Digital public infrastructure, or DPI, provides shared digital capabilities that different organisations can use to deliver services. These capabilities can help establish identity, move money or exchange information securely. Their value comes from making useful services easier to build and access across institutional boundaries.
After reading this page, you should be able to explain DPI, distinguish infrastructure from an application, and identify a shared capability in a service journey.
Start with a service people need
Consider a small business owner applying for support. The programme needs to confirm who the applicant is, whether the business meets its conditions, and where an approved payment should go. Several institutions may already hold relevant information. The owner may still have to collect documents and submit them again.
Putting the application form online improves one step. A shared identity verification service, an agreed way to check eligibility evidence and an interoperable payment service could improve the whole journey. Institutions would also need to agree on responsibilities, access rules and how to correct mistakes.
This is a MOSAIC teaching scenario, not a claim that a particular Indonesian support programme already operates this way.
A working definition for this wiki
For educational purposes, this wiki describes DPI as digital capabilities designed for reuse across services, supported by standards, institutions and safeguards that serve the public interest.
This wording is a MOSAIC wiki editorial synthesis. It draws on the World Bank's treatment of digital identity, payments and trusted data sharing, and CDPI's emphasis on combining technology standards with governance and ecosystem participation. It is not presented as a formally adopted MOSAIC policy definition. World Bank overview · CDPI definition
Three capabilities to recognise
| Capability | Question it helps answer | Everyday example |
|---|---|---|
| Identity and authentication | Who is requesting this service, and can we verify that claim? | An authorised service checks an applicant's identity. |
| Payments | How can money move between participating providers? | A customer pays a merchant using a supported application from a different provider. |
| Trusted data exchange and credentials | What information or evidence can another organisation rely on? | A provider checks a qualification or receives authorised health information. |
These are useful starting categories rather than an exhaustive inventory. Sector infrastructure can combine them with other capabilities. CDPI discusses identity and trust, data and credentials, and payments and transaction networks; the World Bank also uses identity, payments and trusted data sharing as foundational building blocks. CDPI overview · World Bank digital government overview
Infrastructure and applications do different jobs
An application is usually where a person interacts with a service. Infrastructure provides capabilities that the application and other services can reuse.
QRIS makes this distinction tangible. A bank or payment application provides the customer interface. QRIS provides a common payment standard within a participating payment ecosystem. Bank Indonesia explains that supported payment applications can read a merchant's QRIS code even when the customer and merchant use different providers. Bank Indonesia QRIS overview
For health, SATUSEHAT Platform supports data exchange between systems. SATUSEHAT Mobile is a public-facing health application whose data comes from and is integrated with the platform. Understanding this distinction helps readers assess the infrastructure behind the interface. SATUSEHAT Platform introduction · SATUSEHAT Mobile explanation
What makes the public dimension meaningful
For this wiki, the public dimension is assessed through the service's purpose and arrangements: who can benefit, who can participate, how providers are held accountable and what happens when someone cannot use the digital channel.
A useful discussion asks whether shared infrastructure expands access and choice, rather than assuming those benefits follow from its name. The UN Universal DPI Safeguards initiative addresses individual and societal risks throughout implementation. Safeguards belong in the design and operation of infrastructure, including how institutions respond to harm. UNDP announcement · Current safeguards resource
Where verifiable credentials fit
A verifiable credential is a way to represent claims with a verification mechanism. An issuer makes the claim, a holder can present it and a verifier checks it according to the relevant trust and technical rules. The W3C specification explains these roles. W3C Verifiable Credentials Data Model 2.0
In the business support scenario, a credential might carry evidence that an authorised issuer checked a programme condition on a stated date. The programme would still need to decide which issuers it accepts, how long the evidence remains valid and when it must be checked again.
Cryptographic verification can establish integrity and provenance. It cannot by itself establish that the underlying claim is accurate, current or sufficient for an eligibility decision. A credential format also needs an agreed trust framework to work across organisations.
Credentials are one possible component of DPI. They are useful where portable, verifiable evidence solves a real service problem; other journeys may be better served through authorised system-to-system exchange. CDPI credential overview
Common questions
Does open-source software automatically become DPI? No. Reuse across institutions, interoperability and governance matter too. CDPI explicitly distinguishes open-source solutions from DPI implementations. CDPI system assessment
Are digital public goods and DPI interchangeable? No. A digital public good is assessed against requirements such as open licensing, documentation and privacy. It may support a DPI implementation. The Digital Public Goods Alliance states that its review covers the core solution and does not evaluate local implementations. DPG Standard
Can every organisation access the data? Participation and technical interoperability do not remove access restrictions. The wiki's recommended practice is to specify permissions, purpose and safeguards for each exchange.
Try it
Choose a service you use. Identify one repeated task: identity verification, payment or evidence submission. Which part could be reused by another organisation? What agreement would be needed before it could rely on the result? Who would help a person if the check failed?
Key terms
- Interoperability: different systems can exchange and use information through agreed arrangements.
- Building block: a capability designed to be reused in several services.
- Authentication: checking a claimed identity.
- Credential: evidence containing claims from an issuer.
- Governance: rules, responsibilities and oversight for participation and operation.
