Skip to main content

Cookbooks

Each cookbook ends in a working result and has a checkpoint after every step. Start with Issue and verify: the other recipes build on the instance, tenant and wallet credential it creates.

Recipes​

RecipeOutcomePrerequisitesStarts fromTime
Issue and verify: 1. Install and connect, 2. Issue, 3. VerifyA membership credential in your phone's wallet, and a verified presentation of its claimsDocker or Podman, a wallet app on a phone, an HTTPS tunnelNothing60 min
Integrate into your backendYour backend creates offers and requests through the API and receives the results by webhookcurl, jq, Node.js 22+Issue and verify45 min
Issue after loginThe wallet user signs in at Keycloak; the credential carries claims from your attribute providerA Keycloak realm reachable over HTTPS, Node.js 22+Issue and verify60 min
Revocable credentialsYou revoke or suspend one issued credential and the next presentation failscurl and jqIssue and verify30 min
Accept only trusted issuersA presentation request accepts credentials from issuers on your trust list and rejects all otherscurl and jqIssue and verify40 min
Production on one VMEUDIPLO on a Linux server behind a TLS reverse proxy, with backups and a strict health checkA VM with a DNS name, ports 80 and 443 openNothing60 min

For a single task outside these recipes, go to the guides: Issuance, Presentation, Trust and Operate. If a step fails, see Troubleshooting.

Shared values​

All recipes use these values. Keep them unchanged so each recipe can reuse what the previous one created.

ValueUsed for
membership-demoTenant ID
membershipCredential configuration ID
urn:example:membership:1SD-JWT credential type (VCT), used for both issuance and verification
name, member_idClaim paths
Max, M-001Synthetic claim values
membership-checkPresentation configuration ID
membershipCredential query ID inside the presentation request
cookbookCLI instance name of the local deployment

The credential configuration ID names what EUDIPLO issues. The VCT is the credential type the wallet must match. The presentation configuration ID names the reusable verification request.

Choosing a wallet​

Use a wallet that supports SD-JWT VC, the pre-authorized code flow and OpenID4VP. The wallet compatibility record lists tested wallets and their limitations. Whether a wallet accepts self-signed certificates depends on the wallet and its test environment; Wallet and registrar requirements helps you choose.

Learning setup

The recipes use one tenant as both issuer and verifier, test certificates and synthetic data. Before you handle real credentials, follow Production on one VM and the Operate guides.