iSHARE Verifiable Credentials

Give data rights cryptographic proof.

Geef datarechten cryptografisch bewijs.

iSHARE.vc is the open framework for issuing, managing, and verifying Verifiable Credentials across data spaces — public, private, sensitive, and commercial. Built on W3C standards, backed by a global network of certified issuers.

iSHARE.vc is het open framework voor het uitgeven, beheren en verifiëren van Verifiable Credentials over dataspaces heen — publiek, privaat, gevoelig en commercieel. Gebouwd op W3C-standaarden, met een globaal netwerk van gecertificeerde issuers.

Understand iSHARE VC Begrijp iSHARE VC Become a certified issuer → Word gecertificeerde issuer → Developer Docs →
✓ iSHARE VC is
✓ iSHARE VC wél

What iSHARE VC is

Wat iSHARE VC is

  • A non-commercial Scheme Owner — the iSHARE Foundation defines the rules and certifies issuers, but never issues credentials itselfEen niet-commerciële Scheme Owner — de iSHARE Foundation stelt de regels en certificeert issuers, maar geeft zelf nooit credentials uit
  • An open governance framework — certified commercial parties (KPN, Poort8, Protium.ai…) do the actual issuing; iSHARE Foundation approves who they areEen open governanceframework — gecertificeerde commerciële partijen (KPN, Poort8, Protium.ai…) doen de daadwerkelijke uitgifte; iSHARE Foundation keurt goed wie dat zijn
  • A Trusted List of certified issuers anchored in eIDAS, PKIoverheid and other legal entity providersEen Trusted List van gecertificeerde issuers verankerd in eIDAS, PKIoverheid en andere legal entity providers
  • Standardised credential schemas at schemas.ishare.eu, extendable with any W3C-compliant third-party credentialGestandaardiseerde credential schema's op schemas.ishare.eu, uitbreidbaar met elke W3C-conforme externe credential
  • Protocol support for M2M (DCP v1.0) and H2M (OpenID4VCI + OpenID4VP) exchangeProtocol-ondersteuning voor M2M (DCP v1.0) en H2M (OpenID4VCI + OpenID4VP) uitwisseling
  • iSHARE Licences (licenses.ishare.eu) as legal building blocks — every transaction, including open data, carries machine-readable terms of useiSHARE Licenties (licenses.ishare.eu) als juridische bouwblokken — elke transactie, ook open data, draagt machine-leesbare gebruiksvoorwaarden
  • Decentralised verification — no central authority needed at transaction timeGedecentraliseerde verificatie — geen centrale autoriteit nodig bij elke transactie
✗ iSHARE VC is not
✗ iSHARE VC níét

What iSHARE VC is not

Wat iSHARE VC niet is

  • Not a wallet application — iSHARE.vc specifies the interface, not the wallet implementationGeen wallet-applicatie — iSHARE.vc specificeert de interface, niet de walletimplementatie
  • Not a commercial entity — the iSHARE Foundation is a non-profit foundation; it certifies issuers but has no revenue role in individual credential transactionsGeen commerciële partij — de iSHARE Foundation is een non-profit stichting; ze certificeert issuers maar verdient niet aan individuele credential-transacties
  • Not a central issuing authority — iSHARE Foundation certifies issuers, it does not issue credentials itself; the certified issuers doGeen centrale uitgevende instantie — iSHARE Foundation certificeert issuers, geeft zelf geen credentials uit; de gecertificeerde issuers doen dat
  • Not a blockchain — credentials are cryptographically signed, not stored on-chainGeen blockchain — credentials worden cryptografisch gesigned, niet on-chain opgeslagen
  • Not a replacement for existing auth protocols — iSHARE JWTs and VCs coexistGeen vervanging voor bestaande auth-protocollen — iSHARE JWT en VCs bestaan naast elkaar
  • Not a distinction between open and proprietary — even open data carries conditions via iSHARE LicencesGeen onderscheid tussen open en gesloten — ook open data draagt voorwaarden via iSHARE Licenties
  • Not sector-specific — the framework applies equally to public, private, sensitive, and commercial dataNiet sectorspecifiek — het framework geldt gelijk voor publieke, private, gevoelige en commerciële data
How it works
Hoe het werkt

From onboarding to verified data access

Van onboarding tot geverifieerde datadeling

Step 01
Stap 01

Issuer certification

Issuer certificering

A party becomes a certified Participant Credential Issuer or Data Rights Controller via the iSHARE Foundation, anchored in eIDAS or PKIoverheid.

