Identity-key DID resolution, signature-preserving BRC52 credential envelopes, authorized disclosure, and independent SD-JWT helpers.
The 0.3.0 source candidate implements the proposed BRC202/203 profiles. See unified integration guidance and breaking API migration. These custom W3C securing/status mechanisms are proposed and unregistered; the helpers do not establish generic W3C interoperability.
The SD-JWT example below issues a separate JOSE credential; it does not convert or preserve a BRC52 issuer signature. Use the optional @bsv/did/brc52 entry: exportBRC52Envelope(originalBinary) for existing BRC52 certificates, verifyBRC52Envelope('application/json', transport) for strict original-byte verification, produceBRC52Disclosure / receiveBRC52Disclosure for consent and authenticated receipt, and evaluateBRC52Status with an explicit locally selected evidence/privacy policy. Verification success does not approve issuer trust or application reliance.
npm install @bsv/didimport { PrivateKey } from '@bsv/sdk'
import { BsvDid, SdJwtVcIssuer, SdJwtVcHolder, SdJwtVcPresenter, SdJwtVcVerifier } from '@bsv/did'
const issuerPrivateKey = PrivateKey.fromRandom()
const holderPrivateKey = PrivateKey.fromRandom()
const issuer = BsvDid.fromPublicKey(issuerPrivateKey.toPublicKey().toDER() as number[])
const vc = await SdJwtVcIssuer.create({
issuer,
issuerPrivateKey,
holderPublicKey: holderPrivateKey.toPublicKey(),
vct: 'https://credentials.example.com/identity_credential',
claims: {
given_name: 'Alice',
email: 'alice@example.com',
is_over_21: true
},
disclosureFrame: {
given_name: true,
email: true,
is_over_21: true
}
})
const presentation = await SdJwtVcHolder.generatePresentation(vc, ['is_over_21'], {
holderPrivateKey,
audience: 'https://verifier.example',
nonce: 'nonce-123'
})
const result = await SdJwtVcVerifier.verify(SdJwtVcPresenter.present(presentation), {
expectedAudience: 'https://verifier.example',
expectedNonce: 'nonce-123',
requireKeyBinding: true
})did:key identifiers, DID Documents, and QR codescnf.jwkBSV identity keys are secp256k1. JOSE identifies secp256k1 ECDSA as ES256K; ES256 is P-256. This package uses ES256K for BSV identity-key compatibility.
Some eIDAS/EUDI profiles might require P-256 ES256. Those profiles need a P-256 key mode in addition to BSV identity-key mode.