<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-skyfire-oauth-id-verification-02" category="std" consensus="true" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.1 -->
  <front>
    <title>Identity Verification Methods Values</title>
    <seriesInfo name="Internet-Draft" value="draft-skyfire-oauth-id-verification-02"/>
    <author initials="A." surname="Agarwal" fullname="Ankit Agarwal">
      <organization>Skyfire Systems Inc.</organization>
      <address>
        <email>ankit_agarwal@yahoo.com</email>
        <uri>https://skyfire.xyz</uri>
      </address>
    </author>
    <author initials="M." surname="Jones" fullname="Michael B. Jones">
      <organization>Self-Issued Consulting</organization>
      <address>
        <email>michael_b_jones@hotmail.com</email>
        <uri>https://self-issued.info/</uri>
      </address>
    </author>
    <author initials="N." surname="Ali" fullname="Nash Ali">
      <organization>Experian</organization>
      <address>
        <email>nash.ali@experian.com</email>
      </address>
    </author>
    <author initials="S." surname="Thumma" fullname="Srinivasa Thumma">
      <organization>Akamai</organization>
      <address>
        <email>sthumma@akamai.com</email>
      </address>
    </author>
    <date year="2026" month="October" day="02"/>
    <area>Security</area>
    <workgroup>Web Authorization Protocol</workgroup>
    <keyword>agent</keyword>
    <keyword>identity</keyword>
    <keyword>agentic</keyword>
    <keyword>payment</keyword>
    <keyword>commerce</keyword>
    <abstract>
      <?line 92?>

<t>Knowing how a person's identity was verified can be important when making trust decisions.
This specification defines a claim and values for declaring how the person's identity was verified.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://skyfire-xyz.github.io/draft-skyfire-oauth-id-verification/draft-skyfire-oauth-id-verification.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-skyfire-oauth-id-verification/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/skyfire-xyz/draft-skyfire-oauth-id-verification"/>.</t>
    </note>
  </front>
  <middle>
    <?line 98?>

<section anchor="introduction">
      <name>Introduction</name>
      <t>Knowing how a person's identity was verified can be important when making trust decisions.
This specification defines the "ivm" (Identity Verification Methods) claim and values for it
for declaring how the person's identity was verified.
It also creates a registry for Identity Verification Methods Values
and initializes the registry with the values defined in this specification.</t>
      <t>The usage of the "ivm" (Identity Verification Methods) claim parallels that of the
"amr" (Authentication Methods References) claim and uses parallel syntax.
Presence of a value in the claim indicates that the use of the indicated
identity verification method succeeded.</t>
      <t>The "ivm" claim contains a set of identity verification methods that succeeded.
It does not provide evidence for or details of how they were used.
Should that level of detail be desired,
OpenID Identity Assurance Schema Definition 1.0 <xref target="OpenID.IDA"/> can be used,
either with the "ivm" claim, or separately.
Likewise, Vectors of Trust <xref target="RFC8485"/> can be used to provide more detail,
either with the "ivm" claim, or separately.</t>
      <t>While this claim and values are general purpose
and can be used in any JSON Web Token (JWT) <xref target="RFC7519"/>,
one use case for them is use in KYAPay tokens <xref target="I-D.skyfire-oauth-kyapay-token"/>.</t>
    </section>
    <section anchor="conventions-and-definitions">
      <name>Conventions and Definitions</name>
      <t>The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14>REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL
NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECOMMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>",
"<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be interpreted as
described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they
appear in all capitals, as shown here.</t>
      <?line -18?>

</section>
    <section anchor="ivm">
      <name>Identity Verification Methods</name>
      <t>This section defines the "ivm" (Identity Verification Methods) claim and
values used with it to indicate that particular identity verification methods
were used.
In many ways, this parallels the "amr" (Authentication Methods References) claim
defined in <xref target="OpenID.Core"/>.
Like "amr", "ivm" is a JWT claim whose value is
an array that lists a set of methods that were used,
in this case, as identity verification methods,
rather than authentication method references.</t>
      <section anchor="ivmClaim">
        <name>"ivm" (Identity Verification Methods) Claim</name>
        <t>The "ivm" (Identity Verification Methods) claim is a
JSON array of case-sensitive strings that are identifiers for
identity verification methods used.
For instance, values might indicate that both
physical document verification and database PII verification methods were used.
