Skip to main content

Configure the issuer

Set the issuer-wide settings of a tenant: how the issuer is shown in wallets, which authorization servers it offers, and how its token and credential endpoints behave. Each tenant has exactly one issuance configuration; credential types are configured separately in credential configurations.

Prerequisites: a client with the issuance:manage role. In the web client, open Credential Issuance → Issuer Settings.

1. Write the configuration​

{
"display": [
{
"name": "Membership Demo",
"locale": "en-US",
"logo": { "uri": "https://issuer.example.com/logo.png", "alt_text": "Logo" }
}
],
"authorizationServers": [{ "type": "built-in", "id": "issuer-built-in" }],
"batchSize": 10,
"dPopRequired": true,
"offerLifetimeSeconds": 900
}

2. Store it​

curl -X POST "$EUDIPLO_URL/api/issuer/config" \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d @issuance.json

POST /api/issuer/config creates or replaces the configuration. GET /api/issuer/config returns it and creates a default one (a single built-in authorization server) if none exists. To manage it as a file, see Configuration as code.

Check: GET /.well-known/openid-credential-issuer/issuers/{tenant} shows your display, the authorization_servers and the endpoints.

Settings​

FieldDefaultEffect
displaynoneIssuer name and logo per locale, published as display in the credential issuer metadata. Logos use uri; to host them in EUDIPLO, see Object storage.
authorizationServersbuilt-in serverRequired, at least one entry. See Authorization servers.
signingKeyIdTenant default keyKey chain that signs the access tokens of the built-in authorization server, unless its entry sets token.signingKeyId. Credentials are signed with the keyChainId of each credential configuration.
batchSize1Batch issuance: how many credentials (one per key proof) a wallet may request at once. Values above 1 are published as batch_credential_issuance.batch_size. A key attestation proof may carry up to batchSize keys.
dPopRequiredtrueRequire DPoP-bound access tokens at the built-in token endpoint and the credential, deferred credential and notification endpoints. See DPoP.
credentialRequestEncryptionfalseSets encryption_required of credential_request_encryption.
credentialResponseEncryptionfalseSets encryption_required of credential_response_encryption.
notificationEndpointEnabledtruePublish and serve the notification endpoint.
txCodeMaxAttempts5Failed transaction code attempts before a pre-authorized code is invalidated. null restores the default. See Transaction code.
offerLifetimeSecondsunsetDefault lifetime of credential offers (9.0). Unset or null: offers do not expire. Offers can override it. See Lifetime and expiry.
walletAttestationRequired, walletProviderTrustListsfalse, noneDefaults for wallet attestation at EUDIPLO's authorization servers; the trust lists also validate key attestations at the credential endpoint. See Wallet and key attestation.
federationnoneSee OpenID Federation.
registrationCertificatenonePublish a registration certificate in issuer_info. See Registration certificates.

Encryption flags​

EUDIPLO always advertises credential_request_encryption (its encryption key, enc A128GCM or A256GCM) and credential_response_encryption (alg ECDH-ES, enc A128GCM or A256GCM), so wallets may encrypt in either direction. The two flags only set encryption_required in these objects. Set them only if every wallet you serve supports encryption.