You are here. See how this question connects to other ideas.
Select a node to open its page · Expand to read within the map
One question
Can every key in a DID document serve every purpose?
Separate a verification method from its permitted verification relationship.
DID Core distinguishes verification methods from relationships: authentication identifies authentication uses; assertionMethod identifies assertion uses. Merely finding a key in verificationMethod does not establish its suitability for the current verification.
For a credential, ask more than whether a signature matches a key: check the relationship required by the securing mechanism. Applications must still evaluate issuer trust and business eligibility.
| Verification relationship | Purpose |
|---|---|
| authentication | Authenticate the DID subject, such as a login challenge |
| assertionMethod | Verify assertions by the subject, such as issuing a credential |
| keyAgreement | Establish keys for communication |
| capabilityInvocation | Invoke a cryptographic capability, such as access to a protected API |
| capabilityDelegation | Delegate a cryptographic capability |
A DID document need not contain all five. They are purposes, not a hierarchy of permission levels. Multiple relationships can reference the same verification method; a verifier checks the relationship required for the operation.
Sources and further reading
Check your understanding
Does discovering a public key authorize every signing purpose?
No. Check the verification relationship and protocol requirements.