Values used in the "ivm" claim <bcp14>SHOULD</bcp14> be from those registered in the
IANA "Identity Verification Methods" registry
established by <xref target="ivmRegistry"/>;
parties using this claim will need to agree upon the meanings of
any unregistered values used, which may be context specific.</t>
      </section>
      <section anchor="ivmValues">
        <name>Identity Verification Method Values</name>
        <t>The following Identity Verification Method values
are defined by this specification.</t>
        <section anchor="dbvMethod">
          <name>"dbv" (Database Verification of PII) Method</name>
          <dl newline="true">
            <dt>dbv:</dt>
            <dd>
              <t>Database Verification of PII (match of name/address/dob/ssn/nid, etc.)
using an unspecified number of consumer reporting data sources</t>
            </dd>
          </dl>
        </section>
        <section anchor="dbv1Method">
          <name>"dbv1" (Database Verification of PII One Source) Method</name>
          <dl newline="true">
            <dt>dbv1:</dt>
            <dd>
              <t>Database Verification of PII (match of name/address/dob/ssn/nid, etc.)
using one consumer reporting data source</t>
            </dd>
          </dl>
        </section>
        <section anchor="dbvmMethod">
          <name>"dbvm" (Database Verification of PII Multiple Sources) Method</name>
          <dl newline="true">
            <dt>dbvm:</dt>
            <dd>
              <t>Database Verification of PII (match of name/address/dob/ssn/nid, etc.)
using Multiple consumer reporting data sources</t>
            </dd>
          </dl>
        </section>
        <section anchor="digMethod">
          <name>"dig" (Digital ID Document Verification) Method</name>
          <dl newline="true">
            <dt>dig:</dt>
            <dd>
              <t>Digital ID Document Verification (for example Mobile Driver's Licenses)</t>
            </dd>
          </dl>
        </section>
        <section anchor="phyMethod">
          <name>"phy" (Physical ID Document Verification) Method</name>
          <dl newline="true">
            <dt>phy:</dt>
            <dd>
              <t>Physical ID Document Verification (for example via a real time capture of the front and back of DL or Passport photo page)</t>
            </dd>
          </dl>
        </section>
        <section anchor="secMethod">
          <name>"sec" (Secondary Document Verification) Method</name>
          <dl newline="true">
            <dt>sec:</dt>
            <dd>
              <t>Secondary Document Verification (for example via bank statements, financial statements, utility bills, government-issued papers, etc.)</t>
            </dd>
          </dl>
        </section>
        <section anchor="inpMethod">
          <name>"inp" (In-person Verification) Method</name>
          <dl newline="true">
            <dt>inp:</dt>
            <dd>
              <t>In-person Verification</t>
            </dd>
          </dl>
        </section>
        <section anchor="vidMethod">
          <name>"vid" (Video Verification) Method</name>
          <dl newline="true">
            <dt>vid:</dt>
            <dd>
              <t>Video Verification (live video interview)</t>
            </dd>
          </dl>
        </section>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>The security considerations defined in
JSON Web Token (JWT) <xref target="RFC7519"/>
apply to this specification.</t>
    </section>
    <section anchor="privacy-considerations">
      <name>Privacy Considerations</name>
      <t>The privacy considerations defined in
JSON Web Token (JWT) <xref target="RFC7519"/>
apply to this specification.</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <section anchor="json-web-token-claims-registration">
        <name>JSON Web Token Claims Registration</name>
        <t>This specification registers the following Claim in the
IANA "JSON Web Token Claims" <xref target="IANA.JWT.Claims"/>
established by <xref target="RFC7519"/>.</t>
        <section anchor="ivm-claim">
          <name>"ivm" Claim</name>
          <ul spacing="normal">
            <li>
              <t>Claim Name: ivm</t>
            </li>
            <li>
              <t>Claim Description: Identity Verification Methods</t>
            </li>
            <li>
              <t>Change Controller: Michael B. Jones - michael_b_jones@hotmail.com</t>
            </li>
            <li>
              <t>Reference: <xref target="ivmClaim"/> of this specification</t>
            </li>
          </ul>
        </section>
      </section>
      <section anchor="ivmRegistry">
        <name>Identity Verification Methods Registry</name>
        <t>This specification establishes the IANA "Identity Verification Methods" registry
for <tt>ivm</tt> claim array element values.
The registry records the Identity Verification Method value
and a reference to the specification that defines it.
This specification registers the Identity Verification Method values
defined in <xref target="ivmValues"/>.</t>
        <t>Values are registered on an Expert Review
<xref target="RFC5226"/> basis after a three-week review period on the &lt;jwt-reg-review@ietf.org&gt; mailing
list, on the advice of one or more Designated Experts.
To increase potential interoperability, the Designated Experts are requested to encourage
registrants to provide the location of a publicly accessible specification
defining the values being registered,
so that their intended usage can be more easily  understood.</t>
        <t>Registration requests sent to the mailing list for review should use
an appropriate subject
(e.g., "Request to register Identity Verification Method value: example").</t>
        <t>Within the review period, the Designated Experts will either approve or
deny the registration request, communicating this decision to the review list and IANA.
Denials should include an explanation and, if applicable, suggestions as to how to make
the request successful.
