Skip to content

Identity and Reputation Source Pack

Source pack version 0.1 — verified 2 August 2026
This source pack records what each source supports and what it does not establish. Availability of a URL is not proof that a product claim is accurate or legally compliant.

  • Normative baseline — mature standard suitable as a current implementation baseline.
  • Implementation reference — useful architecture or protocol reference, but not mandatory across ANUKA.
  • Conceptual reference — informs design without being adopted wholesale.
  • Legal watch — official source requiring current qualified legal review before implementation.
  • Tracking — emerging work not yet selected as a stable baseline.

NIST SP 800-63-4 — Digital Identity Guidelines

Section titled “NIST SP 800-63-4 — Digital Identity Guidelines”
  • Publisher: U.S. National Institute of Standards and Technology
  • URL: csrc.nist.gov/pubs/sp/800/63/4/final
  • Published: July 2025
  • State: Normative security and assurance reference
  • Used for: Risk-based identity proofing, authentication, federation, privacy, customer experience, and assurance concepts.
  • ANUKA boundary: The guideline is written for U.S. government digital identity systems and does not automatically require ANUKA to use federal assurance levels for every community interaction.
  • Checked: 2 August 2026

NIST SP 800-63A-4 — Identity Proofing and Enrollment

Section titled “NIST SP 800-63A-4 — Identity Proofing and Enrollment”
  • Publisher: NIST
  • URL: csrc.nist.gov/pubs/sp/800/63/A/4/final
  • Published: July 2025
  • State: Normative proofing reference
  • Used for: Separating identity proofing from authentication and selecting proofing appropriate to risk.
  • Checked: 2 August 2026

NIST SP 800-63B-4 — Authentication and Authenticator Management

Section titled “NIST SP 800-63B-4 — Authentication and Authenticator Management”
  • Publisher: NIST
  • URL: csrc.nist.gov/pubs/sp/800/63/B/4/final
  • Published: July 2025
  • State: Normative authentication reference
  • Used for: Authenticator lifecycle, phishing resistance, recovery, session security, and risk-based authentication.
  • Checked: 2 August 2026

NIST SP 800-63C-4 — Federation and Assertions

Section titled “NIST SP 800-63C-4 — Federation and Assertions”
  • Publisher: NIST
  • URL: csrc.nist.gov/pubs/sp/800/63/C/4/final
  • Published: July 2025
  • State: Normative federation reference
  • Used for: Federation relationships, assertions, relying parties, and identity-provider boundaries.
  • Checked: 2 August 2026
  • Publisher: W3C
  • URL: w3.org/TR/did-core
  • Status: W3C Recommendation, 19 July 2022
  • State: Normative identifier baseline candidate
  • Used for: Portable identifiers, DID documents, verification methods, and service endpoints.
  • Important limitation: Each DID method has its own security, privacy, governance, persistence, and cost characteristics.
  • Checked: 2 August 2026
  • Publisher: W3C
  • URL: w3.org/TR/controller-document
  • Status: W3C Recommendation, 15 May 2025
  • State: Normative identifier-control reference
  • Used for: Controller documents, verification methods, cryptographic material, and service endpoints beyond DID-only contexts.
  • Checked: 2 August 2026
  • Publisher: OpenID Foundation
  • URL: openid.net/specs/openid-federation-1_0-final.html
  • Status: OpenID Final Specification, approved 17 February 2026
  • State: Implementation reference
  • Used for: Federated trust chains, entity statements, metadata, and network-of-networks interoperability.
  • ANUKA boundary: Adoption is not required for the MVP; the trust registry must remain replaceable.
  • Checked: 2 August 2026
  • Publisher: OpenID Foundation
  • URL: openid.net/specs/authorization-api-1_0.html
  • Status: OpenID Final Specification, approved 12 January 2026
  • State: Implementation reference
  • Used for: Separating policy decision points from policy enforcement points through an interoperable authorization API.
  • Checked: 2 August 2026

