witnessed/1 draft

Predicate IRI, exact bytes: https://registry.trustoverip.org/dtg/vsc/witnessed/1

Machine-readable: predicate.jsonld, also served at this URL with Accept: application/ld+json. Definition format: predicate.schema.json.

Definition

Label
enwitnessed
debezeugt
nlgetuige geweest van
Meaning
enThe issuer attests that it observed the subject issue the credential the object names, under the conditions of a specific trust task exchange.
Classificationevidence; weighed by: The community whose witnessing policy the attestation is issued under.
ObjectdigestMultibase
Subject–object relationshipcredentialSubject.id MUST be the DID of the issuer of the credential object.digestMultibase names, and a verifier holding that credential MUST check that it is. This binds each statement to one direction of the edge it attests.
Additional members
taskContextREQUIRED, with taskDigestMultibase
Minimum issuer scopedirected
IssuerA member, or a VTA acting according to VTC policy.
Verification establishesThat the issuer attests that, in the exchange identified by taskContext, it observed the subject issue the credential whose claims digest to object.digestMultibase.
Verification does not establish
  • that the referenced credential is currently valid or unrevoked; the digest is computed over its claims and excludes both its proof and its status, so the attestation is a statement about those claims at the moment of witnessing
  • that the referenced credential's claims are true
  • that the exchange reached its terminal state, which requires the outcome evidence of the specification's Outcome Interpretability rules
  • that the witness is a member of any community
  • that any consequential action is authorized
Defined inhttps://trustoverip.github.io/dtgwg-cred-spec/#the-dtg%3Awitnessed-profile-(vwc)
Governed bythe working group that maintains this registry

The type-level bound of the specification's What Verification Establishes applies in full: a statement attests; it never confers representation, authority, membership, admission, governed status or task completion.

Profile

A statement under this predicate is a verifiable witness credential (VWC). The predicate is one of the two core profiles the DTG Credentials Core Specification defines; its normative text is the section this definition links under Defined in, and this entry records it in the registry's format so that verifiers can configure against it. Nothing on the wire changes when the profile text moves here.

What is witnessed

The witness may be a person or a VTA applying the witnessing policies of a VTC: verifying that both parties were present at the same event, say, or that each provided proof of biometric liveness at the time a relationship was formed. Because the meaning of the attestation depends on the conditions under which the witnessing occurred, a statement under this predicate is bound to the trust task exchange in which it was issued: taskContext and taskDigestMultibase are required.

One statement per direction

A witnessed exchange of a complete DTG edge is bidirectional: two edge credentials, one in each direction, are formed in one witnessing event, whether two VRCs for a peer-to-peer edge or the two VMCs of a membership edge. For such exchanges the witness should issue one statement per direction. That is what the subject–object relationship makes checkable: the subject is the issuer of the referenced credential, so each statement names one direction of the edge and a verifier holding that credential can confirm it.

The rule is unconditional, and deliberately so. A verifier holding a witness statement and the credential it names cannot tell whether that credential was one half of a reciprocal pair, so a rule that depended on it could not be checked, and two conformant statements naming the same credential could name different parties. Unconditional binding covers the cases that came up in review without a second rule: on a membership edge the member is named by the statement for the member-issued VMC, and if only the grant was witnessed then naming the community is correct, because the member's participation was not observed; a VDC is likewise a grant and an acceptance, so the delegate is named by the statement for the acceptance.

What the digest binds

credentialSubject.id and taskContext alone identify the observed party and the exchange, not the edge. Binding a statement to a specific edge therefore requires object.digestMultibase: a verifier holding the referenced credential recovers both endpoints of the edge from its issuer and credentialSubject.id and confirms the exact credential the witness attested to. The binding is only as strong as the verifier's access to that credential; a digest without the credential to hand is an opaque hash, not an identified edge. Issuers and holders presenting a witness statement as evidence of a specific edge should make the referenced credential available alongside it. The digest is computed as the specification's Digest Encoding section defines, over the referenced credential excluding its top-level proof.

What this predicate is not

A statement that a party presented, held or received a credential, where the observed party is the referenced credential's subject and its issuer may have been absent, is a different statement with the observed party as its subject. It is a different predicate, defined in this registry rather than expressed by stretching this one.

Notes for implementers

Examples

examples/witnessed-vrc.json

{
  "@context": [
    "https://www.w3.org/ns/credentials/v2",
    "https://registry.trustoverip.org/dtg/context/v1"
  ],
  "type": [
    "VerifiableCredential",
    "DTGCredential",
    "StatementCredential"
  ],
  "issuer": "did:webvh:QmVzTd9hRkPqLu4WgXyN3c8pT2rJ6mK9sB1dF4gH7jL0n:witness-service.example",
  "validFrom": "2026-01-06T10:00:00Z",
  "taskContext": "urn:uuid:2c7f5d19-6e0b-4c3d-8a41-9b2e6f0d4c88",
  "taskDigestMultibase": "zQmWhCFfStzUE4HGseiQ1XWi2eEp1GTQEKnt2jyBe7uqzXD",
  "credentialSubject": {
    "id": "did:key:z6MkpTHR8VNsBxYAAWHut2Geadd9jSwuBV8xRoAnwWsdvktH",
    "predicate": "https://registry.trustoverip.org/dtg/vsc/witnessed/1",
    "object": {
      "digestMultibase": "zQmdfTbBqBPQ7VNxZEYEj14VmRuZBkqFbiwReogJgS1zR1n"
    },
    "witnessContext": {
      "event": "EthDenver 2026",
      "sessionId": "session-abc-123",
      "method": "in-person-proximity"
    }
  },
  "proof": {
    "type": "DataIntegrityProof",
    "cryptosuite": "eddsa-jcs-2022",
    "created": "2026-01-06T10:00:00Z",
    "proofPurpose": "assertionMethod",
    "verificationMethod": "did:webvh:QmVzTd9hRkPqLu4WgXyN3c8pT2rJ6mK9sB1dF4gH7jL0n:witness-service.example#key-1",
    "proofValue": "z3FXQjecWJKT…illustrative…"
  }
}

Last changed 2026-09-25.