Skip to content
Proposed specification for review. We are seeking feedback on key architectural choices in the industry consultation.

Developer Quickstart

Get up and running with PDTF 2.0 in five minutes. This guide covers the three operations every implementer needs: verifying a credential, looking up an issuer’s OpenID Federation Trust Marks, and checking revocation status.

Terminal window
npm install @pdtf/core

Given a W3C Verifiable Credential containing PDTF entity data, verify its signature, issuer authorisation, and revocation status in one call:

import { VcValidator, DidResolver, FederationRegistryResolver } from '@pdtf/core';
const credential = {
"@context": [
"https://www.w3.org/ns/credentials/v2",
"https://propdata.org.uk/ns/v4"
],
"type": ["VerifiableCredential", "PropertyCredential"],
"issuer": "did:web:adapter.propdata.org.uk",
"credentialSubject": {
"id": "urn:pdtf:uprn:100023336956",
"type": "Property",
"energyPerformance": {
"currentRating": "C",
"certificateNumber": "0000-0000-0000-0000-0000"
}
},
"proof": { /* Ed25519 signature */ }
};
const validator = new VcValidator();
const didResolver = new DidResolver();
const trustResolver = new FederationRegistryResolver({
registryUrl: 'https://trust.pdtf.org/.well-known/openid-federation'
});
const result = await validator.validate(credential, {
didResolver,
trustResolver
});
if (result.valid) {
console.log('Credential is valid');
console.log('Issuer trust level:', result.stages.trust.details?.trustLevel);
// → 'root-issuer' | 'accredited-issuer' | 'trusted-proxy'
} else {
console.error('Verification failed:', result.warnings);
}
  1. Structure — validates the credentialSubject against the PDTF v4 JSON schema.
  2. Signature — resolves the issuer’s DID document, extracts the verification method, and validates the eddsa-jcs-2022 proof.
  3. Trust — evaluates the issuer’s OpenID Federation Trust Marks and confirms they are authorised for this entity type and data path.
  4. Status — fetches the Bitstring Status List and checks the credential’s revocation bit.

The OpenID Federation Trust Anchor dictates who is authorised to issue which types of credentials:

import { FederationRegistryResolver } from '@pdtf/core';
const trustResolver = new FederationRegistryResolver({
registryUrl: 'https://trust.pdtf.org/.well-known/openid-federation'
});
// Check if an issuer has a Trust Mark authorising them for a specific path
const isTrusted = await trustResolver.isIssuerTrusted(
'did:web:adapter.propdata.org.uk',
['Property:/energyPerformance']
);
if (isTrusted) {
console.log('Issuer is authorised via OpenID Federation Trust Marks');
} else {
console.log('Issuer lacks Trust Marks for this entity:path');
}
// Fetch the raw entity statement for an issuer within the federation
const statement = await trustResolver.fetchEntityStatement('did:web:adapter.propdata.org.uk');
console.log(`Issuer: ${statement.sub}`);
console.log(`Trust Marks:`, statement.trust_marks);

Every PDTF credential includes a credentialStatus field pointing to a Bitstring Status List. Check it directly:

import { StatusListResolver } from '@pdtf/core';
const statusResolver = new StatusListResolver();
const status = await statusResolver.checkRevocation(credential);
if (status.revoked) {
console.log('Credential has been revoked');
console.log('Revoked at:', status.revokedAt);
} else {
console.log('Credential is active');
}

The status list is a compact bitstring where each credential is assigned an index. Issuers publish the status list at a public URL and flip individual bits to revoke credentials — no need to contact the issuer directly.

Look up a DID document for any PDTF entity that uses did:web:

import { DidResolver } from '@pdtf/core';
const resolver = new DidResolver();
// Resolve a transaction's DID document
const doc = await resolver.resolve('did:web:platform.example.com:transactions:abc123');
console.log('Service endpoints:', doc.service);
// → [{ type: 'PDTFv4API', serviceEndpoint: 'https://...' }]
console.log('Verification methods:', doc.verificationMethod);
// → [{ type: 'Ed25519VerificationKey2020', publicKeyMultibase: 'z6Mkh...' }]

The @pdtf/cli package provides command-line equivalents:

Terminal window
# Verify a credential from a JSON file
pdtf verify credential.json
# Look up an issuer's Trust Marks
pdtf trust resolve did:web:adapter.propdata.org.uk
# Check revocation
pdtf revocation check credential.json
# Resolve a DID
pdtf did resolve did:web:platform.example.com:transactions:abc123