W3C Verifiable Credentials Data Model v2.0

Section titled “W3C Verifiable Credentials Data Model v2.0”
  • Publisher: W3C
  • URL: w3.org/TR/vc-data-model-2.0
  • Status: W3C Recommendation, 15 May 2025
  • State: Normative credential baseline
  • Used for: Issuer, holder, verifier, subject, credential, presentation, validity, status, and privacy concepts.
  • Critical limitation: Verification of cryptographic properties does not by itself establish truth, issuer competence, or suitability for a relying party’s decision.
  • Checked: 2 August 2026

W3C Verifiable Credential Data Integrity 1.0

Section titled “W3C Verifiable Credential Data Integrity 1.0”
  • Publisher: W3C
  • URL: w3.org/TR/vc-data-integrity
  • Status: W3C Recommendation, 15 May 2025
  • State: Normative proof reference
  • Used for: Authenticity and integrity proofs, proof sets, proof chains, verification methods, and privacy considerations.
  • Tracking note: Data Integrity 1.1 became a First Public Working Draft on 16 April 2026; v1.0 remains the selected baseline.
  • Checked: 2 August 2026
  • Publisher: W3C
  • URL: w3.org/TR/vc-bitstring-status-list
  • Status: W3C Recommendation, 15 May 2025
  • State: Normative credential-status reference
  • Used for: Privacy-preserving and space-efficient suspension, revocation, refresh, and status information.
  • Checked: 2 August 2026

OpenID for Verifiable Credential Issuance 1.0

Section titled “OpenID for Verifiable Credential Issuance 1.0”
  • Publisher: OpenID Foundation
  • URL: openid.net/specs/openid-4-verifiable-presentations-1_0-final.html
  • Status: OpenID Final Specification, approved 10 July 2025
  • State: Normative presentation protocol candidate
  • Used for: Requesting and delivering presentations of credentials in same-device and cross-device flows.
  • Checked: 2 August 2026

OpenID4VC High Assurance Interoperability Profile 1.0

Section titled “OpenID4VC High Assurance Interoperability Profile 1.0”
  • Publisher: OpenID Foundation
  • URL: openid.net/specs/openid4vc-high-assurance-interoperability-profile-1_0-final.html
  • Status: OpenID Final Specification, approved 29 December 2025
  • State: High-assurance implementation reference
  • Used for: A constrained interoperability profile for credential issuance and presentation where stronger security and privacy are required.
  • ANUKA boundary: Not required for low-risk community participation.
  • Checked: 2 August 2026
  • Publisher: 1EdTech Consortium
  • URL: 1edtech.org/standards/open-badges
  • State: Normative achievement-credential reference
  • Used for: Portable credentials describing achievements, criteria, evidence, issuers, earners, skills, and endorsements.
  • Current architecture: Open Badges 3.0 credentials are designed as W3C-compatible Verifiable Credentials.
  • ANUKA use: Capability and meaningful achievement credentials, not decorative activity badges.
  • Checked: 2 August 2026

Ethereum Attestation Service — Attestations

Section titled “Ethereum Attestation Service — Attestations”
  • Publisher: Ethereum Attestation Service
  • URL: docs.attest.org/docs/core—concepts/attestations
  • State: Implementation reference
  • Used for: Structured onchain and offchain attestations, attester, recipient, references, expiry, revocation, and schemas.
  • Critical limitation: The protocol can establish who attested and whether the record changed; credibility still depends on the attester and evidence.
  • Checked: 2 August 2026
  • Publisher: Ethereum Attestation Service
  • URL: docs.attest.org/docs/quick—start/faqs
  • State: Implementation reference
  • Used for: EAS positioning as open-source, permissionless, tokenless, and supporting onchain and offchain attestations.
  • Checked: 2 August 2026
  • Publisher: NIST
  • URL: nist.gov/itl/ai-risk-management-framework
  • State: Normative risk-management reference
  • Used for: Govern, Map, Measure, and Manage functions and trustworthy-AI risk practices.
  • Current-status note: NIST has indicated that AI RMF 1.0 is being revised; the baseline must be rechecked before ratification.
  • Checked: 2 August 2026
  • Publisher: U.S. Consumer Financial Protection Bureau
  • URL: consumerfinance.gov Circular 2024-06
  • State: Legal watch
  • Used for: The official view that third-party background dossiers and algorithmic worker scores used for employment decisions are often governed by the Fair Credit Reporting Act.
  • ANUKA implication: A participant reputation service cannot avoid FCRA analysis merely by calling itself a passport, marketplace, or network.
  • Checked: 2 August 2026

