Cookbooks
Each cookbook ends in a working result and has a checkpoint after every step. Start with Issue and verify: the other recipes build on the instance, tenant and wallet credential it creates.
Recipes
| Recipe | Outcome | Prerequisites | Starts from | Time |
|---|---|---|---|---|
| Issue and verify: 1. Install and connect, 2. Issue, 3. Verify | A membership credential in your phone's wallet, and a verified presentation of its claims | Docker or Podman, a wallet app on a phone, an HTTPS tunnel | Nothing | 60 min |
| Integrate into your backend | Your backend creates offers and requests through the API and receives the results by webhook | curl, jq, Node.js 22+ | Issue and verify | 45 min |
| Issue after login | The wallet user signs in at Keycloak; the credential carries claims from your attribute provider | A Keycloak realm reachable over HTTPS, Node.js 22+ | Issue and verify | 60 min |
| Revocable credentials | You revoke or suspend one issued credential and the next presentation fails | curl and jq | Issue and verify | 30 min |
| Accept only trusted issuers | A presentation request accepts credentials from issuers on your trust list and rejects all others | curl and jq | Issue and verify | 40 min |
| Production on one VM | EUDIPLO on a Linux server behind a TLS reverse proxy, with backups and a strict health check | A VM with a DNS name, ports 80 and 443 open | Nothing | 60 min |
For a single task outside these recipes, go to the guides: Issuance, Presentation, Trust and Operate. If a step fails, see Troubleshooting.
Shared values
All recipes use these values. Keep them unchanged so each recipe can reuse what the previous one created.
| Value | Used for |
|---|---|
membership-demo | Tenant ID |
membership | Credential configuration ID |
urn:example:membership:1 | SD-JWT credential type (VCT), used for both issuance and verification |
name, member_id | Claim paths |
Max, M-001 | Synthetic claim values |
membership-check | Presentation configuration ID |
membership | Credential query ID inside the presentation request |
cookbook | CLI instance name of the local deployment |
The credential configuration ID names what EUDIPLO issues. The VCT is the credential type the wallet must match. The presentation configuration ID names the reusable verification request.
Choosing a wallet
Use a wallet that supports SD-JWT VC, the pre-authorized code flow and OpenID4VP. The wallet compatibility record lists tested wallets and their limitations. Whether a wallet accepts self-signed certificates depends on the wallet and its test environment; Wallet and registrar requirements helps you choose.
The recipes use one tenant as both issuer and verifier, test certificates and synthetic data. Before you handle real credentials, follow Production on one VM and the Operate guides.