Sunbird RC

Registries

Sunbird RC is an open-source framework for building electronic registries and issuing W3C Verifiable Credentials, with schema-driven APIs, digital signatures, attestation workflows and consent management. It is a strong candidate for the collection as a registry-plus-credentials building block that has been configured for education, health and civil registry use without changes to its core.

Electronic registries
verifiable credentials (W3C VC)
schema-driven CRUD APIs
PKI digital signatures
attestation workflows
consent management

All DPGs in the DPGs for DPI Collection are assessed by the DPGA Secretariat against the DPGs for DPI criteria v2.0. Assessments use publicly available documentation and link to their evidence below. Assessed September 2026.

15 of 18 checks met

3 partially met

Layer 1

Recognised DPG

Layer 2

DPI Relevance

Layer 1 Recognised Digital Public Good

Listed in the DPG Registry.
VerifiedVerified DPG logo

Layer 2 DPI Relevance

Does it provide a foundational DPI function, reusable across sectors, at population scale?

Domain fit
Cross-sector reuse
Population scale
3/3

It spans the Registries and Trust Infrastructure domains, providing configurable electronic registries with verifiable credential issuance. Reuse across sectors is explicit — health, education and civil registries all run on the same engine — and it is designed for India-scale deployment.

Layer 3 DPI Architecture Alignment

How the solution's architecture reflects the principles that distinguish DPI from conventional digitisation.

A · Interoperability

3/3

Can other systems connect without modifying the core, using documented open standards?

External API docs
Open standards
Open data formats

CRUD APIs are auto-generated from JSON Schema registry definitions and documented via OpenAPI. It adopts W3C Decentralized Identifiers, W3C Verifiable Credentials, JSON-LD and JSON Schema, with data models expressed in open formats.

B · Minimalist & Reusable Design

3/3

Is it a modular building block that does one thing well, rather than a monolithic platform?

Modular architecture
Core/app separation
Config-driven adaptability

Components are modular and registry definitions are declarative, so behaviour is configured rather than coded. There is a clear split between the registry core engine and the applications built on top of it, and any registry type can be configured without forking — proven across education, health and civil sectors.

C · Ecosystem Enablement

3/3

Can other public and private actors build on top of it?

Third-party buildability
External integrations
No vendor lock-in

APIs, SDKs and schema extension points let third parties build custom registries, and multiple organisations have done so across Indian education, health and civil sectors. Governance sits with the EkStep Foundation under an MIT licence, with no single-vendor dependency.

D · Federation Readiness

1/3

Can it run in distributed or federated deployments suited to national infrastructure?

Federated deployment · Partially meets
Data sovereignty
High availability · Partially meets

On-premise deployment keeps data within the deploying jurisdiction. Each deployment is a largely centralised registry, with limited public documentation on federation between registries or on high-availability configurations.

E · Security & Privacy at Scale

2/3

Does it meet the security and privacy bar for population-scale infrastructure?

Infrastructure-grade security
Vulnerability disclosure · Partially meets
Privacy by design

PKI-based digital signatures, encryption, role-based access control and audit logging cover registry operations, and consent management with data minimisation in credential issuance is built in. No vulnerability disclosure policy specific to Sunbird RC was found published.

Criteria: DPGs for DPI Collection criteria v2.0 · Co-stewarded by CDPI, Co-Develop and the DPGA Secretariat.

Spot something out of date? Contact the DPGA