OpenResidency Docs

Glossary

The terms you'll meet across OpenResidency — from DID and VC to subjectRef, pairwise sub, and RAL.

TermMeaning
VC — Verifiable CredentialA tamper-evident, cryptographically signed digital credential (W3C standard). Here, the state residency credential.
VP — Verifiable PresentationA holder-signed wrapper presenting one or more credentials to a specific verifier, with a nonce and audience.
VC-JWTThe compact JWT credential format — fits in a QR, verifies with one signature check. The offline path.
ldp_vcJSON-LD credential with a Data Integrity proof — the format wallets like Inji accept.
IssuerThe party that signs credentials — the State Residency Authority (a deployment).
HolderThe party that holds and presents the credential — the citizen's wallet.
SubjectThe party the credential is about — the citizen. Usually also the holder; holder binding forces them to coincide.
VerifierWhoever receives and checks a credential — a clinic, checkpoint, bank, or sector service.
OIDC Provider (OP / IdP)The identity provider that authenticates users and issues tokens — the residency platform.
Relying Party (RP)An OIDC client (a sector service) that trusts the provider for login.
OperatorGovernment staff who enrol citizens and issue/revoke credentials (roles: registrar, revoker, auditor, support, admin).
DeployerThe day-0 DevOps actor who provisions config, keys, and secrets and boots the platform.
DID — Decentralized IdentifierAn identifier that resolves to a subject's public keys without a central registry.
did:keyA DID whose public key is encoded into the identifier — offline, self-resolving, non-rotatable. Tests/demos.
did:webA domain-based DID resolved via /.well-known/did.json — rotatable. Production.
OpenID4VCIOpenID for Verifiable Credential Issuance — the protocol a wallet uses to pull a credential.
OpenID4VPOpenID for Verifiable Presentations — the protocol for presenting a credential (used in sign-in).
subjectRefA non-reversible HMAC of the national ID — the only linkage stored; the raw number never is.
Pairwise subject (sub)A different opaque user id per relying party (HMAC(pepper, clientId + residentId)), so services can't correlate a citizen.
Status listW3C Bitstring Status List — a cacheable bitstring for offline revocation checks.
Trust artifactIssuer-published data (keys + status list) a verifier caches to evaluate credentials offline.
Verifiable Data RegistryThe issuer-published trust anchor a verifier reads to evaluate a credential — here the DID document (keys) + Bitstring Status List (revocation) at /.well-known. The fourth element of the VC model, alongside issuer/holder/verifier.
RAL — Residence Assurance LevelRAL0–3, the strength of proof that a person resides in the claimed unit.
Applicant bindingProof that the applicant owns the identity they claimed (none, authoritative_authentication, face_match, attended_comparison).
Foundational sourceThe national/foundational ID system verified against (NIN/NIMC, Aadhaar, or a REST/XML/dataset adapter).
SIEIState Identity Enablement Infrastructure — the identity layer of the wider State DPI framework that OpenResidency implements.
DPG — Digital Public GoodOpen-source software meeting the DPGA standard; OpenResidency is Apache-2.0 and DPG-aligned.
RulePackA jurisdiction's versioned, effective-dated residency policy configuration.
Provisional credentialA credential issued offline pending reconciliation when connectivity returns.