Attribute providers
Fetch claim values from your backend at the moment the wallet requests a credential. An attribute provider is a tenant resource with your endpoint's URL and authentication; credential configurations and offers reference it by ID. The request and response format is specified in the Attribute provider API.
Prerequisites: a client with the issuance:manage role and an HTTPS endpoint in your backend. For local development against HTTP or private addresses, set OUTBOUND_URL_ALLOW_HTTP or OUTBOUND_URL_ALLOW_PRIVATE_NETWORK.
1. Implement the endpoint
EUDIPLO posts the session, the requested credential configuration and the identity of the authenticated user. Return the claims under the configuration ID:
app.post("/claims", (req, res) => {
const { session, credential_configuration_id, identity, credentials } = req.body;
const member = members.findBySubject(identity.iss, identity.sub);
if (!member) return res.status(404).end(); // fails the credential request
res.json({
[credential_configuration_id]: { name: member.name, member_id: member.id },
});
});
identitydescribes the user behind the wallet's access token; what it contains per flow is listed in Claims.- After a presentation (OID4VP authorization server or interactive authorization),
credentialsholds the verified presented claims, so you can derive the new credential from a PID. - Return every claim of the credential; the response replaces the static defaults and is validated against the configuration's
fields. - To issue later, for example after a manual review, answer
{ "deferred": true }and follow Deferred issuance. - Any error status fails the credential request. EUDIPLO does not retry.
2. Register the provider
curl -X POST "$EUDIPLO_URL/api/issuer/attribute-providers" \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{
"id": "member-db",
"name": "Member database",
"url": "https://backend.example.com/claims",
"auth": {
"type": "apiKey",
"config": { "headerName": "x-api-key", "value": "change-me" }
}
}'
auth is required: use { "type": "none" } or an API key that EUDIPLO sends in the named header. Check it in your endpoint. In the web client, open Attribute Providers.
3. Use it
Reference the provider in the credential configuration so that every issuance of this type uses it:
{
"id": "membership",
"attributeProviderId": "member-db"
}
To use a different source for a single offer, set credentialClaims in the offer request:
{
"credentialClaims": {
"membership": { "type": "attributeProvider", "attributeProviderId": "member-db-staging" }
}
}
An offer can also define a one-off webhook source with the same contract. Offer sources take precedence over the configuration's provider; see Claims.
Check: issue a credential through an offer and inspect the request your endpoint received. A failing or unreachable endpoint makes the wallet's credential request fail with invalid_credential_request.
Attribute providers only supply claims. To learn whether the wallet stored the credential, use notifications.