Cool, thanks. My LGTM2 stands On Wednesday, September 9, 2026 at 11:18:01 AM UTC-4 Rick Byers wrote:
> On Wed, Sep 9, 2026 at 11:10 AM Chris Harrelson <[email protected]> > wrote: > >> LGTM3 >> >> On Wed, Sep 9, 2026 at 8:09 AM Vladimir Levin <[email protected]> >> wrote: >> >>> LGTM2 assuming that this is supported on all Blink platform. If not, >>> please comment why not. >>> >> > Thanks for spotting that, Vlad. I added this comment: > > Supported on all platforms except WebView. WebView is in discussion but > has a different privacy/security threat model so is being considered > separately. > > >> >>> On Wednesday, September 9, 2026 at 11:07:55 AM UTC-4 Mike Taylor wrote: >>> >>>> LGTM1 >>>> On 9/8/26 3:11 p.m., Rick Byers wrote: >>>> >>>> FWIW I am recused from this (having worked on it some), but I support >>>> shipping. I agree with @Alex Russell <[email protected]>'s >>>> argument in the I2E >>>> <https://groups.google.com/a/chromium.org/g/blink-dev/c/w64MxEdnUgQ/m/pBXYtR6aDwAJ> >>>> extension >>>> that the OT has run long enough; it's time to ship this. >>>> >>>> Rick >>>> >>>> On Wed, Sep 2, 2026 at 12:41 PM Chromestatus < >>>> [email protected]> wrote: >>>> >>>>> *Contact emails* >>>>> [email protected], [email protected], [email protected] >>>>> >>>>> *Explainer* >>>>> https://github.com/w3c-fedid/digital-credentials/blob/main/explainer.md >>>>> >>>>> *Specification* >>>>> https://w3c-fedid.github.io/digital-credentials >>>>> >>>>> *Summary* >>>>> This Web Platform feature enables issuing websites (e.g., a >>>>> university, government agency, or bank) to securely initiate the >>>>> provisioning (issuance) process of digital credentials directly into a >>>>> user's mobile wallet application. On Android, this capability leverages >>>>> the >>>>> Android IdentityCredential CredMan system (Credential Manager). On >>>>> Desktop, >>>>> it leverages cross-device approaches using the CTAP protocol similar to >>>>> Digital Credentials presentation. >>>>> >>>>> *Blink component* >>>>> Blink>Identity>DigitalCredentials >>>>> <https://issues.chromium.org/issues?q=customfield1222907:%22Blink%3EIdentity%3EDigitalCredentials%22> >>>>> >>>>> *Web Feature ID* >>>>> Missing feature >>>>> >>>>> *Motivation* >>>>> Without this, websites and wallets can only communicate in ways that >>>>> are more opaque to the browser and OS. >>>>> >>>>> *Initial public proposal* >>>>> https://w3c-fedid.github.io/digital-credentials/ >>>>> >>>>> *TAG review* >>>>> https://github.com/w3ctag/design-reviews/issues/1119 >>>>> >>>>> *TAG review status* >>>>> Issues addressed >>>>> >>>>> *Origin Trial Name* >>>>> Digital Credentials API - Issuance Support >>>>> >>>>> *Goals for experimentation* >>>>> We want to gather initial feedback from production usage of end-to-end >>>>> scenarios involving at least one wallet and at least one real-world >>>>> issuer >>>>> website including the cross-device flow. One of the initial use cases of >>>>> digital credentials issuance via the origin trial will be the Sparkasse >>>>> age >>>>> credential in Google Wallet. Sparkasse is a network of regional German >>>>> savings banks with more than 50 million customers. Sparkasse will issue >>>>> their customers an 18+ age credential from their website based on >>>>> verified >>>>> information with the bank to Google Wallet, that can be used online to >>>>> prove their adulthood with websites and apps online >>>>> >>>>> *Chromium Trial Name* >>>>> WebIdentityDigitalCredentialsCreation >>>>> >>>>> *Origin