Een partij wordt gecertificeerd als Participant Credential Issuer of Data Rights Controller via de iSHARE Foundation, verankerd in eIDAS of PKIoverheid.

Step 02
Stap 02

Credential issuance

Credential issuance

The certified issuer creates a cryptographically signed credential — Participant, Data Rights, or any compatible third-party credential (e.g. ISO 27001).

De gecertificeerde issuer maakt een cryptografisch gesignede credential — Participant, Data Rights, of een compatibele externe credential (bijv. ISO 27001).

Step 03
Stap 03

Credential storage

Credential opslag

The organisation stores credentials in its own Credential Store (wallet). Data Rights Credentials are issued by a certified Data Rights Controller on behalf of the Data Rightsholder.

De organisatie slaat credentials op in een eigen Credential Store (wallet). Data Rights Credentials worden uitgegeven door een gecertificeerde Data Rights Controller namens de Data Rightsholder.

Step 04
Stap 04

Decentralised verification

Gedecentraliseerde verificatie

The holder presents credentials via DCP or OpenID4VP. The verifier validates cryptographically against the Trusted List — no contact with the issuer required.

De holder presenteert credentials via DCP of OpenID4VP. De verifier valideert cryptografisch tegen de Trusted List — geen contact met de issuer nodig.

Credential types
Credential types

iSHARE-defined credentials — and beyond

iSHARE-gedefinieerde credentials — en meer

The iSHARE framework defines a core set at schemas.ishare.eu. The same W3C VC infrastructure also carries any third-party credential — ISO certifications, sector labels, regulatory proofs — presented alongside iSHARE credentials in one Verifiable Presentation.

Het iSHARE-framework definieert een kernset op schemas.ishare.eu. Dezelfde W3C VC-infrastructuur draagt ook externe credentials — ISO-certificeringen, sectorlabels, compliance-bewijzen — gepresenteerd naast iSHARE-credentials in één Verifiable Presentation.

iSHARE Participant Credential iSHARE Participant Credential

Complete participant passport

Volledig deelnemerspaspoort

= Compliance + Dataspace = Compliance + Dataspace

The top-level iSHARE credential. Proves your organisation is a legitimate data space participant: framework-compliant, registered in one or more data spaces, with signed agreements and valid certificates — in one signed document.

De overkoepelende iSHARE-credential. Bewijst dat uw organisatie een legitieme dataspace-deelnemer is: framework-compliant, geregistreerd in een of meer dataspaces, met ondertekende overeenkomsten en geldige certificaten — in één gesigneerd document.

Issued by:Uitgegeven door: Participant Credential Issuer
iSHARE Compliance Credential iSHARE Compliance Credential

Framework compliance

Framework-naleving

Certifies iSHARE framework membership per framework: roles, signed agreements, X.509 certificates, and identity provider assertions. Packaged inside the Participant Credential.

Bewijst iSHARE-frameworklidmaatschap per framework: rollen, overeenkomsten, X.509-certificaten en IDP-assertions. Onderdeel van het Participant Credential.

Issued by:Uitgegeven door: Participant Credential Issuer
Dataspace Participant Credential Dataspace Participant Credential

Dataspace membership

Dataspace-lidmaatschap

Confirms membership in one or more data spaces — your role, the applicable rulebook, and your signed dataspace agreements. Packaged inside the Participant Credential.

Bevestigt lidmaatschap in een of meer dataspaces — uw rol, het toepasselijke rulebook en ondertekende overeenkomsten. Onderdeel van het Participant Credential.

Issued by:Uitgegeven door: Participant Credential Issuer
Data Rights Credential Data Rights Credential

Data rights delegation

Datarechtendelegatie

Grants access to specific data at a Service Provider. Specifies who, what attributes, for how long — and carries an iSHARE Licence defining permitted use.

