Identity and Reputation Source Pack
Source pack version 0.1 — verified 2 August 2026
This source pack records what each source supports and what it does not establish. Availability of a URL is not proof that a product claim is accurate or legally compliant.
Status labels
Section titled “Status labels”- Normative baseline — mature standard suitable as a current implementation baseline.
- Implementation reference — useful architecture or protocol reference, but not mandatory across ANUKA.
- Conceptual reference — informs design without being adopted wholesale.
- Legal watch — official source requiring current qualified legal review before implementation.
- Tracking — emerging work not yet selected as a stable baseline.
Digital identity
Section titled “Digital identity”NIST SP 800-63-4 — Digital Identity Guidelines
Section titled “NIST SP 800-63-4 — Digital Identity Guidelines”- Publisher: U.S. National Institute of Standards and Technology
- URL: csrc.nist.gov/pubs/sp/800/63/4/final
- Published: July 2025
- State: Normative security and assurance reference
- Used for: Risk-based identity proofing, authentication, federation, privacy, customer experience, and assurance concepts.
- ANUKA boundary: The guideline is written for U.S. government digital identity systems and does not automatically require ANUKA to use federal assurance levels for every community interaction.
- Checked: 2 August 2026
NIST SP 800-63A-4 — Identity Proofing and Enrollment
Section titled “NIST SP 800-63A-4 — Identity Proofing and Enrollment”- Publisher: NIST
- URL: csrc.nist.gov/pubs/sp/800/63/A/4/final
- Published: July 2025
- State: Normative proofing reference
- Used for: Separating identity proofing from authentication and selecting proofing appropriate to risk.
- Checked: 2 August 2026
NIST SP 800-63B-4 — Authentication and Authenticator Management
Section titled “NIST SP 800-63B-4 — Authentication and Authenticator Management”- Publisher: NIST
- URL: csrc.nist.gov/pubs/sp/800/63/B/4/final
- Published: July 2025
- State: Normative authentication reference
- Used for: Authenticator lifecycle, phishing resistance, recovery, session security, and risk-based authentication.
- Checked: 2 August 2026
NIST SP 800-63C-4 — Federation and Assertions
Section titled “NIST SP 800-63C-4 — Federation and Assertions”- Publisher: NIST
- URL: csrc.nist.gov/pubs/sp/800/63/C/4/final
- Published: July 2025
- State: Normative federation reference
- Used for: Federation relationships, assertions, relying parties, and identity-provider boundaries.
- Checked: 2 August 2026
Identifiers and controller documents
Section titled “Identifiers and controller documents”W3C Decentralized Identifiers v1.0
Section titled “W3C Decentralized Identifiers v1.0”- Publisher: W3C
- URL: w3.org/TR/did-core
- Status: W3C Recommendation, 19 July 2022
- State: Normative identifier baseline candidate
- Used for: Portable identifiers, DID documents, verification methods, and service endpoints.
- Important limitation: Each DID method has its own security, privacy, governance, persistence, and cost characteristics.
- Checked: 2 August 2026
W3C Controlled Identifiers v1.0
Section titled “W3C Controlled Identifiers v1.0”- Publisher: W3C
- URL: w3.org/TR/controller-document
- Status: W3C Recommendation, 15 May 2025
- State: Normative identifier-control reference
- Used for: Controller documents, verification methods, cryptographic material, and service endpoints beyond DID-only contexts.
- Checked: 2 August 2026
OpenID Federation 1.0
Section titled “OpenID Federation 1.0”- Publisher: OpenID Foundation
- URL: openid.net/specs/openid-federation-1_0-final.html
- Status: OpenID Final Specification, approved 17 February 2026
- State: Implementation reference
- Used for: Federated trust chains, entity statements, metadata, and network-of-networks interoperability.
- ANUKA boundary: Adoption is not required for the MVP; the trust registry must remain replaceable.
- Checked: 2 August 2026
OpenID AuthZEN Authorization API 1.0
Section titled “OpenID AuthZEN Authorization API 1.0”- Publisher: OpenID Foundation
- URL: openid.net/specs/authorization-api-1_0.html
- Status: OpenID Final Specification, approved 12 January 2026
- State: Implementation reference
- Used for: Separating policy decision points from policy enforcement points through an interoperable authorization API.
- Checked: 2 August 2026
Verifiable credentials and presentations
Section titled “Verifiable credentials and presentations”W3C Verifiable Credentials Data Model v2.0
Section titled “W3C Verifiable Credentials Data Model v2.0”- Publisher: W3C
- URL: w3.org/TR/vc-data-model-2.0
- Status: W3C Recommendation, 15 May 2025
- State: Normative credential baseline
- Used for: Issuer, holder, verifier, subject, credential, presentation, validity, status, and privacy concepts.