FTC — Employment Background Screening Companies and the FCRA

Section titled “FTC — Employment Background Screening Companies and the FCRA”
  • Publisher: U.S. Federal Trade Commission
  • URL: ftc.gov employment screening FCRA guidance
  • State: Legal watch
  • Used for: Consumer reporting agency status, permissible-purpose concepts, and accuracy duties for employment reports.
  • Critical point: The FTC states that merely saying a service is not a consumer reporting agency is not determinative.
  • Checked: 2 August 2026

FTC/EEOC — Background Checks: What Employers Need to Know

Section titled “FTC/EEOC — Background Checks: What Employers Need to Know”
  • Publishers: FTC and U.S. Equal Employment Opportunity Commission
  • URL: ftc.gov background checks employer guide
  • State: Legal watch
  • Used for: Authorization, disclosure, adverse-action, anti-discrimination, and state/local-law cautions.
  • Checked: 2 August 2026
  • Publisher: FTC statutory resource
  • URL: ftc.gov Fair Credit Reporting Act
  • Current source note: FTC page lists a revised March 2026 Act PDF.
  • State: Legal watch
  • Used for: Primary statutory framework governing consumer reports and consumer reporting agencies.
  • Checked: 2 August 2026

EEOC — Prohibited Employment Policies and Practices

Section titled “EEOC — Prohibited Employment Policies and Practices”
  • Publisher: U.S. Equal Employment Opportunity Commission
  • URL: eeoc.gov/prohibited-employment-policiespractices
  • State: Legal watch
  • Used for: Disparate treatment, disparate impact, job-relatedness, and protected-class constraints in employment decisions.
  • Checked: 2 August 2026

EEOC and DOJ — AI and Disability Discrimination

Section titled “EEOC and DOJ — AI and Disability Discrimination”
  • Publisher: U.S. Equal Employment Opportunity Commission
  • URL: eeoc.gov AI and disability discrimination
  • State: Legal watch
  • Used for: Risks that automated applicant or worker assessment can screen out people with disabilities and the need for accommodation processes.
  • Checked: 2 August 2026
  1. Identity proofing, authentication, authority, and reputation remain separate.
  2. W3C VC v2.0 is the selected portable-credential data-model baseline.
  3. OpenID4VCI and OpenID4VP are preferred interoperability protocols for compatible wallet flows.
  4. EAS is an optional attestation implementation, not the source of truth for business claims.
  5. Open Badges should be reused for meaningful capability and achievement credentials where its model fits.
  6. No universal person score may be derived from these standards.
  7. Employment-screening or worker-scoring products require a separate legal and compliance architecture.
  8. Emerging drafts are tracked but do not replace stable baselines automatically.

Before each release:

  1. open every cited source;
  2. confirm status, date, and publisher;
  3. confirm the source supports the exact claim;
  4. identify errata and newer stable versions;
  5. record implementation profile and cryptosuite choices;
  6. review privacy and unlinkability risks;
  7. review employment or eligibility use with qualified counsel;
  8. update superseded links and version statements.

Registry maintenance

  • Last manual validation: 2 August 2026
  • Next review: Before Identity Protocol v0.9 or within 90 days
  • Maintainer status: Founding draft