Issuance
EUDIPLO issues SD-JWT VC (dc+sd-jwt) and mDOC (mso_mdoc) credentials over OpenID for Verifiable Credential Issuance (OID4VCI). You configure the issuer once, define a credential configuration per credential type, and create an offer for every issuance. Pick the flow that matches how you know the user.
Choose a flow
| Situation | Offer flow | Authorization server | Claims come from | Guide |
|---|---|---|---|---|
| Your backend already knows the user, for example in a logged-in portal | pre_authorized_code, optionally with a transaction code | built-in | Inline offer claims, an attribute provider or static defaults | First credential, Credential offers |
| The user logs in at your OpenID provider (Keycloak, Entra ID, …) | authorization_code | chained | Attribute provider, with the upstream user as identity | Issue after login |
| Your OAuth server issues the access tokens and can carry the session ID | authorization_code (an offer is required) | external | Offer claims or attribute provider; static defaults are not accepted | External |
| The user proves who they are with a PID or another credential | authorization_code | oid4vp | Attribute provider, which receives the presented claims | OID4VP |
| The user completes steps in the wallet (presentation, web form) before issuance; experimental | authorization_code | built-in with interactive authorization | Attribute provider, which receives the presented claims | Interactive authorization |
| The wallet starts without an offer | none (wallet-initiated) | built-in | Attribute provider or static defaults | Built-in |
An attribute provider is only mandatory for tokens of an external authorization server; in all other flows it is the recommended source for user-specific claims. To issue after a manual review, let the attribute provider defer the credential.
Build an issuer
- Configure the issuer: display, authorization servers, batch size, DPoP and offer lifetime.
- Configure a credential per credential type: format, type, claims, display, key binding, lifetime and revocation. All fields: credential configuration reference.
- Decide where claim values come from: Claims, Attribute providers, Deferred issuance.
- Create offers from your backend.
- After issuance: receive wallet notifications and revoke or suspend credentials (cookbook).
Which OID4VCI features and formats are supported in detail is listed in Protocols. How issuance works internally is described in Issuance under the hood.