Hypercerts

Trust Center

What we claim, and what tested it.

The page a due-diligence reviewer opens first. We do not summarise the results — they are listed module by module, and the features we do not support are listed too.


Conformance results

OpenID Foundation conformance suite 5.1.44, executed 2026-09-03. Three plans, 84 modules, 0 failures.

RolePlanProfileResult
Issueroid4vci-1_0-issuer-haip-test-plan
sd_jwt_vc · wallet_initiated
OID4VCI 1.0 FINAL + HAIP 1.0 FINALpassed 54 review 3 skipped 5 failed 0
Verifieroid4vp-1final-verifier-haip-test-plan
x509_hash · request_uri_signed
OID4VP 1.0 FINAL + HAIP 1.0 FINALpassed 9 skipped 1 failed 0
Walletoid4vp-1final-wallet-haip-test-plan
sd_jwt_vc · direct_post.jwt
OID4VP 1.0 FINAL + HAIP 1.0 FINALpassed 6 review 6 failed 0

These results were produced by running the suite ourselves. They are not an OpenID Foundation certification, which is a separate process of application, review and listing. Raw execution logs are available on request.


Module-level results

A pass count alone does not tell you which optional features are missing. Here is every module.

Issuer 62

  • oid4vci-1_0-issuer-metadata-test
  • oid4vci-1_0-issuer-metadata-test-signed
  • oid4vci-1_0-issuer-happy-flow
  • oid4vci-1_0-issuer-happy-flow-additional-requests
  • oid4vci-1_0-issuer-happy-flow-multiple-clients
  • oid4vci-1_0-issuer-happy-flow-skip-notification
  • oid4vci-1_0-issuer-fail-invalid-nonce
  • oid4vci-1_0-issuer-fail-invalid-jwt-proof-signature
  • oid4vci-1_0-issuer-fail-invalid-key-attestation-signature
  • oid4vci-1_0-issuer-fail-invalid-client-attestation-signature
  • oid4vci-1_0-issuer-fail-invalid-client-attestation-pop-signature
  • oid4vci-1_0-issuer-fail-client-attestation-exp-in-past
  • oid4vci-1_0-issuer-fail-client-attestation-no-sub
  • oid4vci-1_0-issuer-fail-client-attestation-pop-wrong-aud
  • oid4vci-1_0-issuer-fail-mismatched-client-attestation-pop-key
  • oid4vci-1_0-issuer-fail-missing-proof
  • oid4vci-1_0-issuer-fail-unknown-credential-configuration
  • oid4vci-1_0-issuer-fail-unknown-credential-identifier
  • oid4vci-1_0-issuer-fail-on-access-token-in-query
  • oid4vci-1_0-issuer-happy-flow
  • oid4vci-1_0-issuer-fail-unknown-credential-configuration
  • oid4vci-1_0-issuer-fail-unsupported-encryption-algorithm
  • fapi2-security-profile-final-discovery-end-point-verification
  • fapi2-security-profile-final-happy-flow
  • fapi2-security-profile-final-user-rejects-authentication
  • fapi2-security-profile-final-ensure-authorization-request-without-state-success
  • fapi2-security-profile-final-access-token-type-header-case-sensitivity
  • fapi2-security-profile-final-check-dpop-proof-nbf-exp
  • fapi2-security-profile-final-ensure-dpopproof-with-iat-10seconds-before-succeeds
  • fapi2-security-profile-final-ensure-dpopproof-with-iat-10seconds-after-succeeds
  • fapi2-security-profile-final-ensure-mismatched-dpop-jkt-fails
  • fapi2-security-profile-final-ensure-token-endpoint-fails-with-mismatched-dpop-proof-jkt
  • fapi2-security-profile-final-ensure-token-endpoint-fails-with-mismatched-dpop-jkt
  • fapi2-security-profile-final-ensure-dpopproof-at-par-endpoint-binding-success
  • fapi2-security-profile-final-ensure-dpop-auth-code-binding-success
  • fapi2-security-profile-final-ensure-different-state-inside-and-outside-request-object
  • fapi2-security-profile-final-ensure-authorization-request-with-long-state
  • fapi2-security-profile-final-state-only-outside-request-object-not-used
  • fapi2-security-profile-final-ensure-request-object-without-redirect-uri-fails
  • fapi2-security-profile-final-ensure-registered-redirect-uri
  • fapi2-security-profile-final-ensure-unsigned-authorization-request-without-using-par-fails
  • fapi2-security-profile-final-ensure-redirect-uri-in-authorization-request
  • fapi2-security-profile-final-ensure-response-type-code-idtoken-fails
  • fapi2-security-profile-final-ensure-response-type-token-fails
  • fapi2-security-profile-final-ensure-client-id-in-token-endpoint
  • fapi2-security-profile-final-ensure-holder-of-key-required
  • fapi2-security-profile-final-ensure-authorization-code-is-bound-to-client
  • fapi2-security-profile-final-attempt-reuse-authorization-code-after-one-second
  • fapi2-security-profile-final-ensure-token-endpoint-fails-with-expired-auth-code
  • fapi2-security-profile-final-dpop-negative-tests
  • fapi2-security-profile-final-refresh-token
  • fapi2-security-profile-final-par-ensure-reused-request-uri-prior-to-auth-completion-succeeds
  • fapi2-security-profile-final-par-attempt-reuse-request_uri
  • fapi2-security-profile-final-par-attempt-to-use-expired-request_uri
  • fapi2-security-profile-final-par-attempt-to-use-request_uri-for-different-client
  • fapi2-security-profile-final-par-authorization-request-containing-request_uri-form-param
  • fapi2-security-profile-final-par-attempt-invalid-http-method
  • fapi2-security-profile-final-par-ensure-pkce-required
  • fapi2-security-profile-final-ensure-pkce-code-verifier-required
  • fapi2-security-profile-final-incorrect-pkce-code-verifier-rejected
  • fapi2-security-profile-final-par-plain-pkce-rejected
  • fapi2-security-profile-final-par-without-duplicate-parameters

