Skip to content

registration of and commitment to a particular use case and purpose #266

@npdoty

Description

@npdoty

User agents can help users make decisions about credential presentation, and filter out inappropriate or invasive uses of the credential API, if there is some documented commitment regarding a limited set of purposes for which the site will request credentials.

Sites could indicate (at a well-known location, and perhaps with the signature of a registrar or auditor) what information they will request and what purpose it would be used for. User agents can consume that information in real-time, and researchers/policymakers can review it to detect malfeasance and provide accountability.

(This is related to #136 before that was re-titled to focus on the protocol registry only. #209 also proposes to reflect some of that information for the user in the prompt itself.)

https://github.com/w3c/credential-considerations/blob/main/credentials-considerations.md#registration-of-use-cases

Metadata

Metadata

Assignees

No one assigned

    Labels

    privacy-considerationsprivacy-trackerGroup bringing to attention of Privacy, or tracked by the Privacy Group but not needing response.registryregistry related

    Type

    No type
    No fields configured for issues without a type.

    Projects

    Status
    Todo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions