TridentGold overview
TridentGold is a citizen-held digital identity platform being developed for Barbados. Participating Barbados services integrate with TridentGold so people can use the same holder-controlled account across services, store credentials issued to them in the TridentGold app, and choose whether to disclose only the credential information a service requests. Sign in with TridentGold is intended to augment or replace parts of those services' existing digital account and authentication systems, such as email-and-password sign-in.
Identity proofing and authoritative source records remain outside TridentGold's scope and under the responsible agencies' control. The TridentGold wallet's credential capabilities form a digital layer above those records: agencies attest facts from their existing sources, holders keep the resulting credentials, and services request evidence from them.
The TridentGold system follows an issuer → holder → verifier model:
- An authorized issuer checks its authoritative records and issues a digital credential.
- The citizen, as holder, keeps the credential in the TridentGold app and decides when to use it.
- A verifier asks for authentication or specific evidence and validates the holder's response against trusted issuers and current status data.
This lets a service ask for only what it needs. Depending on the credential and request, the holder may disclose selected facts or prove a condition—such as meeting an age threshold—without sharing every field in the credential.
Authentication and credential-backed facts
These are different assurances:
- Sign in with TridentGold proves that the same holder-controlled account approved a sign-in. Pairwise identifiers are intended to give each user a distinct account identifier with each service, reducing linkability across services. A service may still request identifying information or credential evidence when needed.
- Credential presentation supplies facts attested by an issuer, such as a licence class or eligibility result. The verifier must still check the issuer, proof, request binding, validity, and applicable status information.
An account can therefore authenticate without proving a civil identity, nationality, entitlement, or any other government-backed fact.
Standards and format boundaries
The intended architecture adopts international standards and specifications where they fit, including OpenID4VCI for credential issuance, OpenID4VP with DCQL for credential presentation, SIOPv2 for holder authentication, ICAO 9303 for travel and identity documents, ISO/IEC 18013 for mobile driving licences, and X.509 for issuer trust. It defines TridentGold-specific profiles where additional requirements must be met.
ICAO 9303 travel documents and ISO/IEC 18013 mdoc credentials retain their native formats and trust models. The draft TridentGold ZKNC format is intended for domestic claims. Support for common standards does not by itself guarantee interoperability with every external wallet or verifier; that requires complete profiles, explicit mappings, and conformance testing.
What this documentation covers
Start with How to test to receive and present a synthetic credential using the assigned iOS app and hosted verifier. Issuers can read Connecting your organization; verifiers can follow the request and result guide.
Intended capabilities: secure agency issuance, selective credential presentation, national trust and status services, and integration with Barbados service-delivery workflows. These capabilities depend on the selected credential, environment, and approved deployment profile.
The release and compatibility guide records the current sandbox scope, SDK distribution status, and remaining integration limits. The documented MVP interfaces are provisional and do not define a production integration contract.