Verleent toegang tot specifieke data bij een Service Provider. Legt vast wie, welke attributen, hoe lang — en draagt een iSHARE Licentie met het toegestane gebruik.

Issued by:Uitgegeven door: Data Rights Controller
Bitstring Status List Bitstring Status List

Revocation & status

Revocatie & status

Privacy-preserving mechanism for publishing active / revoked / suspended status of issued credentials via compressed bitstrings.

Privacy-preserving mechanisme voor het publiceren van de status (actief / ingetrokken / gesuspendeerd) via gecomprimeerde bitstrings.

Issued by:Uitgegeven door: All issuing rolesAlle issuing roles
Third-party credentials Externe credentials

Any W3C-compliant credential

Elke W3C-conforme credential

Any credential from a trusted third party presented alongside iSHARE credentials. The Service Provider decides which it accepts.

Elke credential van een vertrouwde derde partij naast iSHARE-credentials. De Service Provider bepaalt welke hij accepteert.

  • ISO 27001 — information security certification
  • ISO 9001 — quality management proof
  • eIDAS qualified certificate (person or seal)
  • Sector label or accreditation (energy, health, finance)
  • NEN / AVG / GDPR compliance attestation
  • ISO 27001 — informatiebeveiliging certificering
  • ISO 9001 — kwaliteitsmanagement bewijs
  • eIDAS gekwalificeerd certificaat (persoon of zegel)
  • Sectorlabel of accreditatie (energie, zorg, finance)
  • NEN / AVG / GDPR compliance-attestatie
Issued by:Uitgegeven door: Any trusted third-party issuerElke vertrouwde externe issuer
Identity Credential eIDAS 2.0 Identity Credential eIDAS 2.0

Human identity (H2M)

Menselijke identiteit (H2M)

Confirms a natural person may act on behalf of an organisation. Will integrate with eIDAS 2.0 and European Digital Identity Wallets. Schema in preparation.

Bevestigt dat een natuurlijk persoon namens een organisatie mag handelen. Integreert met eIDAS 2.0 en European Digital Identity Wallets. Schema in voorbereiding.

Issued by:Uitgegeven door: Identity ProviderIdentity Provider
Data Rights Credential — how it works
Data Rights Credential — hoe het werkt

From rights holder to verified data access

Van rechthebbende tot geverifieerde datadeling

Step through the full credential lifecycle — from the Data Rightsholder instructing a Data Rights Controller, to the connector enforcing the iSHARE Licence when data is actually shared.

Doorloop de volledige credential-lifecycle — van de Data Rightsholder die de Data Rights Controller instrueert, tot de connector die de iSHARE Licentie handhaaft op het moment van datadeling.

Data Rightsholder
(rights holder)
Data Rightsholder
(rechthebbende)
Data Rights Controller
(DRC issuer)
Data Rights Controller
(issuer DRC)
Data Service Provider
(connector)
Data Service Provider
(connector)
Data Consumer
(requestor)
Data Consumer
(aanvrager)
iSHARE Licence
licenses.ishare.eu
Open data with conditions
Open data met voorwaarden

Open data also needs a front door

Open data heeft ook een voordeur nodig

Open data is publicly available — but that does not make it unconditional. An iSHARE Licence on a public source lets rights holders enforce legal conditions without closing the data: geographic restrictions, purpose limitations, logging obligations. The data stays open. The conditions become enforceable.

Open data is vrij beschikbaar — maar dat betekent niet dat het zonder voorwaarden is. Een iSHARE Licentie op een publieke bron stelt rechthebbenden in staat juridische voorwaarden af te dwingen zonder de data te sluiten: geografische beperkingen, doelbinding, logverplichting. De data blijft open. De voorwaarden worden afdwingbaar.

Geographic restriction
Geografische beperking

Only consumers whose Participant Credential confirms a Dutch or EU legal entity get through. Non-NL consumers are refused — even if the endpoint is publicly reachable.

Alleen consumers wier Participant Credential een Nederlandse of EU-rechtspersoon bevestigt komen erdoor. Niet-NL consumers worden geweigerd — ook al is het endpoint publiek bereikbaar.

