Skip to main content

Credential configuration reference

Fields of a credential configuration, as accepted by POST /api/issuer/credentials and by configuration import. The tables are generated from the Zod schema the backend validates with; unknown fields are rejected. For how to use the fields, see Configure a credential.

Configuration​

FieldRequiredType / allowed valuesDescription
idyesstringCredential configuration identifier.
descriptionnostring or nullOptional description for operators and tooling.
configyesobjectIssuer metadata-facing credential configuration.
config.formatyesstring: mso_mdoc | dc+sd-jwtCredential format emitted by this configuration.
config.displayyesarray of objectDisplay metadata shown by wallets.
config.display[].localeyesstringLocale tag for the display entry.
config.display[].nameyesstringHuman-readable field name.
config.display[].descriptionnostringOptional field description for this locale.
config.display[].background_colornostringOptional background color for card-style rendering.
config.display[].text_colornostringOptional text color for card-style rendering.
config.display[].background_imagenoobjectOptional background image.
config.display[].background_image.uriyesstringImage URI.
config.display[].logonoobjectOptional logo image.
config.display[].logo.uriyesstringImage URI.
config.scopenostringOptional OAuth scope associated with this credential type.
config.docTypenostringOptional mDoc document type.
config.keyAttestationsRequirednoobjectOptional key attestation requirements.
config.keyAttestationsRequired.key_storagenoarray of stringRequired key storage attestations.
config.keyAttestationsRequired.user_authenticationnoarray of stringRequired user authentication attestations.
config.proofTypesSupportednoarray of string: jwt | attestationSupported proof types for issuance requests.
config.credentialReusePolicynoobjectOptional PID/EAA reuse policy published in credential metadata.
config.credentialReusePolicy.idyesstring
config.credentialReusePolicy.optionsnoarray of object
config.credentialReusePolicy.options[].detailsyesarray of string: once_only | limited_time | limited-time | rotating-batch | per-relying-party
config.credentialReusePolicy.options[].batch_sizenointeger (minimum 2)
config.credentialReusePolicy.options[].reissue_trigger_unusednointeger (minimum 0)
config.credentialReusePolicy.options[].reissue_trigger_lifetime_leftnointeger (minimum 0)
fieldsyesarray of anyClaim field definitions for credential issuance.
attributeProviderIdnostring or nullOptional attribute provider id used to resolve claim values.
webhookEndpointIdnostring or nullOptional webhook endpoint id notified during issuance events.
vctnoone of 2 shapes or nullOptional VCT value or structured VCT metadata.
vct.vctnostringOnly in shape 1 of 2. VCT identifier.
vct.namenostringOnly in shape 1 of 2. Human-readable VCT name.
vct.descriptionnostringOnly in shape 1 of 2. Optional VCT description.
vct.extendsnostringOnly in shape 1 of 2. Optional base VCT reference.
vct.extends#integritynostringOnly in shape 1 of 2. Integrity hash for the extends reference.
vct.schema_urinostringOnly in shape 1 of 2. Optional schema URI for the VCT.
vct.schema_uri#integritynostringOnly in shape 1 of 2. Integrity hash for schema_uri.
keyBindingnobooleanEnable key binding requirements.
keyChainIdnostringOptional key chain id used for credential signing.
statusManagementnobooleanEnable status management for issued credentials.
activeCredentialsnoobject or nullOptional issuer-side policy limiting simultaneously active credentials per subject. Requires statusManagement.
activeCredentials.enabledyesbooleanEnsure a subject has at most one active credential of this configuration.
activeCredentials.trackingnostring: internalHow the subject's active credential set is tracked. Only 'internal' (pseudonymous, issuer-side) is currently supported.
iaeActionsnoarray of one of 2 shapes or nullOptional in-app experience actions for wallet flows.
iaeActions[].typeyesstring: redirect_to_webOnly in shape 1 of 2. Trigger a redirect-to-web action.
iaeActions[].labelnostringOnly in shape 1 of 2. Optional UI label for the action.
iaeActions[].urlyesstringOnly in shape 1 of 2. Destination URL for the redirect action.
iaeActions[].callbackUrlnostringOnly in shape 1 of 2. Optional callback URL after redirect completion.
iaeActions[].descriptionnostringOnly in shape 1 of 2. Optional action description.
iaeActions[].typeyesstring: openid4vp_presentationOnly in shape 2 of 2. Trigger an OpenID4VP presentation action.
iaeActions[].labelnostringOnly in shape 2 of 2. Optional UI label for the action.
iaeActions[].presentationConfigIdyesstringOnly in shape 2 of 2. Presentation configuration id to execute.
sdJwtTrustFormatnostring or null: x5c | federationTrust format used for SD-JWT verification metadata.
lifeTimenointeger (minimum 1)Credential lifetime in seconds.
schemaMetanoobject or nullOptional schema metadata and trust bindings.
schemaMeta.idnostringOptional schema metadata identifier.
schemaMeta.namenostringOptional schema metadata name.
schemaMeta.versionyesstringSchema metadata version.
schemaMeta.rulebookURInostringOptional rulebook URI reference.
schemaMeta.attestationLoSyesstring: iso_18045_high | iso_18045_moderate | iso_18045_enhanced-basic | iso_18045_basicAssurance level for attestation requirements.
schemaMeta.bindingTypeyesstring: claim | key | biometric | noneSubject binding type.
schemaMeta.schemaURIsnoarray of objectOptional schema URI entries.
schemaMeta.schemaURIs[].credentialConfigIdnostringOptional credential configuration id this schema URI applies to.
schemaMeta.schemaURIs[].formatnostringOptional credential format for this schema URI.
schemaMeta.schemaURIs[].urinostringSchema URI reference.
schemaMeta.schemaURIs[].metanoobjectOptional metadata attached to the schema URI.
schemaMeta.trustedAuthoritiesnoarray of objectOptional trusted authority entries.
schemaMeta.trustedAuthorities[].trustListIdnostringOptional trust list id.
schemaMeta.trustedAuthorities[].frameworkTypenostring: aki | etsi_tl | openid_federationTrust framework type.
schemaMeta.trustedAuthorities[].valuenostringFramework-specific authority value.
schemaMeta.trustedAuthorities[].verificationMethodnoone of 2 shapesVerification method descriptor.
embeddedDisclosurePolicynoone of 4 shapes or nullOptional embedded disclosure policy.
embeddedDisclosurePolicy.policyyesstring: attestationBasedOnly in shape 1 of 4. Attestation-based policy discriminator.
embeddedDisclosurePolicy.valuesyesarray of objectOnly in shape 1 of 4. Attestation requirements used for policy enforcement.
embeddedDisclosurePolicy.values[].claimsnoarray of anyOnly in shape 1 of 4. Claims constraints considered by policy evaluation.
embeddedDisclosurePolicy.values[].credentialsyesarray of anyOnly in shape 1 of 4. Credential constraints considered by policy evaluation.
embeddedDisclosurePolicy.values[].credential_setsnoarray of anyOnly in shape 1 of 4. Optional credential set constraints.
embeddedDisclosurePolicy.policyyesstring: allowListOnly in shape 2 of 4. Allow-list based policy discriminator.
embeddedDisclosurePolicy.valuesyesarray of stringOnly in shape 2 of 4. Allowed values for policy checks.
embeddedDisclosurePolicy.policyyesstring: rootOfTrustOnly in shape 3 of 4. Root-of-trust policy discriminator.
embeddedDisclosurePolicy.valuesyesstringOnly in shape 3 of 4. Root-of-trust identifier or reference.
embeddedDisclosurePolicy.policyyesstring: noneOnly in shape 4 of 4. No disclosure policy enforcement.

