Which digital credential standard, for which use? A Lens after Global Digital Collaboration 2026

I came back from Global Digital Collaboration 2026 with a question I had carried into Palexpo, and a paradox I had not expected to see so clearly. The question was who operates the trust behind a sovereign credential. The paradox is that the digital credential format that pioneered the field is not the one being deployed.

The pioneer that stayed in pilot

W3C verifiable credentials arrived with a strong promise: a credential the citizen holds, combining attributes from many issuers, presented selectively, verifiable without calling the issuer. The COVID years gave it a first real stage. The health passes of North America were built on it, and a wave of pilots followed, in education, in humanitarian aid, in trade.

Five years later, the national scale deployments are few. India is the exception that proves the rule, with a credential ecosystem where the format took root and where MOSIP’s Inji stack, which I analysed in July, gives any government an open source way to issue and verify verifiable credentials. Bhutan built its national digital identity on the same model. Beyond that, the conversations in Geneva kept returning to the same handful of examples, and to a European wallet that hedges its bets between the mdoc format and a JSON based credential rather than committing to the W3C data model.

The transport standard that keeps growing

The mobile driving licence, ISO/IEC 18013-5, tells the opposite story. It was written for a precise use: present a driving licence to a police officer or a shop, face to face, with the phone in hand, and later to a website through the remote verification add on. It is a standard of the transport sector, carried by driver licensing authorities rather than by identity agencies.

That narrowness is exactly why it spreads. In the United States about twenty states issue a mobile driving licence, more than a dozen are live in Apple Wallet and around ten in Google Wallet, and the platforms keep adding states. In Australia, the Northern Territory has just joined and Austroads is running the national trust service that lets a licence issued in one state be verified in another. The announcement in Geneva that the 18013 and 23220 series become free to download is the industry pushing the same door further open.

Neither is the answer for everything

It would be easy to conclude that the market has spoken. It has not. The two families answer different questions.

mDL is a document standard. It shines when one issuer, one credential and one verifier meet, in person or online, and when the verifier needs to trust the issuer’s signature and nothing more. It is close to the physical card it replaces, which is precisely what a licensing authority and a police force want.

Verifiable credentials are an ecosystem standard. They shine when a citizen needs to combine a diploma, a vaccination record, a social protection entitlement and a proof of identity, issued by four institutions, and present only what a service needs. That is the shape of most public service use cases in the countries I work in, where the identity credential is one building block among many.

So the choice depends on the sector, on the use case, and on the context: the density of relying parties, the connectivity, the capacity of the issuer to run a trust infrastructure over ten years.

Who operates the trust

This is where the discussion I had with Benoit Ravier, in the comments of my post on the Apple and Google wallets, belongs. He argued that sovereign credentials, national identity, driving licence, travel credential, must stay under sovereign control, and that outsourcing the wallet layer to device makers creates a dependency a state cannot afford. My answer was that credentials belong to people, who will choose by convenience as they did for payment, and that governments should do what they did for mobile telecommunications: impose global standards and interoperable implementations on the platforms rather than build a wallet per country.

We agree on more than it seems. Whatever the format, the trust framework, the list of who may issue and who may verify, stays with the public authority. The standard is the language; the trust framework is who is allowed to speak. That is the layer a government cannot delegate, and it is the same layer whether the credential travels as an mdoc or as a verifiable credential.

From a catalogue to a selection guide

What struck me in Geneva is that the ecosystem is very good at producing catalogues. Every standards body, every foundation, every consortium presents its list. What a ministry in Apia, Dakar or Port Moresby needs is different: a guide that starts from the use case, the sector and the country’s capacity, and ends with a recommended standard and the reasons for it.

I would like to see the World Bank, the ITU, the DPGA and the standards bodies themselves produce that guide together. In the meantime ID30 will publish a first selection grid, drawn from the programmes we advise, and open it for comment.

Background reading: Options for inclusive digital wallets, the ID30 vision written in 2023 when the GovStack wallet working group started, at the same time as the OpenWallet Foundation. Related: What counts is the credential, not the wallet and Reading Inji with a value proposition lens.

Want to comment, ask a question, or join the discussion? Continue the conversation on LinkedIn.

Read the latest news