Example: NL-only sensor data
Voorbeeld: alleen NL-sensordata
Purpose limitation
Doelbeperking

The iSHARE Licence specifies the permitted purpose — research only, non-commercial, no AI training. The consumer must accept these terms before access is granted.

De iSHARE Licentie legt het toegestane doel vast — alleen onderzoek, niet-commercieel, geen AI-training. De consumer moet deze voorwaarden accepteren voor toegang.

Example: open research datasets
Voorbeeld: open onderzoeksdatasets
Logging obligation
Logverplichting

Every access event is logged against the consumer's verified identity. The rights holder knows who accessed what, when — full audit trail without closing the source.

Elke toegangsgebeurtenis wordt gelogd op basis van de geverifieerde identiteit. De rechthebbende weet wie wat heeft ingezien, wanneer — volledig auditspoor zonder de bron te sluiten.

Example: public government datasets
Voorbeeld: publieke overheidsdata
Attribute-level control
Attribuutniveau controle

Some fields are open, others require a specific sector credential. A smart meter dataset may expose aggregated readings freely but require a sector credential for raw per-address data.

Sommige velden zijn open, andere vereisen een specifieke sectorale credential. Een slimmemeter-dataset kan geaggregeerde metingen vrij aanbieden maar een sectorale credential vereisen voor ruwe per-adresdata.

Example: energy / smart meter data
Voorbeeld: energie / slimmemeterdata
Open data access flow
Open data toegangsflow

The same DRC mechanism on a public source. The front door is the licence check.

Hetzelfde DRC-mechanisme op een publieke bron. De voordeur is de licentietoets.

🏢
NL Consumer
Participant Credential confirms NL legal entity
Participant Credential bevestigt NL rechtspersoon
data request + VP
data aanvraag + VP
Front door
Voordeur
iSHARE Licence check
iSHARE Licentietoets
NL / EU legal entity? Purpose accepted? Credential not revoked?
NL / EU rechtspersoon? Doel geaccepteerd? Credential niet ingetrokken?
✓ access granted
✓ toegang verleend
🗄️
Public data source
Publieke databron
Open — but licence-bound and logged
Open — maar licentiegebonden en gelogd
Non-NL Consumer → refused
Niet-NL Consumer → geweigerd
Participant Credential does not meet the geographic condition — access denied. Data endpoint remains public.
Participant Credential voldoet niet aan de geografische condition — toegang geweigerd. Data-endpoint blijft publiek.
💡
The data stays open. The conditions become enforceable.
De data blijft open. De voorwaarden worden afdwingbaar.

iSHARE does not close open data. It places a licence-enforcing front door in front of it. Any consumer with the right Participant Credential and licence acceptance gets through. Everyone else — including consumers from outside the permitted jurisdiction — is refused. The rights holder finally has legal certainty about who uses their data, for what purpose, and under which conditions — even when the data is public.

iSHARE sluit open data niet. Het plaatst een licentie-afdwingende voordeur ervoor. Elke consumer met het juiste Participant Credential en licentieacceptatie komt erdoor. Iedereen anders — inclusief consumers van buiten de toegestane jurisdictie — wordt geweigerd. De rechthebbende heeft eindelijk juridische zekerheid over wie zijn data gebruikt, met welk doel, en onder welke voorwaarden — ook als de data open is.

Use cases
Toepassingen

The Data Rights Credential across every context

Het Data Rights Credential in elke context

Public, private, sensitive or commercial — the same credential mechanism gives rights holders control and consumers verifiable access, regardless of the domain.

Publiek, privaat, gevoelig of commercieel — hetzelfde credential-mechanisme geeft rechthebbenden controle en consumers verifieerbare toegang, ongeacht het domein.

Public data
Publieke data

Open government & sensor data

Open overheids- & sensordata

A municipality publishes air quality measurements as open data. The DRC enforces: NL legal entities only, research purpose, no commercial resale — while keeping the endpoint publicly reachable.

Een gemeente publiceert luchtkwaliteitsmetingen als open data. Het DRC dwingt af: alleen NL-rechtspersonen, onderzoeksdoel, geen commerciële doorverkoop — terwijl het endpoint publiek bereikbaar blijft.

