The Passport Solved Digital Identity. mDocs Finish the Job.
For years, verifiable credentials have been framed as a new idea. Something experimental. Something still searching for adoption.
The Passport Solved Digital Identity. mDocs Finish the Job.

ePassports: The verifiable credential we’ve been carrying around for decades without realising it.
For years, verifiable credentials have been framed as a new idea. Something experimental. Something still searching for adoption.
That framing is wrong.
The world has already operated the largest and most successful verifiable credential system ever built, and it has done so for decades. We call it the passport. Its close sibling, the national identity card, follows the same model.
Long before blockchains, DIDs, or digital wallets entered the conversation, passports solved the hardest problems digital identity still struggles with today.
“The verifiable credential problem was solved long before we gave it a name.”
Verifiable credentials were never the hard part
A verifiable credential, at its core, is simple. It is issued by an authoritative entity, cryptographically signed, and verifiable by third parties without needing to contact the issuer.
That description fits modern passports and many national ID cards perfectly.
They carry signed identity data. They are validated by independent verifiers. They work offline. They interoperate globally. They have been doing this reliably for years.
The uncomfortable truth for the digital identity ecosystem is that verifiable credentials themselves were never the hard part.
“We did not fail to invent verifiable credentials. We failed to recognise that we already had them.”
What actually scaled was centralised trust with decentralised verification
Early digital identity thinking leaned heavily into decentralising trust itself. The idea was philosophically appealing but operationally flawed.
What actually scaled was a different architecture. Trust was centralised at issuance, anchored in sovereign authorities and audited PKI roots. Verification was decentralised, open, and offline. Any verifier could validate a credential without negotiating bilateral trust or relying on live systems.
Passports proved that decentralised verification scales. Fully decentralised trust does not.
“Decentralised verification scaled. Fully decentralised trust did not.”
This is not an opinion. It is an outcome demonstrated at global scale.
The global trust problem passports had to solve
At scale, the hardest problem for passports was never cryptography. It was trust distribution.
Each country issues passports using its own signing keys. Without coordination, every border authority, airline, or inspection system would need to individually establish trust with more than one hundred issuing states. That approach collapses under its own weight.
The International Civil Aviation Organization’s Public Key Directory (ICAO PKD) changed this.
ICAO PKD aggregates national signing certificates into a single governed repository. Issuers remain sovereign. Verifiers retrieve trust material from one place. Bilateral agreements disappear. Global verification becomes practical.
“PKD did not centralise trust authority. It centralised trust distribution.”
This was not accidental. It was deliberate governance. And it is the reason passports work everywhere.
The scale already exists, largely unnoticed
This model is not limited to passports.
Vietnam provides a clear illustration. Today, more than 70 million Vietnamese citizens already carry chip-based national identity cards that are ICAO-compatible, cryptographically signed, and machine-verifiable. These credentials already satisfy the technical prerequisites for use as mobile documents.
No re-issuance is required. No mass re-enrolment is needed. No policy reset is necessary.
At a global level, the implication is straightforward:
“The future of digital identity already exists at massive scale, across roughly 1.5 billion ePassport and eID credentials worldwide. It is not missing. It is dormant.”
mDocs are evolution, not reinvention
Mobile documents (mDocs) do not replace what works. They extend it.
They preserve issuer trust, PKI verification, and offline capability. At the same time, they eliminate over-disclosure, image uploads, and manual document inspection.
mDocs move identity verification from photographs to signed data.
“Identity verified as images is structurally insecure. Identity verified as data is not.”
mDocs are the only viable convergence point
At this point, it is worth stating the conclusion plainly.
Among all digital identity approaches currently proposed, mDocs are the only model that satisfies every real-world constraint at once.
They work in person, inside apps, and on the web using the same credential. They enjoy native support across mobile platforms and emerging first-class support in browsers. They inherit trust from existing government-issued documents.
Other approaches fail somewhere critical.
“mDocs are not one option among many. They are the only approach that survives contact with reality.”
The benefits are structural, not incremental
For users, the impact is immediate.
They stop uploading identity documents to dozens of services. They stop leaking high-value personal data. They disclose only what is required. Identity theft risk collapses because credentials are verified cryptographically rather than copied and stored.
“The safest identity document is the one you never upload.”
For businesses, the gains are just as decisive.
Fraud drops because forged documents stop passing verification. KYC costs collapse as manual review is replaced with deterministic checks. Onboarding friction falls. Conversion rises. Liability becomes easier to manage.
“This is one of the rare moments where security, cost, and user experience improve together.”
Platform passport-derived mDocs are the near-term catalyst
The fastest path to adoption is platform-enabled, passport-derived mobile documents.
By projecting already trusted passports into mobile wallets, Apple and Google are not reinventing identity. They are activating it. Years of government system redesign are bypassed. Existing credentials are unlocked at scale.
“This is not innovation. It is activation.”
Even when rollouts start in limited markets, the model scales globally by default because it relies on existing standards, PKI, and international trust frameworks.
Actively managed mDocs are unavoidable in the long term
Platform conversion is an on-ramp, not an end state.
Long-term sustainability requires actively managed mDocs issued directly by authorities. Lifecycle control, revocation, governance, and accountability cannot be outsourced indefinitely.
“Conversion unlocks scale. Issuance sustains legitimacy.”
Any system that ignores this distinction will eventually fail under regulatory and operational pressure.
Verifier behaviour will shape the outcome
Verifier behaviour is not neutral.
Verifiers optimise for simplicity, cost, and liability reduction. They will choose the simplest trust model available, regardless of ideology.
“Verifiers will always choose convenience over architecture.”
If unmanaged (passport-derived) platform trust is the easiest option, trust will concentrate by default. This is not a risk. It is a certainty.
Why mDocs need a PKD-style trust fabric
The passport ecosystem avoided trust concentration because ICAO PKD aggregated trust without replacing issuers.
This was a deliberate intervention.
mDocs require the same pattern. Without a global trust fabric, platforms will become de facto trust anchors by accident rather than by design.
“Global scale requires global trust distribution. Fragmented trust does not scale. Concentrated trust does not endure.”
The next phase is not optional
Mobile wallets, browsers, mDoc standards, and verification APIs are converging now.
Identity verification will move from document images to signed data. Identity will become a platform capability. Image-based KYC will soon look reckless in hindsight.
“The next identity revolution will arrive as a default user experience, not a policy announcement.”
The only open question is whether trust will be shaped deliberately or inherited accidentally.
Final thought
Verifiable credentials are not new. They are proven.
The passport solved digital identity. mDocs finish the job!
메타데이터
- post_id
- c8e1946c4f59
- slug
- the-passport-solved-digital-identity-mdocs-finish-the-job-c8e1946c4f59
- url
- https://medium.com/@o.sanderson/the-passport-solved-digital-identity-mdocs-finish-the-job-c8e1946c4f59
- canonical_url
- https://medium.com/@o.sanderson/the-passport-solved-digital-identity-mdocs-finish-the-job-c8e1946c4f59
- author_url
- https://medium.com/@o.sanderson
- status
- ok
- fetched_at
- 2026-07-18 00:11:11