DPoP Enforcement

Status: Released
Published: 05.08.2026
Effective: 17.08.2026
Affected Components: Generic Issuer, swiyu Wallet

We are introducing DPoP (Demonstrating Proof-of-Possession) to strengthen the OpenID4VCI flow. DPoP ties each access token to a cryptographic key that only the user’s swiyu wallet controls. The rollout happens in two steps: first the wallet enables DPoP, then issuers can enforce it via their configuration.

Action required

⚠️ Required soon Will become mandatory soon
🚨 Breaking Action required, something stops working
πŸ†• Optional New feature, opt-in
βœ… Improvement Enhancement, no action needed
🐞 Fix Bug fix
πŸ’‘ Informational Additional background information, no action needed

Wallet

1.17.0 DPoP enablement for iOS and Android

Generic Issuer

Generic Issuer from version 3.2.0. supports enforcing DPoP via configuration. However, newest version 4.x.x. is strongly recommended for security improvements.

Migration steps

  1. Ensure Generic Issuer 3.2.x or higher is deployed.
  2. swiyu Wallet enables DPoP with release 1.17.0.
  3. Issuer enforces DPoP via configuration.

Timeline

17.08.2026 - swiyu Wallet enables DPoP with release 1.17.0 on iOS and Android.