Presentation Configuration
Fields of a presentation configuration, as accepted by POST /api/verifier/config and in config/<tenant>/presentation/<id>.json. PATCH /api/verifier/config/{id} accepts the same fields, all optional. For the task-oriented guide see Configure Verification.
Fields
The table is generated at build time from the Zod schema the backend validates with. The schema is strict: unknown fields are rejected. dcql_query.credentials[] has one shape per format (mso_mdoc and dc+sd-jwt).
| Field | Required | Type / allowed values | Description |
|---|---|---|---|
id | yes | string | Presentation configuration identifier. |
description | no | string or null | Optional presentation configuration description. |
lifeTime | no | integer (minimum 1) | Presentation request lifetime in seconds. |
skewSeconds | no | integer (minimum 0) | Clock skew tolerance in seconds. |
statusCheckMode | no | string: strict | best_effort | disabled | Revocation/status check mode. |
dcql_query | yes | object | DCQL query defining requested credentials and claims. |
dcql_query.credentials | yes | array of one of 2 shapes | Credential queries requested by the verifier. |
dcql_query.credentials[].id | yes | string | Only in shape 1 of 2. Credential query identifier. |
dcql_query.credentials[].multiple | no | boolean | Only in shape 1 of 2. Allow multiple matching credentials. |
dcql_query.credentials[].claim_sets | no | array of array of string | Only in shape 1 of 2. Optional claim set constraints. |
dcql_query.credentials[].trusted_authorities | no | array of one of 2 shapes | Only in shape 1 of 2. Optional trusted authority constraints. |
dcql_query.credentials[].trusted_authorities[].type | yes | string: etsi_tl | Only in shape 1 of 2. Trusted authority type discriminator for ETSI trust lists. |
dcql_query.credentials[].trusted_authorities[].values | yes | array of object | Only in shape 1 of 2. Trust list references for ETSI TL verification. |
dcql_query.credentials[].trusted_authorities[].values[].trustListId | no | string | Only in shape 1 of 2. Optional trust list id reference. |
dcql_query.credentials[].trusted_authorities[].values[].url | no | string | Only in shape 1 of 2. Optional trust list URL reference. |
dcql_query.credentials[].trusted_authorities[].values[].verifierKey | no | object | Only in shape 1 of 2. Optional verifier key material. |
dcql_query.credentials[].trusted_authorities[].values[].verifierX509Der | no | string | Only in shape 1 of 2. Optional verifier certificate in DER/base64 form. |
dcql_query.credentials[].trusted_authorities[].type | yes | string: openid_federation | Only in shape 2 of 2. Trusted authority type discriminator for OpenID Federation. |
dcql_query.credentials[].trusted_authorities[].values | yes | array of string | Only in shape 2 of 2. OpenID Federation authority identifiers. |
dcql_query.credentials[].format | yes | string: mso_mdoc | Only in shape 1 of 2. Credential format discriminator. |
dcql_query.credentials[].meta | yes | object | Only in shape 1 of 2. |
dcql_query.credentials[].meta.doctype_value | yes | string | Only in shape 1 of 2. Expected mDoc doctype value. |
dcql_query.credentials[].claims | no | array of object | Only in shape 1 of 2. Optional mDoc claim-level constraints. |
dcql_query.credentials[].claims[].id | no | string | Only in shape 1 of 2. Optional claim query id. |
dcql_query.credentials[].claims[].path | yes | array of string | number | Only in shape 1 of 2. Path to the claim value in presented credentials. |
dcql_query.credentials[].claims[].values | no | array of one of 3 shapes | Only in shape 1 of 2. Optional allowed values for the claim. A disclosed value must equal one of them in type and value. |
dcql_query.credentials[].claims[].intent_to_retain | no | boolean | Only in shape 1 of 2. Whether relying party intends to retain the claim. |
dcql_query.credentials[].id | yes | string | Only in shape 2 of 2. Credential query identifier. |
dcql_query.credentials[].multiple | no | boolean | Only in shape 2 of 2. Allow multiple matching credentials. |
dcql_query.credentials[].claim_sets | no | array of array of string | Only in shape 2 of 2. Optional claim set constraints. |
dcql_query.credentials[].trusted_authorities | no | array of one of 2 shapes | Only in shape 2 of 2. Optional trusted authority constraints. |
dcql_query.credentials[].trusted_authorities[].type | yes | string: etsi_tl | Only in shape 1 of 2. Trusted authority type discriminator for ETSI trust lists. |
dcql_query.credentials[].trusted_authorities[].values | yes | array of object | Only in shape 1 of 2. Trust list references for ETSI TL verification. |
dcql_query.credentials[].trusted_authorities[].values[].trustListId | no | string | Only in shape 1 of 2. Optional trust list id reference. |
dcql_query.credentials[].trusted_authorities[].values[].url | no | string | Only in shape 1 of 2. Optional trust list URL reference. |
dcql_query.credentials[].trusted_authorities[].values[].verifierKey | no | object | Only in shape 1 of 2. Optional verifier key material. |
dcql_query.credentials[].trusted_authorities[].values[].verifierX509Der | no | string | Only in shape 1 of 2. Optional verifier certificate in DER/base64 form. |
dcql_query.credentials[].trusted_authorities[].type | yes | string: openid_federation | Only in shape 2 of 2. Trusted authority type discriminator for OpenID Federation. |
dcql_query.credentials[].trusted_authorities[].values | yes | array of string | Only in shape 2 of 2. OpenID Federation authority identifiers. |
dcql_query.credentials[].format | yes | string: dc+sd-jwt | Only in shape 2 of 2. Credential format discriminator. |
dcql_query.credentials[].meta | yes | object | Only in shape 2 of 2. |
dcql_query.credentials[].meta.vct_values | yes | array of string | Only in shape 2 of 2. Accepted VCT values. |
dcql_query.credentials[].claims | no | array of object | Only in shape 2 of 2. Optional claim-level constraints. |
dcql_query.credentials[].claims[].id | no | string | Only in shape 2 of 2. Optional claim query id. |
