Skip to content

registration of and commitment to a particular use case and purpose #266

@npdoty

Description

@npdoty

User agents can help users make decisions about credential presentation, and filter out inappropriate or invasive uses of the credential API, if there is some documented commitment regarding a limited set of purposes for which the site will request credentials.

Sites could indicate (at a well-known location, and perhaps with the signature of a registrar or auditor) what information they will request and what purpose it would be used for. User agents can consume that information in real-time, and researchers/policymakers can review it to detect malfeasance and provide accountability.

(This is related to #136 before that was re-titled to focus on the protocol registry only. #209 also proposes to reflect some of that information for the user in the prompt itself.)

https://github.com/w3c/credential-considerations/blob/main/credentials-considerations.md#registration-of-use-cases

Metadata

Metadata

Assignees

No one assigned

    Labels

    privacy-considerationsprivacy-trackerGroup bringing to attention of Privacy, or tracked by the Privacy Group but not needing response.registryregistry related

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions