starting with the first Implementer's Draft, and have been one of the earliest implementers. We’ve flexibly adapted to major changes as the specification was finalized, and we continue to support both the final and draft versions.

Try Authlete's HAIP-Compliant OpenID4VCI implementation with a free trial here.
For inquiries about our OpenID4VCI implementation, contact us here.
Authlete holds OpenID Certification for over 60 standard specifications. For the full list of certified and supported OAuth/OpenID specifications, see here.