Trial documentation link* >>>>> https://w3c-fedid.github.io/digital-credentials >>>>> >>>>> *WebFeature UseCounter name* >>>>> kIdentityDigitalCredentialsCreation >>>>> >>>>> *Risks* >>>>> >>>>> >>>>> *Interoperability and Compatibility* >>>>> There are multiple standards efforts involved here. We have been >>>>> working with WebKit and Mozilla in the WICG on defining this specific >>>>> API. >>>>> But the greater interoperability risk will come from the data that is >>>>> sent >>>>> and returned via this API. Details of that are driven outside the web >>>>> browser community in the OpenID Foundation. >>>>> >>>>> *Gecko*: Negative ( >>>>> https://github.com/mozilla/standards-positions/issues/1003) >>>>> >>>>> *WebKit*: Support ( >>>>> https://github.com/WebKit/standards-positions/issues/332) Presentation >>>>> support is shipped, but timeline for adding issuance support yet. >>>>> >>>>> *Web developers*: No signals >>>>> >>>>> *Other signals*: >>>>> >>>>> *Activation* >>>>> The primary activation concern is enabling existing deployments using >>>>> technology like OpenID4VCI to be able to also support this API. As such >>>>> we >>>>> have left the request protocol unspecified at this layer, to be specified >>>>> along with existing request protocols to maximize activation opportunity. >>>>> >>>>> *WebView application risks* >>>>> >>>>> Does this intent deprecate or change behavior of existing APIs, such >>>>> that it has potentially high risk for Android WebView-based applications? >>>>> This feature does not deprecate or change the behavior of existing >>>>> APIs. This feature adds a new feature via extending the existing >>>>> navigator.credentials.create() with a new type. >>>>> >>>>> >>>>> *Debuggability* >>>>> None necessary - just new JS API. For testing we plan to add a >>>>> developer option to provide a fake wallet, but this effort is still >>>>> ongoing. >>>>> >>>>> *Will this feature be supported on all six Blink platforms (Windows, >>>>> Mac, Linux, ChromeOS, Android, and Android WebView)?* >>>>> No >>>>> >>>>> *Is this feature fully tested by web-platform-tests >>>>> <https://chromium.googlesource.com/chromium/src/+/main/docs/testing/web_platform_tests.md>?* >>>>> Yes >>>>> >>>>> https://wpt.fyi/results/digital-credentials?label=experimental&label=master&aligned >>>>> >>>>> *Flag name on about://flags* >>>>> web-identity-digital-credentials-creation >>>>> >>>>> *Finch feature name* >>>>> WebIdentityDigitalCredentialsCreation >>>>> >>>>> *Rollout plan* >>>>> Will ship enabled for all users >>>>> >>>>> *Requires code in //chrome?* >>>>> True >>>>> >>>>> *Tracking bug* >>>>> https://crbug.com/378330032 >>>>> >>>>> *Launch bug* >>>>> https://launch.corp.google.com/launch/4418038 >>>>> >>>>> *Availability expectation* >>>>> - Feature is in Chromium browsers for the foreseeable future. >>>>> >>>>> *Adoption expectation* >>>>> Feature is used by specific partner(s) to provide functionality within >>>>> 12 months of launch in Chrome. >>>>> >>>>> *Adoption plan* >>>>> - Many partnership are being driven by the Android and the Google >>>>> Wallet teams. - Regulations in the EU recommend incorporating the API in >>>>> Digital Wallets in the EU and hence websites will start adopting this API. >>>>> >>>>> *Non-OSS dependencies* >>>>> >>>>> Does the feature depend on any code or APIs outside the Chromium open >>>>> source repository and its open-source dependencies to function? >>>>> This API passes the request from the issuer website to