Passkey Document Signing Community Group
The mission of this group is to bring legally meaningful, cryptographically verifiable digital signatures to the Web.
Although the Web has historically lacked primitives for digitally signing documents, widespread adoption of passkeys creates new opportunities, while regulatory and market demand for digital signatures continues to grow. For example, a business signing a contract today typically relies on an emailed link and ad hoc identity verification; a citizen seeking a qualified electronic signature under regulations such as eIDAS typically must verify their identity, at cost, with each new signing provider they use.
Prior research found that closing this gap requires no new cryptography: every needed building block already exists, but has not been composed into an open, interoperable whole. This group intends to develop that composition with security as a first-order concern, combining a small number of building blocks into a signing ceremony, an evidence format any third party can verify independently, and a way to express the resulting signature's legal strength.
The group expects to build on WebAuthn, OpenID4VP/the Digital Credentials API, CAdES/PAdES/JAdES, the CSC API, and RFC 3161 as-is. In particular, the group expects to build upon the signing extension under discussion in the Web Authentication Working Group. The group will not define new cryptography or authenticator behavior.
This group intends to publish one or more Specifications, and may produce supporting test suites, use-case documentation, and other material.
- Homepage
- Homepage/Blog
- Shortname
- passkey-signing
Participation
To join or leave this group, please sign in to your account.
Leadership
- Chairs
-
- Mohammed Zakari
Links
- Mailing List
- public-passkey-signing