Skip to content
Proposed specification for review. We are seeking feedback on key architectural choices in the industry consultation.

Identifiers

PDTF 2.0 uses two identifier families:

  • DIDs for actors that sign or act (people, organisations, transactions, adapters).
  • URNs for subjects that are talked about (UPRNs, title numbers, relationship entities, and credential IDs).

This split makes it clear which identifiers must resolve to keys and endpoints, and which are stable subject references.

PDTF uses:

  • did:key for persons (simple, no hosting).
  • did:key or did:web for organisations (provider-managed vs self-hosted).
  • did:web for transactions and most public services, because they need discoverable HTTPS endpoints.

A DID’s DID document binds signatures to keys. In practice, verifiers check that the proof.verificationMethod is present under assertionMethod.

PDTF uses urn:pdtf:* identifiers for the entity graph and credentials, for example:

  • urn:pdtf:uprn:{uprn} for properties
  • urn:pdtf:titleNumber:{number} for registered titles
  • urn:pdtf:unregisteredTitle:{id} for unregistered titles
  • urn:pdtf:capacity:{id} / urn:pdtf:offer:{id} / urn:pdtf:gift:{id} / urn:pdtf:representation:{id} / urn:pdtf:role:{id} for relationship credentials
  • urn:pdtf:vc:{uuid} for credential IDs (when present)

URNs identify the subject of a claim. They do not resolve to DID documents.

  • Verifiers can distinguish who is speaking (DID) from what they are speaking about (URN).
  • Credentials remain meaningful even when delivered out-of-band.
  • Relationship entities become first-class objects with clean revocation semantics.
  • See the DID methods spec for did:key and did:web rules.
  • See the URN scheme reference for exact formats and validation guidance.