Skip to main content
Knowledge mapCan every key in a DID document serve every purpose?Industry concepts and standards

You are here. See how this question connects to other ideas.

Select a node to open its page · Expand to read within the map

Knowledge mapFollow a connection. Understand a question.
← Identity and credentials

One question

Can every key in a DID document serve every purpose?

Separate a verification method from its permitted verification relationship.

DID Core distinguishes verification methods from relationships: authentication identifies authentication uses; assertionMethod identifies assertion uses. Merely finding a key in verificationMethod does not establish its suitability for the current verification.

For a credential, ask more than whether a signature matches a key: check the relationship required by the securing mechanism. Applications must still evaluate issuer trust and business eligibility.

Verification relationshipPurpose
authenticationAuthenticate the DID subject, such as a login challenge
assertionMethodVerify assertions by the subject, such as issuing a credential
keyAgreementEstablish keys for communication
capabilityInvocationInvoke a cryptographic capability, such as access to a protected API
capabilityDelegationDelegate a cryptographic capability

A DID document need not contain all five. They are purposes, not a hierarchy of permission levels. Multiple relationships can reference the same verification method; a verifier checks the relationship required for the operation.

Sources and further reading