Sunbird RC is an open-source framework for building electronic registries and issuing W3C Verifiable Credentials, with schema-driven APIs, digital signatures, attestation workflows and consent management. It is a strong candidate for the collection as a registry-plus-credentials building block that has been configured for education, health and civil registry use without changes to its core.
All DPGs in the DPGs for DPI Collection are assessed by the DPGA Secretariat against the DPGs for DPI criteria v2.0. Assessments use publicly available documentation and link to their evidence below. Assessed September 2026.
3 partially met
Layer 1
Recognised DPG
Layer 2
DPI Relevance
Layer 3
DPI Architecture Alignment

Does it provide a foundational DPI function, reusable across sectors, at population scale?
It spans the Registries and Trust Infrastructure domains, providing configurable electronic registries with verifiable credential issuance. Reuse across sectors is explicit — health, education and civil registries all run on the same engine — and it is designed for India-scale deployment.
How the solution's architecture reflects the principles that distinguish DPI from conventional digitisation.
Can other systems connect without modifying the core, using documented open standards?
CRUD APIs are auto-generated from JSON Schema registry definitions and documented via OpenAPI. It adopts W3C Decentralized Identifiers, W3C Verifiable Credentials, JSON-LD and JSON Schema, with data models expressed in open formats.
Is it a modular building block that does one thing well, rather than a monolithic platform?
Components are modular and registry definitions are declarative, so behaviour is configured rather than coded. There is a clear split between the registry core engine and the applications built on top of it, and any registry type can be configured without forking — proven across education, health and civil sectors.
Can other public and private actors build on top of it?
APIs, SDKs and schema extension points let third parties build custom registries, and multiple organisations have done so across Indian education, health and civil sectors. Governance sits with the EkStep Foundation under an MIT licence, with no single-vendor dependency.
Can it run in distributed or federated deployments suited to national infrastructure?
On-premise deployment keeps data within the deploying jurisdiction. Each deployment is a largely centralised registry, with limited public documentation on federation between registries or on high-availability configurations.
Does it meet the security and privacy bar for population-scale infrastructure?
PKI-based digital signatures, encryption, role-based access control and audit logging cover registry operations, and consent management with data minimisation in credential issuance is built in. No vulnerability disclosure policy specific to Sunbird RC was found published.
Criteria: DPGs for DPI Collection criteria v2.0 · Co-stewarded by CDPI, Co-Develop and the DPGA Secretariat.
Spot something out of date? Contact the DPGA