Skip to main content

Attribute provider API

The HTTP contract EUDIPLO uses to fetch claims from your backend during issuance. It applies to attribute providers and to webhook claim sources of an offer. For setup, see Attribute providers; for when a provider is called, see Claims.

Resource​

Attribute providers are tenant resources managed with the issuance:manage role:

MethodPathPurpose
GET/api/issuer/attribute-providersList providers
GET/api/issuer/attribute-providers/{id}Get one provider
POST/api/issuer/attribute-providersCreate a provider
PATCH/api/issuer/attribute-providers/{id}Update fields of a provider
DELETE/api/issuer/attribute-providers/{id}Delete a provider
FieldRequiredType / allowed valuesDescription
idyesstringUnique attribute provider identifier.
nameyesstringDisplay name of the attribute provider.
descriptionnostring or nullOptional attribute provider description.
urlyesstringBase URL of the attribute provider endpoint.
authyesone of 2 shapesAuthentication configuration for outbound provider requests.
auth.typeyesstring: apiKeyOnly in shape 1 of 2. Use API key authentication.
auth.configyesobjectOnly in shape 1 of 2. API key authentication settings.
auth.config.headerNameyesstringOnly in shape 1 of 2. HTTP header name carrying the API key.
auth.config.valueyesstringOnly in shape 1 of 2. API key value.
auth.typeyesstring: noneOnly in shape 2 of 2. Disable authentication for attribute provider calls.

An offer webhook source has the shape { "url", "auth", "includeRawTokensFor"? } with the same auth options; see Webhooks.

Request​

EUDIPLO sends POST <url> with Content-Type: application/json and, for apiKey authentication, the configured header. It calls the provider when the wallet requests the credential, once per credential request.

{
"session": "a6318799-dff4-4b60-9d1d-58703611bd23",
"credential_configuration_id": "membership",
"identity": {
"iss": "https://keycloak.example.com/realms/eudiplo",
"sub": "f3b1c2d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d",
"token_claims": {
"email": "[email protected]",
"preferred_username": "max"
}
},
"credentials": [
{
"id": "pid",
"values": [
{ "given_name": "Max", "family_name": "Mustermann", "birthdate": "1990-01-15" }
]
}
]
}
FieldPresentDescription
sessionalwaysIssuance session ID. It equals the session returned when the offer was created.
credential_configuration_idalwaysCredential configuration the wallet requested.
identityalwaysiss, sub and token_claims of the authorization behind the wallet's access token. What they contain per flow is listed in Claims.
credentialsafter a presentationVerified claims the wallet presented to an OID4VP authorization server or in an interactive authorization presentation step. One entry per credential query ID of the presentation's DCQL query; values holds the disclosed claims of each matching credential (several with multiple: true).

Response​

Claims​

Answer 200 with the claims under the requested credential configuration ID:

{
"membership": {
"name": "Max",
"member_id": "M-001"
}
}

The claims replace the static defaults of the configuration completely and are validated against its fields before signing; see Claims.

Deferred​

To issue later, answer 200 with:

{ "deferred": true, "interval": 5 }
FieldDescription
deferredtrue defers the credential.
intervalPolling interval in seconds suggested to the wallet. Default 5.

EUDIPLO answers the wallet with a transaction_id. Completing or failing the transaction is described in Deferred issuance.

Errors​

  • Any non-2xx status or network error fails the credential request. The wallet receives HTTP 400 with invalid_credential_request; claims that do not match the configuration lead to credential_request_denied.
  • EUDIPLO does not retry and sets no timeout of its own. The wallet's credential request waits for your answer, so answer quickly or defer.
  • The provider URL must pass the outbound URL policy: HTTPS and public addresses only, unless OUTBOUND_URL_ALLOW_HTTP or OUTBOUND_URL_ALLOW_PRIVATE_NETWORK is set (both false by default since 9.0). See Webhooks.