- Critical limitation: Verification of cryptographic properties does not by itself establish truth, issuer competence, or suitability for a relying party’s decision.
- Checked: 2 August 2026
W3C Verifiable Credential Data Integrity 1.0
Section titled “W3C Verifiable Credential Data Integrity 1.0”- Publisher: W3C
- URL: w3.org/TR/vc-data-integrity
- Status: W3C Recommendation, 15 May 2025
- State: Normative proof reference
- Used for: Authenticity and integrity proofs, proof sets, proof chains, verification methods, and privacy considerations.
- Tracking note: Data Integrity 1.1 became a First Public Working Draft on 16 April 2026; v1.0 remains the selected baseline.
- Checked: 2 August 2026
W3C Bitstring Status List v1.0
Section titled “W3C Bitstring Status List v1.0”- Publisher: W3C
- URL: w3.org/TR/vc-bitstring-status-list
- Status: W3C Recommendation, 15 May 2025
- State: Normative credential-status reference
- Used for: Privacy-preserving and space-efficient suspension, revocation, refresh, and status information.
- Checked: 2 August 2026
OpenID for Verifiable Credential Issuance 1.0
Section titled “OpenID for Verifiable Credential Issuance 1.0”- Publisher: OpenID Foundation
- URL: openid.net/specs/openid-4-verifiable-credential-issuance-1_0-final.html
- Status: OpenID Final Specification, approved 16 September 2025
- State: Normative issuance protocol candidate
- Used for: OAuth-protected issuance of credentials to compatible wallets and holders.
- Checked: 2 August 2026
OpenID for Verifiable Presentations 1.0
Section titled “OpenID for Verifiable Presentations 1.0”- Publisher: OpenID Foundation
- URL: openid.net/specs/openid-4-verifiable-presentations-1_0-final.html
- Status: OpenID Final Specification, approved 10 July 2025
- State: Normative presentation protocol candidate
- Used for: Requesting and delivering presentations of credentials in same-device and cross-device flows.
- Checked: 2 August 2026
OpenID4VC High Assurance Interoperability Profile 1.0
Section titled “OpenID4VC High Assurance Interoperability Profile 1.0”- Publisher: OpenID Foundation
- URL: openid.net/specs/openid4vc-high-assurance-interoperability-profile-1_0-final.html
- Status: OpenID Final Specification, approved 29 December 2025
- State: High-assurance implementation reference
- Used for: A constrained interoperability profile for credential issuance and presentation where stronger security and privacy are required.
- ANUKA boundary: Not required for low-risk community participation.
- Checked: 2 August 2026
Achievement and capability credentials
Section titled “Achievement and capability credentials”1EdTech Open Badges 3.0
Section titled “1EdTech Open Badges 3.0”- Publisher: 1EdTech Consortium
- URL: 1edtech.org/standards/open-badges
- State: Normative achievement-credential reference
- Used for: Portable credentials describing achievements, criteria, evidence, issuers, earners, skills, and endorsements.
- Current architecture: Open Badges 3.0 credentials are designed as W3C-compatible Verifiable Credentials.
- ANUKA use: Capability and meaningful achievement credentials, not decorative activity badges.
- Checked: 2 August 2026
Open Badges 3.0 Implementation Guide
Section titled “Open Badges 3.0 Implementation Guide”- Publisher: 1EdTech Consortium
- URL: standards.1edtech.org/open-badges/guides/standards/v3p0/impl
- State: Implementation reference
- Used for: Issuer, host, displayer, verifier, wallet, endorsement, evidence, and revocation implementation patterns.
- Checked: 2 August 2026
Attestations
Section titled “Attestations”Ethereum Attestation Service — Attestations
Section titled “Ethereum Attestation Service — Attestations”- Publisher: Ethereum Attestation Service
- URL: docs.attest.org/docs/core—concepts/attestations
- State: Implementation reference
- Used for: Structured onchain and offchain attestations, attester, recipient, references, expiry, revocation, and schemas.
- Critical limitation: The protocol can establish who attested and whether the record changed; credibility still depends on the attester and evidence.
- Checked: 2 August 2026
Ethereum Attestation Service — Schemas
Section titled “Ethereum Attestation Service — Schemas”- Publisher: Ethereum Attestation Service
- URL: docs.attest.org/docs/core—concepts/schemas
- State: Implementation reference
- Used for: Reusable typed attestation structures and schema discipline.
- Checked: 2 August 2026
Ethereum Attestation Service — FAQ
Section titled “Ethereum Attestation Service — FAQ”- Publisher: Ethereum Attestation Service
- URL: docs.attest.org/docs/quick—start/faqs
- State: Implementation reference
- Used for: EAS positioning as open-source, permissionless, tokenless, and supporting onchain and offchain attestations.