Registration requests that are undetermined for
a period longer than 21 days can be brought to the IESG's attention
(using the <eref target="mailto:iesg@ietf.org">iesg@ietf.org</eref> mailing list) for resolution.</t>
        <t>IANA must only accept registry updates from the Designated Experts and should direct
all requests for registration to the review mailing list.</t>
        <t>It is suggested that the same Designated Experts evaluate these
registration requests as those who evaluate registration requests
for the IANA "Authentication Method Reference Values" registry <xref target="IANA.AMR"/>.</t>
        <t>Criteria that should be applied by the Designated Experts include
determining whether the proposed registration duplicates existing functionality;
whether it is likely to be of general applicability
or whether it is useful only for a single application;
whether the value is actually being used;
and whether the registration description is clear.</t>
        <section anchor="registration-template">
          <name>Registration Template</name>
          <dl newline="true">
            <dt>Identity Verification Method Name:</dt>
            <dd>
              <t>The name requested (e.g., "dig") for the authentication method
or family of closely related authentication methods.
Because a core goal of this specification is for the resulting
representations to be compact, it is <bcp14>RECOMMENDED</bcp14> that the name be short
-- that is, not to exceed 8 characters without a compelling reason to do so.
To facilitate interoperability, the name must use only
printable ASCII characters excluding double quote ('"') and backslash ('\')
(the Unicode characters with code points U+0021, U+0023 through U+005B, and
U+005D through U+007E).
This name is case sensitive.
Names may not match other registered names in a case-insensitive manner
unless the Designated Experts state that there is a compelling reason
to allow an exception.</t>
            </dd>
            <dt>Identity Verification Method Description:</dt>
            <dd>
              <t>Brief description of the Identity Verification Method
(e.g., "Physical ID Document verification").</t>
            </dd>
            <dt>Change Controller:</dt>
            <dd>
              <t>For Standards Track RFCs, state "IETF". For others, give the name of the
responsible party. Other details (e.g., postal address, email address, home page
URI) may also be included.</t>
            </dd>
            <dt>Specification Document(s):</dt>
            <dd>
              <t>Reference to the document or documents that specify the parameter,
preferably including URIs that
can be used to retrieve copies of the documents.
An indication of the relevant
sections may also be included but is not required.</t>
            </dd>
          </dl>
        </section>
        <section anchor="initial-registry-contents">
          <name>Initial Registry Contents</name>
          <section anchor="dbv-method">
            <name>"dbv" Method</name>
            <ul spacing="normal">
              <li>
                <t>Identity Verification Method Name: dbv</t>
              </li>
              <li>
                <t>Identity Verification Method Description: Database Verification of PII</t>
              </li>
              <li>
                <t>Change Controller: IETF</t>
              </li>
              <li>
                <t>Specification Document(s): <xref target="dbvMethod"/> of this specification</t>
              </li>
            </ul>
          </section>
          <section anchor="dbv1-method">
            <name>"dbv1" Method</name>
            <ul spacing="normal">
              <li>
                <t>Identity Verification Method Name: dbv1</t>
              </li>
              <li>
                <t>Identity Verification Method Description: Database Verification of PII One Source</t>
              </li>
              <li>
