CD-005 - DPoP Enforcement
DPoP Enforcement
Status: Released
Published: 05.08.2026
Effective: 17.98.2026
Affected Components: Generic Issuer, swiyu Wallet
We are introducing DPoP (Demonstrating Proof-of-Possession) to strengthen the OpenID4VCI flow. DPoP ties each access token to a cryptographic key that only the userβs swiyu wallet controls. The rollout happens in two steps: first the wallet enables DPoP, then issuers can enforce it via their configuration.
Action required
Tag β οΈ Required soon Tag π¨ Breaking Tag π Optional Tag β Improvement Tag π Fix
Wallet
1.17.0 DPoP enablement for iOS and Android
Generic Issuer
Generic Issuer from version 3.2.0. supports enforcing DPoP via configuration. However, newest version 4.x.x. is strongly recommended for security improvements.
Migration steps
- Ensure Generic Issuer 3.2.x or higher is deployed.
- swiyu Wallet enables DPoP with release 1.17.0.
- Issuer enforces DPoP via configuration.
Timeline
17.08.2026 - swiyu Wallet enables DPoP with release 1.17.0 on iOS and Android.