Geographic restrictionGeografische beperkingPurpose-boundDoelgebondenAudit log
Private data
Private data

B2B supply chain data sharing

B2B supply chain datadeling

A logistics provider shares shipment data with a carrier — only for specific routes, only for active contracts, only readable by the carrier's system credential. Revocable the moment the contract ends.

Een logistiek dienstverlener deelt zendingdata met een vervoerder — alleen voor specifieke routes, alleen bij actieve contracten, alleen leesbaar door de systeemcredential van de vervoerder. Intrekbaar op het moment het contract eindigt.

Contract-boundContractgebondenRevocableIntrekbaarM2M / DCP
Sensitive data
Gevoelige data

Health & energy personal data

Gezondheids- & energie persoonsdata

A citizen delegates read access to their smart meter data to an energy advisor — strictly scoped to their address, for 30 days, non-transferable. The citizen can revoke at any moment.

Een burger delegeert leestoegang tot zijn slimmemeterdata aan een energieadviseur — strikt beperkt tot zijn adres, voor 30 dagen, niet overdraagbaar. De burger kan op elk moment intrekken.

Time-limitedTijdgebondenCitizen-controlledBurger-gecontroleerdH2M / OpenID4VP
Commercial data
Commerciële data

SaaS & AI model data access

SaaS & AI-model datadeling

An ERP vendor grants an AI model access to live operational data — under a commercial iSHARE Licence specifying permitted inference tasks, data retention zero, no model training. Full legal provability of the terms.

Een ERP-leverancier verleent een AI-model toegang tot live operationele data — onder een commerciële iSHARE Licentie met toegestane inferentietaken, nul dataretentie, geen modeltraining. Volledige juridische bewijsbaarheid van de voorwaarden.

AI-use licensedAI-gebruik gelicentieerdNo retentionGeen retentieiSHARE Licence
AI & Data Sovereignty
AI & Datasouvereiniteit

iSHARE VC addresses the AI training data challenge

iSHARE VC pakt de AI-trainingsdata-uitdaging aan

Governments and international bodies worldwide face a critical bottleneck: AI systems require vast, high-quality datasets — yet rights holders lack a trusted, machine-enforceable way to specify and verify how their data may be used for AI training.

Overheden en internationale organisaties wereldwijd stuiten op een kritieke blokkade: AI-systemen vereisen enorme, hoogwaardige datasets — maar rechthebbenden missen een betrouwbare, machine-afdwingbare manier om te specificeren en te verifiëren hoe hun data voor AI-training mag worden gebruikt.

The challenge
De uitdaging

No machine-enforceable data rights for AI

Geen machine-afdwingbare datarechten voor AI

Today's AI training pipelines ingest data with little verifiable control over provenance or usage conditions. Rights holders — from public bodies to private companies — cannot enforce their terms once data leaves their systems. The EU AI Act, the European Data Act, and G7 AI principles all call for a solution. iSHARE VC is that solution.

Huidige AI-trainingspipelines verwerken data met weinig verifieerbare controle over herkomst of gebruiksvoorwaarden. Rechthebbenden — van overheden tot private bedrijven — kunnen hun voorwaarden niet afdwingen zodra data hun systemen verlaat. De EU AI Act, de European Data Act en G7 AI-principes vragen allemaal om een oplossing. iSHARE VC is die oplossing.

European Commission
Europese Commissie

EU Data Act & AI Act: rights by design

EU Data Act & AI Act: rechten by design

The European Data Act (2024) establishes rights for data holders to control how data — especially IoT and machine-generated data — may be accessed and used. The EU AI Act requires transparency about training data provenance. iSHARE Data Rights Credentials implement exactly these principles: the allowed use, the allowed recipient, and the legal licence are embedded in the credential itself.

De European Data Act (2024) kent rechten toe aan datahouders om te controleren hoe data — met name IoT- en machinegegenereerde data — mag worden benaderd en gebruikt. De EU AI Act vereist transparantie over de herkomst van trainingsdata. iSHARE Data Rights Credentials implementeren precies deze principes: het toegestane gebruik, de toegestane ontvanger en de juridische licentie zijn ingebakken in het credential zelf.