                <t>Change Controller: IETF</t>
              </li>
              <li>
                <t>Specification Document(s): <xref target="dbv1Method"/> of this specification</t>
              </li>
            </ul>
          </section>
          <section anchor="dbvm-method">
            <name>"dbvm" Method</name>
            <ul spacing="normal">
              <li>
                <t>Identity Verification Method Name: dbvm</t>
              </li>
              <li>
                <t>Identity Verification Method Description: Database Verification of PII Multiple Sources</t>
              </li>
              <li>
                <t>Change Controller: IETF</t>
              </li>
              <li>
                <t>Specification Document(s): <xref target="dbvmMethod"/> of this specification</t>
              </li>
            </ul>
          </section>
          <section anchor="dig-method">
            <name>"dig" Method</name>
            <ul spacing="normal">
              <li>
                <t>Identity Verification Method Name: dig</t>
              </li>
              <li>
                <t>Identity Verification Method Description: Digital ID Document Verification</t>
              </li>
              <li>
                <t>Change Controller: IETF</t>
              </li>
              <li>
                <t>Specification Document(s): <xref target="digMethod"/> of this specification</t>
              </li>
            </ul>
          </section>
          <section anchor="phy-method">
            <name>"phy" Method</name>
            <ul spacing="normal">
              <li>
                <t>Identity Verification Method Name: phy</t>
              </li>
              <li>
                <t>Identity Verification Method Description: Physical ID Document Verification</t>
              </li>
              <li>
                <t>Change Controller: IETF</t>
              </li>
              <li>
                <t>Specification Document(s): <xref target="phyMethod"/> of this specification</t>
              </li>
            </ul>
          </section>
          <section anchor="sec-method">
            <name>"sec" Method</name>
            <ul spacing="normal">
              <li>
                <t>Identity Verification Method Name: sec</t>
              </li>
              <li>
                <t>Identity Verification Method Description: Secondary Document Verification</t>
              </li>
              <li>
                <t>Change Controller: IETF</t>
              </li>
              <li>
                <t>Specification Document(s): <xref target="secMethod"/> of this specification</t>
              </li>
            </ul>
          </section>
          <section anchor="inp-method">
            <name>"inp" Method</name>
            <ul spacing="normal">
              <li>
                <t>Identity Verification Method Reference Name: inp</t>
              </li>
              <li>
                <t>Identity Verification Method Reference Description: In-person Verification</t>
              </li>
              <li>
                <t>Change Controller: IETF</t>
              </li>
              <li>
                <t>Specification Document(s): <xref target="inpMethod"/> of this specification</t>
              </li>
            </ul>
          </section>
          <section anchor="vid-method">
            <name>"vid" Method</name>
            <ul spacing="normal">
              <li>
                <t>Identity Verification Method Reference Name: vid</t>
              </li>
              <li>
                <t>Identity Verification Method Reference Description: Video Verification</t>
              </li>
              <li>
                <t>Change Controller: IETF</t>
              </li>
              <li>
                <t>Specification Document(s): <xref target="vidMethod"/> of this specification</t>
              </li>
            </ul>
