Credential configuration reference
Fields of a credential configuration, as accepted by POST /api/issuer/credentials and by configuration import. The tables are generated from the Zod schema the backend validates with; unknown fields are rejected. For how to use the fields, see Configure a credential.
Configuration
| Field | Required | Type / allowed values | Description |
|---|---|---|---|
id | yes | string | Credential configuration identifier. |
description | no | string or null | Optional description for operators and tooling. |
config | yes | object | Issuer metadata-facing credential configuration. |
config.format | yes | string: mso_mdoc | dc+sd-jwt | Credential format emitted by this configuration. |
config.display | yes | array of object | Display metadata shown by wallets. |
config.display[].locale | yes | string | Locale tag for the display entry. |
config.display[].name | yes | string | Human-readable field name. |
config.display[].description | no | string | Optional field description for this locale. |
config.display[].background_color | no | string | Optional background color for card-style rendering. |
config.display[].text_color | no | string | Optional text color for card-style rendering. |
config.display[].background_image | no | object | Optional background image. |
config.display[].background_image.uri | yes | string | Image URI. |
config.display[].logo | no | object | Optional logo image. |
config.display[].logo.uri | yes | string | Image URI. |
config.scope | no | string | Optional OAuth scope associated with this credential type. |
config.docType | no | string | Optional mDoc document type. |
config.keyAttestationsRequired | no | object | Optional key attestation requirements. |
config.keyAttestationsRequired.key_storage | no | array of string | Required key storage attestations. |
config.keyAttestationsRequired.user_authentication | no | array of string | Required user authentication attestations. |
config.proofTypesSupported | no | array of string: jwt | attestation | Supported proof types for issuance requests. |
config.credentialReusePolicy | no | object | Optional PID/EAA reuse policy published in credential metadata. |
config.credentialReusePolicy.id | yes | string | |
config.credentialReusePolicy.options | no | array of object | |
config.credentialReusePolicy.options[].details | yes | array of string: once_only | limited_time | limited-time | rotating-batch | per-relying-party | |
config.credentialReusePolicy.options[].batch_size | no | integer (minimum 2) | |
config.credentialReusePolicy.options[].reissue_trigger_unused | no | integer (minimum 0) | |
config.credentialReusePolicy.options[].reissue_trigger_lifetime_left | no | integer (minimum 0) | |
fields | yes | array of any | Claim field definitions for credential issuance. |
attributeProviderId | no | string or null | Optional attribute provider id used to resolve claim values. |
webhookEndpointId | no | string or null | Optional webhook endpoint id notified during issuance events. |
vct | no | one of 2 shapes or null | Optional VCT value or structured VCT metadata. |
vct.vct | no | string | Only in shape 1 of 2. VCT identifier. |
vct.name | no | string | Only in shape 1 of 2. Human-readable VCT name. |
vct.description | no | string | Only in shape 1 of 2. Optional VCT description. |
vct.extends | no | string | Only in shape 1 of 2. Optional base VCT reference. |
vct.extends#integrity | no | string | Only in shape 1 of 2. Integrity hash for the extends reference. |
vct.schema_uri | no | string | Only in shape 1 of 2. Optional schema URI for the VCT. |
vct.schema_uri#integrity | no | string | Only in shape 1 of 2. Integrity hash for schema_uri. |
keyBinding | no | boolean | Enable key binding requirements. |
keyChainId | no | string | Optional key chain id used for credential signing. |
statusManagement | no | boolean | Enable status management for issued credentials. |
activeCredentials | no | object or null | Optional issuer-side policy limiting simultaneously active credentials per subject. Requires statusManagement. |
activeCredentials.enabled | yes | boolean | Ensure a subject has at most one active credential of this configuration. |
activeCredentials.tracking | no | string: internal | How the subject's active credential set is tracked. Only 'internal' (pseudonymous, issuer-side) is currently supported. |
iaeActions | no | array of one of 2 shapes or null | Optional in-app experience actions for wallet flows. |
iaeActions[].type | yes | string: redirect_to_web | Only in shape 1 of 2. Trigger a redirect-to-web action. |
iaeActions[].label | no | string | Only in shape 1 of 2. Optional UI label for the action. |
iaeActions[].url | yes | string | Only in shape 1 of 2. Destination URL for the redirect action. |
iaeActions[].callbackUrl | no | string | Only in shape 1 of 2. Optional callback URL after redirect completion. |
iaeActions[].description | no | string | Only in shape 1 of 2. Optional action description. |
iaeActions[].type | yes | string: openid4vp_presentation | Only in shape 2 of 2. Trigger an OpenID4VP presentation action. |
iaeActions[].label | no | string | Only in shape 2 of 2. Optional UI label for the action. |
iaeActions[].presentationConfigId | yes | string | Only in shape 2 of 2. Presentation configuration id to execute. |
sdJwtTrustFormat | no | string or null: x5c | federation | Trust format used for SD-JWT verification metadata. |
lifeTime | no | integer (minimum 1) | Credential lifetime in seconds. |
schemaMeta | no | object or null | Optional schema metadata and trust bindings. |
schemaMeta.id | no | string | Optional schema metadata identifier. |
schemaMeta.name | no | string | Optional schema metadata name. |
schemaMeta.version | yes | string | Schema metadata version. |
schemaMeta.rulebookURI | no | string | Optional rulebook URI reference. |
