CREDEBL is an open-source, ledger-agnostic platform for issuing, holding and verifying digital credentials, including DID management, digital wallets and multi-tenant credentialing. Now a Linux Foundation Decentralized Trust project, it is a trust infrastructure building block with unusually strong standards alignment.
All DPGs in the DPGs for DPI Collection are assessed by the DPGA Secretariat against the DPGs for DPI criteria v2.0. Assessments use publicly available documentation and link to their evidence below. Assessed September 2026.
3 partially met
Layer 1
Recognised DPG
Layer 2
DPI Relevance
Layer 3
DPI Architecture Alignment

Does it provide a foundational DPI function, reusable across sectors, at population scale?
Verifiable credentials and decentralised identity place it in the Trust Infrastructure domain. Credential issuance and verification are sector-agnostic by design — usable in health, education, finance and government alike — and the multi-tenant architecture is built for large credential ecosystems.
How the solution's architecture reflects the principles that distinguish DPI from conventional digitisation.
Can other systems connect without modifying the core, using documented open standards?
REST APIs are documented with Swagger for schema, credential and verification operations. Standards adoption is broad: W3C DIDs and Verifiable Credentials, OIDC4VC, ISO mDL, DIF and Trust over IP specifications, and Hyperledger Indy/Aries, with credentials exchanged as JSON-LD and JWT in the standard W3C VC data model.
Is it a modular building block that does one thing well, rather than a monolithic platform?
The platform is built as microservices communicating over NATS — user, ledger, connection, issuance, verification and agent services — with the credentialing core separated from the tenant applications built on it. It is multi-tenant, ledger-agnostic and agent-agnostic, so new contexts are configured rather than forked.
Can other public and private actors build on top of it?
Multi-tenant APIs let organisations build their own credential solutions on the platform, and it is open source under Linux Foundation Decentralized Trust governance. As a relatively young project, public case studies of independent organisations building on it are still limited.
Can it run in distributed or federated deployments suited to national infrastructure?
Multi-tenancy and support for several ledgers enable distributed deployment models, and did:web support means an organisation can keep credential infrastructure and data under its own control. High-availability and redundancy architecture is not prominently documented in the public repositories.
Does it meet the security and privacy bar for population-scale infrastructure?
Encryption and role-based access control provide tenant isolation, and the self-sovereign identity model gives privacy by design through user-controlled sharing and selective disclosure. A GitHub security tab exists but no formal vulnerability disclosure policy is published.
Criteria: DPGs for DPI Collection criteria v2.0 · Co-stewarded by CDPI, Co-Develop and the DPGA Secretariat.
Spot something out of date? Contact the DPGA