          </section>
        </section>
      </section>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="RFC7519">
          <front>
            <title>JSON Web Token (JWT)</title>
            <author fullname="M. Jones" initials="M." surname="Jones"/>
            <author fullname="J. Bradley" initials="J." surname="Bradley"/>
            <author fullname="N. Sakimura" initials="N." surname="Sakimura"/>
            <date month="May" year="2015"/>
            <abstract>
              <t>JSON Web Token (JWT) is a compact, URL-safe means of representing claims to be transferred between two parties. The claims in a JWT are encoded as a JSON object that is used as the payload of a JSON Web Signature (JWS) structure or as the plaintext of a JSON Web Encryption (JWE) structure, enabling the claims to be digitally signed or integrity protected with a Message Authentication Code (MAC) and/or encrypted.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="7519"/>
          <seriesInfo name="DOI" value="10.17487/RFC7519"/>
        </reference>
        <reference anchor="RFC2119">
          <front>
            <title>Key words for use in RFCs to Indicate Requirement Levels</title>
            <author fullname="S. Bradner" initials="S." surname="Bradner"/>
            <date month="March" year="1997"/>
            <abstract>
              <t>In many standards track documents several words are used to signify the requirements in the specification. These words are often capitalized. This document defines these words as they should be interpreted in IETF documents. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="2119"/>
          <seriesInfo name="DOI" value="10.17487/RFC2119"/>
        </reference>
        <reference anchor="RFC8174">
          <front>
            <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
            <author fullname="B. Leiba" initials="B." surname="Leiba"/>
            <date month="May" year="2017"/>
            <abstract>
              <t>RFC 2119 specifies common key words that may be used in protocol specifications. This document aims to reduce the ambiguity by clarifying that only UPPERCASE usage of the key words have the defined special meanings.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="8174"/>
          <seriesInfo name="DOI" value="10.17487/RFC8174"/>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="RFC5226">
          <front>
            <title>Guidelines for Writing an IANA Considerations Section in RFCs</title>
            <author fullname="T. Narten" initials="T." surname="Narten"/>
            <author fullname="H. Alvestrand" initials="H." surname="Alvestrand"/>
            <date month="May" year="2008"/>
            <abstract>
              <t>Many protocols make use of identifiers consisting of constants and other well-known values. Even after a protocol has been defined and deployment has begun, new values may need to be assigned (e.g., for a new option type in DHCP, or a new encryption or authentication transform for IPsec). To ensure that such quantities have consistent values and interpretations across all implementations, their assignment must be administered by a central authority. For IETF protocols, that role is provided by the Internet Assigned Numbers Authority (IANA).</t>
              <t>In order for IANA to manage a given namespace prudently, it needs guidelines describing the conditions under which new values can be assigned or when modifications to existing values can be made. If IANA is expected to play a role in the management of a namespace, IANA must be given clear and concise instructions describing that role. This document discusses issues that should be considered in formulating a policy for assigning values to a namespace and provides guidelines for authors on the specific text that must be included in documents that place demands on IANA.</t>
