DPoP Enforcement

Status: Released
Published: 05.08.2026
Effective: 17.98.2026
Affected Components: Generic Issuer, swiyu Wallet

We are introducing DPoP (Demonstrating Proof-of-Possession) to strengthen the OpenID4VCI flow. DPoP ties each access token to a cryptographic key that only the user’s swiyu wallet controls. The rollout happens in two steps: first the wallet enables DPoP, then issuers can enforce it via their configuration.

Action required

Tag ⚠️ Required soon Tag 🚨 Breaking Tag πŸ†• Optional Tag βœ… Improvement Tag 🐞 Fix

Wallet

1.17.0 DPoP enablement for iOS and Android

Generic Issuer

Generic Issuer from version 3.2.0. supports enforcing DPoP via configuration. However, newest version 4.x.x. is strongly recommended for security improvements.

Migration steps

  1. Ensure Generic Issuer 3.2.x or higher is deployed.
  2. swiyu Wallet enables DPoP with release 1.17.0.
  3. Issuer enforces DPoP via configuration.

Timeline

17.08.2026 - swiyu Wallet enables DPoP with release 1.17.0 on iOS and Android.