# What Is Decentralized Identity?

Source: https://startwithidentity.com/guides/fundamentals/what-is-decentralized-identity/
Last updated: 2026-07-06
License: content by Start with Identity. Cite the source URL.

---

Decentralized identity is a model where individuals and organizations hold their own verifiable credentials in a digital wallet and present them directly to whoever needs to check them, without a central identity provider brokering every interaction. It is often called **self-sovereign identity (SSI)** because the holder, not a platform, controls the credential.

This is a shift away from the [federated model](https://startwithidentity.com/guides/fundamentals/saml-vs-oidc/) most workforce and consumer login runs on today, where an [identity provider](https://startwithidentity.com/glossary/identity-provider/) authenticates you and vouches for you to each application.

## The three roles: issuer, holder, verifier

Every decentralized identity interaction has the same three parties, known as the **trust triangle**:

- **Issuer** signs and gives out a credential (a university issues a degree, a government issues an ID, an employer issues a proof of employment).
- **Holder** stores the credential in a [wallet](https://startwithidentity.com/glossary/digital-wallet/) and decides when and to whom to present it.
- **Verifier** receives a presentation and checks the signature, the issuer, and the status, without needing to call the issuer in real time.

Because the credential is cryptographically signed, the verifier trusts the math and the issuer's public key rather than a live connection to the issuer. See [issuer, holder, verifier](https://startwithidentity.com/glossary/issuer-holder-verifier/) for the model in detail.

## The building blocks

Decentralized identity rests on two W3C standards plus a presentation layer:

- **[Decentralized Identifiers (DIDs)](https://startwithidentity.com/glossary/decentralized-identifier/)** are identifiers the subject controls, resolvable to a [DID document](https://startwithidentity.com/glossary/did-document/) containing public keys and service endpoints. No central registrar issues them. See the [W3C DID Core specification](https://www.w3.org/TR/did/).
- **[Verifiable Credentials (VCs)](https://startwithidentity.com/glossary/verifiable-credential/)** are tamper-evident, signed claims that follow the [W3C VC Data Model](https://www.w3.org/TR/vc-data-model-2.0/). Read our [Verifiable Credentials standard deep dive](https://startwithidentity.com/standards/verifiable-credentials/).
- **Presentation protocols** move credentials between wallets and verifiers. The [OpenID for Verifiable Credentials](https://openid.net/sg/openid4vc/) family (OpenID4VCI for issuance, OpenID4VP for presentation) is emerging as the dominant transport.

## Privacy: selective disclosure and zero-knowledge proofs

A key advantage is that holders can reveal the minimum needed. With [selective disclosure](https://startwithidentity.com/glossary/selective-disclosure/) and formats like [SD-JWT](https://startwithidentity.com/glossary/sd-jwt/), you can prove you are over 18 without showing your birth date or full ID. [Zero-knowledge proofs](https://startwithidentity.com/glossary/zero-knowledge-proof/) and [BBS signatures](https://startwithidentity.com/glossary/bbs-signature/) push this further, proving a statement is true without revealing the underlying data.

## Where it is being used

- **Reusable identity verification and KYC**: verify once, reuse the credential, instead of repeating document checks at every service. This connects directly to the [identity verification](https://startwithidentity.com/vendors/identity-verification/) market.
- **Government and cross-border ID**: the EU's [eIDAS 2.0 and the EUDI Wallet](https://startwithidentity.com/glossary/eudi-wallet/) mandate a wallet for every citizen, and [mobile driver's licenses](https://startwithidentity.com/glossary/mobile-drivers-license/) (ISO/IEC 18013-5) are rolling out across US states. See our [digital IDs by country](https://startwithidentity.com/digital-ids/) directory and [identity regulations](https://startwithidentity.com/regulations/) hub.
- **Workforce**: verifiable employment, certification, and access credentials that survive job changes.

## Decentralized vs federated identity

Federated identity ([SAML](https://startwithidentity.com/standards/saml-2-0/), [OIDC](https://startwithidentity.com/standards/openid-connect/)) is mature, centralized, and excellent for enterprise SSO, but the identity provider is a single point of control and failure. Decentralized identity removes the runtime dependency on that provider and gives the holder portability and privacy, at the cost of a younger ecosystem and wallet adoption still in progress. The two will coexist: expect [identity fabrics](https://startwithidentity.com/guides/fundamentals/what-is-identity-fabric/) to bridge federated and decentralized credentials.

## Where to start

Read [what is self-sovereign identity](https://startwithidentity.com/guides/fundamentals/what-is-self-sovereign-identity/) for the philosophy and history, the [Verifiable Credentials standard](https://startwithidentity.com/standards/verifiable-credentials/) for the data model, and compare tools in [top decentralized identity platforms](https://startwithidentity.com/articles/top-5-decentralized-identity-platforms/) and the [decentralized identity vendor directory](https://startwithidentity.com/vendors/decentralized-identity/). When you are ready to choose, see [best decentralized identity platforms](https://startwithidentity.com/rankings/best-decentralized-identity-platforms/).
