# Decentralized Identifiers (DID)

Source: https://startwithidentity.com/standards/decentralized-identifiers-did/
Last updated: 2026-07-06
License: content by Start with Identity. Cite the source URL.

---

## What it is

A Decentralized Identifier (DID) is a globally unique identifier that its subject controls directly, without a central registration authority. It is the addressing layer of [decentralized identity](https://startwithidentity.com/guides/fundamentals/what-is-decentralized-identity/): where a URL points to a web page, a DID points to a [DID document](https://startwithidentity.com/glossary/did-document/) that holds the public keys and service endpoints needed to interact with the subject, whether that subject is a person, an organization, or a device.

A DID looks like `did:method:identifier`, for example `did:web:example.com` or `did:key:z6Mk...`. It is standardized by [W3C DID Core 1.0](https://www.w3.org/TR/did-core/).

## How it works

- **Resolution:** software resolves a DID to its DID document using the rules of the DID's method. The document lists verification methods (public keys) and services.
- **Control:** the subject holds the private keys, so only they can update the document or sign as the DID. There is no provider to revoke or reassign it.
- **Anchoring credentials:** an issuer's DID lets a [verifier](https://startwithidentity.com/glossary/issuer-holder-verifier/) fetch the issuer's public key and check a [verifiable credential](https://startwithidentity.com/standards/verifiable-credentials/) signature without a central directory.

## DID methods

The `method` segment determines how a DID is created and resolved. They fall into two broad camps, covered in depth in our [DID methods compared](https://startwithidentity.com/guides/decentralized-identity/did-methods-compared/) guide:

- **Ledgerless:** `did:web` (anchored to a domain over HTTPS, the pragmatic enterprise default), `did:key` (a self-contained key, no network lookup), `did:jwk`.
- **Ledger-anchored:** `did:ion` (Bitcoin, Sidetree), `did:ethr` (Ethereum), `did:indy` (Hyperledger Indy). These add decentralization at the cost of ledger dependency. See [DID method](https://startwithidentity.com/glossary/did-method/).

## Status

DID Core 1.0 has been a W3C Recommendation since July 2022. The DID Working Group continues to maintain resolution and specific method specifications. In practice, `did:web` dominates enterprise deployments because it needs no blockchain, while wallet and government programs increasingly reference DIDs alongside [SD-JWT VC](https://startwithidentity.com/standards/verifiable-credentials/) issuance.

## When to use it

Use DIDs when you need issuer and holder identifiers that are portable and not tied to one provider's namespace. For most enterprises starting out, `did:web` gives the benefits of the standard with the operational simplicity of DNS and TLS you already run.

## Pitfalls

- Key management and recovery are your responsibility; losing control of the keys means losing control of the DID.
- Method choice matters: ledger-anchored methods bring governance and cost considerations that `did:web` avoids.
- A DID is only an identifier. Trust still comes from the credentials issued and the [trust registries](https://startwithidentity.com/glossary/trust-registry/) that vouch for issuers.

## Related

Guides: [what is decentralized identity](https://startwithidentity.com/guides/fundamentals/what-is-decentralized-identity/), [DID methods compared](https://startwithidentity.com/guides/decentralized-identity/did-methods-compared/). Standards: [Verifiable Credentials](https://startwithidentity.com/standards/verifiable-credentials/), [OpenID4VC](https://startwithidentity.com/standards/openid4vc/). Glossary: [DID](https://startwithidentity.com/glossary/decentralized-identifier/), [DID document](https://startwithidentity.com/glossary/did-document/), [DID method](https://startwithidentity.com/glossary/did-method/). Vendors: [decentralized identity](https://startwithidentity.com/vendors/decentralized-identity/).

## Who wrote it

The DID 1.0 specification was co-edited by [Drummond Reed](https://startwithidentity.com/experts/drummond-reed/), [Manu Sporny](https://startwithidentity.com/experts/manu-sporny/), and [Christopher Allen](https://startwithidentity.com/experts/christopher-allen/), who also co-authored TLS 1.0 and named self-sovereign identity. [Samuel M. Smith](https://startwithidentity.com/experts/sam-smith/) argues the ledger-less case with KERI. More in the [experts directory](https://startwithidentity.com/experts/).