the underlying >>>>> operating system. Therefore on Android, it replies on the Credential >>>>> Manager API. This is widely deployed via GMSCore though. >>>>> >>>>> *Estimated milestones* >>>>> Shipping on desktop 155 >>>>> Origin trial desktop first 143 >>>>> Origin trial desktop last 148 >>>>> Origin trial extension 1 end milestone 154 >>>>> Origin trial extension 2 end milestone 151 >>>>> Origin trial extension 3 end milestone 160 >>>>> DevTrial on desktop 133 >>>>> Shipping on Android 155 >>>>> Origin trial Android first 143 >>>>> Origin trial Android last 148 >>>>> DevTrial on Android 133 >>>>> >>>>> *Anticipated spec changes* >>>>> >>>>> Open questions about a feature may be a source of future web compat or >>>>> interop issues. Please list open issues (e.g. links to known github >>>>> issues >>>>> in the project for the feature specification) whose resolution may >>>>> introduce web compat/interop risk (e.g., changing to naming or structure >>>>> of >>>>> the API in a non-backward-compatible way). >>>>> https://github.com/w3c-fedid/digital-credentials/issues/382 But the >>>>> solution will most likely be backward compatible since this will be an >>>>> optional extra security hardening for some use cases. >>>>> >>>>> *Link to entry on the Chrome Platform Status* >>>>> https://chromestatus.com/feature/5099333963874304?gate=5147243652972544 >>>>> >>>>> *Links to previous Intent discussions* >>>>> Intent to Experiment: >>>>> https://groups.google.com/a/chromium.org/d/msgid/blink-dev/68ed3208.050a0220.30571e.0360.GAE%40google.com >>>>> Intent to Extend Experiment 1: >>>>> https://groups.google.com/a/chromium.org/d/msgid/blink-dev/6a42465a.198129d7.8452e.0378.GAE%40google.com >>>>> Intent to Extend Experiment 2: >>>>> https://groups.google.com/a/chromium.org/d/msgid/blink-dev/69c3e985.050a0220.38bee9.051b.GAE%40google.com >>>>> Intent to Extend Experiment 3: >>>>> https://groups.google.com/a/chromium.org/d/msgid/blink-dev/6a8c91f5.f0bac957.7b6f1.0c41.GAE%40google.com >>>>> >>>>> >>>>> This intent message was generated by Chrome Platform Status >>>>> <https://chromestatus.com>. >>>>> >>>> -- >>>> You received this message because you are subscribed to the Google >>>> Groups "blink-dev" group. >>>> To unsubscribe from this group and stop receiving emails from it, send >>>> an email to [email protected]. >>>> To view this discussion visit >>>> https://groups.google.com/a/chromium.org/d/msgid/blink-dev/CAFUtAY_vqwkdbFUQ5edniTDyJftTGQ8YRL%2BJPUThJNJo8WY%2BBA%40mail.gmail.com >>>> >>>> <https://groups.google.com/a/chromium.org/d/msgid/blink-dev/CAFUtAY_vqwkdbFUQ5edniTDyJftTGQ8YRL%2BJPUThJNJo8WY%2BBA%40mail.gmail.com?utm_medium=email&utm_source=footer> >>>> . >>>> >>>> -- >>> You received this message because you are subscribed to the Google >>> Groups "blink-dev" group. >>> To unsubscribe from this group and stop receiving emails from it, send >>> an email to [email protected]. >>> To view this discussion visit >>> https://groups.google.com/a/chromium.org/d/msgid/blink-dev/7bfd5967-5605-497a-baf4-d2cd5b84999fn%40chromium.org >>> >>> <https://groups.google.com/a/chromium.org/d/msgid/blink-dev/7bfd5967-5605-497a-baf4-d2cd5b84999fn%40chromium.org?utm_medium=email&utm_source=footer> >>> . >>> >> -- You received this message because you are subscribed to the Google Groups "blink-dev" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion visit https://groups.google.com/a/chromium.org/d/msgid/blink-dev/1f9cb652-f618-431f-af6d-2168962bbc9an%40chromium.org.
