Decentralized Identity (DID)

Last Updated Sep 24, 2026

In One Sentence

Decentralized identity is an approach to managing digital identity that reduces dependence on a single identity provider through independently verifiable identifiers and credentials.

Decentralized identity describes systems that give people or organizations greater control over identifiers and identity information. In W3C standards, DID specifically means “decentralized identifier”: an identifier associated with a subject and a document describing verification methods or services. The identifier is a building block, not a complete identity system.

Identifiers and credentials

A DID method defines how identifiers are created, resolved, updated, or deactivated. Different methods use different infrastructure; a DID does not inherently require a public blockchain or an NFT.

Cryptographic authentication can demonstrate control under the method’s rules. It does not automatically prove a legal name, age, or qualification. Such claims can come from separately issued verifiable credentials. For example, a university might issue a degree credential that a graduate presents to an employer. The employer still decides whether to trust that issuer and accept the claim.

Control needs practical safeguards

Key recovery, credential expiration or revocation, and interoperability depend on the implementation. Losing access to a controlling key can affect an identity workflow even when the identifier still exists.

Decentralization also does not guarantee anonymity. Reusing identifiers or publishing identifying information can connect activities across services. Personal data need not be placed in a public DID document to make the system useful.