Skip to content
Alpha: Odal Node is in active development. APIs, schemas and docs will change before 1.0.

Standards & interoperability

Odal Node builds on published, open standards, so existing tools can read its passports and nothing depends on a format only we understand. This page lists the standards the code relies on and what each is used for. Where the node does not use something yet, the entry says so. The full list, with every EU act the code applies and the articles it relies on, is in Acts and standards.

Identifying a product and resolving its passport

Section titled “Identifying a product and resolving its passport”
  • GS1 Digital Link: the web address behind the QR code. A scan resolves to the passport, and the same link can serve different views and link types; a request for linkset returns an RFC 9264 linkset.
  • ISO/IEC 18004: the QR code itself. The node renders it with the four-module quiet zone the standard requires.
  • EN 18219 (unique identifiers): three of the product identifier schemes it allows, a GS1 Digital Link, the IEC 61406 identification link and a decentralised identifier (DID). The core library and the node accept all three. A passport identified by a GTIN gets a GS1 Digital Link carrier; one identified by a link or a DID gets a carrier that opens the passport at the operator’s own resolver address. See Harmonised standards.
  • ISO 3166-1 country codes, and ISO 17442 legal entity identifiers with their ISO 7064 check characters.
  • JSON Web Signature (RFC 7515) with EdDSA over Ed25519 (RFC 8037): how every passport is signed.
  • did:web: the issuer’s identity, anchored in their own web domain. Verifying a passport is an ordinary web lookup, with no central registry and no dependency on Odal.
  • JSON Canonicalization Scheme (RFC 8785): the byte-exact form data is hashed in, so a check gives the same answer on every machine.
  • W3C Verifiable Credentials 2.0: the access credentials a reader presents to see restricted parts of a passport. The node checks an issuer’s W3C Bitstring Status List for revocation where the issuer publishes one; credentials the node issues itself carry no status list and are limited to 90 days instead (see Access credentials).
  • SD-JWT (RFC 9901): a passport issued as a credential its holder can present in part. The core library has it; the node does not issue it yet.
  • ETSI EN 319 122-1 (CAdES): the format the node’s seals are made in.
  • ETSI TS 119 182-1 (JAdES): the JSON seal format, with the certificate carried in the header as the EU formats act requires.
  • ETSI EN 319 102-1: the validation procedure. The node reports its seal checks in its terms, including when a seal cannot be read.
  • ETSI TS 119 612: the EU trusted lists, which the node reads and verifies to check who issued a seal’s certificate.
  • RFC 5652 (CMS) and RFC 3161 (time stamps): the structures underneath a CAdES seal.
  • IDTA Asset Administration Shell (metamodel IDTA-01001-3-0): a passport can be served in this shape by content negotiation. The structure follows the metamodel; the semantic identifiers are in Odal’s own urn:odal-node: namespace for now, so this is AAS-shaped output, not a claim of IDTA conformance.
  • RFC 9457 problem details: every error the API returns.
  • EN 45554: the scale for repairability scores.
  • ISO 3758: care symbols on textile passports.
  • IEC 62660-1: named as a cycle-life test method a battery passport can cite.

The six harmonised European passport standards

Section titled “The six harmonised European passport standards”

Commission Implementing Decision (EU) 2026/1736 cited six standards from CEN/CENELEC JTC 24 in the Official Journal on 15 July 2026: EN 18216, 18219, 18220, 18221, 18222 and 18223. Under ESPR Art. 41(2), conforming to a cited standard gives a presumption of conformity with the requirements it covers.

We have read EN 18219 and EN 18221, and we do not claim conformance with any of the six. Harmonised standards lists each one and how the software compares.