#standards
- News · Jul 28, 2026MCP's 2026-07-28 spec hardens OAuth and adds enterprise-managed authorization
RFC 9207 issuer validation is now mandatory, dynamic client registration is deprecated in favour of client ID metadata documents, and an enterprise extension lets admins govern agent access through Entra ID or Okta instead of per-server consent clicks.
- Analysis · Jun 25, 2026The world is shipping digital identity: what 51 countries reveal
We catalogued 86 national digital ID schemes across 51 countries. The patterns that emerge, mobile-first, bank-led, biometric, and wallet-bound, tell you where identity is going and what to build for.
- News · May 15, 2025W3C publishes Verifiable Credentials Data Model 2.0 as a Recommendation
VC Data Model 2.0 reached W3C Recommendation on 15 May 2025, moving verifiable credentials from a promising draft to a standard the W3C recommends for wide deployment. It admits several securing mechanisms rather than mandating one.
- News · Aug 21, 2024NIST Digital Identity Guidelines (SP 800-63-4): from draft to final
NIST's rewrite of the Digital Identity Guidelines reached final publication in July 2025 after roughly four years and about 6,000 public comments. It brings syncable passkeys into scope, admits subscriber-controlled wallets to the federation model, and adds controls for injection attacks and forged media.