Identifiers
PDTF 2.0 uses two identifier families:
- DIDs for actors that sign or act (people, organisations, transactions, adapters).
- URNs for subjects that are talked about (UPRNs, title numbers, relationship entities, and credential IDs).
This split makes it clear which identifiers must resolve to keys and endpoints, and which are stable subject references.
DIDs (actors)
Section titled “DIDs (actors)”PDTF uses:
did:keyfor persons (simple, no hosting).did:keyordid:webfor organisations (provider-managed vs self-hosted).did:webfor transactions and most public services, because they need discoverable HTTPS endpoints.
A DID’s DID document binds signatures to keys. In practice, verifiers check that the proof.verificationMethod is present under assertionMethod.
URNs (subjects)
Section titled “URNs (subjects)”PDTF uses urn:pdtf:* identifiers for the entity graph and credentials, for example:
urn:pdtf:uprn:{uprn}for propertiesurn:pdtf:titleNumber:{number}for registered titlesurn:pdtf:unregisteredTitle:{id}for unregistered titlesurn:pdtf:capacity:{id}/urn:pdtf:offer:{id}/urn:pdtf:gift:{id}/urn:pdtf:representation:{id}/urn:pdtf:role:{id}for relationship credentialsurn:pdtf:vc:{uuid}for credential IDs (when present)
URNs identify the subject of a claim. They do not resolve to DID documents.
Why this matters
Section titled “Why this matters”- Verifiers can distinguish who is speaking (DID) from what they are speaking about (URN).
- Credentials remain meaningful even when delivered out-of-band.
- Relationship entities become first-class objects with clean revocation semantics.
Where to go next
Section titled “Where to go next”- See the DID methods spec for
did:keyanddid:webrules. - See the URN scheme reference for exact formats and validation guidance.