EU Data Act EU AI Act GDPR-aligned GDPR-conform
Global AI data governance
Wereldwijde AI-datagovernance

From Japan to Canada to Singapore

Van Japan tot Canada tot Singapore

The G7 Hiroshima AI Process, Japan's DFFT (Data Free Flow with Trust), the US NIST AI RMF, and Singapore's Model AI Governance Framework all call for trustworthy, auditable data-sharing with clear provenance. iSHARE VC provides a standards-based, interoperable layer that any jurisdiction can plug into — built on W3C VC 2.0 and open standards, not a proprietary platform.

Het G7 Hiroshima AI Process, Japan's DFFT (Data Free Flow with Trust), het US NIST AI RMF en Singapore's Model AI Governance Framework vragen allemaal om betrouwbare, controleerbare datadeling met duidelijke herkomst. iSHARE VC biedt een op standaarden gebaseerde, interoperabele laag die elke jurisdictie kan aansluiten — gebouwd op W3C VC 2.0 en open standaarden, niet op een proprietair platform.

G7 HAIP DFFT NIST AI RMF W3C VC 2.0
What iSHARE VC adds
Wat iSHARE VC toevoegt

Machine-enforceable rights — end to end

Machine-afdwingbare rechten — end-to-end

A Data Rights Credential embeds: who may access the data, what attributes are allowed, at which connector, under which licence (including AI training restrictions), and for how long. The connector enforces these conditions at the moment of data transfer. The rights holder gets cryptographic, timestamped proof that the consumer accepted the terms.

Een Data Rights Credential bevat: wie de data mag benaderen, welke attributen zijn toegestaan, bij welke connector, onder welke licentie (inclusief AI-trainingsbeperkingen), en hoe lang. De connector dwingt deze voorwaarden af op het moment van datatransfer. De rechthebbende krijgt cryptografisch, tijdgestempeld bewijs dat de consumer de voorwaarden heeft geaccepteerd.

AI training restrictions AI-trainingsbeperkingen Cryptographic proof Cryptografisch bewijs Licence audit trail Licentie-audittrail
iSHARE VC as a global building block for responsible AI
iSHARE VC als wereldwijd bouwblok voor verantwoorde AI

iSHARE Foundation is working with European and international bodies on frameworks for trustworthy AI data governance. The Data Rights Credential is designed to serve as a reusable building block — interoperable across jurisdictions, open to any standards-compliant implementation, and governed by a non-commercial, neutral scheme owner. If your government or organisation is working on AI data policy, contact us.

iSHARE Foundation werkt samen met Europese en internationale instanties aan kaders voor betrouwbare AI-datagovernance. Het Data Rights Credential is ontworpen als herbruikbaar bouwblok — interoperabel over jurisdicties, open voor elke standaardsconforme implementatie, en beheerd door een niet-commerciële, neutrale scheme owner. Als uw overheid of organisatie werkt aan AI-databeleid, neem dan contact op.

Trusted Issuers

The iSHARE Trusted Issuers List

De Trusted List van iSHARE-issuers

The iSHARE Foundation certifies two independent networks — one for Participant Credentials (who you are) and one for Data Rights Credentials (what you may access). A verifier checks both when validating a Verifiable Presentation.

De iSHARE Foundation certificeert twee onafhankelijke netwerken — één voor Participant Credentials (wie je bent) en één voor Data Rights Credentials (wat je mag inzien). Een verifier controleert beide bij het valideren van een Verifiable Presentation.

What the Registry contains
Wat het Register bevat

Two layers: the Certificate Authority chain that anchors trust, and the public key of each certified party. Both are published and machine-readable — no central call-back required to verify a credential.

Twee lagen: de Certificate Authority-keten die het vertrouwen verankert, en de public key van elke gecertificeerde partij. Beide zijn gepubliceerd en machine-leesbaar — geen centrale call-back nodig om een credential te verifiëren.

Why it matters for issuers
Waarom het telt voor issuers

A credential signed by a key that is not on the Trusted Issuers Registry is rejected by every verifier in the ecosystem — automatically. Being on the list is what makes your credentials commercially viable.

Een credential ondertekend met een sleutel die niet in de Trusted Issuers Registry staat, wordt automatisch afgewezen door elke verifier in het ecosysteem. Op de lijst staan is wat uw credentials commercieel inzetbaar maakt.

