Cookbook: Verify the Membership Credential
This is chapter 3 of the Issue and verify cookbook. You request the name and member_id claims of the membership credential from chapter 2, approve the request in the wallet, and inspect the verified result.
What you will build
A presentation configuration membership-check with one DCQL credential query membership. It asks for the two claims of urn:example:membership:1, and the request is signed with the access certificate from chapter 2.
Before you start
- Starts from: chapter 2, Issue a membership credential. The wallet holds the
Membershipcredential withMaxandM-001. - You are signed in as
membership-demo-admin, and the public HTTPS URL is unchanged. - The access key chain
Membership verifier accesshas a certificate that your wallet's test environment accepts.
Step 1: Define what to request
Open Credential Verification → Verification Configs and choose + (Create Configuration).
-
On 1. Name, enter ID
membership-checkand DescriptionVerify a membership name and ID. Choose Continue. -
On 2. Credentials, choose Add credential and enter:
Field Value Query ID membershipCredential format SD-JWT VC Credential type (VCT) urn:example:membership:1Claim path name -
Choose Add claim and enter
member_idas the second Claim path. -
Leave Issuer trust empty and keep Require all selected credentials under Accepted credential combinations. Choose Continue.
Checkpoint: the query asks for exactly two claims of the VCT you issued. The wallet matches on VCT and claim paths, not on the credential configuration ID.
Equivalent DCQL for API users
{
"credentials": [
{
"id": "membership",
"format": "dc+sd-jwt",
"meta": {
"vct_values": ["urn:example:membership:1"]
},
"claims": [{ "path": ["name"] }, { "path": ["member_id"] }]
}
]
}
For other credentials, Import from Issuer fills in the types and claim paths from issuer metadata. See DCQL for claim options and alternatives.
Step 2: Review the verification settings
On 3. Settings:
- Keep Lifetime of the request at
300seconds and Status List Check Mode at Strict. The cookbook credential has no status entry, so there is nothing to check yet. - In Access Key Chain (optional), select
Membership verifier access. Do not select the credential signing key. - Leave the registration certificate empty unless your wallet requires one.
- Leave redirect URI, webhook and the other options empty.
- Choose Continue, check that the review lists
nameandmember_id, then choose Create Configuration.
Checkpoint: membership-check appears under Verification Configs. It has no issuer trust constraint yet: any correctly signed credential of this type passes. Accept only trusted issuers adds one.
Step 3: Generate and approve a request
- Open
membership-checkand choose the Create offer button, or open Credential Verification → New Verification and selectmembership-checkas Presentation Configuration. - Choose Generate Request.
- Scan the QR code with the wallet that holds the credential.
- Check that the wallet offers the membership credential and asks for name and member ID, then approve before the request expires.
Checkpoint: the wallet reports that the data was shared. That alone does not prove that verification succeeded; check the session in the next step.
Step 4: Inspect the verified session
Open Sessions → All Sessions and open the new presentation session. Its status chip shows completed. The Credentials tab shows the verified claims for query membership:
| Claim | Expected value |
|---|---|
name | Max |
member_id | M-001 |
Checkpoint: the session is completed and shows both values. A failed session is never a success, even if the wallet reported that it shared the data.
You have now issued and verified a credential end to end. In an application, you receive this result by webhook instead of reading the session view; see Integrate into your backend.
Troubleshooting
| Symptom | Cause | Fix |
|---|---|---|
| Wallet finds no matching credential | VCT or claim path differ from chapter 2, or the credential expired | Compare urn:example:membership:1, name and member_id with the credential type; issue a fresh credential. |
| Reminder about a missing access certificate | No access key chain selected, or its certificate is not active | Select Membership verifier access in Access Key Chain (optional). |
| Request expired | Approved after the 300-second lifetime | Generate a new request and approve it right away. |
| Changed claims do not show up | A wallet credential keeps the claims it was issued with | Issue a new credential, then generate a new request. |
Verifier trust, overasking and failed-session errors are covered in Troubleshooting.
Next steps
- Integrate into your backend: create offers and requests from your code and receive the results by webhook.
- Revocable credentials: revoke the credential and watch verification fail.
- Accept only trusted issuers: restrict
membership-checkto issuers on your trust list. - All recipes