              <t>This document obsoletes RFC 2434. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="5226"/>
          <seriesInfo name="DOI" value="10.17487/RFC5226"/>
        </reference>
        <reference anchor="RFC8485">
          <front>
            <title>Vectors of Trust</title>
            <author fullname="J. Richer" initials="J." role="editor" surname="Richer"/>
            <author fullname="L. Johansson" initials="L." surname="Johansson"/>
            <date month="October" year="2018"/>
            <abstract>
              <t>This document defines a mechanism for describing and signaling several aspects of a digital identity transaction and its participants. These aspects are used to determine the amount of trust to be placed in that transaction.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8485"/>
          <seriesInfo name="DOI" value="10.17487/RFC8485"/>
        </reference>
        <reference anchor="I-D.skyfire-oauth-kyapay-token">
          <front>
            <title>KYAPay Token</title>
            <author fullname="Ankit Agarwal" initials="A." surname="Agarwal">
              <organization>Skyfire Systems Inc.</organization>
            </author>
            <author fullname="Michael B. Jones" initials="M. B." surname="Jones">
              <organization>Self-Issued Consulting</organization>
            </author>
            <date day="19" month="July" year="2026"/>
            <abstract>
              <t>   This document defines a token format for agent identity and payment
   tokens in JSON Web Token (JWT) format.  Authorization servers and
   resource servers from different vendors can leverage this token
   format to consume identity and payment tokens in an interoperable
   manner.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-skyfire-oauth-kyapay-token-01"/>
        </reference>
        <reference anchor="OpenID.Core" target="https://openid.net/specs/openid-connect-core-1_0.html">
          <front>
            <title>OpenID Connect Core 1.0 incorporating errata set 2</title>
            <author initials="N." surname="Sakimura" fullname="Nat Sakimura">
              <organization/>
            </author>
            <author initials="J." surname="Bradley" fullname="John Bradley">
              <organization/>
            </author>
            <author initials="M. B." surname="Jones" fullname="Michael B. Jones">
              <organization/>
            </author>
            <author initials="B. de" surname="Medeiros" fullname="Breno de Medeiros">
              <organization/>
            </author>
            <author initials="C." surname="Mortimore" fullname="Chuck Mortimore">
              <organization/>
            </author>
            <date year="2023" month="December" day="15"/>
          </front>
        </reference>
        <reference anchor="IANA.JWT.Claims" target="https://www.iana.org/assignments/jwt">
          <front>
            <title>JSON Web Token Claims</title>
            <author>
              <organization>IANA</organization>
            </author>
            <date/>
          </front>
        </reference>
        <reference anchor="IANA.AMR" target="https://www.iana.org/assignments/authentication-method-reference-values">
          <front>
            <title>Authentication Method Reference Values</title>
            <author>
              <organization>IANA</organization>
            </author>
            <date/>
          </front>
        </reference>
        <reference anchor="OpenID.IDA" target="https://openid.net/specs/openid-ida-verified-claims-1_0.html">
          <front>
            <title>OpenID Identity Assurance Schema Definition 1.0 incorporating errata set 1</title>
            <author initials="T." surname="Lodderstedt" fullname="Torsten Lodderstedt">
              <organization/>
            </author>
            <author initials="D." surname="Fett" fullname="Daniel Fett">
              <organization/>