dcql_query.credentials[].claims[].path | yes | array of string | number | Only in shape 2 of 2. Path to the claim value in presented credentials. |
dcql_query.credentials[].claims[].values | no | array of one of 3 shapes | Only in shape 2 of 2. Optional allowed values for the claim. A disclosed value must equal one of them in type and value. |
dcql_query.credential_sets | no | array of object | Optional higher-level credential set requirements. |
dcql_query.credential_sets[].options | yes | array of array of string | Alternative credential query id combinations. |
dcql_query.credential_sets[].required | no | boolean | Whether this credential set is mandatory. |
transaction_data | no | array of object or null | Optional transaction data descriptors. |
transaction_data[].type | yes | string | Transaction data type identifier. |
transaction_data[].credential_ids | yes | array of string | Credential query ids this transaction data applies to. |
transaction_data[].payload | no | any | Transaction details. Required for TS12 SCA transaction data. |
registration_cert | no | object or null | Optional registration certificate request settings. |
registration_cert.id | no | string | |
registration_cert.body | no | object | |
registration_cert.body.privacy_policy | no | string | |
registration_cert.body.support_uri | no | string | |
registration_cert.body.intermediary | no | string | |
registration_cert.body.purpose | no | array of object | |
registration_cert.body.purpose[].lang | yes | string | |
registration_cert.body.purpose[].content | yes | string | |
registration_cert.body.credentials | no | array of object | |
registration_cert.body.provides_attestations | no | array of string | |
registration_cert.jwt | no | string | |
registrationCertImportJwt | no | string or null | Optional imported registration certificate JWT. |
registrationCertImportId | no | string or null | Optional registrar-side registration certificate id. |
registrationCertBodyPrivacyPolicy | no | string or null | Optional registration certificate privacy policy URI. |
registrationCertBodySupportUri | no | string or null | Optional registration certificate support URI. |
registrationCertBodyIntermediary | no | string or null | Optional registration certificate intermediary. |
registrationCertBodyPurpose | no | array of object or null | Optional registration certificate purpose entries. |
registrationCertBodyPurpose[].lang | no | string | |
registrationCertBodyPurpose[].content | no | string | |
webhookEndpointId | no | string or null | Optional webhook endpoint id for presentation callbacks. |
attached | no | array of object or null | Optional attachments included with presentation requests. |
attached[].format | yes | string | Attachment format identifier. |
attached[].data | yes | any | Attachment payload. |
attached[].credential_ids | no | array of string | Optional credential query ids bound to this attachment. |
redirectUri | no | string or null | Optional redirect URI after presentation completion. |
accessKeyChainId | no | string or null | Optional key chain id for access token/auth operations. |
readerAuth | no | boolean or null | Whether reader authentication is required for mDoc requests. |
Defaults and behavior
| Field | Default and behavior |
|---|---|
id | Used as requestId in presentation requests. |
description | Internal only; not shown to the wallet user. |
lifeTime | 300. Seconds until a request created from this configuration expires (expiresAt of the session). |
skewSeconds | 60. Clock skew tolerance for credential time checks; a request can override it. |
statusCheckMode | strict: status lists are checked and verification fails if a status list cannot be fetched or validated. best_effort: verification continues without the status result when the status list is unavailable. disabled: no status check. Applies to SD-JWT VC and mDOC, including ISO 18013-7. |
dcql_query | See DCQL. <TENANT_URL> anywhere in the query is replaced with <PUBLIC_URL>/issuers/<tenant>. |
transaction_data | Sent with every request unless the request sets its own transaction_data. Ignored for ISO 18013-7. See Transaction Data. |
registration_cert | Strategies jwt, id, body. Only attached when the tenant has a registrar configuration. See Registration Certificates. |
registrationCert* | Flat form fields used by the Web Client. They are converted into registration_cert (only when registration_cert is not sent) and are not stored. |
webhookEndpointId | ID of a webhook endpoint that receives results. A request can override it with an inline webhook. |
attached | Stored with the configuration; currently not sent to the wallet. |
redirectUri | Same-device redirect target. {sessionId} is replaced with the session ID. A request can override it, except for ISO 18013-7. See Receive Results. |
accessKeyChainId | Access key chain that signs the request, determines the client_id and signs readerAuth. Without it, EUDIPLO uses an access key chain of the tenant; set it when the tenant has several. |
readerAuth | false. ISO 18013-7 only: sign the DeviceRequest with the access key chain. Requires the db KMS provider for that key. |
Validation rules
Rules that the table cannot show:
dcql_query.credentialsneeds at least one entry; credential query IDs contain only letters, digits,_and-, and are unique.metais required:vct_values(at least one) fordc+sd-jwt,doctype_valueformso_mdoc.- Every ID in
claim_setsmust reference theidof a claim in the same credential query; claim IDs are unique. transaction_dataentries whosetypestarts withurn:eudi:sca:must be a supported TS12 type with a valid payload.
Server-managed fields
Responses also contain createdAt, updatedAt and registrationCertCache (the registration certificate EUDIPLO resolved, with fingerprints and expiry). They are read-only and not part of the schema, so the API rejects them in a request body. EUDIPLO clears the cache when registration_cert or dcql_query changes and refreshes it in the background. To force a new certificate, call POST /api/verifier/config/{id}/registration-cert/reissue.