- Checked: 2 August 2026
AI and risk management
Section titled “AI and risk management”NIST AI Risk Management Framework 1.0
Section titled “NIST AI Risk Management Framework 1.0”- Publisher: NIST
- URL: nist.gov/itl/ai-risk-management-framework
- State: Normative risk-management reference
- Used for: Govern, Map, Measure, and Manage functions and trustworthy-AI risk practices.
- Current-status note: NIST has indicated that AI RMF 1.0 is being revised; the baseline must be rechecked before ratification.
- Checked: 2 August 2026
NIST Generative AI Profile
Section titled “NIST Generative AI Profile”- Publisher: NIST
- URL: nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence
- Publication: NIST AI 600-1, 26 July 2024; source page updated in 2026
- State: AI implementation reference
- Used for: Generative-AI-specific risks, provenance, evaluation, and controls.
- Checked: 2 August 2026
Employment, dossiers, and scoring
Section titled “Employment, dossiers, and scoring”CFPB Circular 2024-06
Section titled “CFPB Circular 2024-06”- Publisher: U.S. Consumer Financial Protection Bureau
- URL: consumerfinance.gov Circular 2024-06
- State: Legal watch
- Used for: The official view that third-party background dossiers and algorithmic worker scores used for employment decisions are often governed by the Fair Credit Reporting Act.
- ANUKA implication: A participant reputation service cannot avoid FCRA analysis merely by calling itself a passport, marketplace, or network.
- Checked: 2 August 2026
FTC — Employment Background Screening Companies and the FCRA
Section titled “FTC — Employment Background Screening Companies and the FCRA”- Publisher: U.S. Federal Trade Commission
- URL: ftc.gov employment screening FCRA guidance
- State: Legal watch
- Used for: Consumer reporting agency status, permissible-purpose concepts, and accuracy duties for employment reports.
- Critical point: The FTC states that merely saying a service is not a consumer reporting agency is not determinative.
- Checked: 2 August 2026
FTC/EEOC — Background Checks: What Employers Need to Know
Section titled “FTC/EEOC — Background Checks: What Employers Need to Know”- Publishers: FTC and U.S. Equal Employment Opportunity Commission
- URL: ftc.gov background checks employer guide
- State: Legal watch
- Used for: Authorization, disclosure, adverse-action, anti-discrimination, and state/local-law cautions.
- Checked: 2 August 2026
Fair Credit Reporting Act
Section titled “Fair Credit Reporting Act”- Publisher: FTC statutory resource
- URL: ftc.gov Fair Credit Reporting Act
- Current source note: FTC page lists a revised March 2026 Act PDF.
- State: Legal watch
- Used for: Primary statutory framework governing consumer reports and consumer reporting agencies.
- Checked: 2 August 2026
EEOC — Prohibited Employment Policies and Practices
Section titled “EEOC — Prohibited Employment Policies and Practices”- Publisher: U.S. Equal Employment Opportunity Commission
- URL: eeoc.gov/prohibited-employment-policiespractices
- State: Legal watch
- Used for: Disparate treatment, disparate impact, job-relatedness, and protected-class constraints in employment decisions.
- Checked: 2 August 2026
EEOC and DOJ — AI and Disability Discrimination
Section titled “EEOC and DOJ — AI and Disability Discrimination”- Publisher: U.S. Equal Employment Opportunity Commission
- URL: eeoc.gov AI and disability discrimination
- State: Legal watch
- Used for: Risks that automated applicant or worker assessment can screen out people with disabilities and the need for accommodation processes.
- Checked: 2 August 2026
Adoption rules for ANUKA
Section titled “Adoption rules for ANUKA”- Identity proofing, authentication, authority, and reputation remain separate.
- W3C VC v2.0 is the selected portable-credential data-model baseline.
- OpenID4VCI and OpenID4VP are preferred interoperability protocols for compatible wallet flows.
- EAS is an optional attestation implementation, not the source of truth for business claims.
- Open Badges should be reused for meaningful capability and achievement credentials where its model fits.
- No universal person score may be derived from these standards.
- Employment-screening or worker-scoring products require a separate legal and compliance architecture.
- Emerging drafts are tracked but do not replace stable baselines automatically.
Review procedure
Section titled “Review procedure”Before each release:
- open every cited source;
- confirm status, date, and publisher;
- confirm the source supports the exact claim;
- identify errata and newer stable versions;
- record implementation profile and cryptosuite choices;
- review privacy and unlinkability risks;
- review employment or eligibility use with qualified counsel;
- update superseded links and version statements.
Registry maintenance
- Last manual validation: 2 August 2026
- Next review: Before Identity Protocol v0.9 or within 90 days
- Maintainer status: Founding draft