Verifier 10

  • oid4vp-1final-verifier-happy-flow
  • oid4vp-1final-verifier-minimal-cnf-jwk
  • oid4vp-1final-verifier-request-uri-method-post
  • oid4vp-1final-verifier-invalid-kb-jwt-signature
  • oid4vp-1final-verifier-invalid-credential-signature
  • oid4vp-1final-verifier-invalid-sd-hash
  • oid4vp-1final-verifier-invalid-kb-jwt-nonce
  • oid4vp-1final-verifier-invalid-kb-jwt-aud
  • oid4vp-1final-verifier-kb-jwt-iat-in-past
  • oid4vp-1final-verifier-kb-jwt-iat-in-future

Wallet 12

  • happy-flow
  • alternate-happy-flow
  • request-uri-method-post
  • fewer-claims-than-available
  • optional-credential-set
  • no-claims-in-dcql-query
  • negative-test-invalid-request-object-signature
  • negative-test-mismatched-client-id
  • negative-test-redirect-uri-with-direct-post
  • negative-test-missing-nonce
  • negative-test-invalid-client-id-prefix
  • negative-test-unknown-transaction-data-type

Secure development

Design
Requirements from the published specs (HAIP, OID4VCI/VP, FAPI 2.0) are written as acceptance criteria first. We do not retrofit the spec after building.
Implementation
Every change goes through a pull request with at least one reviewer.
Testing
Unit and integration tests run automatically; protocol behaviour is regression-tested with the OIDF conformance suite.
Dependencies
A CycloneDX 1.5 SBOM is produced on every build and retained. 841 components; no strong copyleft (GPL/AGPL).
Release
Shipped as container images, pinned by tag.

Vulnerability disclosure

Report to info@hypercerts.com, with [security] in the subject line. Include the affected component and version, minimal reproduction steps and expected impact.

Acknowledgement
3 business days
Assessment
10 business days
Fix target
30–90 days

We do not pursue legal action against good-faith research. Please do not disclose to third parties before a fix, and do not access other people's data or disrupt the service. Contact details are also published at /.well-known/security.txt.

Need anything else for your review?

Raw execution logs, architecture detail and security design documents are available on request.