Glossary
The terms you'll meet across OpenResidency — from DID and VC to subjectRef, pairwise sub, and RAL.
| Term | Meaning |
|---|---|
| VC — Verifiable Credential | A tamper-evident, cryptographically signed digital credential (W3C standard). Here, the state residency credential. |
| VP — Verifiable Presentation | A holder-signed wrapper presenting one or more credentials to a specific verifier, with a nonce and audience. |
| VC-JWT | The compact JWT credential format — fits in a QR, verifies with one signature check. The offline path. |
ldp_vc | JSON-LD credential with a Data Integrity proof — the format wallets like Inji accept. |
| Issuer | The party that signs credentials — the State Residency Authority (a deployment). |
| Holder | The party that holds and presents the credential — the citizen's wallet. |
| Subject | The party the credential is about — the citizen. Usually also the holder; holder binding forces them to coincide. |
| Verifier | Whoever receives and checks a credential — a clinic, checkpoint, bank, or sector service. |
| OIDC Provider (OP / IdP) | The identity provider that authenticates users and issues tokens — the residency platform. |
| Relying Party (RP) | An OIDC client (a sector service) that trusts the provider for login. |
| Operator | Government staff who enrol citizens and issue/revoke credentials (roles: registrar, revoker, auditor, support, admin). |
| Deployer | The day-0 DevOps actor who provisions config, keys, and secrets and boots the platform. |
| DID — Decentralized Identifier | An identifier that resolves to a subject's public keys without a central registry. |
did:key | A DID whose public key is encoded into the identifier — offline, self-resolving, non-rotatable. Tests/demos. |
did:web | A domain-based DID resolved via /.well-known/did.json — rotatable. Production. |
| OpenID4VCI | OpenID for Verifiable Credential Issuance — the protocol a wallet uses to pull a credential. |
| OpenID4VP | OpenID for Verifiable Presentations — the protocol for presenting a credential (used in sign-in). |
subjectRef | A non-reversible HMAC of the national ID — the only linkage stored; the raw number never is. |
Pairwise subject (sub) | A different opaque user id per relying party (HMAC(pepper, clientId + residentId)), so services can't correlate a citizen. |
| Status list | W3C Bitstring Status List — a cacheable bitstring for offline revocation checks. |
| Trust artifact | Issuer-published data (keys + status list) a verifier caches to evaluate credentials offline. |
| Verifiable Data Registry | The issuer-published trust anchor a verifier reads to evaluate a credential — here the DID document (keys) + Bitstring Status List (revocation) at /.well-known. The fourth element of the VC model, alongside issuer/holder/verifier. |
| RAL — Residence Assurance Level | RAL0–3, the strength of proof that a person resides in the claimed unit. |
| Applicant binding | Proof that the applicant owns the identity they claimed (none, authoritative_authentication, face_match, attended_comparison). |
| Foundational source | The national/foundational ID system verified against (NIN/NIMC, Aadhaar, or a REST/XML/dataset adapter). |
| SIEI | State Identity Enablement Infrastructure — the identity layer of the wider State DPI framework that OpenResidency implements. |
| DPG — Digital Public Good | Open-source software meeting the DPGA standard; OpenResidency is Apache-2.0 and DPG-aligned. |
| RulePack | A jurisdiction's versioned, effective-dated residency policy configuration. |
| Provisional credential | A credential issued offline pending reconciliation when connectivity returns. |