The Credential Is the First Thing About Your Identity You Are Given Rather Than Registered In

Almost every page about this is written for the verifier

Which makes sense, because the verifier pays. So the arguments are about cost per check, integration effort and fraud rates, and the person the credential is about appears as a conversion funnel.

This page is about what the holder gets, because a system that gives them nothing does not get adopted, and adoption is what the verifier's saving depends on.

What a person actually holds today

Nothing. That is the honest baseline.

Your identity, as far as any institution is concerned, is a set of records about you held by them. You can sometimes request a copy. You cannot present it to anyone else in a form they would accept, because a copy of a bank's record is not evidence to another bank.

So the thing a person "has" is a series of relationships in which they are the subject rather than the holder. Every one of those relationships was established by proving the same facts, and none of them can be reused.

What changes when the credential is the artefact

It is issued to you and held by you. Not a copy of a record, but a signed statement you can present, that a verifier can check without contacting the issuer.

You choose what to reveal. A verifier asking whether you are over a threshold can be given that and nothing else, rather than the document that contains your address, your document number and your place of birth.

And the same statement works in more than one place. That is the property with actual value to the person: proving something once and presenting it repeatedly, rather than repeating the proof.

The honest limits on all three

The issuer still decides what it says. Holding a credential does not mean controlling its contents. If an issuer records something you disagree with, you hold a signed statement you disagree with.

And revocation is the issuer's lever, not yours. You can decline to present. You cannot make a credential say something else, and you cannot stop an issuer withdrawing it.

So "self-sovereign" oversells it. What you get is custody and disclosure control, which is a real improvement over having neither, and is not sovereignty.

What to ask any credential vendor

"What does the holder get that they did not have?" If the answer is only convenience for the business, adoption will be a marketing spend rather than a pull.

"Where else does this credential work?" For us today the honest answer is nowhere unaffiliated.

"What happens if the issuer disagrees with the holder?" Custody is not authorship, and a vendor implying otherwise is overselling the model.

"Can the holder present it without the issuer knowing?" Offline verification and issuer blindness are different properties, and both are worth asking about separately.

Where this leaves a decision

If you are counting on holders to adopt something because it is philosophically better, that has been tried for a decade and has not worked.

If your customers are people who repeatedly prove the same facts to different institutions, the credential is worth holding for a concrete reason, that is the adoption argument, and the limit is that it becomes worth holding at the second place that accepts it rather than the first.

Keep reading

The Credential Is the First Thing About Your Identity You Are Given Rather Than Registered In · Solidus