Skip to content
Proposed specification for review. We are seeking feedback on key architectural choices in the industry consultation.

Federation Schema

This page documents the JWT formats for entity statements and Property Trust Marks as used in the PDTF federation. These follow the OpenID Federation 1.0 specification with PDTF-specific trust mark definitions.

Every federation participant publishes a self-signed entity statement at {entity_url}/.well-known/openid-federation. The Trust Anchor also publishes subordinate statements for each entity it trusts.

{
"alg": "EdDSA",
"kid": "key-1",
"typ": "entity-statement+jwt"
}
{
"iss": "https://adapters.propdata.org.uk/hmlr",
"sub": "https://adapters.propdata.org.uk/hmlr",
"iat": 1711929600,
"exp": 1743465600,
"jwks": {
"keys": [
{
"kty": "OKP",
"crv": "Ed25519",
"kid": "key-1",
"x": "base64url-encoded-public-key",
"use": "sig"
}
]
},
"authority_hints": [
"https://propdata.org.uk"
],
"metadata": {
"federation_entity": {
"organization_name": "PDTF HMLR Adapter",
"homepage_uri": "https://platform.example.com",
"contacts": ["trust@propdata.org.uk"]
},
"openid_credential_issuer": {
"credential_endpoint": "https://adapters.propdata.org.uk/hmlr/credentials",
"credential_configurations_supported": {}
}
},
"trust_marks": [
{
"id": "https://propdata.org.uk/trust-marks/title-data-provider",
"trust_mark": "eyJhbGciOiJFZERTQSIs..."
}
]
}
FieldTypeRequiredDescription
issstring✓Issuer — the entity itself (self-signed) or the superior (subordinate statement)
substring✓Subject — the entity being described
iatnumber✓Issued-at timestamp (Unix seconds)
expnumber✓Expiration timestamp
jwksobject✓The entity’s public keys (JWK Set)
authority_hintsstring[]✓*URLs of superior entities. Required for non-anchor entities
metadataobject✓Entity metadata (see below)
trust_marksarray—Trust marks held by this entity
constraintsobject—Policy constraints on subordinates (anchor only)

The Trust Anchor publishes subordinate statements at {anchor}/.well-known/openid-federation/fetch?sub={entity_url}:

{
"iss": "https://propdata.org.uk",
"sub": "https://adapters.propdata.org.uk/hmlr",
"iat": 1711929600,
"exp": 1743465600,
"jwks": {
"keys": [{ "..." : "..." }]
},
"metadata_policy": {
"openid_credential_issuer": {
"credential_endpoint": { "value": "https://adapters.propdata.org.uk/hmlr/credentials" }
}
}
}

The subordinate statement is signed by the superior (the Trust Anchor), not by the subject. This is what creates the trust chain.

General information about the organisation:

{
"organization_name": "PDTF HMLR Adapter",
"homepage_uri": "https://platform.example.com",
"contacts": ["trust@propdata.org.uk"],
"logo_uri": "https://platform.example.com/logo.png",
"policy_uri": "https://platform.example.com/trust-policy"
}

Present when the entity issues credentials via OID4VCI:

{
"credential_endpoint": "https://adapters.propdata.org.uk/hmlr/credentials",
"credential_configurations_supported": {
"TitleCredential": {
"format": "ldp_vc",
"cryptographic_binding_methods_supported": ["did:key", "did:web"],
"credential_definition": {
"type": ["VerifiableCredential", "TitleCredential"]
}
}
}
}

Present when the entity is a verifier requesting credentials via OID4VP:

{
"redirect_uris": ["https://platform.example.com/callback"],
"vp_formats": {
"ldp_vp": {
"proof_type": ["DataIntegrityProof"]
}
}
}

Trust marks are signed JWTs issued by the Trust Anchor.

{
"alg": "EdDSA",
"kid": "anchor-key-1",
"typ": "trust-mark+jwt"
}
{
"iss": "https://propdata.org.uk",
"sub": "https://adapters.propdata.org.uk/hmlr",
"id": "https://propdata.org.uk/trust-marks/title-data-provider",
"iat": 1711929600,
"exp": 1743465600,
"trust_level": "trustedProxy",
"proxy_for": "https://hmlr.gov.uk",
"authorised_paths": [
"Title:/titleNumber",
"Title:/titleExtents",
"Title:/registerExtract/*",
"Title:/ownership/*"
],
"ref": "https://propdata.org.uk/trust-marks/title-data-provider"
}
FieldTypeRequiredDescription
issstring✓The Trust Anchor that issued this mark
substring✓The entity this mark is issued to
idstring✓Trust mark type URI
iatnumber✓Issued-at timestamp
expnumber—Expiration (null = no expiry, check via status endpoint)
trust_levelstring✓rootIssuer, trustedProxy, or accountProvider
proxy_forstring—Required for trustedProxy — the root issuer entity URL
authorised_pathsstring[]✓Entity:path combinations this entity is authorised for
refstring—Reference URI for the trust mark definition
IDSlugPurpose
https://propdata.org.uk/trust-marks/title-data-providertitle-data-providerIssue Title credentials
https://propdata.org.uk/trust-marks/property-data-providerproperty-data-providerIssue Property credentials
https://propdata.org.uk/trust-marks/regulated-conveyancerregulated-conveyancerAct as conveyancer in transactions
https://propdata.org.uk/trust-marks/account-provideraccount-providerIssue user/organisation DIDs
LevelDescription
rootIssuerPrimary authoritative source (e.g. HMLR for title data)
trustedProxyAuthorised adapter fetching from a primary source API
accountProviderPlatform issuing user or organisation identifiers

Authorised paths follow the pattern Entity:/json/pointer/path using JSON Pointer (RFC 6901):

PatternMatches
Title:/registerExtract/scheduleExactly that path
Title:/registerExtract/*All paths under /registerExtract
Property:/*All paths on the Property entity

Wildcards (*) are only supported as the final path segment.

A verifier resolves trust by:

  1. Fetch the leaf entity statement from {entity}/.well-known/openid-federation
  2. For each entry in authority_hints, fetch the subordinate statement from {superior}/.well-known/openid-federation/fetch?sub={entity}
  3. Verify the subordinate statement signature against the superior’s keys
  4. Repeat up the chain until reaching a recognised Trust Anchor
  5. The chain is valid if every signature checks out and the anchor is trusted
  • Maximum chain depth: 5 (configurable)
  • Every statement must be within its iat/exp window
  • The leaf entity’s jwks must match the keys in the subordinate statement
  • Trust marks must be signed by a Trust Anchor in the resolved chain

The Trust Anchor operates a status endpoint for checking trust mark validity:

GET https://propdata.org.uk/.well-known/openid-federation/trust-mark-status
?sub=https://adapters.propdata.org.uk/hmlr
&trust_mark_id=https://propdata.org.uk/trust-marks/title-data-provider

Response:

{
"active": true
}

This allows real-time revocation checking without waiting for trust mark expiry.