# What Is Self-Sovereign Identity (SSI)?

Source: https://startwithidentity.com/guides/fundamentals/what-is-self-sovereign-identity/
Last updated: 2026-07-06
License: content by Start with Identity. Cite the source URL.

---

Self-sovereign identity (SSI) is a model in which individuals and organizations own and control their own digital identity and credentials directly, rather than renting that control from platforms, identity providers, or governments. It is the guiding principle behind [decentralized identity](https://startwithidentity.com/guides/fundamentals/what-is-decentralized-identity/).

## The idea

In today's systems your identity is scattered across accounts you do not really control. Each provider can lock you out, change terms, mine your data, or disappear. SSI flips the model: you hold cryptographically signed [verifiable credentials](https://startwithidentity.com/glossary/verifiable-credential/) in your own [wallet](https://startwithidentity.com/glossary/digital-wallet/) and present them peer to peer, so no single party sits between you and the services you use.

## Christopher Allen's ten principles

The modern framing comes from Christopher Allen's 2016 essay [The Path to Self-Sovereign Identity](http://www.lifewithalacrity.com/article/the-path-to-self-soverereign-identity/), which proposed ten principles: **existence, control, access, transparency, persistence, portability, interoperability, consent, minimalization, and protection**. In practice these reduce to three demands: the user must control the identity, the identity must be portable across providers, and disclosure must be minimized to only what a transaction needs.

## How SSI works in practice

SSI is realized through the same building blocks as decentralized identity:

- **[Decentralized Identifiers (DIDs)](https://startwithidentity.com/glossary/decentralized-identifier/)** the subject controls, defined by [W3C DID Core](https://www.w3.org/TR/did-core/).
- **[Verifiable Credentials](https://startwithidentity.com/standards/verifiable-credentials/)** issued, held, and presented within the [issuer, holder, verifier](https://startwithidentity.com/glossary/issuer-holder-verifier/) trust triangle.
- **[Selective disclosure](https://startwithidentity.com/glossary/selective-disclosure/)** and [zero-knowledge proofs](https://startwithidentity.com/glossary/zero-knowledge-proof/) to satisfy the minimalization principle: prove you are eligible without oversharing.
- **Governance and [trust registries](https://startwithidentity.com/glossary/trust-registry/)** so verifiers know which issuers to trust. The [Trust over IP](https://startwithidentity.com/glossary/trust-over-ip/) framework organizes this into technical and governance layers.

## Where SSI meets the real world

The principles are now colliding with regulation and rollout. The EU's [eIDAS 2.0 and EUDI Wallet](https://startwithidentity.com/glossary/eudi-wallet/) put a state-issued wallet in every citizen's hands, [mobile driver's licenses](https://startwithidentity.com/glossary/mobile-drivers-license/) are shipping in phone wallets, and reusable [identity verification](https://startwithidentity.com/vendors/identity-verification/) is turning SSI from theory into a KYC cost saver. Track national schemes in the [digital IDs directory](https://startwithidentity.com/digital-ids/).

## The honest tradeoffs

SSI is powerful but not free. Wallet recovery, issuer governance, revocation, and getting verifiers to actually accept credentials are hard, unfinished problems. Adoption depends on network effects that are still forming. For most enterprises the near-term reality is hybrid: [federated identity](https://startwithidentity.com/guides/fundamentals/saml-vs-oidc/) for existing SSO, decentralized credentials for reusable verification and portable proofs, stitched together by an [identity fabric](https://startwithidentity.com/guides/fundamentals/what-is-identity-fabric/).

## Where to start

Read [what is decentralized identity](https://startwithidentity.com/guides/fundamentals/what-is-decentralized-identity/) for the architecture, the [Verifiable Credentials standard](https://startwithidentity.com/standards/verifiable-credentials/) for the data model, and browse the [decentralized identity vendor directory](https://startwithidentity.com/vendors/decentralized-identity/) to see who is building it.