schemaMeta.attestationLoS | yes | string: iso_18045_high | iso_18045_moderate | iso_18045_enhanced-basic | iso_18045_basic | Assurance level for attestation requirements. |
schemaMeta.bindingType | yes | string: claim | key | biometric | none | Subject binding type. |
schemaMeta.schemaURIs | no | array of object | Optional schema URI entries. |
schemaMeta.schemaURIs[].credentialConfigId | no | string | Optional credential configuration id this schema URI applies to. |
schemaMeta.schemaURIs[].format | no | string | Optional credential format for this schema URI. |
schemaMeta.schemaURIs[].uri | no | string | Schema URI reference. |
schemaMeta.schemaURIs[].meta | no | object | Optional metadata attached to the schema URI. |
schemaMeta.trustedAuthorities | no | array of object | Optional trusted authority entries. |
schemaMeta.trustedAuthorities[].trustListId | no | string | Optional trust list id. |
schemaMeta.trustedAuthorities[].frameworkType | no | string: aki | etsi_tl | openid_federation | Trust framework type. |
schemaMeta.trustedAuthorities[].value | no | string | Framework-specific authority value. |
schemaMeta.trustedAuthorities[].verificationMethod | no | one of 2 shapes | Verification method descriptor. |
embeddedDisclosurePolicy | no | one of 4 shapes or null | Optional embedded disclosure policy. |
embeddedDisclosurePolicy.policy | yes | string: attestationBased | Only in shape 1 of 4. Attestation-based policy discriminator. |
embeddedDisclosurePolicy.values | yes | array of object | Only in shape 1 of 4. Attestation requirements used for policy enforcement. |
embeddedDisclosurePolicy.values[].claims | no | array of any | Only in shape 1 of 4. Claims constraints considered by policy evaluation. |
embeddedDisclosurePolicy.values[].credentials | yes | array of any | Only in shape 1 of 4. Credential constraints considered by policy evaluation. |
embeddedDisclosurePolicy.values[].credential_sets | no | array of any | Only in shape 1 of 4. Optional credential set constraints. |
embeddedDisclosurePolicy.policy | yes | string: allowList | Only in shape 2 of 4. Allow-list based policy discriminator. |
embeddedDisclosurePolicy.values | yes | array of string | Only in shape 2 of 4. Allowed values for policy checks. |
embeddedDisclosurePolicy.policy | yes | string: rootOfTrust | Only in shape 3 of 4. Root-of-trust policy discriminator. |
embeddedDisclosurePolicy.values | yes | string | Only in shape 3 of 4. Root-of-trust identifier or reference. |
embeddedDisclosurePolicy.policy | yes | string: none | Only in shape 4 of 4. No disclosure policy enforcement. |
Notes on fields whose generated description is incomplete:
| Field | Note |
|---|---|
config.display[].name, .locale, .description | Name, locale and description of the credential (the schema shares these descriptions with claim display entries). |
config.scope | Published as scope in the issuer metadata only. EUDIPLO does not map OAuth scopes to credential configurations; wallets select credentials with authorization_details. |
config.proofTypesSupported | Defaults to both jwt and attestation. |
config.credentialReusePolicy.options[] | batch_size (minimum 2) is required for once_only, rotating-batch and per-relying-party. reissue_trigger_unused is required for once_only and must be lower than batch_size. reissue_trigger_lifetime_left (seconds) is required for limited_time, rotating-batch and per-relying-party. options is required when id is arf_annex_ii. See Reuse policy. |
webhookEndpointId | Stored with the configuration but not used. Notifications use the webhookEndpointId of the credential offer. |
iaeActions | Actions of the Interactive Authorization Endpoint. |
activeCredentials | Rejected unless statusManagement is true. See Single active credential. |
sdJwtTrustFormat | x5c (default) or federation. See OpenID Federation. |
schemaMeta | See Schema metadata. |
Claim field (fields[])
Each entry of fields describes one claim. children holds nested entries with the same shape.
| Field | Required | Type / allowed values | Description |
|---|---|---|---|
path | yes | array of string | number or null | Path to this claim inside the credential payload. |
type | yes | string: string | number | integer | boolean | object | array | Data type of the claim value. |
defaultValue | no | any | Optional default value for this field. |
mandatory | no | boolean | Whether the field is required at issuance time. |
disclosable | no | boolean | Whether the claim is selectively disclosable. |
namespace | no | string | Optional namespace for claim grouping. |
display | no | array of object | Localized display metadata for this field. |
display[].locale | yes | string | Locale tag for the display entry. |
display[].name | yes | string | Human-readable field name. |
display[].description | no | string | Optional field description for this locale. |
constraints | no | object | Optional validation constraints for the claim value. |
children | no | array of any | Nested child claim definitions for object or array fields. |
Defaults that are not part of the schema: mandatory and disclosable are false when omitted. namespace (mDOC only) defaults to the first path segment of a nested path, otherwise to the document type (org.iso.18013.5.1 for org.iso.18013.5.1.mDL). In path, null stands for every element of an array.
Example
{
"id": "membership",
"description": "Membership card",
"config": {
"format": "dc+sd-jwt",
"display": [
{
"name": "Membership",
"locale": "en-US",
"background_color": "#12107c",
"text_color": "#FFFFFF",
"logo": { "uri": "https://issuer.example.com/logo.png" }
}
]
},
"vct": "urn:example:membership:1",
"keyBinding": true,
"statusManagement": true,
"lifeTime": 31536000,
"fields": [
{
"path": ["name"],
"type": "string",
"mandatory": true,
"disclosable": true,
"display": [{ "locale": "en-US", "name": "Name" }]
},
{
"path": ["member_id"],
"type": "string",
"mandatory": true,
"disclosable": true,
"display": [{ "locale": "en-US", "name": "Member ID" }]
}
]
}