One membership, all roles
Één lidmaatschap, alle rollen

A certified party issues any combination of Participant Credentials and Data Rights Credentials under one membership. Your public key appears once in the Registry, regardless of credential types issued.

Een gecertificeerde partij geeft elke combinatie van Participant Credentials en Data Rights Credentials uit onder één lidmaatschap. Uw public key staat eenmalig in het Register, ongeacht welke credential-typen u uitgeeft.

1ApplyAanmelden
2AssessmentBeoordeling
3Accreditation feeAccreditatievergoeding
4Annual membershipJaarlijks lidmaatschap
5Public key on RegistryPublic key in Register
6Start issuing credentialsStart met credentials uitgeven
View membership & fees — start your application → Bekijk lidmaatschap & tarieven — start uw aanvraag →
Participant Credential IssuersParticipant Credential Issuers

Certified parties that validate legal entity identity and issue Participant Credentials confirming iSHARE adherence.

Gecertificeerde partijen die de rechtspersoon valideren en Participant Credentials uitgeven die iSHARE-aansluiting bevestigen.

  • KPNCertified iSHARE Participant Credential Issuer. Anchored in PKIoverheid / eIDAS.Gecertificeerde iSHARE Participant Credential Issuer. Verankerd in PKIoverheid / eIDAS.
  • Poort8Certified iSHARE Participant Credential Issuer. Active in logistics and data space implementations.Gecertificeerde iSHARE Participant Credential Issuer. Actief in logistieke en dataspace-implementaties.
  • Protium.aiCertified iSHARE Participant Credential Issuer, focused on AI-driven data space participation.Gecertificeerde iSHARE Participant Credential Issuer, gericht op AI-gedreven dataspace-deelname.
  • VismaCertified iSHARE Participant Credential Issuer. Integrates credential issuance into ERP and HR ecosystems.Gecertificeerde iSHARE Participant Credential Issuer. Integreert credential issuance in ERP- en HR-ecosystemen.
  • DXC TechnologyCertified iSHARE Participant Credential Issuer. Brings credential issuance to enterprise IT environments globally.Gecertificeerde iSHARE Participant Credential Issuer. Brengt credential issuance naar enterprise IT-omgevingen wereldwijd.
  • Become a certified Participant Credential Issuer →Word gecertificeerde Participant Credential Issuer →Any party meeting iSHARE's conformance requirements can apply to join the Trusted List.Elke partij die voldoet aan de iSHARE conformance-eisen kan aanvragen om op de Trusted List te komen.
Data Rights ControllersData Rights Controllers

Certified issuers of Data Rights Credentials on behalf of Data Rightsholders — specifying who may access what, under which iSHARE Licence.

Gecertificeerde issuers van Data Rights Credentials namens Data Rightsholders — met vastlegging van wie wat mag inzien, onder welke iSHARE Licentie.

  • Certified Data Rights ControllersGecertificeerde Data Rights ControllersOnly controllers certified by the iSHARE Foundation and on the Trusted List may issue Data Rights Credentials. They act as issuer on behalf of the Data Rightsholder — the actual rights holder.Alleen controllers gecertificeerd door de iSHARE Foundation en op de Trusted List mogen Data Rights Credentials uitgeven. Zij treden op als issuer namens de Data Rightsholder — de daadwerkelijke rechthebbende.
  • What a DRC specifiesWat een DRC vastlegtWho may access · Which attributes · How long valid · How data may be used — via an iSHARE LicenceWie toegang heeft · Welke attributen · Hoe lang geldig · Hoe data gebruikt mag worden — via een iSHARE Licentie
  • Active sectorsActieve sectorenLogistics · Mobility · Energy · Construction · Green Deal · AgricultureLogistiek · Mobiliteit · Energie · Bouw · Green Deal · Landbouw
  • Become a certified Data Rights Controller →Word gecertificeerde Data Rights Controller →Any party meeting iSHARE's technical and legal requirements can be certified.Elke partij die voldoet aan de technische en juridische eisen van iSHARE kan gecertificeerd worden.