            </author>
            <author initials="M." surname="Haine" fullname="Mark Haine">
              <organization/>
            </author>
            <author initials="A." surname="Pulido" fullname="Alberto Pulido">
              <organization/>
            </author>
            <author initials="K." surname="Lehmann" fullname="Kai Lehmann">
              <organization/>
            </author>
            <author initials="K." surname="Koiwai" fullname="Kosuke Koiwai">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
      </references>
    </references>
    <?line 400?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>We would like to thank
Jean Diaconu
and
Rob Zagarella
for their contributions to the specification.</t>
    </section>
    <section numbered="false" anchor="document-history">
      <name>Document History</name>
      <t>[[ to be removed by the RFC Editor before publication as an RFC ]]</t>
      <t>-02</t>
      <ul spacing="normal">
        <li>
          <t>Described that the "ivm" claim contains a set of identity verification methods that succeeded.</t>
        </li>
        <li>
          <t>Described the relationship to the OpenID Identity Assurance claims.</t>
        </li>
        <li>
          <t>Added {:vspace} syntax to definition list entries.</t>
        </li>
      </ul>
      <t>-01</t>
      <ul spacing="normal">
        <li>
          <t>Added "dbv1", "dbvm", "inp", and "vid" methods.</t>
        </li>
        <li>
          <t>Added Nash Ali and Srinivasa Thumma as authors.</t>
        </li>
      </ul>
      <t>-00</t>
      <ul spacing="normal">
        <li>
          <t>Initial draft.</t>
        </li>
      </ul>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA8Vb63IbN5b+30+Bpasm0ixJmUo88crZjGnJTuRYtlaS7cpm
UhmwGyQRdTc4DbRoxqV32WfZJ9vvHKBvFC1KTlKbH3ETDRycG87lQ2swGERO
u1QdiN5xonI8r8Q7VeipjqXTJhcnys1NYsU7mZbK9qIHcjIp1BXm9yJMUTNT
rA6EdUkUJSbOZQZSSSGnbmAvV1NdqIGRpZsPdDK4atEdPNyPbDnJtLX45VYL
LDt+fvFCiAdCptaAvs4TtVA5cdXri55KtDOFlin9OB4/wz+mwNPZxQtwlZfZ
RBUHUQKWDqLY5FbltrQHwhWlisDul5EslDwQ5youC0gZLU1xOStMuTgQ79VE
jMEkyP/mpT4tjDOxSaNLtcLE5CASAyFnYIUedNBUPahjelzIVRZmxCbLVBFj
Z5WXYEiImXbzcgKxKrV8WP22dwdFQTYsDnx+Rz+8st6DfZ3PxHf0ioYzqVOa
8lR9kNkiVUPwQOOyiOcHYu7cwh7s7bVe7oGcECkUZh34qma0+Bt6pofa3IXT
u8wZzl2W9qJIsrYPogE48D4zzi+1E+OZLJYyxagpZjIP5oDVPFFxvrJOZVYc
5/EQk5QXWtLaX6Rf+3Ql58aw9ELA1I3sgbMhJOONdQ7/OBmKlyZXtmbkRMdz
qVLxrHmxxotKp4Nja0uViEM4Wpk6GKLhJvMEfpn88iutfzo3jl5s5IhIaSY1
1PnU7LUU8lrauRin+sb+zz8soFGZNzvmmDqUqYbp/SveqyF1XuhcX0krxcW8
zDJ5g+T4UoJSQ9A6nvdU8jhTi3JTZJh+xd589uLw60ej/ziIImK7++LR/v7f
wuPjrx4/osfjwdGw6xeXK4njMnDmUuU04w1O+vHR8NAUTAZeLouZco2qDCbo
ZJgrt2cXKrZhYICjnqvY4V/QHv3ykD3MUwhxzZMmU9FEQVuI0fAhzI81C1NI
Mp9QBR6ksMqJ/R6v51Ai9h/ufzkY7Q9Gj3iwclzB/w1qWzlxLi91VhZy7dVL
M8/Fs0ImqVqtvdrgae3XzwqVG5EohOBE6cKsvz+cl/GlODGF0xlkIjWPX4+H
L99fDA9TqTN7cIPjAdn9gOdtVPJyuRzCfeQQ0/YkQvMsp4hm935durZOX56/
ec1R84LsJ/x2LaVNEcJrhsYnZ38gJ0SEI65PIxmnp0GhpgrqitXgivNUm9lx
Z0VIaOKsWhEy2wbug08eH43v55I6kSHoKfgn6+ZWz6wT7xiRoJDE03k8x1EU
R2qKk8ts3+qxo7bHjsTLMl2R4/7tFpe9MAVCaS5emSRR9Ji4tRlHCBDwzhfK
rb85kcWl+F7qXK29GKdIws6I0zLViVl7+YPU4pWaZzLP198YW14q/KOXiELR
cDiMosEAuXViXSFjF0U/5GZJMs/NUkiBIGdN/oWtE7FYSisqlYtY5mKihM6g
KidzJ5awP/Ij50vUA9bhVMWaCg87jC7m2gqyX1PzJKR2ZbETWw/5JRHerwSC
HS1OZVGxA+fawhCkYXEynSAKREjKx7krTFLGtNv/l3DEd09fZT2xc2vlt7tZ
CdpFn6eLY8cFnohRjjlWcqFmGoZeMd27VKER8cIHA0nvtyBLTWWJooVHArde
YFqA0XV1wDYXmFpa1HHCTO+tlYUsZJqqlHhAEvAUop7MClDYGHlsE3o6ui0t
eK3ICbvKnfwwjE4LZTlKgbL0EnlBVFiKKpnoq8CAY2FqUaq3SVRbo12OCR8+
hS3jWCHLJEEdXgN+AyRYh6NOhqJQA8K3kQpstAjC3okBe7lxYlGYK6wWiv5P
UpHF2YuwBXQI4sGNYEboiEQBifO5KdPEU07VFdSDiX4NnYVEWRQWST+6bzz9
+LEJ8dfX1dGiPfuRgheponGmlkq48bCKbOVUuhpGr/SlWmqr+nCVGE0KC3LB
Z/Hjx1AGdekLBMlKGZS8gzT32zZ6P9ep8k5944yi2xFoTRT8SSxKZA2kNHrd
ZgKOJPPVejbfQQWx6xmnGu/6uh+hOmGviqX1NgNrcD3Lg6Dyw4/jU7kSXM1Z
LL293ru+poj4gCqyK7KUIecCa411rHfDS3IDdF9W9E7enl9Q40f/itdv+Pns
+X+9PT57fkTP59+PX72qH6Iw4/z7N29fHTVPzcrDNycnz18f+cUYFZ2hqHcy
