Standards/divoc
DIVOC
Overview
DIVOC (Digital Infrastructure for Verifiable Open Credentialing) is an open-source platform that lets governments digitally orchestrate large-scale health campaigns — vaccination, testing, and certification — and issue verifiable digital certificates at national scale [1]. The certificates are based on the W3C Verifiable Credentials Data Model 1.0 and are delivered as a qr-code that can be printed, sent via SMS, or exported to a digital wallet [2].
DIVOC is built and maintained by India's eGov Foundation, released as MIT-licensed open-source software, and positioned as a digital public good ("built in India for the world") [2]. Its flagship deployment is India's CoWIN platform, through which it issued over one billion COVID-19 vaccination certificates [3].
History
2021 — Built for India's vaccination drive. DIVOC was created to issue verifiable digital vaccination certificates at the scale of India's national COVID-19 program, integrated into the Government of India's CoWIN platform [3].
October 2021 — One billion certificates. eGov Foundation announced that one billion vaccination certificates had been issued via DIVOC on the CoWIN platform — among the largest verifiable-credential issuances ever recorded [3].
Open-source / digital-public-good positioning. DIVOC is hosted and maintained by the eGov Foundation under an MIT license, supported by multilateral funding institutions and global contributors, and offered to other countries as reusable digital public infrastructure [2].
International adoption. Beyond India, DIVOC has been used to issue digital vaccination certificates in Sri Lanka and the Philippines, with stated expansion plans across South/Southeast Asia and Africa [2].
Technical specification
DIVOC certificates are W3C Verifiable Credentials [2]:
- Data model — based on the W3C Verifiable Credential Data Model 1.0, expressed as JSON-LD; DIVOC's vaccination certificate uses the JSON-JWT VC type [2].
- Content — vaccination data plus holder information (name, address, date of birth, gender) [2].
- Signing — each implementing country uses centralized signing keys controlled by the national authority; there is no single global trust registry, so adopting countries run their own trust frameworks [2].
- Carrier — the signed credential is rendered as a qr-code for offline verification, printable on paper and embeddable in apps [2].
- Distribution — printed at vaccination sites, downloadable via SMS link, or exported to consumer health wallets / digital lockers through authenticated APIs (e.g. Mobile-OTP-protected) [2].
Because DIVOC predates a single finalized cross-border spec, adopter countries publish their own variant specifications; DIVOC credentials were tested for compatibility with eu-dcc and icao-vds-nc formats to enable interoperability [2].
Use cases
- National vaccination certification — the core use; proof of COVID-19 vaccination issued at population scale (India's CoWIN) [3].
- Test result certificates — DIVOC supports certification beyond vaccination as a general health-campaign platform [1].
- Cross-border recognition — interoperability work with EU DCC and ICAO VDS-NC aimed to make DIVOC certificates acceptable for international travel [2].
- Reusable health-credential infrastructure — offered as a digital public good for any government running large health campaigns [1, 2].
Implementations
- Documentation / specs — egovernments/divoc-docs — 3★, last active 2023. The maintained DIVOC documentation repository under the eGov Foundation org [4].
- Platform docs —
divoc.digit.organddivoc.egov.org.inhost the platform introduction, certificate features (v2.0), and native COVID-19 certificate specification [1, 5]. - CoWIN integration (India) — the largest production deployment, with verification via the government's
verify.cowin.gov.inservice [3]. - National deployments — Sri Lanka and the Philippines among adopters [2].
Note: DIVOC's original monorepo (formerly egovernments/DIVOC) is no longer publicly resolvable at that path; the eGov Foundation org currently hosts divoc-docs and supporting repositories.
Comparison
| DIVOC | eu-dcc | smart-health-cards | icao-vds-nc | |
|---|---|---|---|---|
| Data model | W3C VC (JSON-LD / JSON-JWT) | CWT / CBOR + COSE | W3C VC as JWS over FHIR | signed JSON/CBOR seal |
| Encoding | JSON-LD in QR | Base45 + ZLIB, HC1: |
numeric shc:/, Deflate |
signed JSON in QR/Data Matrix |
| Signature | issuer-controlled (national keys) | ES256 / PS256 | ES256 | ES256 / ES384 |
| Governance | eGov Foundation (India), MIT, digital public good | EU eHealth Network → WHO | VCI consortium / HL7 | ICAO (UN body) |
| Trust model | per-country, no global registry | EU Gateway CSCA/DSC PKI | issuer JWKS + VCI directory | eMRTD CSCA PKI |
| Geography | India, Sri Lanka, Philippines | EU + 51 countries | US, Canada, others | ICAO member states |
DIVOC's distinguishing trait is its identity as open-source, MIT-licensed national infrastructure designed for reuse by any government, paired with the W3C VC / JSON-LD data model — versus the EU DCC's binary CBOR/COSE format and ICAO's MRTD-rooted seal. Its weakness relative to EU DCC is the absence of a unified cross-border trust registry; each country runs its own [2].
Fun facts
One of the largest VC issuances in history. Through CoWIN, DIVOC issued over one billion verifiable vaccination certificates — a single open-source platform producing credentials at a scale rivaling entire national identity systems [3].
Status
DIVOC remains an actively documented open-source platform maintained by the eGov Foundation and positioned as reusable digital public infrastructure for health campaigns beyond COVID-19 [1, 2]. Its peak activity was India's pandemic vaccination drive; post-pandemic it continues as a general verifiable-credentialing toolkit, with its codebase reorganized under the eGov Foundation's GitHub org and its specs hosted on the DIVOC/DIGIT documentation sites [4, 5].
Sources
- Introduction to DIVOC — divoc.digit.org
- DIVOC COVID Certificate Summary — Linux Foundation Public Health, 2021
- 1 billion vaccination certificates issued via DIVOC on CoWIN — eGov Foundation
- egovernments/divoc-docs — GitHub
- DIVOC's Native COVID-19 Certificate Specification — divoc.digit.org
- One billion vaccination certificates via DIVOC — divoc.egov.org.in
Deployments
No country reports mention this standard by name.
Regions / aggregations not mapped to a single country
- Universal