A verifier must confirm the credential was issued by a Trusted List party, the signature is valid, and the credential has not been revoked via the Bitstring Status List.

Een verifier moet bevestigen dat de credential is uitgegeven door een Trusted List-partij, de handtekening geldig is, en dat de credential niet ingetrokken is via de Bitstring Status List.

Schemas
Schema's

Credential schemas at schemas.ishare.eu

Credential schema's op schemas.ishare.eu

All iSHARE credentials must conform to JSON schemas published by the Scheme Owner — guaranteeing interoperability across all implementations.

Alle iSHARE-credentials moeten conformeren aan de door de Scheme Owner gepubliceerde JSON-schema's — dit garandeert interoperabiliteit over alle implementaties heen.

SchemaSchema vv Scenario DescriptionBeschrijving LinkLink
iSHARE Participant CredentialiSHARE Participant Credential v3v3 M2M H2M Compound credential — combines Compliance + Dataspace participation in one documentSamengesteld credential — combineert Compliance + Dataspace-deelname in één document schema.json ↗schema.json ↗
iSHARE Compliance CredentialiSHARE Compliance Credential v3v3 M2M H2M Framework roles, agreements, X.509 certificates and IDP assertions per frameworkFrameworkrollen, overeenkomsten, X.509-certificaten en IDP-assertions per framework schema.json ↗schema.json ↗
Dataspace Participant CredentialDataspace Participant Credential v3v3 M2M H2M Dataspace membership, roles, rulebook and agreements per dataspaceDataspace-lidmaatschap, rollen, rulebook en overeenkomsten per dataspace schema.json ↗schema.json ↗
Data Rights CredentialData Rights Credential v3v3 M2M H2M Delegation proof with iSHARE Licence specifying permitted use, attributes and validityDelegatiebewijs met iSHARE Licentie, attributen en geldigheidsduur schema.json ↗schema.json ↗
Bitstring Status ListBitstring Status List v3v3 M2M H2M Privacy-preserving revocation and status for all issued credentialsPrivacy-preserving revocatie en status voor alle uitgegeven credentials schema.json ↗schema.json ↗
Identity CredentialIdentity Credential H2M Natural person acting on behalf of an organisation — schema in preparation (eIDAS 2.0 / EUDIW)Natuurlijk persoon namens organisatie — schema in voorbereiding (eIDAS 2.0 / EUDIW) Coming soonBinnenkort
Issuance framework
Issuance framework

Three protocols for every scenario

Drie protocollen voor elke situatie

Three open standards — together covering machine-to-machine and human-to-machine credential exchange completely.

Drie open standaarden — samen dekken ze machine-to-machine én mens-naar-machine uitwisseling volledig af.

Machine-to-Machine
Machine-naar-machine

Eclipse Decentralized Claims Protocol (DCP) v1.0

Fully automated credential exchange between systems. No human intervention required.

Volledig geautomatiseerde credential-uitwisseling tussen systemen. Geen menselijke tussenkomst vereist.

Human-to-Machine — Issuance
Mens-naar-machine — Uitgifte

OpenID for Verifiable Credential Issuance 1.0

Credential issuance where a user requests credentials from an issuer via a holder application. OAuth 2.0-based.

Credential-uitgifte waarbij een gebruiker via een holder-applicatie credentials aanvraagt bij een issuer. OAuth 2.0-gebaseerd.

Human-to-Machine — Presentation
Mens-naar-machine — Presentatie

OpenID for Verifiable Presentations 1.0

Credential presentation by a user to a verifier. Supports selective attribute disclosure via Verifiable Presentations.

Credential-presentatie door een gebruiker aan een verifier. Ondersteunt selectieve attribuutdisclosure via Verifiable Presentations.

Get involved
Meedoen

Ready to verify without a central authority?

Klaar om te verifiëren zonder centrale autoriteit?

Your Data. Your Choice.

Jouw Data. Jouw Keuze.

Become a certified issuer, implement iSHARE VC as a Service Provider, or verify credentials as part of your data space.

Word certified issuer, implementeer iSHARE VC als Service Provider, of verifieer credentials als deel van jouw dataspace.

Become a participant Word deelnemer Technical docs → Technische documentatie →