VC + DID coverage program: canivc evals + EECC interop as the drivers#

Date: 2026-07-10. Status: PLAN. Owner directive (2026-07-10): "Add to goal the canivc site evals and eecc github work on VC. Use these to spawn new work towards better VC and DID coverage."

This doc turns two external reference points — the canivc.com community dashboard (which we already integrated, task #88, commit 12cd438) and the European EPC Competence Center (EECC) GitHub VC/DID stack — into a staged burndown toward broader, measured VC and DID conformance. It supersedes the "remaining" stubs in .github/test-suites/vc.yaml, vc-di-eddsa.yaml, vc20-api.yaml, did.yaml.

Update 2026-07-14 (obsolescence sweep): both suites named in the baseline below are now fully green — vc_di_eddsa 31 pass, 0 fail (out of 31, proof sets/chains + previousProof landed) and vc20_api 59 pass, 0 fail (out of 59, structural VC Data Model validator now wired into the HTTP verify path + relatedResource checks landed). The baseline below is the historical 2026-07-10 starting point for this plan, not the current score.

Measured baseline (2026-07-10, from the canivc integration)#

Run by our own VC-API shim (bin/vc-api-shim) against the vendored official suites — same tests, same denominators as the published community numbers:

EECC stack (researched 2026-07-10) — what it gives us#

GitHub org european-epc-competence-center. Relevant repos and how each informs our roadmap (LICENCE noted — it gates vendoring):

Repo Licence Use to us
vc-verifier AGPL-3.0 Interop TARGET only (do NOT vendor AGPL). Verifies Ed25519Signature2018/2020, JsonWebSignature2020(ES256), DataIntegrityProof; cryptosuites eddsa-rdfc-2022, ecdsa-rdfc-2019, rsa-rdfc-2025, ecdsa-sd-2023; VC-JWT; status via StatusList2021 / BitstringStatusList / RevocationList2020. HTTP REST API + GS1 product-passport UI. A second independent verifier to cross-check credentials WE issue.
vc-verifier-rules Apache-2.0 Vendorable. Rule catalogue for verification — a source of conformance checks + fixtures.
webuild-attestations Apache-2.0 Vendorable. Real-world VC schemas + rulebooks (WeBuild Large-Scale Pilot). Concrete non-synthetic credential fixtures.
didwebvh Apache-2.0 Reference for a DID method beyond did:key — did:webvh (did:web + verifiable history). Motivates DID-method expansion.
es256-signature-2020, ps256-signature-2020, rsa-multikey, rsa-rdfc-2025-cryptosuite BSD-3 Reference implementations of cryptosuites we don't yet have — ECDSA P-256 (ES256), RSA. Test-vector sources.
vc-render-method (HTML) Rendering methods for VCs — ties into the MathML/rendering track for credential display.

Licence rule: AGPL (vc-verifier) is an interop target reached over HTTP or by running its published verification against our output — its code is NEVER vendored into this repo. Apache-2.0 / BSD-3 repos may be vendored as test vectors / reference with PROVENANCE.md per skills/test-suites external-suite policy.

Program — three tracks, staged, each a commit-sized wave#

Track A — canivc burndown (the measured, directly-comparable numbers)#

Track B — EECC interop + new coverage the EECC stack motivates#

Track C — cross-check + honesty surface#

Sequencing + constraints#

Order: A2 (biggest measured jump, no new crypto) → A1 → A3 → B1 → B2 → B3 → C. Each wave: one commit, immediate push, labelled scores, floors (vc_stage1 117/0, did_key 8/0, SPARQL 631/0, RDF 1031/0), and the rule-#11 boundary — the shim stays a consumer tool with ZERO semantic logic; all VC/DID/crypto logic lives in F*. No AGPL code vendored. No hand-rolled crypto (crypto-policy). Issues: open/attach a tracking issue per track under the VC epic and tick as waves land (issue-hygiene).

Environment note#

Written during an account-credit exhaustion (Fable 5) + repeated container-rollback window on 2026-07-10; the build-dependent waves (A1–B3) are queued for a stable container with credits. The did:key envelope (A3) and the structural-validator wiring (A2) are the highest value-per-token first strikes.