Regulation

What is Attestation rulebook?

An attestation rulebook specifies one credential type in full: attribute set, encodings, mandatory and optional fields, credential format and trust requirements. Rulebooks are written by Attestation Scheme Providers and listed in the Commission catalogue of attestation schemes. They are what makes credentials interoperable in practice.

In detail

How it actually works

Standards like OpenID4VP say how to request and present a credential, not what a driving licence or a diploma contains. The rulebook fills that in, so a verifier knows a PID from any member state carries the same mandatory attributes under the same identifiers.

The Commission maintains the rulebooks for PID and mDL. Sectoral and cross-border organisations are expected to write the EU-wide rulebooks for other types, and the ARF deliberately does not say which organisation owns which type. An individual provider can add a provider-specific rulebook on top of an EU-wide or sectoral one to carry domestic attributes, and a single organisation can write one for an attestation used only internally.

A rulebook now travels with a machine-readable partner. The rulebook is documentation for people, the attestation scheme is the specification software reads to build requests and verify responses, and the catalogue is where both are found. Listing there is optional and obliges nobody to accept the credential.

They are versioned separately from the ARF main document, so credential-level changes can land without a full framework revision.

Defined in

EUDI Wallet ARF v3.0.0 section 5.5 and Annex 2 Topic 12; Regulation (EU) 2024/1183 Art. 45e(2)

Why it matters

What this changes for you

Interoperability lives in the rulebook, not the protocol spec. Two implementations can both be correct and still fail against each other.

Authbound handles the protocols, formats, trust lists and revocation checks behind these terms. See what people build with them.