Skip to main content

Introduction

The NFC Credential represents a unique government-issued document. It supports passports and eIDs. Availability varies by country and continues to expand over time. An NFC Credential is guaranteed to be issued to a single World ID per unique document. The Japanese My Number Card (MNC) has its own issuer schema ID, 9310, and its own enrollment handling, distinct from passport/eID (9303), but it still counts as the user’s one NFC credential. Request MNC and passport/eID as alternatives, never together.

Use Cases

Use the NFC Credential when you need proof of a unique government document. This is useful for applications that need document-level Sybil resistance without requiring a proof of a unique human.

Credential Structure

This credential implements the following attributes beyond the defaults in the Credential.
AttributeDescription
genesis_issued_atThe timestamp of when the unique document was first verified.
expires_atThe expiration of the document with a maximum of 10 years.
associated_data_commitmentA commitment to the user’s Associated Data (seeNFC Issuer implementation notes).
The following shared issuer claim definitions cover passport/eID and MNC enrollment. MNC-specific entries describe the MNC flow; they do not mean a passport/eID request accepts MNC. In IDKit, request passport/eID with passport (schema 9303) and MNC with mnc (schema 9310); to accept either, use any(CredentialRequest("passport"), CredentialRequest("mnc")).

Claim 0 - Authentication Claim

Identifies the type of authentication performed when enrolling a document. This helps determine the state of the document at enrollment time. For example, documents that only undergo Passive Authentication have no guarantee that the data isn’t cloned from an original document. Please note that not all authentications are supported for all documents, and it usually varies per country. The strongest authentication available is always selected.

Claim 1 - SOD Signature

Contains a hash of the document’s signature from the issuing authority. For passports and other ICAO-9303 compliant documents, the signature is retrieved from SignedData.SignerInfos[0].Signature in the EF.SOD (Security Object Document) (see Section 4.6.2.1 from ICAO-9303 Part 10). The raw signature bytes are then hashed with blake3 and converted to a field element with modulo reduction. Please note that this claim is not set for credentials from My Number Cards.

Credential Renewal

Renewal is not supported for this credential. A document can only be enrolled once. From a user standpoint, they will generally obtain a new document from their issuing authority (e.g. a new passport) and register it as a new credential.

Technical Reference

For issuer endpoints, migration payloads, and implementation-specific details, see the NFC Issuer reference.