Skip to content

feat: add credential catalog service description (registry.siros.org)#121

Open
leifj wants to merge 2 commits into
mainfrom
feat/credential-catalog-service
Open

feat: add credential catalog service description (registry.siros.org)#121
leifj wants to merge 2 commits into
mainfrom
feat/credential-catalog-service

Conversation

@leifj

@leifj leifj commented Jul 16, 2026

Copy link
Copy Markdown

Summary

This PR adds a service description for the weBuild Credential Catalog at registry.siros.org, placed in task4-trust-infrastructure-api/ alongside the existing LoTL and Trust Infrastructure API descriptions.

What's included

credential-catalog-service.md — Describes:

  • Service instance — URL, operator (SIROS Foundation), source code, status
  • Role in WP4 — Implements TS11 catalogue of attestation schemes; relationship to LoTL, Trusted Lists, and Onboarding API
  • Architecture — How registry-cli discovers, validates, and publishes credential metadata from source repositories (including webuild-attestation-rulebooks-catalog)
  • TS11 API — Endpoints for credential schema discovery
  • Onboarding — How credentials were onboarded for the pilot, and how new ones can be added (attestation rulebook PR or VCTM autodiscovery)
  • Security — JWS signing, immutable static publication, source transparency

README.md — Updated to reference the new document.

Context

Per discussion with @peppelinux — this documents registry.siros.org as the official weBuild credential catalog instance, covering how it works and how credentials are onboarded. Giuseppe will handle harmonisation and cross-linking with other deliverables.

References

leifj added 2 commits July 16, 2026 22:12
Define registry.siros.org as the official weBuild Credential Catalog,
implementing the TS11 catalogue of attestation schemes. Covers:

- Service instance details and operator
- Role in the WP4 trust infrastructure (relationship to LoTL, TLs)
- Architecture and build pipeline (registry-cli, GitHub Actions)
- Credential detection and TS11 API endpoints
- How credentials were onboarded for the pilot
- How to onboard new credential types (rulebook PR or VCTM autodiscovery)
- Security and integrity properties
…covery

- Method 1 now explains that both a JSON Schema data definition AND a
  governance rulebook are required (not just a rulebook)
- Document the full EUDI ARF directory structure expected by the
  rulebook-catalog plugin
- Explain how vct, mandatory claims, and selective disclosure are
  extracted from JSON Schema 2020-12
- Add Visual Assets section documenting SVG card template and logo
  discovery conventions (assets/<slug>/, co-located, display/)
- Update onboarding history to mention schema creation step
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant