)]}'
{"id": 6492906882990080, "name": "More specific protocol filtering in Digital Credential API", "summary": "Chrome 151 began deprecating support for unspecified presentation and issuance protocols in the **Digital Credentials API**; final removal is scheduled for Chrome 160.\n\nThe Digital Credentials API was originally designed to be an opaque pipeline for arbitrary exchange protocols. In November 2025, the [FedID WG resolved](https://github.com/w3c-fedid/digital-credentials/issues/396) to change this so that the spec normatively referenced only a specific set of exchange protocols.\n\nThe removal of support for arbitrary, opaque pipelines ensures that only verified protocols are used, enabling a more robust privacy and security threat model for identity verification. This change aligns Chromium with updated industry specifications that normatively reference only a specific set of exchange protocols. ", "markdown_fields": ["summary"], "blink_components": ["Blink>Identity>DigitalCredentials"], "star_count": 33, "search_tags": [], "created": {"by": "rbyers@chromium.org", "when": "2026-06-05 20:03:23.522423"}, "updated": {"by": "siobhankeating@google.com", "when": "2026-08-26 12:57:01.414230"}, "category": "Miscellaneous", "category_int": 2, "feature_notes": null, "web_feature": null, "is_official_web_feature": null, "webdx_usecounter_enum": null, "enterprise_feature_categories": [], "enterprise_product_category": 0, "is_releasenotes_content_reviewed": true, "is_releasenotes_publish_ready": true, "stages": [{"id": 6657572963745792, "created": "2026-06-05 20:03:25.123024", "feature_id": 6492906882990080, "stage_type": 410, "display_name": null, "intent_stage": 1, "pm_emails": [], "tl_emails": [], "ux_emails": [], "te_emails": [], "intent_thread_url": null, "announcement_url": null, "experiment_goals": null, "experiment_risks": null, "origin_trial_id": null, "origin_trial_feedback_url": null, "ot_action_requested": false, "ot_approval_buganizer_component": null, "ot_approval_buganizer_custom_field_id": null, "ot_approval_criteria_url": null, "ot_approval_group_email": null, "ot_chromium_trial_name": null, "ot_description": null, "ot_display_name": null, "ot_documentation_url": null, "ot_emails": [], "ot_feedback_submission_url": null, "ot_has_third_party_support": false, "ot_is_critical_trial": false, "ot_is_deprecation_trial": false, "ot_owner_email": null, "ot_requester_email": null, "ot_require_approvals": false, "ot_use_counter_bucket_number": null, "ot_webfeature_use_counter": null, "extensions": [], "experiment_extension_reason": null, "ot_stage_id": null, "finch_url": null, "rollout_milestone": null, "rollout_platforms": [], "rollout_details": null, "rollout_impact": 2, "rollout_stage_plan": null, "enterprise_policies": [], "desktop_first": null, "android_first": null, "ios_first": null, "webview_first": null, "desktop_last": null, "android_last": null, "ios_last": null, "webview_last": null}, {"id": 4616879382593536, "created": "2026-06-05 20:03:25.124779", "feature_id": 6492906882990080, "stage_type": 430, "display_name": null, "intent_stage": 2, "pm_emails": [], "tl_emails": [], "ux_emails": [], "te_emails": [], "intent_thread_url": null, "announcement_url": null, "experiment_goals": null, "experiment_risks": null, "origin_trial_id": null, "origin_trial_feedback_url": null, "ot_action_requested": false, "ot_approval_buganizer_component": null, "ot_approval_buganizer_custom_field_id": null, "ot_approval_criteria_url": null, "ot_approval_group_email": null, "ot_chromium_trial_name": null, "ot_description": null, "ot_display_name": null, "ot_documentation_url": null, "ot_emails": [], "ot_feedback_submission_url": null, "ot_has_third_party_support": false, "ot_is_critical_trial": false, "ot_is_deprecation_trial": false, "ot_owner_email": null, "ot_requester_email": null, "ot_require_approvals": false, "ot_use_counter_bucket_number": null, "ot_webfeature_use_counter": null, "extensions": [], "experiment_extension_reason": null, "ot_stage_id": null, "finch_url": null, "rollout_milestone": null, "rollout_platforms": [], "rollout_details": null, "rollout_impact": 2, "rollout_stage_plan": null, "enterprise_policies": [], "desktop_first": 151, "android_first": 151, "ios_first": null, "webview_first": null, "desktop_last": null, "android_last": null, "ios_last": null, "webview_last": null}, {"id": 5742779289436160, "created": "2026-06-05 20:03:25.126742", "feature_id": 6492906882990080, "stage_type": 450, "display_name": null, "intent_stage": 3, "pm_emails": [], "tl_emails": [], "ux_emails": [], "te_emails": [], "intent_thread_url": null, "announcement_url": null, "experiment_goals": null, "experiment_risks": null, "origin_trial_id": null, "origin_trial_feedback_url": null, "ot_action_requested": false, "ot_approval_buganizer_component": null, "ot_approval_buganizer_custom_field_id": null, "ot_approval_criteria_url": null, "ot_approval_group_email": null, "ot_chromium_trial_name": null, "ot_description": null, "ot_display_name": null, "ot_documentation_url": null, "ot_emails": [], "ot_feedback_submission_url": null, "ot_has_third_party_support": false, "ot_is_critical_trial": false, "ot_is_deprecation_trial": false, "ot_owner_email": null, "ot_requester_email": null, "ot_require_approvals": false, "ot_use_counter_bucket_number": null, "ot_webfeature_use_counter": null, "extensions": [], "experiment_extension_reason": null, "ot_stage_id": null, "finch_url": null, "rollout_milestone": null, "rollout_platforms": [], "rollout_details": null, "rollout_impact": 2, "rollout_stage_plan": null, "enterprise_policies": [], "desktop_first": null, "android_first": null, "ios_first": null, "webview_first": null, "desktop_last": null, "android_last": null, "ios_last": null, "webview_last": null}, {"id": 5179829336014848, "created": "2026-06-05 20:03:25.128505", "feature_id": 6492906882990080, "stage_type": 460, "display_name": null, "intent_stage": 5, "pm_emails": [], "tl_emails": [], "ux_emails": [], "te_emails": [], "intent_thread_url": "https://groups.google.com/a/chromium.org/d/msgid/blink-dev/6a29cf6a.f2d2b681.29210.0589.GAE%40google.com", "announcement_url": null, "experiment_goals": null, "experiment_risks": null, "origin_trial_id": null, "origin_trial_feedback_url": null, "ot_action_requested": false, "ot_approval_buganizer_component": null, "ot_approval_buganizer_custom_field_id": null, "ot_approval_criteria_url": null, "ot_approval_group_email": null, "ot_chromium_trial_name": null, "ot_description": null, "ot_display_name": null, "ot_documentation_url": null, "ot_emails": [], "ot_feedback_submission_url": null, "ot_has_third_party_support": false, "ot_is_critical_trial": false, "ot_is_deprecation_trial": false, "ot_owner_email": null, "ot_requester_email": null, "ot_require_approvals": false, "ot_use_counter_bucket_number": null, "ot_webfeature_use_counter": null, "extensions": [], "experiment_extension_reason": null, "ot_stage_id": null, "finch_url": null, "rollout_milestone": null, "rollout_platforms": [], "rollout_details": null, "rollout_impact": 2, "rollout_stage_plan": null, "enterprise_policies": [], "desktop_first": 160, "android_first": 160, "ios_first": null, "webview_first": 160, "desktop_last": null, "android_last": null, "ios_last": null, "webview_last": null}, {"id": 6305729242857472, "created": "2026-06-05 20:03:25.129931", "feature_id": 6492906882990080, "stage_type": 470, "display_name": null, "intent_stage": 0, "pm_emails": [], "tl_emails": [], "ux_emails": [], "te_emails": [], "intent_thread_url": null, "announcement_url": null, "experiment_goals": null, "experiment_risks": null, "origin_trial_id": null, "origin_trial_feedback_url": null, "ot_action_requested": false, "ot_approval_buganizer_component": null, "ot_approval_buganizer_custom_field_id": null, "ot_approval_criteria_url": null, "ot_approval_group_email": null, "ot_chromium_trial_name": null, "ot_description": null, "ot_display_name": null, "ot_documentation_url": null, "ot_emails": [], "ot_feedback_submission_url": null, "ot_has_third_party_support": false, "ot_is_critical_trial": false, "ot_is_deprecation_trial": false, "ot_owner_email": null, "ot_requester_email": null, "ot_require_approvals": false, "ot_use_counter_bucket_number": null, "ot_webfeature_use_counter": null, "extensions": [], "experiment_extension_reason": null, "ot_stage_id": null, "finch_url": null, "rollout_milestone": null, "rollout_platforms": [], "rollout_details": null, "rollout_impact": 2, "rollout_stage_plan": null, "enterprise_policies": [], "desktop_first": null, "android_first": null, "ios_first": null, "webview_first": null, "desktop_last": null, "android_last": null, "ios_last": null, "webview_last": null}], "accurate_as_of": "2026-06-05 20:03:23.522216", "creator_email": "rbyers@chromium.org", "updater_email": "siobhankeating@google.com", "owner_emails": ["rbyers@chromium.org", "mamir@chromium.org"], "editor_emails": [], "cc_emails": [], "spec_mentor_emails": [], "unlisted": false, "deleted": false, "editors": [], "cc_recipients": [], "spec_mentors": [], "creator": "rbyers@chromium.org", "feature_type": "Feature removal", "feature_type_int": 3, "intent_stage": "None", "intent_stage_int": 0, "active_stage_id": 5179829336014848, "bug_url": "https://crbug.com/465006289", "launch_bug_url": null, "new_crbug_url": "https://bugs.chromium.org/p/chromium/issues/entry?components=Blink>Identity>DigitalCredentials&blocking=465006289&cc=rbyers@chromium.org,mamir@chromium.org", "screenshot_links": [], "first_enterprise_notification_milestone": 150, "enterprise_impact": 2, "breaking_change": false, "confidential": false, "shipping_year": 2027, "flag_name": "#enable-experimental-web-platform-features", "finch_name": "DigitalCredentialsProtocolFilter", "non_finch_justification": null, "ongoing_constraints": null, "rollout_plan": 0, "rollout_plan_displayname": "Will ship enabled for all users", "motivation": "When arbitrary protocols were supported in the spec it made security and privacy analyses less precise since there was more ambiguity about how the API could be used in practice. In order to get more broad browser industry alignment on the privacy and security properties of the API, the specification was changed to normatively reference specific exchange protocols (which themselves have privacy and security threat models associated with them).\n\nChromium is updating to reflect this specification change because of the reduction in potential for confusion and compatibility issues by matching other browser engines, and because (contrary to original expectations) this extra flexibility was not actually being used by anyone in production. ", "devtrial_instructions": null, "activation_risks": null, "measurement": null, "availability_expectation": null, "adoption_expectation": null, "adoption_plan": null, "initial_public_proposal_url": null, "explainer_links": ["https://github.com/w3c-fedid/digital-credentials/issues/396"], "requires_embedder_support": false, "spec_link": "https://w3c-fedid.github.io/digital-credentials/#protocols", "api_spec": false, "automation_spec": false, "interop_compat_risks": "A UseCounter was added for unknown protocols in the DC API, it has fallen to essentially zero starting in April 2026: https://chromestatus.com/metrics/feature/timeline/popularity/5770\n\nLooking at more detailed internal metrics, the exact value is not exactly zero and amounts to about 3% of all DC API calls (itself very rare). We believe this represents some limited testing by developers considering migrating from custom schemes to the DC API, no real deployments. But in order to avoid negatively impacting those developers we want to hold actual removal until the start of 2027. In order to reduce the risk of surprises we want to add a deprecation warning / report now.", "all_platforms": true, "all_platforms_descr": null, "non_oss_deps": null, "anticipated_spec_changes": null, "security_risks": null, "ergonomics_risks": null, "wpt": true, "wpt_descr": "Covered by https://wpt.fyi/results/digital-credentials/get.https.html", "webview_risks": null, "devrel_emails": ["devrel-chromestatus-all@google.com"], "debuggability": null, "doc_links": [], "sample_links": [], "prefixed": null, "tags": [], "tag_review": null, "tag_review_status": "Not applicable", "tag_review_status_int": 4, "security_review_status": "Pending", "security_review_status_int": 1, "privacy_review_status": "Pending", "privacy_review_status_int": 1, "security_continuity_id": null, "security_launch_issue_id": null, "updated_display": null, "resources": {"samples": [], "docs": []}, "comments": null, "ff_views": 5, "safari_views": 1, "web_dev_views": 4, "browsers": {"chrome": {"bug": "https://crbug.com/465006289", "blink_components": ["Blink>Identity>DigitalCredentials"], "devrel": ["devrel-chromestatus-all@google.com"], "owners": ["rbyers@chromium.org", "mamir@chromium.org"], "origintrial": false, "prefixed": null, "flag": false, "status": {"text": "Proposed", "val": 2, "milestone_str": "Proposed"}, "announced": false, "desktop": 160, "android": 160, "webview": 160, "ios": null}, "ff": {"view": {"url": "https://mozilla.github.io/standards-positions/#digital-credentials", "notes": "Mozilla is officially negative on the DC API itself. In the FedID WG meeting for restricting the API to specified protocols only, Mozilla representatives argued in favor of the change.", "text": "No signal", "val": 5}}, "safari": {"view": {"url": "https://webkit.org/blog/17431/online-identity-verification-with-the-digital-credentials-api", "notes": "Supports only the org-iso-mdoc protocol already", "text": "Shipped/Shipping", "val": 1}}, "webdev": {"view": {"text": "No signals", "val": 4, "url": null, "notes": null}}, "other": {"view": {"text": null, "val": null, "url": null, "notes": null}}}, "standards": {"spec": "https://w3c-fedid.github.io/digital-credentials/#protocols", "maturity": {"text": null, "short_text": "Unknown status", "val": 0}}, "is_released": false, "is_enterprise_feature": false, "experiment_timeline": null, "ai_test_eval_report": null, "ai_test_eval_run_status": null, "ai_test_eval_status_timestamp": null}