Hi, thanks for sharing this info, looks promising.
Just a remark regarding the unique 'authentication code' related to each SCA which is requested by PSD2 RTS (cf. article 4): I don't see how it's managed in your proposition. I would add such attribute in the P2Pay, next to the payment-id. One could argue that the payment-id is unique, and then the hash is unique, but the payment-id is not assigned by the authentication but prior to it; it's not the same purpose.
Without such info, the approach could be seen as not compliant with PSD2 RTS (and these requirements related to SCA are still applicable with PSD3 & PSR).
Or is there already a code which is automatically assigned to each VP in OpenID4VP protocol which could be used?
Hi, thanks for sharing this info, looks promising.
Just a remark regarding the unique 'authentication code' related to each SCA which is requested by PSD2 RTS (cf. article 4): I don't see how it's managed in your proposition. I would add such attribute in the P2Pay, next to the payment-id. One could argue that the payment-id is unique, and then the hash is unique, but the payment-id is not assigned by the authentication but prior to it; it's not the same purpose.
Without such info, the approach could be seen as not compliant with PSD2 RTS (and these requirements related to SCA are still applicable with PSD3 & PSR).
Or is there already a code which is automatically assigned to each VP in OpenID4VP protocol which could be used?