User agents can help users make decisions about credential presentation, and filter out inappropriate or invasive uses of the credential API, if there is some documented commitment regarding a limited set of purposes for which the site will request credentials.
Sites could indicate (at a well-known location, and perhaps with the signature of a registrar or auditor) what information they will request and what purpose it would be used for. User agents can consume that information in real-time, and researchers/policymakers can review it to detect malfeasance and provide accountability.
(This is related to #136 before that was re-titled to focus on the protocol registry only. #209 also proposes to reflect some of that information for the user in the prompt itself.)
https://github.com/w3c/credential-considerations/blob/main/credentials-considerations.md#registration-of-use-cases
User agents can help users make decisions about credential presentation, and filter out inappropriate or invasive uses of the credential API, if there is some documented commitment regarding a limited set of purposes for which the site will request credentials.
Sites could indicate (at a well-known location, and perhaps with the signature of a registrar or auditor) what information they will request and what purpose it would be used for. User agents can consume that information in real-time, and researchers/policymakers can review it to detect malfeasance and provide accountability.
(This is related to #136 before that was re-titled to focus on the protocol registry only. #209 also proposes to reflect some of that information for the user in the prompt itself.)
https://github.com/w3c/credential-considerations/blob/main/credentials-considerations.md#registration-of-use-cases