Skip to main content

Issuance

EUDIPLO issues SD-JWT VC (dc+sd-jwt) and mDOC (mso_mdoc) credentials over OpenID for Verifiable Credential Issuance (OID4VCI). You configure the issuer once, define a credential configuration per credential type, and create an offer for every issuance. Pick the flow that matches how you know the user.

Choose a flow​

SituationOffer flowAuthorization serverClaims come fromGuide
Your backend already knows the user, for example in a logged-in portalpre_authorized_code, optionally with a transaction codebuilt-inInline offer claims, an attribute provider or static defaultsFirst credential, Credential offers
The user logs in at your OpenID provider (Keycloak, Entra ID, …)authorization_codechainedAttribute provider, with the upstream user as identityIssue after login
Your OAuth server issues the access tokens and can carry the session IDauthorization_code (an offer is required)externalOffer claims or attribute provider; static defaults are not acceptedExternal
The user proves who they are with a PID or another credentialauthorization_codeoid4vpAttribute provider, which receives the presented claimsOID4VP
The user completes steps in the wallet (presentation, web form) before issuance; experimentalauthorization_codebuilt-in with interactive authorizationAttribute provider, which receives the presented claimsInteractive authorization
The wallet starts without an offernone (wallet-initiated)built-inAttribute provider or static defaultsBuilt-in

An attribute provider is only mandatory for tokens of an external authorization server; in all other flows it is the recommended source for user-specific claims. To issue after a manual review, let the attribute provider defer the credential.

Build an issuer​

  1. Configure the issuer: display, authorization servers, batch size, DPoP and offer lifetime.
  2. Configure a credential per credential type: format, type, claims, display, key binding, lifetime and revocation. All fields: credential configuration reference.
  3. Decide where claim values come from: Claims, Attribute providers, Deferred issuance.
  4. Create offers from your backend.
  5. After issuance: receive wallet notifications and revoke or suspend credentials (cookbook).

Which OID4VCI features and formats are supported in detail is listed in Protocols. How issuance works internally is described in Issuance under the hood.