/hFviKvem9OL4zevx696dQRBo1tSNcJKhiUpHudOFYtC4agJaSO4ZFzoidfx
s8PT//2f0VfQy79Bp/sj0mn48Xj09Vf4QTHc72ZypG7/k05BJBcLJQu2VJpC
/wvtED0xF3EMRyUX8BYFdf71J9LMzwfim0m8GH31bRgggTuDlc46g6yzmyM3
FnslbhjasE2tzc74mqa7/I5/7Pyu9N4a/ObvKUK5GIwe//3biH3o9nTx8QGO
z3UU0qCKf28CjMLh4tPDZxQ9KxygCrM+ROGEIuaXKdnttlAZtULcMeXwnHLl
yva9l7VTCzi9X0qJWlmvDnPU+tDho3jlCfaDBjSFd5z7IOpyjnBRZRtKt/D0
gg44R2Ck2VY26MT9WqJ+VB0Wihnsr7fqoh8hqlHkA5lcdIv8KkvVRT4Km+jB
gzsaj5sT7wn8eN1OcXezPGkn4ijp1QCpSaoBYUyaOl80zFQDBSVQVPDCouIp
uFy6Nf3a4AMvqKzKraOM1a/ieKZnc7fmYBPj5tFivrIYS5to1CFNwQT9gJxQ
yD49Pt68ccsD37VcO1QY7TIgHHSEumlhMrwmD/E1F2hUSyJq6LZAib26VIsU
hJ3An+YgMFnBUbHhWXh5ff0k4pPETHF12yS6pUY0zJVPpHJWKEixMJ7rTKFx
IWOYaURHqsxbbLYOcB9ujg4c525FYlGdoz64ujz0PnabJKEa9b7ln4NzTU2a
+pr+1vWhV5Wc//1xnaw2F6kPyN+TyRVc9qiyaockfBJW3q1If3yAyf4ZPH08
uLILGavrCKMHEfV2n6YhdjLpoBf8ovZsTyYJilC7l5jJnrX5HlrcvlAuHu4S
nMWWwZEt88AyhPBgLB8TwscyPBeK+hWam3DTasoC57iRa7RFMPEGcf+cV3Vl
HG0WcvQnSElV0O0CNfJk2+Q5IdhwkVZC2a5U2Wapsj9BqpqRO9pKz0g0PaNC
RKDaPqrCT5udtjR6tkkYPWNZttARO1RtBtBanJgJFbxHBUJugQ7zlY4RgaG7
wBtCIng7rQLjHZjDig3MYZSY20qoy92VltzMYoHTGRXLC1cWdSuGsEkVI8Ly
RMaXNHr0iir6U2kt6Vss5oa6AjSilTyoWCDPuYJlEonOdps0mL9BGoySNFvI
3JRlIvNLJDZkHUbe+gIRCqkJPXdntHQ6pQAH01BhOjOwDWN1AdiGRAQJVG7n
JdP5gpJvPvBowacEwrQNAmGUBNq8OmyAzgobvEPaNZ8ijikbiGOUiN9cKXZS
yvRX/ILL/SutlrtchVaXSnwfgAmFbHUxtnoZd162cIloWwdGbUBK/dXm5AAO
TnEmZLyZgUV492fuz3l/fXMYYiNSLEKODwbbAFJVGdvXvk06PQyYR6vW2LhD
j5rQLhoOKW6UG7WAVYblgofno6UKu71mjBJv6pEj7u4W/u7k1lqHlqCgnSnS
jSsghypuAv9icOul0V+b8v7A10i+kL32oWVdeVvrllr/K1+61BXXRlM0SvPG
uF+FR0Hln9jjn1UTxQW0SpWvWLkAGrKX1vhdgUBVJGGzreUTgxqy6Q28k6o1
Ibhsrho/7TYCo12fu0vh1umxmhqQvOldg8K0qk+uy/0FnoMRKIBE7IV0ZwZ7
Iq1TrzHFbMjk5qhrB0ulLkGD5hK2qg2TIRb/kronvy7dABsM/ISnWrkpXZn8
Zeae8I0w3UxSw9avFsnkSns4kcoZWIfhJ3i0nuUEFAbuyCgU5gilRamxMI7U
gdDPkc9gipxw3GecYsP6IPq/oAXny3RYB5UE0lsUTC2RP9pAGBFKTVPPSLEo
4XkxIo+MUYFYPUnXDOtN4JuDGvCdKBpo1N6PrKnRUV2wCHmikoD6BkSM9QBh
NbZDNcuXIsYQItqOVpVIBCfkrnK2oGlujRkfC/ayHrgsGXsTCKLQXKGpj7Pl
5FcVu2hHDWdDQqQ8WSJYMX4HFzyoEnZvl+BAjWCQBzC85S+fNBF3UQFxZOau
yCOg03zVhtQ7gvf524YyZ3aqpqy6caj0EbZnddD55FAcHakcHmQrrcC50hJm
h2bUh0Uq87px7Qs9JYZge4Qe9MK2nM2wt0cK2WcYJjZ076Eiv6PXHwPP1k7L
dPgJu9UtOtkYas74CFOPLqvzlRpE7ABF7I9QBa9s5SWTwpTUkAdBj5+ff4dC
VDrngcxop2pVlfgGneusPpHfdpxkN3iJNWkZkijH1YwwY8YAyeMXromK5SJh
lD9035uPHFQdlJvogtyLQMNacr9lSydda7X5I34c4R5B8ypprhcs8uGm3RW5
pMcolG0OeVf7ZD2GDpZz06zYODcKQHPIOHe7xm1ST1UBjE/OOCIfogajjyPC
BYVXEyzKflZ13hsFC44aVe5CSlrOVYCrqL4yBK8nXTGSkv2XbKY+YJhWTcuc
MUhJkfNJVBHRrOpUXypfZE04PlfofXUQONxG0El3GYILvN07DWkMDRu2SlW1
jvZrtqrDJINasSvhIasQMQkUecL5tD27K1RT+QgGY5QsQu3UOW0XClEJsrcr
61vDGRdZqLupEqDOtZU6qhBJnedudfuwGSLkD1vEVGYUxAl+SGGXlEqKlC26
cZGlL4meqVjSZYYU9CEJuhiZbq6uSOyKB5zf+uMfNM18VedCde3NiFgJ4RE0
va1a0HdznlhczIVLFnTTPhj4dxo9E12aUer8QLdp4rFAkUgX4lSkEPxsSscc
ZwuVpj7pSesPdmLQuJNkSONTGZPz0EnbnL6ZBY49fHcIV8JCZKqcSj8lxueH
x8ftvcEPTgQjBKakGf8qUSCInS96X+zWLa5N6QumnS/+8Y8vCG3YoY3eIm8Y
xPw1OQQPLoymiuDtvz98uD/q+3+/pCqIQi7/fPSMb0lAjX8ddV5+/XyX5SWT
sUABfBY1TEuvydEsY36k24CWsLO36rScJ9Gliwd6dd5AvfT9gioIPslTZJpP
BQ1ukWsjF/683TQV6BCCSf2NT4QU9X1CuOPJaTcjEX01pNW0c04D/nAbETJP
OGUbQY/OB4m7Hd5utjdggpDscycJbkAhf1EQ4IEqFw7t1dKjTz17Q57Hyifg
gJRbO2O4SKdzZRfUVpKXERy8Goo3bK7qzjgwjghMQFIAvPr+S7bm59xkirEV
8p2z4132AP4OgS/vOMAnHcHOO6e+UsWO3SUBz9bbjRqEp9vs8FzdhTMhn13o
TiejNNLnA0ZUcMJWgQNyCzDn12HC2oVxoRyMe0VRZUGoeDBsvR259ziv7gpa
pkf4Q6qlL1OrSzC7UX4xKTlM0cmg+Eu36tzeU0PpP7doWkeyOO3KrytwOrgT
Wtbt0V5gxbaJnU77NuBzc6NNboY3nzYlioQGJ7+ln25Q6vtKOPrDRGxB4L9L
2tGdxc3uL272x4m7jpD/LqGzOwpN6Pb9ZNaz+4m8BfH+HVLWQPsWIRkmv5eQ
WHEvIbci558vZYPYb5GSwfN7SYkV95JyC6L++TI2OP4WGRlGv6OMTcoKgGa+
uPuSLuK5GXj/bHEblH+LuAzqf6a4WPuZ4t68Cvh8UZs7h0+Kyp+KUv3MuPo4
vszNMlXJjFM86pNwu6qS/+zxh8q96yh6j36a+1nqIX1JIvPL6KVCAXGkJdy0
pL4uOjMT8d/0dxKoQWXVX+uC774LPSnr1uUGgupR/trPv0cNYIrVJ9j56afQ
/hQqM1dNb40SUDznP+PByyn1WR7gC8APARg85+efoYWH+2Tjo/pDqrpf+iM/
TuxuoHyjSEqY60Wlh09/Vei/7SYq44TKp7p4DJ9vch/WfHLIcJgiTfMXLIOH
o6he6quLfki7fX+0wwdo7PZ1r1qtqP4+hOes/4UHK5O/+/Y7PeTzEko4/jud
YfR/xmedtPw1AAA=

-->

</rfc>