Notes on fields whose generated description is incomplete:

FieldNote
config.display[].name, .locale, .descriptionName, locale and description of the credential (the schema shares these descriptions with claim display entries).
config.scopePublished as scope in the issuer metadata only. EUDIPLO does not map OAuth scopes to credential configurations; wallets select credentials with authorization_details.
config.proofTypesSupportedDefaults to both jwt and attestation.
config.credentialReusePolicy.options[]batch_size (minimum 2) is required for once_only, rotating-batch and per-relying-party. reissue_trigger_unused is required for once_only and must be lower than batch_size. reissue_trigger_lifetime_left (seconds) is required for limited_time, rotating-batch and per-relying-party. options is required when id is arf_annex_ii. See Reuse policy.
webhookEndpointIdStored with the configuration but not used. Notifications use the webhookEndpointId of the credential offer.
iaeActionsActions of the Interactive Authorization Endpoint.
activeCredentialsRejected unless statusManagement is true. See Single active credential.
sdJwtTrustFormatx5c (default) or federation. See OpenID Federation.
schemaMetaSee Schema metadata.

Claim field (fields[])​

Each entry of fields describes one claim. children holds nested entries with the same shape.

FieldRequiredType / allowed valuesDescription
pathyesarray of string | number or nullPath to this claim inside the credential payload.
typeyesstring: string | number | integer | boolean | object | arrayData type of the claim value.
defaultValuenoanyOptional default value for this field.
mandatorynobooleanWhether the field is required at issuance time.
disclosablenobooleanWhether the claim is selectively disclosable.
namespacenostringOptional namespace for claim grouping.
displaynoarray of objectLocalized display metadata for this field.
display[].localeyesstringLocale tag for the display entry.
display[].nameyesstringHuman-readable field name.
display[].descriptionnostringOptional field description for this locale.
constraintsnoobjectOptional validation constraints for the claim value.
childrennoarray of anyNested child claim definitions for object or array fields.

Defaults that are not part of the schema: mandatory and disclosable are false when omitted. namespace (mDOC only) defaults to the first path segment of a nested path, otherwise to the document type (org.iso.18013.5.1 for org.iso.18013.5.1.mDL). In path, null stands for every element of an array.

Example​

{
"id": "membership",
"description": "Membership card",
"config": {
"format": "dc+sd-jwt",
"display": [
{
"name": "Membership",
"locale": "en-US",
"background_color": "#12107c",
"text_color": "#FFFFFF",
"logo": { "uri": "https://issuer.example.com/logo.png" }
}
]
},
"vct": "urn:example:membership:1",
"keyBinding": true,
"statusManagement": true,
"lifeTime": 31536000,
"fields": [
{
"path": ["name"],
"type": "string",
"mandatory": true,
"disclosable": true,
"display": [{ "locale": "en-US", "name": "Name" }]
},
{
"path": ["member_id"],
"type": "string",
"mandatory": true,
"disclosable": true,
"display": [{ "locale": "en-US", "name": "Member ID" }]
}
]
}